DynoWiper is a destructive Windows malware family discovered during coordinated attacks against Poland’s energy sector on December 29, 2025. It was deployed against compromised Windows systems, including human-machine interface (HMI) workstations, in a campaign targeting renewable-energy facilities and a combined heat and power plant. Its purpose is data destruction rather than encryption for ransom.
Implemented as a 32-bit Windows executable, DynoWiper enumerates fixed and removable drives and recursively traverses their directories. It clears file-protection attributes, overwrites file headers and selected offsets with pseudorandom data generated using the MT19937 Mersenne Twister algorithm, and subsequently deletes targeted files. The analyzed implementation writes 16-byte corruption blocks at the beginning of files and at up to 4,096 additional offsets per file. It excludes selected system and application directories, preserving host stability while destructive processing proceeds. Version A enables the shutdown privilege and forcibly reboots the system after corruption and deletion; Version B omits the reboot function and introduces a five-second delay between those phases. No persistence mechanism or command-and-control functionality has been identified in the analyzed variants.
The wider campaign involved initial access through internet-exposed Fortinet FortiGate remote-access infrastructure and subsequent deployment inside compromised networks. The UK and European Union formally attributed the campaign to Russia’s FSB Centre 16; attack infrastructure was associated with the cluster tracked as Static Tundra, Berserk Bear, Ghost Blizzard, and Dragonfly. Behavioral endpoint protections blocked DynoWiper’s destructive activity in affected environments, and the campaign did not cause widespread power disruption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A custom wiper malware dubbed DYNOWIPER was used to irreversibly destroy data across compromised networks targeting Poland's energy infrastructure.
In this post I’m going over my analysis of DynoWiper, a wiper family that was discovered during attacks against Polish energy companies in late December of 2025.
Although ultimately unsuccessful in causing widespread disruption, the attackers attempted to deploy the destructive DynoWiper malware, a tactic associated with Russian state-backed operations.
Although ultimately unsuccessful in causing widespread disruption, the attackers attempted to deploy the destructive DynoWiper malware, a tactic associated with Russian state-backed operations.
Attackers tried to deploy the destructive DynoWiper malware, a move typically associated with Russian state-backed operations.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
VPN interfaces allowing authentication without multi-factor authentication; Reused credentials across multiple facilities.
The threat actor reportedly gained initial access through Fortinet FortiGate devices exposed to the internet.
MITRE ATT&CK Mapping Tactic Execution Technique Scheduled Task/Job T1053.005 ... Monitor for ... GPO modifications creating scheduled tasks with SYSTEM privileges.
MITRE ATT&CK Mapping Tactic Execution Technique Scheduled Task/Job T1053.005 ... Monitor for ... GPO modifications creating scheduled tasks with SYSTEM privileges.
VPN interfaces allowing authentication without multi-factor authentication; Reused credentials across multiple facilities.
“Defense Evasion T1070 Indicator Removal” (Sicarii) and “Defense Evasion T1070 Indicator Removal on Host” (DynoWiper).
VPN interfaces allowing authentication without multi-factor authentication; Reused credentials across multiple facilities.
Removing file protection attributes via SetFileAttributesW(FILE_ATTRIBUTE_NORMAL).
For each applicable file, attributes are cleared with SetFileAttributesW()
Overwriting the file header with 16 bytes of random data ... generating up to 4,096 random offsets and overwriting each with 16-byte sequences.
The references include multiple wiper campaigns and destructive malware operations such as NotPetya, SwiftSlicer, AcidRain, AcidPour, and DynoWiper associated with Sandworm/APT44.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
53 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive malware referenced as part of the wider Polish campaign; contrasted with this incident because the intrusion here achieved disruption through direct manipulation of industrial devices rather than malware deployment.
Destructive wiper malware used in an attempted cyberattack against Poland’s energy sector; its architecture shows clear destructive intent.
A wiper malware hypothetically delivered via a compromised Apple iOS update, causing disruption of payment services and device ecosystem functionality.
A destructive wiper malware reportedly attempted for use in the December 2025 cyberattack on Poland's power grid, intended to disrupt operations rather than conduct espionage or financial theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.