Have you heard about the latest cyberattack on Poland’s energy system? ESET researchers have analyzed the data-wiping malware behind it and named it DynoWiper.
23 Jan 2026
•
,
1 min. read
Let’s dive into the details of the recent cyberattack on Poland’s energy system that has been linked to the Russia-aligned APT group Sandworm. ESET Research has uncovered crucial information about the attack and its perpetrators.

If you’re wondering about the impact of this cyberattack and the significance of the DynoWiper malware, keep reading. ESET security solutions have identified DynoWiper as Win32/KillFiles.NMO, shedding light on the tactics used by Sandworm in their malicious activities.
As we reflect on the history of Sandworm’s cyberattacks, particularly in Ukraine, it becomes evident that their operations pose a significant threat to critical infrastructure. Stay informed about the latest developments by checking out ESET’s latest APT Activity Report.
If you have any questions or want to learn more about our research, feel free to reach out to us at threatintel@eset.com.For tailored APT intelligence reports and data feeds, explore the offerings on the ESET Threat Intelligence page.
IoCs
| SHA-1 | Detection | Description |
| 4EC3C90846AF6B79EE1A5188EEFA3FD21F6D4CF6 | Win32/KillFiles.NMO | DynoWiper |
