DynoWiper Data-Wiping Malware Attacking Energy Companies to Destroy Data
ID: cb4538ec-0c61-52be-a275-c92eb66c8ed7
STIX ID: report--cb4538ec-0c61-52be-a275-c92eb66c8ed7
Feed Name: cybersecurityNews.com
DynoWiper is a destructive data-wiping malware observed in December 2025 targeting a Polish energy firm; attributed to the Sandworm APT and similar to the ZOV wiper, it overwrites files using a 16-byte buffer and was deployed via Active Directory Group Policy after attackers performed credential theft (Rubeus, LSASS dumping) and established reverse connections via a SOCKS5 proxy. Multiple variants and iterative attempts to bypass defenses were noted, but endpoint detection and response successfully blocked execution and significantly limited impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
