ESET Attributes Late 2025 Poland Power Grid Cyberattack to Sandworm APT
ESET Research has attributed a significant cyberattack on Poland’s power grid in late 2025 to the Russia-aligned advanced persistent threat (APT) group Sandworm. The incident, described as one of the largest cyberattacks on Poland in recent years, involved the use of data-wiping malware identified by ESET as DynoWiper. While researchers attribute the attack to Sandworm with medium confidence due to strong overlaps with previous tactics, techniques, and procedures, they confirmed that no successful disruption of energy services occurred. The timing of the attack coincided with the tenth anniversary of Sandworm’s historic 2015 assault on Ukraine’s power grid, which caused widespread blackouts. This latest incident underscores the continued threat posed by Sandworm to critical infrastructure in Eastern Europe, particularly following a pattern of regular wiper attacks against Ukrainian targets observed throughout 2025. ESET security solutions detect the specific malware variant as Win32/KillFiles.NMO. The findings highlight the persistent geopolitical tensions manifesting through cyber warfare, with state-aligned actors targeting essential services in neighboring countries. Although the immediate physical impact was mitigated, the event signals an escalation in cyber operations against NATO member states' critical infrastructure.
Wire timeline
ESET Attributes Late 2025 Poland Power Grid Cyberattack to Sandworm APT
ESET Research has attributed a significant cyberattack on Poland’s power grid in late 2025 to the Russia-aligned advanced persistent threat (APT) group Sandworm. The incident, described as one of the largest cyberattacks on Poland in recent years, involved the use of data-wiping malware identified by ESET as DynoWiper. While researchers attribute the attack to Sandworm with medium confidence due to strong overlaps with previous tactics, techniques, and procedures, they confirmed that no successful disruption of energy services occurred. The timing of the attack coincided with the tenth anniversary of Sandworm’s historic 2015 assault on Ukraine’s power grid, which caused widespread blackouts. This latest incident underscores the continued threat posed by Sandworm to critical infrastructure in Eastern Europe, particularly following a pattern of regular wiper attacks against Ukrainian targets observed throughout 2025. ESET security solutions detect the specific malware variant as Win32/KillFiles.NMO. The findings highlight the persistent geopolitical tensions manifesting through cyber warfare, with state-aligned actors targeting essential services in neighboring countries. Although the immediate physical impact was mitigated, the event signals an escalation in cyber operations against NATO member states' critical infrastructure.
WeLiveSecurity