DynoWiper update: Technical analysis and attribution
ID: 95928fb8-f23b-5760-b3d0-79b78894d836
STIX ID: report--95928fb8-f23b-5760-b3d0-79b78894d836
Feed Name: WeLiveSecurity (ESET Research)
ESET Research analyzes DynoWiper, a destructive data-wiping malware deployed against a Polish energy company in December 2025, describing its three-phase overwrite-and-reboot workflow, file-selection/exclusion logic, deployment methods (including Active Directory Group Policy and execution from a shared directory), associated tools (Rubeus, rsocx), and provided IoCs and MITRE ATT&CK mappings; ESET attributes the wiper to the Russia-aligned Sandworm group with medium confidence and notes that ESET PROTECT blocked execution, limiting impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
