logo

DynoWiper update: Technical analysis and attribution

ID: 95928fb8-f23b-5760-b3d0-79b78894d836

STIX ID: report--95928fb8-f23b-5760-b3d0-79b78894d836

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2026-01-30

Date Updated: 2026-05-01

...
...

ESET Research analyzes DynoWiper, a destructive data-wiping malware deployed against a Polish energy company in December 2025, describing its three-phase overwrite-and-reboot workflow, file-selection/exclusion logic, deployment methods (including Active Directory Group Policy and execution from a shared directory), associated tools (Rubeus, rsocx), and provided IoCs and MITRE ATT&CK mappings; ESET attributes the wiper to the Russia-aligned Sandworm group with medium confidence and notes that ESET PROTECT blocked execution, limiting impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.