In December 2025, Poland faced a serious cybersecurity incident when its national energy infrastructure became the target of the country’s most significant cyberattack in years.
Investigations pointed to the Russian-aligned threat actor Sandworm, a group infamous for some of the most destructive cyber operations against critical infrastructure worldwide. The attackers introduced a previously unknown data-wiping malware, now dubbed DynoWiper, adding a new tool to Sandworm’s well-documented arsenal.
The incident marked a notable escalation in regional cyber tensions. Strikingly, it occurred exactly ten years after Sandworm’s landmark 2015 attack on Ukraine’s power grid—the first known malware-induced blackout, which left around 230,000 people without electricity. The timing appears intentional, underscoring the group’s intent to send a symbolic and strategic message while showcasing its capabilities.
As DynoWiper propagated within Poland’s electrical networks, the country’s power systems were exposed to real operational risk. Analysts from WeLiveSecurity and researchers at ESET uncovered the malware during an in-depth forensic investigation. They classified it under the detection name Win32/KillFiles.NMO, identifying it as the primary destructive component of the attack. Code analysis further revealed strong links to Sandworm’s established tactics, techniques, and procedures.
DynoWiper’s Destructive Role and Impact
DynoWiper functions as a dedicated file-wiping tool designed to overwrite and permanently destroy data on compromised systems. True to Sandworm’s operational style, the malware focuses on rapid and irreversible damage rather than espionage or long-term persistence. By erasing critical files, it both disables systems and complicates forensic recovery.
Technically, the malware demonstrates a deep understanding of Windows environments and the specific weaknesses found in energy sector networks. Despite the successful breach and deployment of DynoWiper, investigators reported no confirmed disruptions to Poland’s electricity distribution. This outcome suggests that defensive controls may have limited the attack’s effectiveness or that the attackers encountered unforeseen obstacles during execution.
Even without immediate outages, the incident highlights a troubling reality: the successful deployment of wiper malware inside national power infrastructure signals a severe security breach and reinforces growing concerns about the resilience of Europe’s critical energy systems.














Comments