DynoWiper is a destructive data-wiping malware family used in attacks against Poland’s energy sector in late December 2025. It is designed to damage Windows systems by corrupting files across fixed and removable drives, deleting targeted data, and then forcing a reboot to leave affected hosts inoperable. Reporting links its deployment to Russian state-aligned activity, with multiple assessments associating the campaign with Sandworm at medium confidence.
The analyzed DynoWiper variant is a 32-bit Windows executable that enumerates logical drives, selects fixed and removable media, and recursively traverses directories while excluding key operating-system and application paths. Before modifying files, it clears file attributes, then overwrites the beginning of each targeted file with pseudo-random junk data and, for larger files, writes the same corruption buffer at multiple pseudo-random offsets throughout the file. The malware uses an MT19937 Mersenne Twister pseudorandom number generator to produce overwrite data and limits the number of random corruption offsets per file. After the corruption phase, it performs a second traversal to delete targeted files, enables shutdown privileges, and forces a system reboot.
DynoWiper was observed in a broader destructive campaign affecting critical infrastructure, particularly energy organizations and HMI workstations in operational environments. The wider operation also involved destructive actions against industrial devices and attempts to disrupt communications between renewable-energy hardware and distribution operators. DynoWiper’s role in that campaign was focused on destructive impact rather than espionage, credential theft, or financial extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The DynoWiper variant deployed against HMI systems was implemented in a specific manner, leveraging the Mersenne Twister (MT19937) pseudorandom number generator to produce random data used for overwriting files.
In this post I’m going over my analysis of DynoWiper, a wiper family that was discovered during attacks against Polish energy companies in late December of 2025.
Although ultimately unsuccessful in causing widespread disruption, the attackers attempted to deploy the destructive DynoWiper malware, a tactic associated with Russian state-backed operations.
Although ultimately unsuccessful in causing widespread disruption, the attackers attempted to deploy the destructive DynoWiper malware, a tactic associated with Russian state-backed operations.
Attackers tried to deploy the destructive DynoWiper malware, a move typically associated with Russian state-backed operations.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
“The following are the TTPs … Initial Access T1190 Exploit Public-Facing Application” (DynoWiper section).
EXECUTION Exploitation for Client Execution T1203 Exploited CVE-2011-0611 in Adobe Flash Player to gain execution on a targeted system. Scheduled Task/Job: Scheduled Task T1053.005 Distribution of the wiper within the domain using a Scheduled Task
EXECUTION Exploitation for Client Execution T1203 Exploited CVE-2011-0611 in Adobe Flash Player to gain execution on a targeted system. Scheduled Task/Job: Scheduled Task T1053.005 Distribution of the wiper within the domain using a Scheduled Task
The references include multiple wiper campaigns and destructive malware operations such as NotPetya, SwiftSlicer, AcidRain, AcidPour, and DynoWiper associated with Sandworm/APT44.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive malware referenced as part of the wider Polish campaign; contrasted with this incident because the intrusion here achieved disruption through direct manipulation of industrial devices rather than malware deployment.
Destructive wiper malware used in an attempted cyberattack against Poland’s energy sector; its architecture shows clear destructive intent.
A wiper malware hypothetically delivered via a compromised Apple iOS update, causing disruption of payment services and device ecosystem functionality.
A destructive wiper malware reportedly attempted for use in the December 2025 cyberattack on Poland's power grid, intended to disrupt operations rather than conduct espionage or financial theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.