
New 'FrostyGoop' Variants Identified in Targeted Sabotage of European Renewable Energy Grids
Security researchers have identified evolved iterations of FrostyGoop malware targeting distributed energy resources. The latest activity follows a major sabotage attempt on Polish wind and solar farms.
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Europe
- Confidence:
- High Confidence
- Source:
- Dragos / CISA
- Read Time:
- 5 min
Executive Summary
In the last 48 hours, a joint intelligence advisory from CISA and European cybersecurity partners has highlighted a significant escalation in the use of specialized Industrial Control Systems (ICS) malware against the power sector. Recent forensic analysis of an intrusion targeting distributed energy resources (DERs) in Eastern Europe has confirmed the deployment of an evolved variant of the 'FrostyGoop' malware. This variant, which specifically targets Modbus TCP communications, was instrumental in a recent attempt to disrupt over 30 wind and photovoltaic farms. The incident underscores a strategic shift by state-sponsored actors to target the decentralized edge of the modern power grid, causing 'loss of view' and 'loss of control' for facility operators.
Threat Analysis
The threat landscape for critical infrastructure has shifted toward the exploitation of Distributed Energy Resources (DERs). Unlike traditional cyberattacks that target centralized high-voltage transmission substations, the current campaign focuses on the numerous, smaller-scale generation sites that characterize the green energy transition. The actors leverage the inherent vulnerabilities of these decentralized systems, which often rely on internet-facing edge devices for remote management. By targeting the communications between these installations and the primary distribution system operators (DSOs), attackers can induce regional instability without needing to breach the core transmission network. This 'death by a thousand cuts' approach poses a severe risk to grid frequency stability.
Technical Details
The identified malware, a refined version of the Golang-based FrostyGoop, is designed to interact directly with industrial controllers via Port 502. The attack sequence begins with the exploitation of vulnerable internet-facing edge devices, such as industrial routers and VPN gateways, to gain initial access to the Operational Technology (OT) network. Once inside, the malware executes unauthorized Modbus TCP commands to reset or modify operational parameters on Remote Terminal Units (RTUs).
Key technical features of this variant include:
-
Firmware Corruption: The malware is capable of corrupting system firmware on RTUs, necessitating physical hardware replacement to restore service.
-
HMI Data Destruction: Attackers deployed a wiper component that specifically targets and destroys data on Human-Machine Interfaces (HMIs), preventing operators from seeing the actual state of the plant.
-
Modbus Payload Persistence: The malware utilizes custom function codes to maintain persistent unauthorized access even after network-level remediation.
Attribution Assessment
Intelligence from Poland's Computer Emergency Response Team (CERT.PL) and supporting NATO partners indicates a high degree of overlap with infrastructure and tactics used by Russian state-sponsored groups. Specifically, the technical overlaps in the wiper code and the use of the 'KV Botnet' for initial staging suggest the involvement of APT44 (also known as Sandworm). The timing and targeting align with broader geopolitical objectives in the region, aiming to demonstrate the vulnerability of Western-aligned energy infrastructure.
Implications
This development marks a milestone in OT/ICS security. The successful targeting of DERs demonstrates that the attack surface of the modern grid has expanded beyond the reach of traditional centralized security models. The ability to cause 'loss of view' across multiple generation sites simultaneously can lead to cascading failures in the wider distribution network. For the energy sector, this necessitates a move away from perimeter-based security toward a zero-trust model for all Modbus-based communications.
Recommendations
-
Disable Public Modbus Access: Ensure that no Modbus TCP services (Port 502) are accessible from the public internet. Use dedicated, encrypted tunnels (VPN/SD-WAN) with strict access control lists.
-
Firmware Integrity Monitoring: Implement regular integrity checks for RTU and PLC firmware to detect unauthorized modifications or corruption.
-
Network Segmentation: Physically or logically segment the DER control network from the corporate IT network and other non-essential services.
-
Enforce MFA: Mandate hardware-based multi-factor authentication for all remote access into the OT environment.
-
Monitor Protocol Anomalies: Deploy OT-native deep packet inspection (DPI) to monitor for unusual Modbus function codes or high frequencies of 'write' commands to critical registers.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Iranian State Actors Paralyze UK Power Plant; CISA Warns of AI-Driven Exploitation of Critical OT Infrastructure

Iranian-Linked Cyberattack Triggers Four-Day Shutdown of UK Power Station; CISA Warns of AI-Driven PLC Exploits

