News Room
16
Share
New 'FrostyGoop' Variants Identified in Targeted Sabotage of European Renewable Energy Grids
criticalCritical Infrastructure

New 'FrostyGoop' Variants Identified in Targeted Sabotage of European Renewable Energy Grids

Security researchers have identified evolved iterations of FrostyGoop malware targeting distributed energy resources. The latest activity follows a major sabotage attempt on Polish wind and solar farms.

12 July 2026Last updated 20 August 20265 min readDragos / CISA
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Critical Infrastructure
Severity:
Critical
Actor Type:
Nation-State
Geography:
Europe
Confidence:
High Confidence
Source:
Dragos / CISA
Read Time:
5 min

Executive Summary

In the last 48 hours, a joint intelligence advisory from CISA and European cybersecurity partners has highlighted a significant escalation in the use of specialized Industrial Control Systems (ICS) malware against the power sector. Recent forensic analysis of an intrusion targeting distributed energy resources (DERs) in Eastern Europe has confirmed the deployment of an evolved variant of the 'FrostyGoop' malware. This variant, which specifically targets Modbus TCP communications, was instrumental in a recent attempt to disrupt over 30 wind and photovoltaic farms. The incident underscores a strategic shift by state-sponsored actors to target the decentralized edge of the modern power grid, causing 'loss of view' and 'loss of control' for facility operators.

Threat Analysis

The threat landscape for critical infrastructure has shifted toward the exploitation of Distributed Energy Resources (DERs). Unlike traditional cyberattacks that target centralized high-voltage transmission substations, the current campaign focuses on the numerous, smaller-scale generation sites that characterize the green energy transition. The actors leverage the inherent vulnerabilities of these decentralized systems, which often rely on internet-facing edge devices for remote management. By targeting the communications between these installations and the primary distribution system operators (DSOs), attackers can induce regional instability without needing to breach the core transmission network. This 'death by a thousand cuts' approach poses a severe risk to grid frequency stability.

Technical Details

The identified malware, a refined version of the Golang-based FrostyGoop, is designed to interact directly with industrial controllers via Port 502. The attack sequence begins with the exploitation of vulnerable internet-facing edge devices, such as industrial routers and VPN gateways, to gain initial access to the Operational Technology (OT) network. Once inside, the malware executes unauthorized Modbus TCP commands to reset or modify operational parameters on Remote Terminal Units (RTUs).

Key technical features of this variant include:

  • Firmware Corruption: The malware is capable of corrupting system firmware on RTUs, necessitating physical hardware replacement to restore service.

  • HMI Data Destruction: Attackers deployed a wiper component that specifically targets and destroys data on Human-Machine Interfaces (HMIs), preventing operators from seeing the actual state of the plant.

  • Modbus Payload Persistence: The malware utilizes custom function codes to maintain persistent unauthorized access even after network-level remediation.

Attribution Assessment

Intelligence from Poland's Computer Emergency Response Team (CERT.PL) and supporting NATO partners indicates a high degree of overlap with infrastructure and tactics used by Russian state-sponsored groups. Specifically, the technical overlaps in the wiper code and the use of the 'KV Botnet' for initial staging suggest the involvement of APT44 (also known as Sandworm). The timing and targeting align with broader geopolitical objectives in the region, aiming to demonstrate the vulnerability of Western-aligned energy infrastructure.

Implications

This development marks a milestone in OT/ICS security. The successful targeting of DERs demonstrates that the attack surface of the modern grid has expanded beyond the reach of traditional centralized security models. The ability to cause 'loss of view' across multiple generation sites simultaneously can lead to cascading failures in the wider distribution network. For the energy sector, this necessitates a move away from perimeter-based security toward a zero-trust model for all Modbus-based communications.

Recommendations

  1. Disable Public Modbus Access: Ensure that no Modbus TCP services (Port 502) are accessible from the public internet. Use dedicated, encrypted tunnels (VPN/SD-WAN) with strict access control lists.

  2. Firmware Integrity Monitoring: Implement regular integrity checks for RTU and PLC firmware to detect unauthorized modifications or corruption.

  3. Network Segmentation: Physically or logically segment the DER control network from the corporate IT network and other non-essential services.

  4. Enforce MFA: Mandate hardware-based multi-factor authentication for all remote access into the OT environment.

  5. Monitor Protocol Anomalies: Deploy OT-native deep packet inspection (DPI) to monitor for unusual Modbus function codes or high frequencies of 'write' commands to critical registers.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo