DynoWiper is a Windows data-wiping malware identified during destructive attacks against Poland’s energy sector in late December 2025. It enumerates fixed and removable drives, recursively traverses files while excluding selected system-critical directories, clears file attributes, overwrites file headers and random offsets with pseudorandom data, and deletes targeted files. Documented variants use the MT19937 Mersenne Twister pseudorandom-number generator for overwrite data; one variant enables shutdown privileges and forcibly reboots the compromised host after completing its corruption and deletion phases. The malware is intended to destroy data while retaining sufficient operating-system stability for execution. ESET assessed DynoWiper activity as attributable to the Russia-aligned Sandworm threat group with medium confidence, based on overlaps in destructive tradecraft and coding patterns with prior Sandworm-linked wipers. Its observed use against energy-sector systems demonstrates a focus on disruptive operations against critical infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A custom wiper malware dubbed DYNOWIPER was used to irreversibly destroy data across compromised networks targeting Poland's energy infrastructure.
In this post I’m going over my analysis of DynoWiper, a wiper family that was discovered during attacks against Polish energy companies in late December of 2025.
Although ultimately unsuccessful in causing widespread disruption, the attackers attempted to deploy the destructive DynoWiper malware, a tactic associated with Russian state-backed operations.
Although ultimately unsuccessful in causing widespread disruption, the attackers attempted to deploy the destructive DynoWiper malware, a tactic associated with Russian state-backed operations.
Attackers tried to deploy the destructive DynoWiper malware, a move typically associated with Russian state-backed operations.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
VPN interfaces allowing authentication without multi-factor authentication; Reused credentials across multiple facilities.
The threat actor reportedly gained initial access through Fortinet FortiGate devices exposed to the internet.
Attackers gained initial access through Fortinet FortiGate devices exposed to the internet ... exploiting ... Historical vulnerabilities in unpatched devices.
MITRE ATT&CK Mapping Tactic Execution Technique Scheduled Task/Job T1053.005 ... Monitor for ... GPO modifications creating scheduled tasks with SYSTEM privileges.
MITRE ATT&CK Mapping Tactic Execution Technique Scheduled Task/Job T1053.005 ... Monitor for ... GPO modifications creating scheduled tasks with SYSTEM privileges.
MITRE ATT&CK Mapping Tactic Execution Technique Scheduled Task/Job T1053.005 ... Monitor for ... GPO modifications creating scheduled tasks with SYSTEM privileges.
VPN interfaces allowing authentication without multi-factor authentication; Reused credentials across multiple facilities.
Overwriting the file header with 16 bytes of random data ... generating up to 4,096 random offsets and overwriting each with 16-byte sequences.
The references include multiple wiper campaigns and destructive malware operations such as NotPetya, SwiftSlicer, AcidRain, AcidPour, and DynoWiper associated with Sandworm/APT44.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
52 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive malware referenced as part of the wider Polish campaign; contrasted with this incident because the intrusion here achieved disruption through direct manipulation of industrial devices rather than malware deployment.
Destructive wiper malware used in an attempted cyberattack against Poland’s energy sector; its architecture shows clear destructive intent.
A wiper malware hypothetically delivered via a compromised Apple iOS update, causing disruption of payment services and device ecosystem functionality.
A destructive wiper malware reportedly attempted for use in the December 2025 cyberattack on Poland's power grid, intended to disrupt operations rather than conduct espionage or financial theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.