logo

DYNOWIPER: Destructive Malware Targeting Poland's Energy Sector

ID: 7ff2cb98-d97e-5f60-b482-430cca808eec

STIX ID: report--7ff2cb98-d97e-5f60-b482-430cca808eec

Feed Name: Elastic Security Labs

Threat Score
90/100

Date Published: 2026-02-06

Date Updated: 2026-04-27

...
...

On December 29, 2025 a coordinated destructive cyber campaign leveraging a custom wiper called DYNOWIPER targeted more than 30 renewable energy sites and a major CHP plant in Poland; the report provides sample metadata and technical analysis of the wiper, IOCs (file hashes, distribution scripts, IPs), a YARA rule, mapped MITRE ATT&CK TTPs, vendor attributions to a state-aligned threat cluster, and operational recommendations (behavioral canary protection, MFA, FortiGate audits, backup recovery).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.