Power Grid
Lvivteploenergo district heating — FrostyGoop Modbus attack
22–23 January 2024
Lviv, Ukraine
What happened
Attackers used FrostyGoop, the first known malware to disrupt operational technology by speaking Modbus TCP directly, against a municipal district-energy company serving Lviv. Malicious Modbus commands to ENCO controllers in heating substations produced false measurements and malfunctions, and the actors downgraded controller firmware to a version without monitoring, blinding operators. More than 600 apartment buildings lost heating and hot water for about two days in sub-zero January temperatures before manual recovery. Dragos, which analyzed the malware, did not formally attribute it; the attack occurred amid sustained Russian cyber and kinetic operations against Ukrainian energy. The marker is placed at Lviv.
When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.
- Evidence
- Documented
- Confidence
- High
- Infrastructure
- Power Grid
- Latitude
- 49.8420°
- Longitude
- 24.0310°
Attribution
Responsibility has not been established in the cited reporting.
