CERT Polska. (2026, January 30). Energy Sector Incident Report – 29 December. Retrieved April 22, 2026.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries attempted to dump credentials utilizing LSASS. |
| T1003.002 Security Account Manager |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had stolen Security Account Manager (SAM) and SYSTEM registry hives. |
| T1003.003 NTDS |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries dumped the entire Active Directory database by extracting the contents of the ntds.dit file. |
| T1006 Direct Volume Access |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries copied volume shadow copies through executing `vssadmin` in order to dump the `NTDS.dit` file. |
| T1016 System Network Configuration Discovery |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries gathered network configuration details utilizing `arp -a` and `nslookup` commands. |
| T1021.001 Remote Desktop Protocol |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, adversaries utilized RDP to log into jump hosts and then moved laterally to other victim devices to include a domain controller. |
| T1027.013 Encrypted/Encoded File |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized a Base64-encoded ZIP archive to prevent content analysis. |
| T1036 Masquerading |
MalwareDynoWiper | DynoWiper has been named after well-known files schtask.exe, schtask2.exe, and <redacted>_update.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries created rules that mimicked the name of an institution already present in the network device configuration to avoid detection. |
| T1046 Network Service Discovery |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized Ping, the Advanced Port Scanner and Advanced IP Scanner to enumerate network devices. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries exfiltrated data to an actor-controlled infrastructure using HTTP POSTs. |
| T1049 System Network Connections Discovery |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries identified network connections utilizing `netstat -nao` and `netstat -r`. |
| T1053 Scheduled Task/Job |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries set FortiGate scheduled tasks to run the adversary generated CLI scripts weekly. |
| T1057 Process Discovery |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries enumerated current running processes using `tasklist`. |
| T1059.001 PowerShell |
MalwareLazyWiper | LazyWiper has used PowerShell to enable data destruction on targeted systems. |
| T1059.003 Windows Command Shell |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run `cmd.exe` commands on multiple victim machines. |
| T1059.004 Unix Shell |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized the Linux `dd` command to overwrite portions of the disks with random data. |
| T1059.008 Network Device CLI |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged the native CLI of the targeted FortiGate device. |
| T1074.001 Local Data Staging |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries compiled discovery data locally on the victim host in a file located within `C:\Windows\TEMP\outlog.txt`. |
| T1078.002 Domain Accounts |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, threat actors utilized privileged accounts to access the FortiGate VPN solution and subsequent subnets. |
| T1078.004 Cloud Accounts |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials from on-premises environments to access cloud services. |
| T1082 System Information Discovery |
MalwareLazyWiper | LazyWiper has used `[System.Net.Dns]::GetHostName()` and `$env:COMPUTERNAME` to enumerate the hostname of a system and determine if it is a domain controller. |
| T1083 File and Directory Discovery |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries obtained the contents of users’ directories using `dir /s /b C:\Users` command. |
| T1083 File and Directory Discovery |
MalwareLazyWiper | LazyWiper can specifically target multiple files by extension including: .rar, .tar.gz, .zip, .7z, .json, .bcp, .bak, .gho, .erf, .edb, .onepkg, .pst, and .ldiff. |
| T1083 File and Directory Discovery |
MalwareDynoWiper | DynoWiper has used the Microsoft Windows native `FindFirstFile()` and `FindNextFile()` to recursively enumerate directories and files on the system. |
| T1090 Proxy |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized the rsocx tool identified as `r.exe` and `rsocx.exe` to tunnel within the internal infrastructure using a Reverse SOCKS Proxy. |
| T1090.003 Multi-hop Proxy |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized Tor nodes for C2. |
| T1102.002 Bidirectional Communication |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had communicated to both Dropbox and Pastebin. |
| T1105 Ingress Tool Transfer |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries downloaded malicious payloads to the victim server. |
| T1106 Native API |
MalwareDynoWiper | DynoWiper has used multiple native Windows functions, such as `GetLogicalDrives` and `FindNextFile` for discovery and file deletion. |
| T1110.002 Password Cracking |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries attempted to crack user passwords. |
| T1113 Screen Capture |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries captured screenshots of devices using |
| T1114.002 Remote Email Collection |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials within cloud services to gather data and email messages from Exchange services related to OT topics and technical work carried out within organizations. |
| T1133 External Remote Services |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, threat actors leveraged the FortiGate VPN interface that was exposed to the internet to gain access to the victim environment. |
| T1140 Deobfuscate/Decode Files or Information |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries decoded a Base64-encoded ZIP archive using the built-in certutil. |
| T1480 Execution Guardrails |
MalwareLazyWiper | LazyWiper can halt execution if `[System.Net.Dns]::GetHostName()` or `$env:COMPUTERNAME` contains `“pe-dc”`. |
| T1484.001 Group Policy Modification |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had leveraged Group Policy Objects to distribute wiper malware to victim devices through a network share. |
| T1485 Data Destruction |
MalwareLazyWiper | LazyWiper has overwritten files with pseudorandom 32‑byte sequences written at 16‑byte intervals making the file unrecoverable. |
| T1485 Data Destruction |
MalwareDynoWiper | DynoWiper has overwritten files with 16-byte sequences of random data generated by the Mersenne Twister algorithm using the Microsoft Windows native `CreateFileW()` function to open the file and the `SetFilePointerEx()` and `WriteFile()` functions to overwrite the file. Additionally, versions of DynoWiper can also delete files using the `DeleteFileW` API. |
| T1490 Inhibit System Recovery |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries deleted Windows Volume Shadow Copies using `vssadmin delete shadows`. |
| T1495 Firmware Corruption |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, adversaries performed a factory-reset on compromised devices that hampered forensic investigations. |
| T1529 System Shutdown/Reboot |
MalwareDynoWiper | DynoWiper has used the Microsoft Windows native `ExitWindowsEx()` function to log off the interactive user and shutdown the system. |
| T1530 Data from Cloud Storage |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials within cloud services to download targeted data from SharePoint, and Teams. |
| T1550.002 Pass the Hash |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries attempted to reuse password hash values to gain access to other systems. |
| T1555 Credentials from Password Stores |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries configured a native CLI to gather a targeted elevated users password using `grep`. |
| T1556.006 Multi-Factor Authentication |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries modified two-factor settings within the FortiGate solution to `unset`. |
| T1558 Steal or Forge Kerberos Tickets |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries used the Rubeus tool to forge a Diamond Ticket that is a modified legitimate Kerberos ticket. |
| T1560.001 Archive via Utility |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries compressed stolen files into a zip file prior to exfiltration. |
| T1567.004 Exfiltration Over Webhook |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries leveraged an attacker-controlled Slack channel to exfiltrate data. |
| T1570 Lateral Tool Transfer |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had placed the malicious payload on an accessible network share to facilitate propagation. |
Showing the first 50.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.