Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian Sandworm Hackers Blamed for Cyberattack on Polish Power Grid

Russian Sandworm Hackers Blamed for Cyberattack on Polish Power Grid

Posted on January 26, 2026January 26, 2026 By CWS

The Russian state-sponsored APT named Sandworm was behind the December 2025 cyberattack focusing on Poland’s energy grid, cybersecurity agency ESET stories.

Poland’s power infrastructure, together with two mixed warmth and energy (CHP) crops and a renewable power administration system, was focused by hackers on December 29-30, and Polish officers blamed Russia for the assault.

Stated to have been the most important cyberattack towards Poland in years, the December 2025 incident was thwarted earlier than it might trigger a blackout or compromise crucial infrastructure, the nation’s officers mentioned earlier this month.

The assault occurred 10 years after Sandworm used the BlackEnergy malware in a disruptive assault towards Ukraine’s energy grid, leading to a number of blackouts within the Ivano-Frankivsk area.

Lively since at the very least 2009, the menace actor is believed to be related to Russia’s Basic Employees Major Intelligence Directorate (GRU) army unit 74455.

Also called APT44, BlackEnergy Lite, Seashell Blizzard, Telebots, and Voodoo Bear, Sandworm has develop into infamous for its espionage and knowledge operations, in addition to cyber disruptions.Commercial. Scroll to proceed studying.

In line with ESET, the APT was more than likely behind the December 2025 cyberattack on the Polish energy grid, based mostly on the employed malware and related TTPs.

The cybersecurity agency mentioned that Sandworm deployed a brand new knowledge wiper within the assault, however didn’t trigger disruptions. The supposed impression of the assault has but to be decided.

“We’re not conscious of any profitable disruption occurring on account of this assault,” ESET mentioned.

The malware, dubbed DynoWiper (Win32/KillFiles.NMO), aligns with earlier Sandworm wiper assaults, the cybersecurity agency famous. No technical particulars on the menace have been printed.

Underlining the hyperlink between the Polish assault and the anniversary of Sandworm’s assault on Ukraine’s energy grid, ESET identified that the APT continues to often mount wiper assaults towards Ukrainian targets.

“Quick ahead a decade and Sandworm continues to focus on entities working in varied crucial infrastructure sectors, particularly in Ukraine,” ESET mentioned.

Associated: Russia’s APT28 Focusing on Vitality Analysis, Protection Collaboration Entities

Associated: Professional-Russian Hackers Declare Cyberattack on French Postal Service

Associated: Denmark Blames Russia for Cyberattacks Forward of Elections and on Water Utility

Associated: Amazon: Russian Hackers Now Favor Misconfigurations in Crucial Infrastructure Assaults

Security Week News Tags:Blamed, Cyberattack, Grid, Hackers, Polish, Power, Russian, Sandworm

Post navigation

Previous Post: Konni Hackers Deploy AI-Generated PowerShell Backdoor Against Blockchain Developers
Next Post: Microsoft Releases Out-of-Band Update KB5078127 to Fix Windows 11 File System and Outlook Freezes

Related Posts

Cyber Insights 2026: Offensive Security; Where It is and Where Its Going Cyber Insights 2026: Offensive Security; Where It is and Where Its Going Security Week News
Apono Raises  Million for Cloud Identity Management Platform Apono Raises $34 Million for Cloud Identity Management Platform Security Week News
Upwind Raises 0 Million at .5 Billion Valuation Upwind Raises $250 Million at $1.5 Billion Valuation Security Week News
Asus DriverHub Vulnerabilities Expose Users to Remote Code Execution Attacks Asus DriverHub Vulnerabilities Expose Users to Remote Code Execution Attacks Security Week News
Improperly Patched Samsung MagicINFO Vulnerability Exploited by Botnet Improperly Patched Samsung MagicINFO Vulnerability Exploited by Botnet Security Week News
DanaBot Botnet Disrupted, 16 Suspects Charged DanaBot Botnet Disrupted, 16 Suspects Charged Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News