ATT&CKCampaigns2025 Poland Wiper Attacks

2025 Poland Wiper Attacks

C0063

Campaign, Mar 2025 to Dec 2025.View on attack.mitre.org

About this campaign

2025 Poland Wiper Attacks is a Russian state-sponsored campaign that conducted destructive cyberattacks against Polish energy infrastructure in December 2025. Targets included more than 30 wind and photovoltaic farms, a combined heat and power (CHP) plant, and a manufacturing sector company. The attacks on the distributed energy resources (DER) disrupted communications between affected facilities and the distribution system operator, but did not impact electricity generation or heat supply. Across the campaign, threat actors deployed two previously undocumented wiper tools, DynoWiper, a Windows-based wiper and LazyWiper, a PowerShell wiper, distributed via malicious Group Policy Objects. At the CHP plant, threat actors had maintained access since at least March 2025, using that foothold to obtain credentials and move laterally before attempting wiper deployment. Some reporting has assessed the activity to be consistent with Russian Federal Security Service (FSB) threat activity group Dragonfly, also tracked as STATIC TUNDRA, while other reporting attributes the destructive wiper activities to the Russian General Staff Main Intelligence Directorate (GRU) threat activity group ELECTRUM, also tracked as Sandworm Team.

Techniques used53

Procedure examples53

TechniqueProcedure example
T1003.001
LSASS Memory

During the 2025 Poland Wiper Attacks, the adversaries attempted to dump credentials utilizing LSASS.

T1003.002
Security Account Manager

During the 2025 Poland Wiper Attacks, the adversaries had stolen Security Account Manager (SAM) and SYSTEM registry hives.

T1003.003
NTDS

During the 2025 Poland Wiper Attacks, the adversaries dumped the entire Active Directory database by extracting the contents of the ntds.dit file.

T1006
Direct Volume Access

During the 2025 Poland Wiper Attacks, the adversaries copied volume shadow copies through executing `vssadmin` in order to dump the `NTDS.dit` file.

T1016
System Network Configuration Discovery

During the 2025 Poland Wiper Attacks, the adversaries gathered network configuration details utilizing `arp -a` and `nslookup` commands.

T1021.001
Remote Desktop Protocol

During the 2025 Poland Wiper Attacks, adversaries utilized RDP to log into jump hosts and then moved laterally to other victim devices to include a domain controller.

T1027.013
Encrypted/Encoded File

During the 2025 Poland Wiper Attacks, the adversaries utilized a Base64-encoded ZIP archive to prevent content analysis.

T1036.005
Match Legitimate Resource Name or Location

During the 2025 Poland Wiper Attacks, the adversaries created rules that mimicked the name of an institution already present in the network device configuration to avoid detection.

T1046
Network Service Discovery

During the 2025 Poland Wiper Attacks, the adversaries utilized Ping, the Advanced Port Scanner and Advanced IP Scanner to enumerate network devices.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

During the 2025 Poland Wiper Attacks, the adversaries exfiltrated data to an actor-controlled infrastructure using HTTP POSTs.

T1049
System Network Connections Discovery

During the 2025 Poland Wiper Attacks, the adversaries identified network connections utilizing `netstat -nao` and `netstat -r`.

T1053
Scheduled Task/Job

During the 2025 Poland Wiper Attacks, the adversaries set FortiGate scheduled tasks to run the adversary generated CLI scripts weekly.

T1057
Process Discovery

During the 2025 Poland Wiper Attacks, the adversaries enumerated current running processes using `tasklist`.

T1059.003
Windows Command Shell

During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run `cmd.exe` commands on multiple victim machines.

T1059.004
Unix Shell

During the 2025 Poland Wiper Attacks, the adversaries utilized the Linux `dd` command to overwrite portions of the disks with random data.

View all 53 procedure examples

Attributed groups0

MITRE does not attribute this campaign to a group.

Software11

References4

  1. CERT Polska Open source
    CERT Polska. (2026, January 30). Energy Sector Incident Report – 29 December. Retrieved April 22, 2026.
  2. Dragos ELECTRUM JAN 2026 Open source
    https://5943619.hs-sites.com/hubfs/Reports/dragos-2025-poland-attack-report.pdf. (2026, January). ELECTRUM: CYBER ATTACK ON POLAND’S ELECTRIC SYSTEM 2025. Retrieved April 22, 2026.
  3. ESET DynoWiper JAN 2026 Open source
    ESET. (2026, January 30). Russian Sandworm group attacks energy company in Poland with DynoWiper, ESET Research discovers. Retrieved April 22, 2026.
  4. ESET DynoWiper Update JAN 2026 Open source
    ESET. (2026, January 30). DynoWiper update: Technical analysis and attribution. Retrieved April 22, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.