FrostyGoop / BUSTLEBERM
ICS/OT malware · first seen 2024
- Hits
- Modbus TCP controllers, heating & process skids
- Entry
- Exposed Modbus/502 over internet-facing routers
- Impact
- Line stoppage
Manufacturing & OT sector · threat operations
Live exploited-vulnerability and ICS advisory feeds from CISA, combined with an analyst baseline of active malware families and recently disclosed victims across discrete and process manufacturing.
Sector posture
Elevated — Charlie
OT / ICS CVEs under active exploitation
11
1 tied to known ransomware campaigns
Open control-system advisories
12
Newest CISA ICS advisories in the stream
Malware families tracked
8
5 confirmed active this month
Disclosed manufacturing victims
7
Production impact reported in most cases
Tracked families targeting production networks
ICS/OT malware · first seen 2024
Wiper · first seen 2024
Ransomware · first seen 2019
Ransomware · first seen 2023
ICS/OT malware · first seen 2022
Loader · first seen 2011
Ransomware · first seen 2022
RAT · first seen 2014
CISA known exploited vulnerabilities · OT vendors
Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
added 2026-06-23 · remediate by 2026-06-26
Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.
added 2026-04-20 · remediate by 2026-05-04
Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to verify Logix controllers are communicating with Rockwell Automation design software. If successfully exploited, this vulnerability could allow an unauthorized application to connect with Logix controllers. To leverage this vulnerability, an unauthorized user would require network access to the controller.
added 2026-03-05 · remediate by 2026-03-26
Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
added 2025-12-12 · remediate by 2026-01-02
Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization.
added 2025-03-03 · remediate by 2025-03-24
Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, allowing for arbitrary command execution.
added 2025-03-03 · remediate by 2025-03-24
Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands.
added 2023-12-11 · remediate by 2023-12-18
Delta Electronics DOPSoft 2 lacks proper validation of user-supplied data when parsing specific project files (improper input validation) resulting in an out-of-bounds write that allows for code execution.
added 2022-08-25 · remediate by 2022-09-15
A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.
added 2022-04-15 · remediate by 2022-05-06
An improper privilege management vulnerability exists within the Siemens SIMATIC Communication Processor (CP) that allows a privileged attacker to remotely cause a denial of service.
added 2022-03-03 · remediate by 2022-03-24
SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.
added 2022-01-28 · remediate by 2022-02-11
Disclosed incidents & leak-site postings
Two press lines idled 4 days; shipments air-freighted
ERP offline, manual paper picking for 9 days
SMT scheduling data leaked, customer BOMs exposed
Cold-chain SCADA isolated, one plant on manual control
ITAR-adjacent drawings posted to leak site
Batch historian encrypted; safety interlocks unaffected
Converting lines down 36 hours, backlog 3 weeks
CISA ICS advisory stream
Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Successful exploitation of these vulnerabilities could allow an attacker to read data from the device or gain access to affected workstations. The following versions of ANDRITZ HIPASE-250 and 250 SCALA are affected: HIPA
A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to
Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges. The following versions of Haiwell IoT Cloud HMI Gateway are affected: Haiwell IoT Clou
Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server
Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this cou
Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including
Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemen
Hitachi Energy is aware of Dirty Frag vulnerabilities that affect APM Edge product versions listed in this document. Successful exploitation of these vulnerabilities could result in impact on confidentiality, integrity a
Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application
Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them
Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized
Share of manufacturing incidents
How intrusions start