new

Enterprise

Offensive

Defensive

New in Operation Red Horizon: PolarPlunder

The mission continues with a Sherlock.
Following the events of Safety Off (Challenge), Team Phoenix has intercepted new intelligence linked to FrostyGoop, a real-world ICS malware used to manipulate industrial systems through Modbus commands.
What will you learn?
  • Navigate MITRE ATT&CK for ICS to connect adversary techniques, software, assets, detection strategies, and mitigations.
  • Correlate ATT&CK data with vendor threat reports to build a coherent intelligence profile of FrostyGoop/BUSTLEBERM.
  • Explain how Modbus TCP commands can read and modify PLC holding registers, creating potential physical impact in OT environments.
  • Extract and interpret technical intelligence, including malware hashes, dependencies, YARA indicators, Golang binaries, anti-debugging checks, and encryption methods.
Polar Plunder