Security

Hackers shut down heating in Ukrainian city with malware, researchers say

Comment

A tram in Katedralna Square at night, Lviv, western Ukraine.
Image Credits: Anastasiia Smolienko / Ukrinform/Future Publishing / Getty Images

For two days in mid-January, some Ukrainians in the city of Lviv had to live without central heating and suffer freezing temperatures because of a cyberattack against a municipal energy company, security researchers and Ukrainian authorities have since concluded. 

On Tuesday, the cybersecurity company Dragos published a report with details about a new malware dubbed FrostyGoop, which the company says is designed to target industrial control systems — in this particular case, specifically against a type of heating system controller. 

Dragos researchers wrote in their report that they first detected the malware in April. At that point, Dragos did not have more information on FrostyGoop apart from the malware sample, and believed it was only used for testing. Later on, however, Ukrainian authorities warned Dragos that they had found evidence that the malware was actively used in a cyberattack in Lviv during the late evening of January 22 through January 23. 

“And that resulted in the loss of heating to over 600 apartment buildings for almost 48 hours,” said Magpie Graham, a researcher at Dragos, during a call with reporters briefed on the report prior to its release.

Dragos researchers Graham, Kyle O’Meara, and Carolyn Ahlers wrote in the report that “remediation of the incident took almost two days, during which time the civilian population had to endure sub-zero temperatures.”

This is the third known outage linked to cyberattacks to hit Ukrainians in recent years. While the researchers said the malware was unlikely to cause widespread outages, it shows an increased effort by malicious hackers to target critical infrastructure, like energy grids.

The FrostyGoop malware is designed to interact with industrial control devices (ICS) over Modbus, a decades-old protocol widely used across the world to control devices in industrial environments, meaning FrostyGoop could be used to target other companies and facilities anywhere, according to Dragos. 

“There’s at least 46,000 Internet exposed ICS devices that allow Modbus today,” Graham told reporters. 

Dragos said that FrostyGoop is the ninth ICS-specific malware it has encountered over the years. The most famous of these are Industroyer (also known as CrashOverride), which was used by the infamous Russian-government linked hacking group Sandworm to turn off the lights in Kyiv and later to disconnect electrical substations in Ukraine. Outside of those cyberattacks targeting Ukraine, Dragos has also seen Triton, which was deployed against a Saudi petrochemical plant and against an unknown second facility later on; and the CosmicEnergy malware, which was discovered by Mandiant last year.

Contact Us

Do you have more information about this cyberattack? Or similar attacks targeting ICS in Ukraine and beyond? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

Dragos researchers wrote that they believe that the hackers in control of the FrostyGoop malware first gained access to the targeted municipal energy company’s network by exploiting a vulnerability in an internet-exposed Mikrotik router. The researchers said the router was not “adequately segmented” along with other servers and controllers, including one made by ENCO, a Chinese company.

Graham said in the call that they found open ENCO controllers in Lithuania, Ukraine, and  Romania, underscoring once again that while FrostyGoop was used in a targeted attack in Lviv this time, the hackers in control could target the malware elsewhere. 

ENCO and its employees did not immediately respond to TechCrunch’s request for comment.

“The adversaries did not attempt to destroy the controllers. Instead, the adversaries caused the controllers to report inaccurate measurements, resulting in the incorrect operation of the system and the loss of heating to customers,” the researchers wrote.

During the investigation, the researchers said they concluded that the hackers “possibly gained access” to the targeted network in April 2023, almost a year before deploying the malware and turning off the heat. In the following months, the hackers kept accessing the network and on January 22, 2024, connected to through Moscow-based IP addresses, according to the report.

Despite the Russian IP addresses, Dragos didn’t point the finger at any known particular hacking group or government as responsible for this cyber-enabled outage, because the company couldn’t find ties to previous activities or tools, and because of the company’s longstanding policy on not attributing cyberattacks, said Graham.  

