Malware caused Ukranian Energy Company to Disconnect Heating Services

August 5, 2024

INCIDENT

Russian-linked malware was used in a January 2024 cyberattack to cut off the heating of over 600 apartment buildings in Lviv, Ukraine, for two days during sub-zero temperatures. The attack forced district heating company Lvivteploenergo to disconnect heating services on January 23, impacting over 100,000 people across Lviv's Sykhiv residential area.

An investigation into the January 2024 cyberattack in Lviv showed that the attackers may have entered Lvivteploenergo's network almost a year earlier, on 17 April 2023, by exploiting an unidentified vulnerability in an Internet-exposed Mikrotik router. Three days later, they deployed a webshell that allowed them to maintain access and helped them connect to the breached network in November and December to steal user credentials from the Security Account Manager (SAM) registry hive. On the day of the attack, the attackers used L2TP (Layer Two Tunnelling Protocol) connections from Moscow-based IP addresses to access the district energy company's network assets.

FrostyGoop, the Windows malware used in this attack, is designed to target industrial control system (ICS) using the Modbus TCP communications, a standard ICS protocol across all industrial sectors.

Incident Date

January 22, 2024

Location

Ukraine

Estimated Cost


No cost values disclosed.

Type of Malware

Threat Source

No threat source identified