DynoWiper is a destructive Windows data-wiping malware first documented in late 2025 during attacks against Poland’s energy sector and other critical infrastructure environments. It is designed to damage systems rather than support espionage, credential theft, or monetization. The malware overwrites data on fixed and removable drives, deletes or corrupts file contents at scale, and in some observed variants forces a reboot after the wiping phase, leaving affected systems inoperable and hindering recovery. Reported behavior includes selective avoidance of some system-critical directories to preserve execution long enough to maximize destructive impact, as well as use in conjunction with broader recovery-inhibition measures such as shadow-copy deletion and boot-impacting actions during the overall intrusion.
DynoWiper was deployed during coordinated destructive operations in Poland that affected renewable-energy facilities, a combined heat and power plant, and related industrial environments. In those incidents, attackers used DynoWiper alongside native commands to destroy data on HMI workstations and to support disruptive effects against OT-connected environments, while separate destructive actions targeted RTUs, protection relays, and other field devices. Distribution inside victim networks was achieved through enterprise administration mechanisms including Group Policy Objects after the adversary had already obtained privileged access.
The malware has been attributed with medium confidence by ESET to Sandworm, the Russian state-linked threat group also tracked as APT44, based on overlaps in tactics and coding patterns with prior Sandworm wiper activity. Other public reporting on the broader Poland incidents has also discussed overlap with Russia-linked clusters tracked under names including Static Tundra, Berserk Bear, Ghost Blizzard, and Dragonfly, so unit-level attribution for the campaign is not fully settled across all sources. What is consistent is DynoWiper’s role as a purpose-built destructive wiper used in attacks on critical infrastructure, especially the energy sector.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Although ultimately unsuccessful in causing widespread disruption, the attackers attempted to deploy the destructive DynoWiper malware, a tactic associated with Russian state-backed operations.
Although ultimately unsuccessful in causing widespread disruption, the attackers attempted to deploy the destructive DynoWiper malware, a tactic associated with Russian state-backed operations.
Attackers tried to deploy the destructive DynoWiper malware, a move typically associated with Russian state-backed operations.
The incident was later attributed to the Russian state-backed hacking group Sandworm, which attempted to deploy the destructive DynoWiper data-wiping malware and disable compromised devices.
Malware Family DYNOWIPER Destructive wiper malware attributed to ENERGETIC BEAR; hosted on CLODO CLOUD SERVICE (UAE)
15 distinct techniques documented for this family, organized by ATT&CK tactic.
“Distribution of the wiper within the domain using a Scheduled Task” / “defines a ScheduledTask that executes with NT AUTHORITY\SYSTEM… deletes itself…”
Attackers tried to deploy the destructive DynoWiper malware, a move typically associated with Russian state-backed operations.
The references include multiple wiper campaigns and destructive malware operations such as NotPetya, SwiftSlicer, AcidRain, AcidPour, and DynoWiper associated with Sandworm/APT44.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A wiper malware hypothetically delivered via a compromised Apple iOS update, causing disruption of payment services and device ecosystem functionality.
A destructive wiper malware reportedly attempted for use in the December 2025 cyberattack on Poland's power grid, intended to disrupt operations rather than conduct espionage or financial theft.
A destructive data-wiping malware used in an attempted attack on Poland's power grid operational technology environment.
Destructive wiper malware reportedly attempted for use in the December 2025 cyberattack on Poland's power grid.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.