What Graham did say is that he and his colleagues believe this disruptive operation was conducted over the internet — as opposed to launching missiles at the facility — likely as an effort to undermine the morale of Ukrainians living there.

“I think it’s very much a psychological effort here, facilitated through cyber means when kinetic perhaps here wasn’t the best choice,” said Graham.

Finally, Dragos’ field chief technology officer Phil Tonking said that while it’s important not to underplay FrostyGoop, it’s also important not to overhype it.

“It’s important to recognize that whilst this is something that has been actively used,” he said during the call with the press, “it’s also very, very important that we don’t think that this is something that is immediately going to bring down the nation’s power grid.”

More TechCrunch

The EC has announced an investigation into Berlin-based food delivery giant Delivery Hero and its Spanish subsidiary, Glovo, citing cartel concerns.

EU to investigate Delivery Hero and Glovo over food delivery cartel concerns

Singapore’s ride-hailing and food delivery company Grab is expanding its services beyond ride and food delivery by doubling down on the competitive restaurant booking industry in Southeast Asia. Grab confirmed…

Grab acquires Singapore’s restaurant reservation platform Chope  

After doing some consulting for Microsoft to develop protections against zero-day exploits, software engineer Joran Dirk Greef worked with Coil, a web monetization startup in San Francisco, to help build…

TigerBeetle is building database software optimized for financial transactions

GM’s self-driving car subsidiary Cruise is scrapping plans to build the Origin  — a purpose-built robotaxi with no steering wheel or pedals — and will instead use the next-generation Chevrolet…

GM’s Cruise abandons Origin robotaxi, takes $583 million charge

Cybersecurity firm Dragos and Ukrainian authorities found a cyberattack targeting critical infrastructure in Lviv.

Hackers shut down heating in Ukrainian city with malware, researchers say
Image Credits: Anastasiia Smolienko / Ukrinform/Future Publishing / Getty Images

Messaging app Telegram has reached 950M active users, and it aims to cross the 1 billion mark this year, founder Pavel Durov said.

Telegram’s userbase climbs to 950M, plans to launch app store

India’s federal government has removed the so-called “angel tax” for all classes of investors, delivering a major victory to the country’s startup ecosystem that had lobbied for years against the…

India scraps ‘angel tax’ in boost for startups

A Seoul court issued an arrest warrant for Brian Kim, the founder of South Korean internet giant Kakao, on allegations of stock price manipulation related to the company’s takeover of…

Kakao founder issued arrest warrant by Seoul court

Cybersecurity startup Wiz has turned down a $23 billion acquisition offer from Alphabet, Google’s parent company, according to a source familiar with discussions. Despite the offer representing a substantial premium…

Wiz walks away from Google’s $23B acquisition offer: Read the CEO’s note to employees

Monarch Tractor was in a tricky spot late last year as the autonomous electric tractor startup juggled growth and an uncertain fundraising environment. Now, with $133 million in new funds,…

Monarch Tractor CEO says $133M raise will help it escape ‘quite a challenging time’

Hello and welcome back to TechCrunch Space. Before we begin, a quick note: I write this newsletter on Friday and it gets delivered to you on Monday. So if I…

Eric Zhu started building Aviato, an analytical platform for private market data, in a very atypical place for an entrepreneur: the bathroom in his Carmel, Indiana, high school. Now the 17-year-old’s…

17-year-old Eric Zhu’s startup was built in a high school bathroom — now it’s raised $2.3M and is emerging from stealth

Choosing between New York City’s nearly 25,000 restaurants can be overwhelming. The pressure is especially high when you’re trying to impress a first date (or investor) or entertain family from…

The Scene’s new app helps New Yorkers find dining and nightlife spots

Nine months on, and Jigsaw is now formally handing Altitude over to Tech Against Terrorism, which will continue its development and maintenance.

