PULSE NAME
Energy Sector Incident Report
WHITE Static Tundra AlienVault 2026-04-30 Modified: 2026-05-30
38
IOCs
MEDIUM VOLUME
On December 29, 2025, coordinated destructive cyberattacks targeted Poland's energy infrastructure during severe winter weather. Approximately 30 wind and solar farms, a manufacturing company, and a combined heat and power plant serving nearly 500,000 customers were affected. Attackers exploited vulnerable FortiGate perimeter devices using stolen credentials and default passwords to access industrial control systems. Multiple types of wiper malware, including DynoWiper and LazyWiper, were deployed to destroy data across IT and OT environments. While renewable facilities lost communication with distribution operators without affecting electricity generation, the incidents demonstrated significant capability to cause physical disruption. Infrastructure analysis revealed connections to threat clusters known as Static Tundra, Ghost Blizzard, and potentially Sandworm, marking a notable escalation in cyber-sabotage operations.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
DynoWiper LazyWiper Impacket Rubeus
Indicators of Compromise (7 / 38 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 033cb31c081ff4292f82e528f5cb78a503816462daba8cc18a6c4531009602c2 2026-04-30
FileHash-SHA256 60c70cdcb1e998bffed2e6e7298e1ab6bb3d90df04e437486c04e77c411cae4b 2026-04-30
FileHash-SHA256 65099f306d27c8bcdd7ba3062c012d2471812ec5e06678096394b238210f0f7c 2026-04-30
FileHash-SHA256 835b0d87ed2d49899ab6f9479cddb8b4e03f5aeb2365c50a51f9088dcede68d5 2026-04-30
FileHash-SHA256 8759e79cf3341406564635f3f08b2f333b0547c444735dba54ea6fce8539cf15 2026-04-30
FileHash-SHA256 d1389a1ff652f8ca5576f10e9fa2bf8e8398699ddfc87ddd3e26adb201242160 2026-04-30
FileHash-SHA256 f4e9a3ddb83c53f5b7717af737ab0885abd2f1b89b2c676d3441a793f65ffaee 2026-04-30