Critical Infrastructure Under Constant Fire

▶ Watch (3:27)

In a couple of years, attacks on critical infrastructure jumped 300%. Almost 5,000 critical infrastructure organizations reported incidents to the FBI, and actual numbers are higher since many don’t report. At 30 attacks per second across 50 billion connected devices, the attack surface now includes solar panels, water treatment plants, and HVAC systems. Texas water plants and the Colonial Pipeline are US examples. Every one of those systems runs legacy OT with no security baked in.

The Strategic Logic Behind Climate Infrastructure Attacks

▶ Watch (8:11)

Twelve nation-state APT groups actively target climate infrastructure. Russia, Ukraine, China, and North Korea are developing warfare doctrines around it. Russia hits energy systems to destroy. North Korea combines financial theft with data collection. Environmental damage is a side effect that nations now treat as a feature: Oliveira argues it provides strategic amplification well beyond the primary espionage or disruption goal. Ransomware groups add another layer, chasing money and data from the same OT targets.

Timing Attacks to Weather Stress Periods

▶ Watch (9:50)

67% of confirmed OT incidents were timed with extreme weather. APTs hit during winter, summer heat waves, droughts, and floods. When electricity or water infrastructure fails during a climate crisis, civilian casualties follow. Cascading effects multiply the damage: attack water infrastructure and you also knock out agriculture and power generation. During Brazil’s floods, attackers ran phishing and charity scams targeting disaster victims, exploiting the same window of chaos.

FrostyGoop: Cutting Heat with 200 Lines of Go

▶ Watch (17:11)

FrostyGoop hit a municipal district energy company in Ukraine during winter. For two days, thousands of people had no heat in below-freezing temperatures. The malware, written in Go, fit in roughly 200 lines of code. It ran as a single executable on Windows, Linux, and industrial controllers, worked in air-gapped networks, and needed no external dependencies. It exploited no vulnerability. It sent Modbus TCP commands to drop setpoint temperatures from roughly 22°C to 5°C.

Modbus: No Authentication Since 1979

▶ Watch (19:34)

Modbus dates to 1979. It carries no authentication, no encryption, no integrity check, and no access control. It runs on port 502 and is the language that thermostats, pumps, and sensors use to talk to each other. A Shodan search on port 502 in July showed hosts with it exposed. Changing a setpoint takes a single write-register command. Upgrading the world’s OT infrastructure costs too much to do quickly, which means this exposure persists for years.

Notable Quotes

new gold, but climate control. Cybelle Oliveira · ▶ 13:04

thank you threat actors to exist. Cybelle Oliveira · ▶ 15:06

food for days but not without water. Cybelle Oliveira · ▶ 22:32

Key Takeaways

  • 89% of confirmed OT incidents caused real physical damage, three per week last year.
  • FrostyGoop needed zero exploits and only 200 lines of Go to cut heat for thousands.
  • Modbus, born in 1979, still runs with no authentication on internet-exposed port 502.

About the Speaker(s)

Cybelle Oliveira is a Cyber Threat Intelligence researcher and Master’s student in Cyber Intelligence based in Brazil. She co-founded La Villa Hacker, the first DEF CON village for the Portuguese and Spanish-speaking community. She has presented at DEF CON, BSides Las Vegas, 8.8 Chile, Cryptorave, Radical Networks, and Mozilla Festival. Her research focuses on the intersection of cyber threats, geopolitics, and underreported regions.