Google’s Jigsaw open sources Altitude to help online platforms weed out extremist content

TechCrunch Disrupt 2024 in San Francisco is fast approaching, and we’re seeking highly motivated volunteers to support our events team. If you dream of becoming a startup founder, marketer, or…

Be a TechCrunch Disrupt 2024 volunteer

Unlike OpenAI, Anthropic, Mistral and many of its generative AI startup rivals, Cohere doesn’t have a big consumer focus.

Cohere raises $500M to beat back generative AI rivals

Indian food delivery and quick commerce startup Swiggy is pivoting one of its smaller businesses, Swiggy Minis, into a link-in-bio service.

Swiggy turns Minis into a link-in-bio platform

Fragment’s digital ledger API applies real-time, double entry accounting to find where things aren’t adding up.

Fintech Fragment eases ledger problems, nabs $9M from Stripe, Jack Altman, BoxGroup, others

Identity management is one of the most common fulcrums around which security breaches have pivoted in the last several years. One of the main reasons it has become the gift…

Linx emerges from stealth with $33M to lock down the new security perimeter: Identity

Featured Article

Pesa unlocks new markets to keep remittances flowing to emerging economies

Founders of Pesa, a remittance fintech, know too well how costly, inaccessible and unreliable remittance services drive people to opt for risky informal channels —  like WhatsApp groups  — to transfer money.  Their firsthand experience using informal channels and realizing how prevalent their use was among Africans living in the…

Pesa unlocks new markets to keep remittances flowing to emerging economies

A little more than a year after launching the ROG Ally, Asus is releasing a refined version of its portable device, the ROG Ally X. This Windows-based machine starts shipping…

The Asus ROG Ally X turns PC gaming into a portable console

As a part of TechCrunch’s ongoing Women in AI series, which seeks to give AI-focused women academics and others their well-deserved — and overdue — time in the spotlight, TechCrunch interviewed Lakshmi…

CIA AI director Lakshmi Raman claims the agency is taking a ‘thoughtful approach’ to AI

With President Joe Biden dropping out of the race, Vice President Kamala Harris may become the Democrats’ new nominee. In announcing his plans, Biden offered his “full support and endorsement…

What Kamala Harris has said about AI, tech regulation and more

U.S. President Joe Biden has announced he no longer plans to seek reelection, a decision that follows weeks of growing pressure from some Democratic Party supporters, including high-profile tech investors…

Joe Biden drops out of presidential race

Google is expected to announce four Pixel devices: the Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL and Pixel 9 Pro Premium, running Android 15.

Made by Google 2024: Pixel 9, Gemini, a new foldable and other things to expect from the event

WazirX, one of India’s largest cryptocurrency exchanges, has “temporarily” suspended all trading activities on its platform days after losing about $230 million, nearly half of its reserves, in a security…

WazirX halts trading after $230 million ‘force majeure’ loss

Featured Article

From Yandex’s ashes comes Nebius, a ‘startup’ with plans to be a European AI compute leader

Subject to shareholder approval, Yandex N.V. is adopting the name of one of its few remaining assets, an AI cloud platform called Nebius AI which it birthed last year.

From Yandex’s ashes comes Nebius, a ‘startup’ with plans to be a European AI compute leader

Employees at Bethesda Game Studios — the Microsoft-owned game developer that produces the Elder Scrolls and Fallout franchises — are joining the Communications Workers of America union. Quality assurance testers…

Bethesda Game Studios employees form a ‘wall-to-wall’ union

This week saw one of the most widespread IT disruptions in recent years linked to a faulty software update from popular cybersecurity firm CrowdStrike. Businesses across the world reported IT…

CrowdStrike’s update fail causes global outages and travel chaos

Alphabet, the parent company of Google, is in advanced talks to acquire cybersecurity startup Wiz for $23 billion, the Wall Street Journal reported on Sunday. TechCrunch’s sources heard similar and…

Unpacking how Alphabet’s rumored Wiz acquisition could affect VC