Russia-linked Sandworm APT implicated in major cyber attack on Poland’s power grid
ID: 696911ab-c3c2-5cf3-acd9-a2e04bf50726
STIX ID: report--696911ab-c3c2-5cf3-acd9-a2e04bf50726
Feed Name: Security Affairs
Threat Score
ESET reported discovery of DynoWiper, a destructive Win32 wiper used in an attempted attack on Poland’s energy sector on 29 December 2025, attributing the operation with medium confidence to the Russia-linked Sandworm APT based on strong overlaps in malware traits and TTPs; the firm shared IoC data for defenders, and while the malware shows clear destructive intent, no confirmed disruption of service has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
