← Back to Pulse Feed
PULSE DETAIL
On December 29, 2025, coordinated destructive cyberattacks targeted Poland's energy infrastructure during severe winter weather. Approximately 30 wind and solar farms, a manufacturing company, and a combined heat and power plant serving nearly 500,000 customers were affected. Attackers exploited vulnerable FortiGate perimeter devices using stolen credentials and default passwords to access industrial control systems. Multiple types of wiper malware, including DynoWiper and LazyWiper, were deployed to destroy data across IT and OT environments. While renewable facilities lost communication with distribution operators without affecting electricity generation, the incidents demonstrated significant capability to cause physical disruption. Infrastructure analysis revealed connections to threat clusters known as Static Tundra, Ghost Blizzard, and potentially Sandworm, marking a notable escalation in cyber-sabotage operations.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
DynoWiper
LazyWiper
Impacket
Rubeus
Indicators of Compromise (7 / 38 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 033cb31c081ff4292f82e528f5cb78a503816462daba8cc18a6c4531009602c2 | — | 2026-04-30 | |
| FileHash-SHA256 | 60c70cdcb1e998bffed2e6e7298e1ab6bb3d90df04e437486c04e77c411cae4b | — | 2026-04-30 | |
| FileHash-SHA256 | 65099f306d27c8bcdd7ba3062c012d2471812ec5e06678096394b238210f0f7c | — | 2026-04-30 | |
| FileHash-SHA256 | 835b0d87ed2d49899ab6f9479cddb8b4e03f5aeb2365c50a51f9088dcede68d5 | — | 2026-04-30 | |
| FileHash-SHA256 | 8759e79cf3341406564635f3f08b2f333b0547c444735dba54ea6fce8539cf15 | — | 2026-04-30 | |
| FileHash-SHA256 | d1389a1ff652f8ca5576f10e9fa2bf8e8398699ddfc87ddd3e26adb201242160 | — | 2026-04-30 | |
| FileHash-SHA256 | f4e9a3ddb83c53f5b7717af737ab0885abd2f1b89b2c676d3441a793f65ffaee | — | 2026-04-30 |