logo

Sandworm hackers linked to failed wiper attack on Poland’s energy systems

ID: 50f4138b-e607-5d66-af11-b310841c9dab

STIX ID: report--50f4138b-e607-5d66-af11-b310841c9dab

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-01-24

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

A late-December 2025 cyberattack on Polish energy infrastructure has been attributed to Russian state-sponsored APT Sandworm (linked to GRU unit 74455). The actors attempted to deploy a destructive data-wiping malware called DynoWiper (detected by ESET as Win32/KillFiles.NMO, SHA-1: 4EC3C90846AF6B79EE1A5188EEFA3FD21F6D4CF6) against combined heat and power plants and a renewable generation management system; attribution and impact are reported by Polish officials and ESET, but technical details and public samples are limited.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.