Sandworm Linked to 2025 Poland Power Grid Attack via DynoWiper, Says ESET

TL;DR Summary
ESET researchers attribute the late-2025 Poland power grid attack to the Russia-aligned Sandworm APT with medium confidence, identifying the data-wiping malware DynoWiper (Win32/KillFiles.NMO). There are no reports of disruption; the incident aligns with Sandworm’s ongoing wiper activity in Ukraine and falls on the 10th anniversary of the 2015 Ukrainian grid attack.
- ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025 WeLiveSecurity
- New DynoWiper Malware Used in Attempted Sandworm Attack on Polish Power Sector The Hacker News
- Cyberattack Targeting Poland’s Energy Grid Used a Wiper zetter-zeroday.com
- Researchers say Russian government hackers were behind attempted Poland power outage TechCrunch
- Wiper malware targeted Poland energy grid, but failed to knock out electricity Ars Technica
Reading Insights
Total Reads
0
Unique Readers
2
Time Saved
2 min
vs 2 min read
Condensed
85%
351 → 51 words
Want the full story? Read the original article
Read on WeLiveSecurity