ZeroHour
Ars Technica · Securitypublished ()ingested

How Russia-linked malware cut heat to 600 Ukrainian buildings in deep winter

mediumMalwareimportance 30
Full article348 words · extracted from arstechnica.com · click to collapse

Dragos first discovered the FrostyGoop malware in April after it was uploaded in several forms to an online malware scanning service—most likely the Google-owned scanning service and malware repository VirusTotal, though Dragos declined to confirm which service—perhaps by the malware’s creators, in an attempt to test whether it was detected by antivirus systems. Working with Ukraine’s Cyber Security Situation Center, a part of the country’s SBU cybersecurity and intelligence agency, Dragos says it then learned that the malware had been used in the cyberattack that targeted a heating utility starting on January 22 in Lviv, the largest city in western Ukraine.

Dragos declined to name the victim utility, and in fact says it hasn’t independently confirmed the utility’s name, since it only became aware of the targeting from the Ukrainian government. Dragos’ description of the attack, however, closely matches reports of a heating outage at the Lvivteploenergo utility around the same time, which, according to local media, led to a loss of heating and hot water for close to 100,000 people.

Lviv mayor Andriy Sadovyi at the time called the event a “malfunction” in a post to the messaging service Telegram, but added, “there is a suspicion of external interference in the company’s work system, this information is currently being checked.” A Lvivteploenergo statement on January 23 described the outage more conclusively as the “result of a hacker attack.”

Lvivteploenergo didn’t respond to WIRED’s request for comment, nor did the SBU. Ukraine’s cybersecurity agency, the State Services for Special Communication and Information Protection, declined to comment.

In its breakdown of the heating utility attack, Dragos says that the FrostyGoop malware was used to target ENCO control devices—Modbus-enabled industrial monitoring tools sold by the Lithuanian firm Axis Industries—and change their temperature outputs to turn off the flow of hot water. Dragos says that the hackers had actually gained access to the network months before the attack, in April 2023, by exploiting a vulnerable MikroTik router as an entry point. They then set up their own VPN connection into the network, which connected back to IP addresses in Moscow.

Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2024/07/how-russia-linked-malware-cut-heat-to-600-ukrainian-buildings-in-deep-winter/