PULSE NAME
Energy Sector Incident Report
WHITE Static Tundra AlienVault 2026-04-30 Modified: 2026-05-30
38
IOCs
MEDIUM VOLUME
On December 29, 2025, coordinated destructive cyberattacks targeted Poland's energy infrastructure during severe winter weather. Approximately 30 wind and solar farms, a manufacturing company, and a combined heat and power plant serving nearly 500,000 customers were affected. Attackers exploited vulnerable FortiGate perimeter devices using stolen credentials and default passwords to access industrial control systems. Multiple types of wiper malware, including DynoWiper and LazyWiper, were deployed to destroy data across IT and OT environments. While renewable facilities lost communication with distribution operators without affecting electricity generation, the incidents demonstrated significant capability to cause physical disruption. Infrastructure analysis revealed connections to threat clusters known as Static Tundra, Ghost Blizzard, and potentially Sandworm, marking a notable escalation in cyber-sabotage operations.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
DynoWiper LazyWiper Impacket Rubeus
Indicators of Compromise (5 / 38 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 0e7dba87909836896f8072d213fa2da9afae3633 2026-04-30
FileHash-SHA1 4ec3c90846af6b79ee1a5188eefa3fd21f6d4cf6 2026-04-30
FileHash-SHA1 608a0b34ab3a1625cb88fcbc9a5e4be809519390 2026-04-30
FileHash-SHA1 69ede7e341fd26fa0577692b601d80cb44778d93 2026-04-30
FileHash-SHA1 86596a5c5b05a8bfbd14876de7404702f7d0d61b 2026-04-30