new
Enterprise
Offensive
Defensive
New in Operation Red Horizon: PolarPlunder
The mission continues with a Sherlock.
Following the events of Safety Off (Challenge), Team Phoenix has intercepted new intelligence linked to FrostyGoop, a real-world ICS malware used to manipulate industrial systems through Modbus commands.
What will you learn?
- Navigate MITRE ATT&CK for ICS to connect adversary techniques, software, assets, detection strategies, and mitigations.
- Correlate ATT&CK data with vendor threat reports to build a coherent intelligence profile of FrostyGoop/BUSTLEBERM.
- Explain how Modbus TCP commands can read and modify PLC holding registers, creating potential physical impact in OT environments.
- Extract and interpret technical intelligence, including malware hashes, dependencies, YARA indicators, Golang binaries, anti-debugging checks, and encryption methods.
