logo

Russia-linked Sandworm APT implicated in major cyber attack on Poland’s power grid

ID: 696911ab-c3c2-5cf3-acd9-a2e04bf50726

STIX ID: report--696911ab-c3c2-5cf3-acd9-a2e04bf50726

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-01-26

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

ESET reported discovery of DynoWiper, a destructive Win32 wiper used in an attempted attack on Poland’s energy sector on 29 December 2025, attributing the operation with medium confidence to the Russia-linked Sandworm APT based on strong overlaps in malware traits and TTPs; the firm shared IoC data for defenders, and while the malware shows clear destructive intent, no confirmed disruption of service has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.