Power Grid

Lvivteploenergo district heating — FrostyGoop Modbus attack

22–23 January 2024

Lviv, Ukraine

What happened

Attackers used FrostyGoop, the first known malware to disrupt operational technology by speaking Modbus TCP directly, against a municipal district-energy company serving Lviv. Malicious Modbus commands to ENCO controllers in heating substations produced false measurements and malfunctions, and the actors downgraded controller firmware to a version without monitoring, blinding operators. More than 600 apartment buildings lost heating and hot water for about two days in sub-zero January temperatures before manual recovery. Dragos, which analyzed the malware, did not formally attribute it; the attack occurred amid sustained Russian cyber and kinetic operations against Ukrainian energy. The marker is placed at Lviv.

When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.

Evidence
Documented
Confidence
High
Infrastructure
Power Grid
Latitude
49.8420°
Longitude
24.0310°

Attribution

Responsibility has not been established in the cited reporting.

Sources

  1. FrostyGoop malware left 600 Ukrainian households without heat this winterThe Record, citing Dragos · Incident reporting