Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot
    Fake or real, the “inside traders” on Polymarket are great engagement bait

    Fake or real, the “inside traders” on Polymarket are great engagement bait

    April 2, 2026
    The best Amazon Big Spring Sale deals you can still get

    The best Amazon Big Spring Sale deals you can still get

    April 1, 2026
    Snapchat’s ‘Reals’ joke mocks Instagram’s many ripoffs

    Snapchat’s ‘Reals’ joke mocks Instagram’s many ripoffs

    April 1, 2026
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » How Russia-Linked Malware Cut Heat to 600 Ukrainian Buildings in Deep Winter
    Security

    How Russia-Linked Malware Cut Heat to 600 Ukrainian Buildings in Deep Winter

    News RoomBy News RoomJuly 25, 20244 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    How Russia-Linked Malware Cut Heat to 600 Ukrainian Buildings in Deep Winter

    Lvivteploenergo didn’t respond to WIRED’s request for comment, nor did the SBU. Ukraine’s cybersecurity agency, the State Services for Special Communication and Information Protection, declined to comment.

    In its breakdown of the heating utility attack, Dragos says that the FrostyGoop malware was used to target ENCO control devices—Modbus-enabled industrial monitoring tools sold by the Lithuanian firm Axis Industries—and change their temperature outputs to turn off the flow of hot water. Dragos says that the hackers had actually gained access to the network months before the attack, in April 2023, by exploiting a vulnerable MikroTik router as an entry point. They then set up their own VPN connection into the network, which connected back to IP addresses in Moscow.

    Despite that Russia connection, Dragos says it hasn’t tied the heating utility intrusion to any known hacker group it tracks. Dragos noted in particular that it hasn’t, for instance, tied the hacking to the usual suspects such as Kamacite or Electrum, Dragos’ own internal names for groups more widely referred to collectively as Sandworm, a notorious unit of Russia’s military intelligence agency, the GRU.

    Dragos found that, while the hackers used their breach of the heating utility’s network to send FrostyGoop’s Modbus commands that targeted the ENCO devices and crippled the utility’s service, the malware appears to have been hosted on the hackers’ own computer, not on the victim’s network. That means simple antivirus alone, rather than network monitoring and segmentation to protect vulnerable Modbus devices, likely won’t prevent future use of the tool, warns Dragos analyst Mark “Magpie” Graham. “The fact that it can interact with devices remotely means it doesn’t necessarily need to be deployed to a target environment,” Graham says. “You may potentially never see it in the environment, only its effects.”

    While the ENCO devices in the Lviv heating utility were targeted from within the network, Dragos also warns that the earlier version of FrostyGoop it found was configured to target an ENCO device that was instead publicly accessible over the open internet. In its own scans, Dragos says it found at least 40 such ENCO devices that were similarly left vulnerable online. The company warns that there may in fact be tens of thousands of other Modbus-enabled devices connected to the internet that could potentially be targeted in the same way. “We think that FrostyGoop would be able to interact with a huge number of these devices, and we’re in the process of conducting research to verify which devices would indeed be vulnerable,” Graham says.

    While Dragos hasn’t officially linked the Lviv attack to the Russian government, Graham himself doesn’t shy away from describing the attack as a part of Russia’s war against the country—a war that has brutally decimated Ukrainian critical infrastructure with bombs since 2022 and with cyberattacks starting far earlier, since 2014. He argues that the digital targeting of heating infrastructure in the midst of Ukraine’s winter may actually be a sign that Ukrainians’ increasing ability to shoot down Russian missiles has pushed Russia back to hacking-based sabotage, particularly in western Ukraine. “Cyber may actually be more efficient or likely to be successful towards a city over there, while kinetic weapons are maybe still successful at a closer range,” Graham says. “They’re trying to use the full spectrum, the full gamut of available tools in the armory.”

    Even as those tools evolve, though, Graham describes the hackers’ goals in terms that have changed little in Russia’s decade-long history of terrorizing its neighbor: psychological warfare aimed at undermining Ukraine’s will to resist. “This is how you chip away at the will of the people,” says Graham. “It wasn’t aimed at disrupting the heating for all of winter. But enough to make people to think, is this the right move? Do we continue to fight?”

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleMeta’s New Llama 3.1 AI Model Is Free, Powerful, and Risky
    Next Article Coast-to-coast in a solar-powered car — and a new Cannonball Run record

    Related Posts

    Cloudflare Has Blocked 416 Billion AI Bot Requests Since July 1

    Cloudflare Has Blocked 416 Billion AI Bot Requests Since July 1

    December 6, 2025
    The Louisiana Department of Wildlife and Fisheries Is Detaining People for ICE

    The Louisiana Department of Wildlife and Fisheries Is Detaining People for ICE

    December 5, 2025
    Your Data Might Determine How Much You Pay for Eggs

    Your Data Might Determine How Much You Pay for Eggs

    December 4, 2025
    Russia Wants This Mega Missile to Intimidate the West, but It Keeps Crashing

    Russia Wants This Mega Missile to Intimidate the West, but It Keeps Crashing

    December 4, 2025
    This Hacker Conference Installed a Literal Antivirus Monitoring System

    This Hacker Conference Installed a Literal Antivirus Monitoring System

    December 4, 2025
    Flock Uses Overseas Gig Workers to Build Its Surveillance AI

    Flock Uses Overseas Gig Workers to Build Its Surveillance AI

    December 4, 2025
    Our Picks
    The best Amazon Big Spring Sale deals you can still get

    The best Amazon Big Spring Sale deals you can still get

    April 1, 2026
    Snapchat’s ‘Reals’ joke mocks Instagram’s many ripoffs

    Snapchat’s ‘Reals’ joke mocks Instagram’s many ripoffs

    April 1, 2026
    April Fools’ Day 2026: the best and cringiest pranks

    April Fools’ Day 2026: the best and cringiest pranks

    April 1, 2026
    Everything is iPhone now

    Everything is iPhone now

    April 1, 2026
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    Testing the  Ikea speaker that lets you connect 100 at once Reviews

    Testing the $10 Ikea speaker that lets you connect 100 at once

    By News RoomApril 1, 2026

    Ikea’s $10 Kallsup Bluetooth speaker is fun and colorful and sounds better than its price…

    The Shokz OpenRun Pro 2 are now at their lowest price in months

    The Shokz OpenRun Pro 2 are now at their lowest price in months

    April 1, 2026
    SpaceX reportedly files for IPO but it’s keeping the numbers secret (for now)

    SpaceX reportedly files for IPO but it’s keeping the numbers secret (for now)

    April 1, 2026
    The Korg Handytraxx Play finally got me learning to scratch

    The Korg Handytraxx Play finally got me learning to scratch

    April 1, 2026
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2026 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.