Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New DynoWiper Malware Used in Attempted Sandworm Attack on Polish Power Sector

New DynoWiper Malware Used in Attempted Sandworm Attack on Polish Power Sector

Posted on January 24, 2026January 24, 2026 By CWS

Ravie LakshmananJan 24, 2026Malware / Important Infrastructure
The Russian nation-state hacking group often called Sandworm has been attributed to what has been described because the “largest cyber assault” concentrating on Poland’s energy system within the final week of December 2025.
The assault was unsuccessful, the nation’s power minister, Milosz Motyka, stated final week.
“The command of the our on-line world forces has identified within the final days of the yr the strongest assault on the power infrastructure in years,” Motyka was quoted as saying.

In keeping with a brand new report by ESET, the assault was the work of Sandworm, which deployed a beforehand undocumented wiper malware codenamed DynoWiper. The hyperlinks to Sandworm are based mostly on overlaps with prior wiper exercise related to the adversary, notably within the aftermath of Russia’s navy invasion of Ukraine in February 2022.
The Slovakian cybersecurity firm, which recognized using the wiper as a part of the tried disruptive assault aimed on the Polish power sector on December 29, 2025, stated there isn’t any proof of profitable disruption.
The December 29 and 30, 2025, assaults focused two mixed warmth and energy (CHP) crops, in addition to a system enabling the administration of electrical energy generated from renewable power sources similar to wind generators and photovoltaic farms, the Polish authorities stated.
“The whole lot signifies that these assaults had been ready by teams instantly linked to the Russian companies,” Prime Minister Donald Tusk stated, including the federal government is readying further safeguards, together with a key cybersecurity laws that may impose strict necessities on threat administration, safety of data expertise (IT) and operational expertise (OT) techniques, and incident response.
It is value noting that the exercise occurred on the tenth anniversary of the Sandworm’s assault in opposition to the Ukrainian energy grid in December 2015, which led to the deployment of the BlackEnergy malware, plunging elements of the Ivano-Frankivsk area of Ukraine into darkness.
The trojan, which was used to plant a wiper malware dubbed KillDisk, brought about a 4–6 hour energy outage for roughly 230,000 individuals.

“Sandworm has an extended historical past of disruptive cyberattacks, particularly on Ukraine’s essential infrastructure,” ESET stated. “Quick ahead a decade and Sandworm continues to focus on entities working in varied essential infrastructure sectors.”
In June 2025, Cisco Talos stated a essential infrastructure entity inside Ukraine was focused by a beforehand unseen knowledge wiper malware named PathWiper that shares some degree of purposeful overlap with Sandworm’s HermeticWiper.
The Russian hacking group has additionally been noticed deploying data-wiping malware, similar to ZEROLOT and Sting, in a Ukrainian college community, adopted by serving a number of data-wiping malware variants in opposition to Ukrainian entities lively within the governmental, power, logistics, and grain sectors between June and September 2025.

The Hacker News Tags:Attack, Attempted, DynoWiper, Malware, Polish, Power, Sandworm, Sector

Post navigation

Previous Post: Who Approved This Agent? Rethinking Access, Accountability, and Risk in the Age of AI Agents
Next Post: Threat Actors Leverage SharePoint Services in Sophisticated AiTM Phishing Campaign

Related Posts

New UEFI Flaw Enables Early-Boot DMA Attacks on ASRock, ASUS, GIGABYTE, MSI Motherboards New UEFI Flaw Enables Early-Boot DMA Attacks on ASRock, ASUS, GIGABYTE, MSI Motherboards The Hacker News
Microsoft Alerts on OAuth Redirect Exploitation in Phishing Attacks Microsoft Alerts on OAuth Redirect Exploitation in Phishing Attacks The Hacker News
Speagle Malware Exploits Security Software for Data Theft Speagle Malware Exploits Security Software for Data Theft The Hacker News
U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing 0K Crypto Transfers and M+ Profits U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits The Hacker News
WebRTC Skimmer Evades CSP to Steal E-Commerce Data WebRTC Skimmer Evades CSP to Steal E-Commerce Data The Hacker News
Critical PAN-OS Flaw Exploited for Root Access Critical PAN-OS Flaw Exploited for Root Access The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark