NVISO Publishes a Refinery Attack Walkthrough Built on Labshock
Part two of NVISO's operational technology series stands up a virtual oil plant, finds the PLC, reads its Modbus registers and then scripts the write that moves the pumps.

July 29, 2025 — NVISO has published Refinery raid, a step-by-step walkthrough by Nick Foulon that builds a virtual oil processing plant on Labshock and then attacks it. It is the second entry in the firm's Operational Technology Security series.
The article runs the whole path rather than summarising it. It installs Docker and Labshock on an Ubuntu virtual machine, maps the environment and its attack surface from the architecture, locates the PLC by inspecting container addresses, reads coils and registers over Modbus with mbtget, and finally scripts a write in Python that takes control of the refinery pumps.
What makes it a security article rather than a tutorial is the section that asks whether this happens in real life. The walkthrough sets its own Modbus write against FrostyGoop, the ICS malware that manipulated heating controllers in Ukraine — the same class of operation, performed for real.
Foulon notes that few ready-built environments of this kind are available at no cost, and thanks Labshock for providing one. The environment used in the article runs under a Labshock Pro License.
NVISO is listed as a community entry in the Labshock ecosystem. The full article is linked below.
Media enquiries: info@labshocksecurity.com
