{"id":40091,"date":"2024-07-23T10:30:57","date_gmt":"2024-07-23T10:30:57","guid":{"rendered":"https:\/\/abujacityjournal.com\/livenews\/?p=40091"},"modified":"2024-07-23T10:30:57","modified_gmt":"2024-07-23T10:30:57","slug":"how-russia-linked-malware-cut-heat-to-600-ukrainian-buildings-in-deep-winter","status":"publish","type":"post","link":"https:\/\/abujacityjournal.com\/livenews\/2024\/07\/23\/how-russia-linked-malware-cut-heat-to-600-ukrainian-buildings-in-deep-winter\/","title":{"rendered":"How Russia-Linked Malware Cut Heat to 600 Ukrainian Buildings in Deep Winter"},"content":{"rendered":"<p>By Emmanuel Ogbodo<\/p>\n<p>Over the past decade, Russia has tested various methods to attack Ukraine\u2019s civilians, using both physical and digital means. Winter has often been a key part of this strategy, with cyberattacks on electric utilities leading to blackouts and relentless bombing of heating infrastructure. Last January, Russia-linked hackers adopted a new tactic to leave Ukrainians shivering: a piece of malware that directly interfered with a Ukrainian heating utility, cutting off heat and hot water to hundreds of buildings during a severe winter freeze.<\/p>\n<p>On Tuesday, industrial cybersecurity firm Dragos unveiled FrostyGoop, a newly discovered malware sample believed to have been used in a late January cyberattack against a heating utility in Lviv, Ukraine. The attack disabled service to 600 buildings for about 48 hours by altering temperature readings and tricking control systems into cooling the hot water in the buildings&#8217; pipes. This incident marks the first confirmed case of hackers directly sabotaging a heating utility.<\/p>\n<p>Dragos reports that the attack occurred during Lviv&#8217;s typical January cold spell, forcing residents to endure sub-zero temperatures. Dragos analyst Kyle O&#8217;Meara bluntly describes the attack as \u201ca shitty thing\u201d to do in the middle of winter.<\/p>\n<p>The FrostyGoop malware, one of fewer than ten known samples designed to interact with industrial control systems, is unique in its use of Modbus, a common but insecure protocol for industrial communication. Dragos discovered the malware in April, likely uploaded to a malware scanning service for testing. Collaborating with Ukraine&#8217;s Cyber Security Situation Center, Dragos linked the malware to the January 22 attack on Lviv\u2019s heating utility.<\/p>\n<p>Though Dragos has not confirmed the utility\u2019s name, the attack closely aligns with reports of a heating outage at Lvivteploenergo, affecting nearly 100,000 people. The utility&#8217;s outage was initially described as a \u201cmalfunction,\u201d but later acknowledged as a \u201chacker attack.\u201d<\/p>\n<p>Dragos explains that FrostyGoop targeted ENCO control devices\u2014Modbus-enabled tools from Axis Industries\u2014by altering their temperature outputs to stop hot water flow. Hackers accessed the network months prior through a vulnerable MikroTik router, establishing a VPN connection to IP addresses in Moscow.<\/p>\n<p>Despite the connection to Russia, Dragos has not linked the attack to any known hacker group, such as Kamacite or Electrum, associated with Russia&#8217;s GRU. The malware appears to have been hosted on the hackers&#8217; own computers rather than the victim&#8217;s network, meaning traditional antivirus alone may not detect it. Dragos warns that FrostyGoop\u2019s ability to interact with devices remotely means it may not always be visible in the target environment.<\/p>\n<p>Dragos also found an earlier version of FrostyGoop targeting an ENCO device accessible over the open internet. They identified at least 40 such vulnerable devices and suspect tens of thousands of other Modbus-enabled devices online could be similarly targeted.<\/p>\n<p>While Dragos hasn&#8217;t officially connected the Lviv attack to the Russian government, Graham views it as part of Russia&#8217;s broader campaign against Ukraine. He suggests that as Ukrainian defences against Russian missiles improve, Russia may increasingly rely on cyber sabotage. \u201cCyber may be more effective in certain situations while kinetic weapons remain useful closer to the front lines,\u201d Graham notes. The goal remains psychological warfare aimed at eroding Ukraine&#8217;s resolve. \u201cThis is how you chip away at the will of the people,\u201d Graham says. \u201cIt\u2019s not about disrupting heat for the entire winter but making people question their resistance.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Emmanuel Ogbodo Over the past decade, Russia has tested various methods to attack Ukraine\u2019s civilians, using both physical and digital means. Winter has often been a key part of this strategy, with cyberattacks on electric utilities leading to blackouts and relentless bombing of heating infrastructure. Last January, Russia-linked hackers adopted a new tactic to [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":12658,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[172],"tags":[],"class_list":["post-40091","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/abujacityjournal.com\/livenews\/wp-json\/wp\/v2\/posts\/40091","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/abujacityjournal.com\/livenews\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/abujacityjournal.com\/livenews\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/abujacityjournal.com\/livenews\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/abujacityjournal.com\/livenews\/wp-json\/wp\/v2\/comments?post=40091"}],"version-history":[{"count":1,"href":"https:\/\/abujacityjournal.com\/livenews\/wp-json\/wp\/v2\/posts\/40091\/revisions"}],"predecessor-version":[{"id":40093,"href":"https:\/\/abujacityjournal.com\/livenews\/wp-json\/wp\/v2\/posts\/40091\/revisions\/40093"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/abujacityjournal.com\/livenews\/wp-json\/wp\/v2\/media\/12658"}],"wp:attachment":[{"href":"https:\/\/abujacityjournal.com\/livenews\/wp-json\/wp\/v2\/media?parent=40091"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/abujacityjournal.com\/livenews\/wp-json\/wp\/v2\/categories?post=40091"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/abujacityjournal.com\/livenews\/wp-json\/wp\/v2\/tags?post=40091"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}