FrostyGoop

MITRE ATT&CK: S1165 View on attack.mitre.org

Aliases: BUSTLEBERM

Malware type
trojan
Family
Malware family
Operating systems
control-server, field-controller/rtu/plc/ied
Profile updated
2026-07-07 15:02:07

Targeted industries: energy-and-utilities

Targeted regions: country_code:ua

Context

FrostyGoop is a Windows-based binary written in Golang that allows for interaction with industrial control system (ICS) equipment via Modbus TCP over port 502. FrostyGoop allows for reading and writing data to holding registers on targeted devices, manipulating the operation of systems for malicious purposes. FrostyGoop is associated with the FrostyGoop Incident in Ukraine.

Detection coverage

  • 1 YARA rules

Malware & tools used

  • Modify Parameter (attack-pattern)
  • Monitor Process State (attack-pattern)
  • Standard Application Layer Protocol (attack-pattern)
  • Commonly Used Port (attack-pattern)
  • Command-Line Interface (attack-pattern)

Used by threat actors

  • FrostyGoop Incident (campaign)

Detection rules

  • SIGNATURE_BASE_MAL_Go_Modbus_Jul24_1 (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Frostygoop (report)
  • dragos.com — Protect Against Frostygoop Ics Malware Targeting Operational Technology (report)
  • Palo Alto Unit 42 — Frostygoop Malware Analysis (report)

External references