Campaign · all campaigns
2025 Poland Wiper AttacksC0063 state
🇷🇺 RU
aka 2025 Poland Wiper Attacks, 2025 Poland Wiper Campaign
Last updated: 2026-08-20
About this actor
[2025 Poland Wiper Attacks](https://attack.mitre.org/campaigns/C0063) is a Russian state-sponsored campaign that conducted destructive cyberattacks against Polish energy infrastructure in December 2025. Targets included more than 30 wind and photovoltaic farms, a combined heat and power (CHP) plant, and a manufacturing sector company. The attacks on the distributed energy resources (DER) disrupted communications between affected facilities and the distribution system operator, but did not impact electricity generation or heat supply. Across the campaign, threat actors deployed two previously undocumented wiper tools, [DynoWiper](https://attack.mitre.org/software/S9038), a Windows-based wiper and [LazyWiper](https://attack.mitre.org/software/S9039), a PowerShell wiper, distributed via malicious Group Policy Objects. At the CHP plant, threat actors had maintained access since at least March 2025, using that foothold to obtain credentials and move laterally before attempting wiper deployment. Some reporting has assessed the activity to be consistent with Russian Federal Security Service (FSB) threat activity group [Dragonfly](https://attack.mitre.org/groups/G0035), also tracked as STATIC TUNDRA, while other reporting attributes the destructive wiper activities to the Russian General Staff Main Intelligence Directorate (GRU) threat activity group ELECTRUM, also tracked as [Sandworm Team](https://attack.mitre.org/groups/G0034).(Citation: CERT Polska)(Citation: Dragos ELECTRUM JAN 2026)(Citation: ESET DynoWiper JAN 2026)(Citation: ESET DynoWiper Update JAN 2026)
Source: MITRE ATT&CK
How we know this
- Data origin
- MITRE ATT&CK campaign Imported from the MITRE ATT&CK STIX bundle as a campaign object.
- Techniques
- MITRE ATT&CK STIX mappings — 77 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1003OS Credential Dumping ↗T1003.001LSASS Memory ↗T1003.002Security Account Manager ↗T1003.003NTDS ↗T1006Direct Volume Access ↗T1016System Network Configuration Discovery ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1027Obfuscated Files or Information ↗T1027.013Encrypted/Encoded File ↗T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1046Network Service Discovery ↗T1048Exfiltration Over Alternative Protocol ↗T1048.003Exfiltration Over Unencrypted Non-C2 Protocol ↗T1049System Network Connections Discovery ↗T1053Scheduled Task/Job ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.003Windows Command Shell ↗T1059.004Unix Shell ↗T1059.008Network Device CLI ↗T1074Data Staged ↗T1074.001Local Data Staging ↗T1078Valid Accounts ↗T1078.002Domain Accounts ↗T1078.004Cloud Accounts ↗T1083File and Directory Discovery ↗T1090Proxy ↗T1090.003Multi-hop Proxy ↗T1102Web Service ↗T1102.002Bidirectional Communication ↗T1105Ingress Tool Transfer ↗T1110Brute Force ↗T1110.002Password Cracking ↗T1113Screen Capture ↗T1114Email Collection ↗T1114.002Remote Email Collection ↗T1133External Remote Services ↗T1140Deobfuscate/Decode Files or Information ↗T1484Domain or Tenant Policy Modification ↗T1484.001Group Policy Modification ↗T1485Data Destruction ↗T1490Inhibit System Recovery ↗T1495Firmware Corruption ↗T1529System Shutdown/Reboot ↗T1530Data from Cloud Storage ↗T1550Use Alternate Authentication Material ↗T1550.002Pass the Hash ↗T1555Credentials from Password Stores ↗T1556Modify Authentication Process ↗T1556.006Multi-Factor Authentication ↗T1558Steal or Forge Kerberos Tickets ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1567Exfiltration Over Web Service ↗T1567.004Exfiltration Over Webhook ↗T1570Lateral Tool Transfer ↗T1571Non-Standard Port ↗T1583Acquire Infrastructure ↗T1583.006Web Services ↗T1584Compromise Infrastructure ↗T1584.001Domains ↗T1584.003Virtual Private Server ↗T1584.008Network Devices ↗T1587Develop Capabilities ↗T1587.001Malware ↗T1588Obtain Capabilities ↗T1588.007Artificial Intelligence ↗T1590Gather Victim Network Information ↗T1590.006Network Security Appliances ↗T1602Data from Configuration Repository ↗T1602.002Network Device Configuration Dump ↗T1608Stage Capabilities ↗T1608.002Upload Tool ↗T1686Disable or Modify System Firewall ↗T1686.002Network Device Firewall ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 44 / 77 | 57% |
CM-6 | 43 / 77 | 56% |
AC-3 | 42 / 77 | 55% |
CM-2 | 40 / 77 | 52% |
AC-6 | 34 / 77 | 44% |
AC-2 | 31 / 77 | 40% |
CM-7 | 30 / 77 | 39% |
SI-3 | 30 / 77 | 39% |
CA-7 | 29 / 77 | 38% |
IA-2 | 26 / 77 | 34% |
AC-4 | 22 / 77 | 29% |
AC-5 | 22 / 77 | 29% |
SC-7 | 21 / 77 | 27% |
SI-7 | 21 / 77 | 27% |
CM-5 | 20 / 77 | 26% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Volt Typhoon 0.28
- FIN13 0.26
- Chimera 0.25
- Ke3chang 0.25
- Magic Hound 0.25
Same nation-state
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00