Cyber Security News

Researchers Detailed FrostyGoop Malware Attacking ICS Devices

FrostyGoop, a newly discovered OT-centric malware that exploited Modbus TCP to disrupt critical infrastructure in Ukraine, capable of both internal and external attacks, targets industrial control systems (ICS) devices. 

By sending malicious Modbus commands, FrostyGoop can cause physical damage to the environment, as analysis has uncovered additional samples, configuration files, and network communication patterns associated with this threat. 

It’s appearance brings to light the growing concern regarding operational technology malware and the potential for it to have significant effects in the real world.

Maximizing Cybersecurity ROI: Expert Tips for SME & MSP Leaders – Attend Free Webinar

A newly discovered ICS-centric malware leverages Modbus TCP to target critical infrastructure devices, where attackers exploited a vulnerability in a MikroTik router to deploy the malware, which can be configured to execute specific operations on Modbus devices. 

Disassembled code from a FrostyGoop sample showing a check for the PEB’s BeingDebugged flag.

The malware’s unique characteristics, including its use of an obscure Modbus implementation, JSON configuration, and Goccy’s go-json library, enable its detection and analysis. 

An implementation of a debugger evasion technique demonstrates the level of sophistication it possesses as well as its potential for negative application.

Analysis revealed a Go-based executable, go-encrypt.exe, designed to encrypt and decrypt JSON files using AES-CFB encryption, which generates a 32-byte key stored in a separate file. 

While its direct involvement in the FrostyGoop attack is uncertain, its temporal appearance and alignment with FrostyGoop’s JSON file encryption suggest potential use by attackers to obscure sensitive information within JSON files.

Example of a Python script to convert the decimal value of the key to hexadecimal.

FrostyGoop malware, first seen in October 2023, targets ENCO control devices, primarily in Romania and Ukraine, by exploiting vulnerable Telnet ports to access devices and execute Modbus operations. 

The targeted ENCO devices, often using outdated WR740N routers, pose additional security risks due to potential vulnerabilities, which underscores the critical need for securing industrial control systems and addressing outdated infrastructure.

Information gleaned from accessing an ENCO device over a web browser.

FrostyGoop samples primarily utilize the Modbus TCP protocol to interact with devices over port 502, whose primary function is reading holding registers using function code 3, as defined in the task_test.json configuration. 

The number of registers read is determined by the word count value in the configuration, while the samples can also perform write operations to single or multiple registers using function codes 6 and 16, respectively.

Recent cyberattacks on ICS/OT devices and critical infrastructure have exposed the vulnerability of OT environments.

Nations like Ukraine, Romania, Israel, China, Russia, and the US have faced attacks, highlighting the need for stronger cybersecurity measures. 

According to Palo Alto Networks, the integration of OT and IT networks has created new attack vectors, while the rise of CS-centric malware like FrostyGoop further exacerbates the threat.

Are you from SOC/DFIR Teams? – Analyse Malware Files & Links with ANY.RUN -> Try for Free

Aman Mishra

Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Recent Posts

New Undetectable Batch Script Uses PowerShell and Visual Basic to Install XWorm

A novel malware delivery framework employing advanced obfuscation techniques has evaded detection by security tools…

7 minutes ago

2,850+ Ivanti Connect Secure Devices Exposed to Potential Cyberattacks

A sweeping cybersecurity alert has emerged as researchers identify 2,850+ unpatched Ivanti Connect Secure devices worldwide, leaving…

1 hour ago

US Employee Background Check Firm Hacked, 3 Million Records Exposed

DISA Global Solutions, a Houston-based provider of employee background checks and workplace safety services, disclosed…

2 hours ago

Have I Been Pwned Reports Huge Data Leak, Adds 284 Million Stolen Accounts

Cybersecurity service Have I Been Pwned (HIBP) has disclosed one of the largest data exposure…

2 hours ago

Google Issues Warning on Phishing Campaigns Targeting Higher Education Institutions

Google, in collaboration with its Mandiant Threat Intelligence team, has issued a warning about a…

14 hours ago

TgToxic Android Malware Updated it’s Features to Steal Login Credentials

The TgToxic Android malware, initially discovered in July 2022, has undergone significant updates, enhancing its…

14 hours ago