Skip to content
Breaking
Latest technical intelligence from Northeast India • Infrastructure, AI, Cloud & Security Analysis • Precision Analysis | Raw Intelligence | Your North Star of Tech Latest technical intelligence from Northeast India • Infrastructure, AI, Cloud & Security Analysis • Precision Analysis | Raw Intelligence | Your North Star of Tech
SECURITY

Analysis: New DynoWiper Malware Used in Attempted Sandworm Attack on Polish Power Sector

Sandworm's Resurgence: A Threat to Critical Infrastructure in Poland and Beyond

A Significant Cyber Threat to Poland's Power Sector

In a chilling reminder of the growing cyber threats against critical infrastructure, Poland faced an attempted cyber attack on its power system by the Russian hacking group Sandworm in late December 2025. Despite the attack's failure, the incident serves as a stark warning of the vulnerabilities in the energy sector and the potential for disastrous consequences.

The Emergence of DynoWiper Malware

The attack, uncovered by Slovakian cybersecurity company ESET, involved a previously undocumented wiper malware known as DynoWiper. The links to Sandworm are based on overlaps with prior wiper activity associated with the adversary, particularly in the aftermath of Russia's military invasion of Ukraine in February 2022. ESET identified the use of DynoWiper as part of the attempted disruptive attack aimed at the Polish energy sector on December 29, 2025.

Targeted Infrastructure

The attacks targeted two combined heat and power (CHP) plants, as well as a system enabling the management of electricity generated from renewable energy sources such as wind turbines and photovoltaic farms. The Polish government stated that everything indicates these attacks were prepared by groups directly linked to the Russian services.

The Broader Implications

The activity occurred on the tenth anniversary of Sandworm's attack against the Ukrainian power grid in December 2015, which led to the deployment of the BlackEnergy malware, plunging parts of the Ivano-Frankivsk region of Ukraine into darkness. The incident underscores Sandworm's long history of disruptive cyberattacks, especially on Ukraine's critical infrastructure.

The North East India Connection

While the immediate impact of this cyber threat is felt in Poland and Ukraine, the implications for the North East region of India are not insignificant. The region is home to several critical infrastructure facilities, including power plants, and is increasingly reliant on digital systems for their operation. The success of such attacks could have devastating consequences for the region's energy security.

A Shifting Cyber Landscape

The continued use of data-wiping malware by Sandworm against critical infrastructure entities in various sectors suggests a growing trend in cyber warfare. As nations become more dependent on digital systems, the potential for disruptive attacks increases, making it crucial for governments and private entities to invest in robust cybersecurity measures.