Sandworm Targets Poland with Wiper Malware
Executive Summary
The Russian state-sponsored Sandworm group targeted Poland's power grid in late December 2025, attempting to deploy the DynoWiper malware. The attack aimed to disrupt energy infrastructure but was ultimately unsuccessful.
Key TTPs
- Execution: The attackers attempted to deploy DynoWiper, a data-wiping malware, to destroy files and render systems inoperable.
Campaign Analysis
This attack occurred almost ten years after Sandworm's attack on Ukraine's energy grid. Following the incident, reports suggest the Polish government may accelerate the drafting of stricter cybersecurity rules for critical infrastructure, though official details remain forthcoming.
Targeting & Infrastructure
- Target Profile: The attack targeted Poland's energy generator and distribution infrastructure, including two combined heat and power plants and a system managing electricity from renewable sources.
Actionable Intelligence
- Hashes:
4EC3C90846AF6B79EE1A5188EEFA3FD21F6D4CF6
Relevant Terms
- Data Wiper: A type of malware designed to erase data from a system, making it unusable.
- APT (Advanced Persistent Threat): A sophisticated, long-term cyberattack campaign conducted by a skilled actor, often a state-sponsored group.
Source: BleepingComputer
