FrostyGoop and PIPEDREAM: The New Generation of ICS Malware
For years, malware that could touch industrial control systems was rare and usually built for one specific target. Two more recent cases, PIPEDREAM and FrostyGoop, point to a different and more worrying direction: tools that speak standard industrial protocols, work across equipment from multiple vendors, and can disrupt operations without needing a custom exploit for each device. Understanding the shift helps defenders prepare for what is coming, not just what has already happened.
PIPEDREAM: capability found before it was used
In April 2022, a joint advisory from US agencies, including CISA, the Department of Energy, the NSA and the FBI, carrying the identifier AA22-103A, warned about a new set of tools for attacking industrial control systems. Working alongside the advisory, the security firms Dragos and Mandiant published their own analyses. Dragos named the toolkit PIPEDREAM and the group behind it CHERNOVITE; Mandiant called the tools INCONTROLLER.
Several things made PIPEDREAM stand out:
It was modular and cross-vendor. Rather than targeting one device, it included components aimed at Schneider Electric and OMRON programmable logic controllers and at OPC UA servers, a widely used industrial data standard.
It used standard protocols. The toolkit leaned on native industrial functionality and protocols rather than one-off exploits, which is part of what made it adaptable.
It was found before deployment. Unusually, PIPEDREAM was identified before it had been used to cause a known disruptive effect. Researchers described this as a rare chance to defend ahead of an attack.
Mandiant assessed the tools as very likely state-sponsored and noted the activity was consistent with Russia's known interest in industrial systems, while being careful to say the evidence tying it to any specific government was largely circumstantial. The accurate framing is that it was assessed as state-sponsored, without a firm public attribution to a named state.
FrostyGoop: a protocol-native attack that landed
If PIPEDREAM showed the potential, FrostyGoop showed the reality. In July 2024, Dragos disclosed malware it called FrostyGoop and tied it to an incident months earlier.
In January 2024, a district heating company in Lviv, Ukraine, was attacked. The malware used Modbus TCP, one of the most common industrial protocols in the world, to manipulate heating controllers. The result was that roughly 600 apartment buildings lost heat for about two days, in sub-zero winter temperatures.
What makes FrostyGoop notable is not complexity but reach. Modbus is everywhere, and the malware communicated with equipment using that ordinary protocol. The affected facility also lacked internal network separation, which let the attackers move from an initial foothold to the control devices. Dragos noted that tens of thousands of Modbus-speaking devices are exposed to the internet worldwide, which hints at how broadly this kind of approach could apply.
The trend: ICS-specific, protocol-native, cross-vendor

Put together, these two cases describe where industrial malware is heading:
ICS-specific. These are not repurposed IT tools. They are built with industrial systems in mind.
Protocol-native. By using standard protocols like Modbus and OPC UA, attackers can reach many devices without a separate exploit for each one.
Cross-vendor. Tools increasingly target multiple manufacturers' equipment, so relying on a particular brand is not protection.
Lower barrier to disruption. Speaking the native language of control systems means an attacker often does not need a software vulnerability at all; the equipment is doing what it was built to do, just on the wrong instructions.
Practical defensive lessons
The good news is that protocol-native malware still has to reach the equipment and still stands out when you are watching for it.
Segment OT networks internally. FrostyGoop spread in part because there was no internal separation. Dividing the control network into zones with controlled flows limits how far an intruder can move.
Monitor industrial protocols. Passive monitoring that understands protocols like Modbus and OPC UA can flag unusual commands, new connections or unexpected sources without affecting operations.
Reduce internet exposure. Every control device reachable from the internet is a candidate. Remove direct exposure and front remote access with strong authentication.
Build a defensible architecture. The same fundamentals that help against targeted malware, which are good separation, a clear architecture, monitoring and a practised OT incident response plan, apply here directly.
Know your protocols and assets. You cannot monitor or protect what you have not inventoried. Know which controllers you run, which protocols they use and where they sit.
Key takeaways
PIPEDREAM/INCONTROLLER, disclosed in April 2022, is a modular, cross-vendor ICS toolkit that was found before it was used to cause a known disruption.
FrostyGoop, disclosed by Dragos in July 2024, used Modbus TCP in a January 2024 attack that cut heating to about 600 Lviv apartment buildings for roughly two days.
The trend is toward ICS-specific, protocol-native, cross-vendor tools that need no per-device exploit.
Lack of internal segmentation and internet exposure are repeat enablers.
Segmentation, protocol-aware monitoring and a defensible architecture are the core defences.
How QBits Networks can help
Protocol-native malware depends on reaching your controllers and going unseen, which is exactly what good separation and visibility prevent. Our network segmentation reviews assess whether your OT environment is divided into defensible zones, and our OT visibility snapshots use passive capture to show what is really talking on your network, including the industrial protocols these tools abuse. Tell us what you need through our contact page and we'll scope it with you.