Researchers and Polish incident responders linked a late-2025 cyberattack on Poland’s energy sector to Russia-aligned group Sandworm, with ESET attributing the operation with medium confidence based on overlaps with earlier Sandworm wiper activity. ESET said the attackers deployed a new data-wiping malware family it named DynoWiper, detected as Win32/KillFiles.NMO, against power-grid targets, while CERT Polska published an incident report on the 29 December 2025 energy-sector attack. ESET said it was not aware of any confirmed successful disruption, and the intended operational impact remained under investigation.
Separate technical analysis of attacks against Polish wind and solar farm grid-connection substations described destructive actions against operational technology used to connect distributed energy resources to distribution operators. The attackers reportedly abused default credentials and weak security on Hitachi Relion IEDs, Hitachi RTU560 controllers, Mikronika RTUs, and Moxa NPort 6000 serial device servers, deleting critical files, wiping filesystems, resetting configurations, and in some cases uploading malicious firmware to effectively soft- or hard-brick devices. Analysts warned that such OT-focused destruction can prolong outages and recovery far beyond conventional IT wiping, echoing tactics seen in earlier Sandworm-linked grid operations such as BlackEnergy and Industroyer.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
CERT Polska published a report covering the incident in the energy sector from 29 December 2025. The reference explicitly identifies the event date in the report title.
On 2025-12-29, attackers hit Poland's energy sector, including wind and solar farm grid-connection substations, causing loss of communications between Grid Connection Points and Distribution System Operators. According to Midnight Blue, the attackers used default credentials and weak device security to access and disrupt multiple OT devices, including Hitachi Relion IEDs, Hitachi RTU560 controllers, Mikronika RTUs, and Moxa NPort 6000 devices.
In the last week of December 2025, the Poland power-grid attack involved a data-wiping malware family that ESET named DynoWiper and detects as Win32/KillFiles.NMO. ESET also published an indicator of compromise for the malware, including SHA-1 hash 4EC3C90846AF6B79EE1A5188EEFA3FD21F6D4CF6.
ESET's APT Activity Report for April to September 2025 said Sandworm was regularly conducting wiper attacks against targets in Ukraine. This established ongoing destructive activity preceding the Poland energy-sector incident.
In 2016, the Industroyer attack targeted the Ukrainian electric grid. The Midnight Blue reference cites it as a prior grid attack and notes use of CVE-2015-5374 against Siemens SIPROTEC 4 IEDs to disable protection and control functions until power-cycled.
In December 2015, Sandworm used BlackEnergy to access critical systems at several electrical substations in Ukraine. The operation caused a multi-hour power outage affecting about 230,000 people.
ESET Research attributed the late-2025 cyberattack targeting Poland's power grid and energy sector to the Russia-aligned APT group Sandworm with medium confidence, based on malware analysis and overlap with prior Sandworm wiper tradecraft. ESET said it was not aware of any successful disruption from the attack and that the intended impact remained under investigation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cert.pl
Open sourcemidnightblue.nl
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.