Sandworm behind cyberattack on Poland’s power grid in late 2025

Have you heard about the latest cyberattack on Poland’s energy system? ESET researchers have analyzed the data-wiping malware behind it and named it DynoWiper.

Let’s dive into the details of the recent cyberattack on Poland’s energy system that has been linked to the Russia-aligned APT group Sandworm. ESET Research has uncovered crucial information about the attack and its perpetrators.

Screenshot 2026-01-23 200943
Source: ESET Research

If you’re wondering about the impact of this cyberattack and the significance of the DynoWiper malware, keep reading. ESET security solutions have identified DynoWiper as Win32/KillFiles.NMO, shedding light on the tactics used by Sandworm in their malicious activities.

As we reflect on the history of Sandworm’s cyberattacks, particularly in Ukraine, it becomes evident that their operations pose a significant threat to critical infrastructure. Stay informed about the latest developments by checking out ESET’s latest APT Activity Report.

If you have any questions or want to learn more about our research, feel free to reach out to us at threatintel@eset.com.

For tailored APT intelligence reports and data feeds, explore the offerings on the ESET Threat Intelligence page.

IoCs

SHA-1 Detection Description
4EC3C90846AF6B79EE1A5188EEFA3FD21F6D4CF6 Win32/KillFiles.NMO DynoWiper

Leave a Reply

Your email address will not be published. Required fields are marked *