Tag

Dynowiper

All articles tagged with #dynowiper

Coordinated Wiper Attacks Hit 30+ Renewable Farms, Sparking Grid Security Concerns
technology2 months ago

Coordinated Wiper Attacks Hit 30+ Renewable Farms, Sparking Grid Security Concerns

CERT Polska disclosed a coordinated, destructive cyber campaign on Dec 29, 2025 that hit more than 30 wind/solar farms and a CHP plant, disrupting substation communications but not stopping electricity or heat delivery. The attackers deployed wipers (DynoWiper, LazyWiper) via compromised Fortinet devices and Active Directory, used multiple accounts with no two-factor authentication, and leveraged Tor/IPs to access energy networks, with several variants and likely LLM involvement; data was also exfiltrated from OT/cloud services. Attribution to Static Tundra tied to Russia's FSB is stated by CERT Polska, though some researchers link activity to Sandworm.

Sandworm Linked to 2025 Poland Power Grid Attack via DynoWiper, Says ESET
technology2 months ago

Sandworm Linked to 2025 Poland Power Grid Attack via DynoWiper, Says ESET

ESET researchers attribute the late-2025 Poland power grid attack to the Russia-aligned Sandworm APT with medium confidence, identifying the data-wiping malware DynoWiper (Win32/KillFiles.NMO). There are no reports of disruption; the incident aligns with Sandworm’s ongoing wiper activity in Ukraine and falls on the 10th anniversary of the 2015 Ukrainian grid attack.