NEWS

  • HOME PAGE
  • Bitcoin News
  • FOOT news
  • Kpop News
  • SPORTS
  • Bitcoin News
  • Tech News
  • Forum

Hackers shut down heating in Ukrainian city with malware, researchers say

23rd July 2024 by admin

  • Texas pushes three-loss playoff debate to next level with third top-10 victory against Texas A&M
  • “Squid Game” Actor Admits Co-star Burst Into Tears After Filming Explicit Scene With Him
  • The Progression of Cam Ward

  • For two days in mid-January, some Ukrainians in the city of Lviv had to live without central heating and suffer freezing temperatures because of a cyberattack against a municipal energy company, security researchers and Ukrainian authorities have since concluded. 

    On Tuesday, the cybersecurity company Dragos published a report with details about a new malware dubbed FrostyGoop, which the company says is designed to target industrial control systems — in this particular case, specifically against a type of heating system controller. 

    Dragos researchers wrote in their report that they first detected the malware in April. At that point, Dragos did not have more information on FrostyGoop apart from the malware sample, and believed it was only used for testing. Later on, however, Ukrainian authorities warned Dragos that they had found evidence that the malware was actively used in a cyberattack in Lviv during the late evening of January 22 through January 23. 

    “And that resulted in the loss of heating to over 600 apartment buildings for almost 48 hours,” said Magpie Graham, a researcher at Dragos, during a call with reporters briefed on the report prior to its release.

    Dragos researchers Graham, Kyle O’Meara, and Carolyn Ahlers wrote in the report that “remediation of the incident took almost two days, during which time the civilian population had to endure sub-zero temperatures.”

    This is the third known outage linked to cyberattacks to hit Ukrainians in recent years. While the researchers said the malware was unlikely to cause widespread outages, it shows an increased effort by malicious hackers to target critical infrastructure, like energy grids.

    The FrostyGoop malware is designed to interact with industrial control devices (ICS) over Modbus, a decades-old protocol widely used across the world to control devices in industrial environments, meaning FrostyGoop could be used to target other companies and facilities anywhere, according to Dragos. 

    “There’s at least 46,000 Internet exposed ICS devices that allow Modbus today,” Graham told reporters. 

    Dragos said that FrostyGoop is the ninth ICS-specific malware it has encountered over the years. The most famous of these are Industroyer (also known as CrashOverride), which was used by the infamous Russian-government linked hacking group Sandworm to turn off the lights in Kyiv and later to disconnect electrical substations in Ukraine. Outside of those cyberattacks targeting Ukraine, Dragos has also seen Triton, which was deployed against a Saudi petrochemical plant and against an unknown second facility later on; and the CosmicEnergy malware, which was discovered by Mandiant last year.

    Contact Us

    Do you have more information about this cyberattack? Or similar attacks targeting ICS in Ukraine and beyond? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

    Dragos researchers wrote that they believe that the hackers in control of the FrostyGoop malware first gained access to the targeted municipal energy company’s network by exploiting a vulnerability in an internet-exposed Mikrotik router. The researchers said the router was not “adequately segmented” along with other servers and controllers, including one made by ENCO, a Chinese company.

    Graham said in the call that they found open ENCO controllers in Lithuania, Ukraine, and  Romania, underscoring once again that while FrostyGoop was used in a targeted attack in Lviv this time, the hackers in control could target the malware elsewhere. 

    ENCO and its employees did not immediately respond to TechCrunch’s request for comment.

    “The adversaries did not attempt to destroy the controllers. Instead, the adversaries caused the controllers to report inaccurate measurements, resulting in the incorrect operation of the system and the loss of heating to customers,” the researchers wrote.

    During the investigation, the researchers said they concluded that the hackers “possibly gained access” to the targeted network in April 2023, almost a year before deploying the malware and turning off the heat. In the following months, the hackers kept accessing the network and on January 22, 2024, connected to through Moscow-based IP addresses, according to the report.

    Despite the Russian IP addresses, Dragos didn’t point the finger at any known particular hacking group or government as responsible for this cyber-enabled outage, because the company couldn’t find ties to previous activities or tools, and because of the company’s longstanding policy on not attributing cyberattacks, said Graham.  

    What Graham did say is that he and his colleagues believe this disruptive operation was conducted over the internet — as opposed to launching missiles at the facility — likely as an effort to undermine the morale of Ukrainians living there.

    “I think it’s very much a psychological effort here, facilitated through cyber means when kinetic perhaps here wasn’t the best choice,” said Graham.

    Finally, Dragos’ field chief technology officer Phil Tonking said that while it’s important not to underplay FrostyGoop, it’s also important not to overhype it.

    “It’s important to recognize that whilst this is something that has been actively used,” he said during the call with the press, “it’s also very, very important that we don’t think that this is something that is immediately going to bring down the nation’s power grid.”

