Wiper malware targets Poland's energy grid but causes no blackout

Researchers have attributed a failed cyberattack on Poland's electric grid to Russian state hackers, coinciding with the 10th anniversary of a similar assault on Ukraine. The wiper malware aimed to disrupt power distribution but did not succeed in knocking out electricity. Security firm ESET linked the incident to the notorious Sandworm group.

In late December, Poland's energy infrastructure faced a cyber threat when wiper malware was deployed against its electric grid. The attack, which occurred during the last week of the month, sought to sever communications between renewable energy installations and power distribution operators. However, it failed to cause any disruptions to electricity supply, for reasons that remain unclear.

ESET, a cybersecurity firm, analyzed the malware and identified it as DynoWiper, a destructive tool designed to permanently erase code and data on servers. The researchers attributed the operation to the Russia-aligned Sandworm advanced persistent threat (APT) group with medium confidence, citing overlaps in tactics, techniques, and procedures with prior Sandworm activities. "Based on our analysis of the malware and associated TTPs, we attribute the attack to the Russia-aligned Sandworm APT with medium confidence due to a strong overlap with numerous previous Sandworm wiper activity we analyzed," the firm stated. ESET emphasized that no successful disruptions resulted from this incident.

Sandworm has a track record of deploying wipers in geopolitical conflicts. Notably, on December 23, 2015—exactly 10 years before this attack—the group used BlackEnergy malware to black out power for about 230,000 Ukrainians for six hours during winter. More recently, in 2022, Sandworm's AcidRain wiper targeted 270,000 satellite modems in Ukraine, marking the seventh such tool used since Russia's invasion. The group also hit Ukrainian universities and critical infrastructure with multiple wipers last year. The 2017 NotPetya worm, another Sandworm creation, spread globally despite targeting Ukraine, causing an estimated $10 billion in damages.

Speculation surrounds DynoWiper's failure: it might have been a deliberate show of force to avoid escalating tensions with Poland's NATO allies, or robust cyber defenses could have neutralized it. This event underscores ongoing hybrid threats to European energy systems amid regional tensions.

Makala yanayohusiana

Dramatic illustration of Stryker's operations center disrupted by Iran-linked cyberattack, with error-filled screens and intact medical devices.
Picha iliyoundwa na AI

Iran-linked hackers disrupt Stryker's network in apparent retaliation

Imeripotiwa na AI Picha iliyoundwa na AI

A cyberattack attributed to the Iran-aligned Handala Hack group has disrupted the Microsoft environment of medical device maker Stryker, paralyzing much of its global operations. The incident, which emerged shortly after US and Israeli airstrikes on Iran, involved data wiping across tens of thousands of computers. Stryker confirmed the attack is contained, with no impact on its critical medical devices.

Journalists reported mysterious phishing attempts by unknowns a few weeks ago. The Dutch secret service now holds Russia responsible for attacks on the messaging apps WhatsApp and Signal. The report explains how the attacks work and how users can protect themselves.

Imeripotiwa na AI

Daemon Tools, a popular disk image mounting app, was compromised in a supply-chain attack starting April 8, delivering malware through official updates. Security firm Kaspersky reported infections on thousands of machines across over 100 countries. Users are urged to scan their systems immediately.

Jumapili, 10. Mwezi wa tano 2026, 02:50:39

FBI urges router security steps after Russian GRU attacks

Jumanne, 7. Mwezi wa nne 2026, 17:23:00

Western agencies warn of russian hackers on tp-link routers

Jumanne, 7. Mwezi wa nne 2026, 12:51:14

US agencies warn of Iranian hackers targeting critical infrastructure PLCs

Jumamosi, 21. Mwezi wa tatu 2026, 06:05:18

Cyberattack on car breathalyzer firm leaves drivers stuck

Alhamisi, 12. Mwezi wa tatu 2026, 22:40:07

US and Europe disrupt SocksEscort proxy network

Tovuti hii inatumia vidakuzi

Tunatumia vidakuzi kwa uchambuzi ili kuboresha tovuti yetu. Soma sera ya faragha yetu kwa maelezo zaidi.
Kataa