{"id":11187,"date":"2026-01-26T23:04:46","date_gmt":"2026-01-26T23:04:46","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=11187"},"modified":"2026-01-26T23:04:46","modified_gmt":"2026-01-26T23:04:46","slug":"sandworm-behind-cyberattack-on-polands-energy-grid-in-late-2025","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=11187","title":{"rendered":"Sandworm behind cyberattack on Poland\u2019s energy grid in late 2025"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"sub-title\">The assault concerned data-wiping malware that ESET researchers have now analyzed and named DynoWiper<\/p>\n<div class=\"article-authors d-flex flex-wrap\">\n<div class=\"article-author d-flex\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/our-experts\/eset-research\/\" title=\"ESET Research\"><picture><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x45\/wls\/2022\/03\/twitter_profile_picture_400x400.png\" media=\"(max-width: 768px)\"\/><img decoding=\"async\" class=\"author-image me-3\" src=\"https:\/\/web-assets.esetstatic.com\/tn\/-x45\/wls\/2022\/03\/twitter_profile_picture_400x400.png\" alt=\"ESET Research\"\/><\/picture><\/a><\/div>\n<\/div>\n<p class=\"article-info mb-5\">\n        <span>23 Jan 2026<\/span><br \/>\n        <span class=\"d-none d-lg-inline\">\u00a0\u2022\u00a0<\/span><br \/>\n        <span class=\"d-inline d-lg-none\">, <\/span><br \/>\n        <span>1 min. learn<\/span>\n    <\/p>\n<div class=\"hero-image-container\">\n        <picture><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x266\/wls\/2026\/01-26\/sandworm-poland-attack.jpg\" media=\"(max-width: 768px)\"\/><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x425\/wls\/2026\/01-26\/sandworm-poland-attack.jpg\" media=\"(max-width: 1120px)\"\/><img decoding=\"async\" class=\"hero-image\" src=\"https:\/\/web-assets.esetstatic.com\/tn\/-x700\/wls\/2026\/01-26\/sandworm-poland-attack.jpg\" alt=\"ESET Research: Sandworm behind cyberattack on Poland\u2019s power grid in late 2025\"\/><\/picture>    <\/div>\n<\/div>\n<div>\n<p>In late 2025, Poland\u2019s power system confronted what has been described because the \u201c<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.reuters.com\/sustainability\/climate-energy\/massive-cyberattack-polish-power-system-december-failed-minister-says-2026-01-13\/\">largest cyberattack<\/a>\u201d focusing on the nation in years. ESET Analysis has now discovered that the assault was the work of the infamous Russia-aligned APT group Sandworm.<\/p>\n<p>\u201cPrimarily based on our evaluation of the malware\u00a0and related TTPs, we attribute\u00a0the assault to the Russia-aligned Sandworm APT with medium confidence resulting from a robust overlap with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/2023\/02\/24\/year-wiper-attacks-ukraine\/\" target=\"_blank\" rel=\"noopener\">quite a few earlier Sandworm wiper exercise<\/a> we analyzed,\u201d stated ESET researchers. \u201cWe\u2019re not conscious of any profitable disruption occurring because of this assault,\u201d they added.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2026\/01-26\/screenshot-2026-01-23-200943.png\" alt=\"Screenshot 2026-01-23 200943\" width=\"\" height=\"\"\/><figcaption>Supply:\u00a0<a rel=\"nofollow\" target=\"_blank\" title=\"https:\/\/bsky.app\/profile\/esetresearch.bsky.social\/post\/3md44r4veyc2e\" href=\"https:\/\/bsky.app\/profile\/esetresearch.bsky.social\/post\/3md44r4veyc2e\" target=\"_blank\" rel=\"noopener\">ESET Analysis<\/a><\/figcaption><\/figure>\n<p><a rel=\"nofollow\" target=\"_blank\" name=\"_Hlk220075053\"\/>Sandworm has a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/2022\/03\/21\/sandworm-tale-disruption-told-anew\/\" target=\"_blank\" rel=\"noopener\">lengthy historical past<\/a> of disruptive cyberattacks, particularly on Ukraine\u2019s vital infrastructure. In the meantime, the assault on Poland\u2019s energy grid within the final week of December concerned data-wiping malware that ESET has now analyzed and named DynoWiper. ESET safety options detect DynoWiper as Win32\/KillFiles.NMO.<\/p>\n<p>Whereas particulars concerning the supposed affect proceed to be investigated, ESET researchers have highlighted the truth that the coordinated assault occurred on the ten<sup>th<\/sup> anniversary of the Sandworm-orchestrated assault in opposition to the Ukrainian energy grid, which resulted within the first ever malware-facilitated blackout. Again in December 2015, Sandworm used the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/2016\/01\/04\/blackenergy-trojan-strikes-again-attacks-ukrainian-electric-power-industry\/\" target=\"_blank\" rel=\"noopener\">BlackEnergy<\/a> malware to realize entry to vital techniques at a number of electrical substations, leaving round 230,000 folks with out electrical energy for a number of hours.<\/p>\n<p>Quick ahead a decade and Sandworm continues to focus on entities working in varied vital infrastructure sectors, particularly in Ukraine. Of their <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/web-assets.esetstatic.com\/wls\/en\/papers\/threat-reports\/eset-apt-activity-report-q2-2025-q3-2025.pdf#page=21\" target=\"_blank\" rel=\"noopener\">newest APT Exercise Report<\/a>, overlaying April to September 2025, ESET researchers famous that they noticed Sandworm conducting wiper assaults in opposition to targets in Ukraine regularly.<\/p>\n<blockquote>\n<div>For any inquiries about our analysis revealed on WeLiveSecurity, please contact us at\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/eset-research-sandworm-cyberattack-poland-power-grid-late-2025\/mailto:threatintel@eset.com?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=autotagging&amp;utm_content=eset-research&amp;utm_term=en\">threatintel@eset.com<\/a>.<\/p>\n<div>ESET Analysis affords personal APT intelligence stories and knowledge feeds. For any inquiries about this service, go to the\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.eset.com\/int\/business\/services\/threat-intelligence\/\" target=\"_blank\" rel=\"noopener\">ESET Risk Intelligence<\/a>\u00a0web page.<\/div>\n<\/div>\n<\/blockquote>\n<h3>IoCs<\/h3>\n<table border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"322\"><strong>SHA-1 <\/strong><\/td>\n<td width=\"94\"><strong>Detection<\/strong><\/td>\n<td width=\"94\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"322\"><span style=\"font-family: courier new, courier, monospace;\">4EC3C90846AF6B79EE1A5188EEFA3FD21F6D4CF6<\/span><\/td>\n<td width=\"94\">Win32\/KillFiles.NMO<\/td>\n<td width=\"94\">DynoWiper.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>The assault concerned data-wiping malware that ESET researchers have now analyzed and named DynoWiper 23 Jan 2026 \u00a0\u2022\u00a0 , 1 min. learn In late 2025, Poland\u2019s power system confronted what has been described because the \u201clargest cyberattack\u201d focusing on the nation in years. ESET Analysis has now discovered that the assault was the work of [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":11189,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[2701,2197,5468,7573,763,7572],"class_list":["post-11187","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cyberattack","tag-grid","tag-late","tag-polands","tag-power","tag-sandworm"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/11187","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=11187"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/11187\/revisions"}],"predecessor-version":[{"id":11188,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/11187\/revisions\/11188"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/11189"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=11187"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=11187"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=11187"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69c6f7b5190636d50e9f6768. Config Timestamp: 2026-03-27 21:33:41 UTC, Cached Timestamp: 2026-04-05 13:03:12 UTC -->