    Related

    Lucid Motors sets record as Gravity sales pick up and tax credit expires Lucid Motors sets record as Gravity sales pick up and tax credit expires
    Lucid Motors sets record as Gravity sales pick up and tax credit expires Lucid Motors sets record as Gravity sales pick up and tax credit expires
    Lucid Motors sets record as Gravity sales pick up and tax credit expires Lucid Motors sets record as Gravity sales pick up and tax credit expires
    Microsoft buys another 100 MW of solar, this time in Japan Microsoft buys another 100 MW of solar, this time in Japan
    Microsoft buys another 100 MW of solar, this time in Japan Microsoft buys another 100 MW of solar, this time in Japan
    OpenAI ramps up developer push with more powerful models in its API  OpenAI ramps up developer push with more powerful models in its API 
    OpenAI launches AgentKit to help developers build and ship AI agents  OpenAI launches AgentKit to help developers build and ship AI agents 
    Okosix will show its biodegradable plastic at TechCrunch Disrupt 2025 Okosix will show its biodegradable plastic at TechCrunch Disrupt 2025

    Filed Under: Tech News Tagged With: “Plastic, 2025, biodegradable, Disrupt, Okosix, Show, TechCrunch

    eNews Extended

    Enter your Email to receive the latest promotional information from the Website

    Featured Post

    Texas pushes three-loss playoff debate to next level with third top-10 victory against Texas A&M Texas pushes three-loss playoff debate to next level with third top-10 victory against Texas A&M
    The Progression of Cam Ward The Progression of Cam Ward
    The Progression of Cam Ward The Progression of Cam Ward
    The Progression of Cam Ward The Progression of Cam Ward
    Glenville vs. Indian Valley live score, updates, highlights from OHSAA D-IV state semifinal game Glenville vs. Indian Valley live score, updates, highlights from OHSAA D-IV state semifinal game
    Avon vs. Walsh Jesuit live score, updates, highlights from OHSAA D-II state semifinal game Avon vs. Walsh Jesuit live score, updates, highlights from OHSAA D-II state semifinal game

    Laptop

    44.990.000đ
    Laptop LG Gram 2022 17Z90Q-G.AH76A5 (Core-i7 1260P/16GB/512GB/17″ WQXGA/Win 11/Xám)
    24.790.000đ
    Laptop LG Gram 2021 16ZD90P-G.AX54A5 (i5-1135G7/8GB RAM/512GB SSD/16″WQXGA/Dos/Trắng)
    14.590.000đ
    Laptop Acer Gaming Aspire 7 A715-42G-R4ST NH.QAYSV.004 (R5 5500U/8GB RAM/256GB SSD/15.6″FHD IPS/GTX1650 4GB/Win10) – Hàng chính hãng
    15.190.000đ
    Laptop Acer Aspire 3 A315-58G-50S4 (Core i5 1135G7/8GB RAM/512GB/15.6″FHD/MX350 2GB/Win 10/Bạc)
    21.990.000đ
    Laptop Acer Swift 5 SF514-55TA-59N4 NX.A6SSV.001 (i5-1135G7/16GB RAM/1TB SSD/14″FHD_Touch/Win10/Xanh) – Hàng chính hãng
    14.890.000đ
    Laptop Acer Aspire 5 A514-54-59QK (Core i5 1135G7/8GB RAM/512GB/14″FHD/Win 11/Vàng)

    Tech news

    Lucid Motors sets record as Gravity sales pick up and tax credit expires Lucid Motors sets record as Gravity sales pick up and tax credit expires
    Lucid Motors sets record as Gravity sales pick up and tax credit expires Lucid Motors sets record as Gravity sales pick up and tax credit expires
    Lucid Motors sets record as Gravity sales pick up and tax credit expires Lucid Motors sets record as Gravity sales pick up and tax credit expires
    Microsoft buys another 100 MW of solar, this time in Japan Microsoft buys another 100 MW of solar, this time in Japan
    Microsoft buys another 100 MW of solar, this time in Japan Microsoft buys another 100 MW of solar, this time in Japan
    OpenAI ramps up developer push with more powerful models in its API  OpenAI ramps up developer push with more powerful models in its API 

    Fashion

    299.000đ
    QUẦN JEAN ỐNG RỘNG CẠP CAO, DÀI XẺ GẤU PHONG CÁCH J6
    99.000đ
    ÁO KHOÁC CARDIGAN MẶT CƯỜI NỮ CHẤT NỈ COTTON
    150.000đ
    ÁO KHOÁC HOODIE NAM NỮ PHỐI THEO PHONG CÁCH HÀN QUỐC FORM RỘNG HÌNH THÊU SIÊU ĐẸP CỰC CHẤT LƯỢNG HÀNG HOT TREND
    148.000đ
    QUẦN DÀI NỮ SUÔNG KẺ CARO
    148.000đ
    SET ĐẦM MẶC HAI KIỂU KÈM BÔNG CỔ MOCKING THÂN SAU(CÓ MÚT) MD126
    49.000đ
    ÁO THUN NỮ, ÁO PHÔNG UNISEX COTTON SU MÁT MẺ EDIE BAUER

    Recent post

    • Texas pushes three-loss playoff debate to next level with third top-10 victory against Texas A&M
    • “Squid Game” Actor Admits Co-star Burst Into Tears After Filming Explicit Scene With Him
    • The Progression of Cam Ward
    • The Progression of Cam Ward
    • The Progression of Cam Ward

    Tags

    2024 2025 About After Best BTS’s Channel College Fans First football Former From Game Goes Group highlights Idol Idols injury Korean KPop Latest League Live match More Netizens Over Popular Reactions Results Schedule score Sparks Star Stream Their Time Today” Trade Updates Viral Watch Week

    Calendar

    July 2024
    M T W T F S S
    1234567
    891011121314
    15161718192021
    22232425262728
    293031  
    « Jun   Aug »

    © Copyright 2026 · All Rights Reserved · Website Design By: www.tctshop.com