DYNOWIPER: Destructive Malware Targeting Poland's Energy Sector
ID: 89ee2657-bc41-54b1-94f9-db12af2ea9f4
STIX ID: report--89ee2657-bc41-54b1-94f9-db12af2ea9f4
Feed Name: Elastic Security Labs
**Executive Summary:** On 2025-12-29 a coordinated destructive campaign attributed to an APT cluster targeted Poland's energy infrastructure, impacting 30+ wind and solar farms and a major CHP plant using a custom wiper (DYNOWIPER) that irreversibly corrupted files; the report includes a technical analysis of the sample (hashes, behavior, PRNG-based partial overwrites, forced reboot), IoCs (file hashes, distribution scripts, IP addresses, YARA rule), MITRE ATT&CK mapping, and recommendations such as deploying behavioral canary-based ransomware protection, enforcing MFA on VPNs, and auditing FortiGate/OT device configurations—Elastic Defend canary protection is credited with detecting and blocking execution on many hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
