ESET Attributes DynoWiper Cyberattack on Polish Energy Firm to Sandworm
ESET researchers have released a technical analysis attributing a recent data destruction incident targeting a company in Poland’s energy sector to the Russia-aligned threat group Sandworm. The attack utilized a newly identified data-wiping malware named DynoWiper. Analysts observed that the tactics, techniques, and procedures (TTPs) employed in this incident closely resemble those used in earlier attacks involving the ZOV wiper in Ukraine. Consequently, ESET attributes DynoWiper to Sandworm with medium confidence, distinguishing it from the high-confidence attribution of the ZOV wiper. Sandworm, associated with Unit 74455 of the Russian GRU, has a long history of conducting destructive cyberoperations against critical infrastructure, including previous power grid attacks in Ukraine and the NotPetya campaign. This report highlights the group's continued evolution in deploying unique wiper malware variants to evade detection while targeting strategic sectors in neighboring countries. The findings underscore the persistent threat posed by state-sponsored actors to European energy infrastructure and the sophisticated nature of their destructive capabilities.
Wire timeline
ESET Attributes DynoWiper Cyberattack on Polish Energy Firm to Sandworm
ESET researchers have released a technical analysis attributing a recent data destruction incident targeting a company in Poland’s energy sector to the Russia-aligned threat group Sandworm. The attack utilized a newly identified data-wiping malware named DynoWiper. Analysts observed that the tactics, techniques, and procedures (TTPs) employed in this incident closely resemble those used in earlier attacks involving the ZOV wiper in Ukraine. Consequently, ESET attributes DynoWiper to Sandworm with medium confidence, distinguishing it from the high-confidence attribution of the ZOV wiper. Sandworm, associated with Unit 74455 of the Russian GRU, has a long history of conducting destructive cyberoperations against critical infrastructure, including previous power grid attacks in Ukraine and the NotPetya campaign. This report highlights the group's continued evolution in deploying unique wiper malware variants to evade detection while targeting strategic sectors in neighboring countries. The findings underscore the persistent threat posed by state-sponsored actors to European energy infrastructure and the sophisticated nature of their destructive capabilities.
WeLiveSecurity