Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian ELECTRUM Tied to December 2025 Cyber Attack on Polish Power Grid

Russian ELECTRUM Tied to December 2025 Cyber Attack on Polish Power Grid

Posted on January 28, 2026January 28, 2026 By CWS

Ravie LakshmananJan 28, 2026Critical Infrastructure / Risk Intelligence

The “coordinated” cyber assault focusing on a number of websites throughout the Polish energy grid has been attributed with medium confidence to a Russian state-sponsored hacking crew often called ELECTRUM.
Operational know-how (OT) cybersecurity firm Dragos, in a brand new intelligence transient printed Tuesday, described the late December 2025 exercise as the primary main cyber assault focusing on distributed vitality sources (DERs).
“The assault affected communication and management techniques at mixed warmth and energy (CHP) amenities and techniques managing the dispatch of renewable vitality techniques from wind and photo voltaic websites,” Dragos stated. “Whereas the assault didn’t end in energy outages, adversaries gained entry to operational know-how techniques important to grid operations and disabled key tools past restore on the website.”

It is price stating that ELECTRUM and KAMACITE share overlaps with a cluster known as Sandworm (aka APT44 and Seashell Blizzard). KAMACITE focuses on establishing and sustaining preliminary entry to focused organizations utilizing spear-phishing, stolen credentials, and exploitation of uncovered companies.

Past preliminary entry, the risk actor performs reconnaissance and persistence actions over prolonged intervals of time as a part of efforts to burrow deep into goal OT environments and hold a low profile, signaling a cautious preparatory section that precedes actions executed by ELECTRUM focusing on the economic management techniques.
“Following entry enablement, ELECTRUM conducts operations that bridge IT and OT environments, deploying tooling inside operational networks, and performs ICS-specific actions that manipulate management techniques or disrupt bodily processes,” Dragos stated. “These actions have included each guide interactions with operator interfaces and the deployment of purpose-built ICS malware, relying on the operational necessities and aims.”
Put in another way, the 2 clusters have clear separation of roles and obligations, enabling flexibility in execution and facilitating sustained OT-focused intrusions when circumstances are beneficial. As just lately as July 2025, KAMACITE is alleged to have engaged in scanning exercise towards industrial gadgets situated within the U.S.
Though no follow-on OT disruptions have been publicly reported to this point, this highlights an operational mannequin that isn’t geographically constrained and facilitates early-stage entry identification and positioning.
“KAMACITE’s access-oriented operations create the circumstances underneath which OT influence turns into doable, whereas ELECTRUM applies execution tradecraft when timing, entry, and danger tolerance align,” it defined. “This division of labor permits flexibility in execution and permits OT influence to stay an choice, even when it isn’t instantly exercised. This extends danger past discrete incidents and into extended intervals of latent publicity.”

Dragos stated the Poland assault focused techniques that facilitate communication and management between grid operators and DER property, together with property that allow community connectivity, permitting the adversary to efficiently disrupt operations at about 30 distributed era websites.
The risk actors are assessed to have breached Distant Terminal Models (RTUs) and communication infrastructure on the affected websites utilizing uncovered community gadgets and exploited vulnerabilities as preliminary entry vectors. The findings point out that the attackers possess a deep understanding {of electrical} grid infrastructure, permitting them to disable communications tools, together with some OT gadgets.

That stated, the total scope of the malicious actions undertaken by ELECTRUM is unknown, with Dragos noting that it is unclear if the risk actor tried to situation operational instructions to this tools or centered solely on disabling communications.
The Poland assault can also be assessed to be extra opportunistic and rushed than a exactly deliberate operation, permitting the hackers to reap the benefits of the unauthorized entry to inflict as a lot harm as doable by wiping Home windows-based gadgets to impede restoration, resetting configurations, or trying to completely brick tools. Nearly all of the tools is focused at grid security and stability monitoring, per Dragos.
“This incident demonstrates that adversaries with OT-specific capabilities are actively focusing on techniques that monitor and management distributed era,” it added. “The disabling of sure OT or industrial management system (ICS) tools past restore on the website moved what may have been seen as a pre-positioning try by the adversary into an assault.”

The Hacker News Tags:Attack, Cyber, December, ELECTRUM, Grid, Polish, Power, Russian, Tied

Post navigation

Previous Post: ZAP JavaScript Engine Memory Leak Issue Impacts Active Scan Usage
Next Post: Gemini MCP Tool 0-day Vulnerability Allows Remote Attackers to Execute Arbitrary Code

Related Posts

Microsoft Patches Critical Entra ID Flaw Enabling Global Admin Impersonation Across Tenants Microsoft Patches Critical Entra ID Flaw Enabling Global Admin Impersonation Across Tenants The Hacker News
Forg365 PhaaS Exploits Microsoft 365 with Advanced Tactics Forg365 PhaaS Exploits Microsoft 365 with Advanced Tactics The Hacker News
Google Launches ‘Private AI Compute’ — Secure AI Processing with On-Device-Level Privacy Google Launches ‘Private AI Compute’ — Secure AI Processing with On-Device-Level Privacy The Hacker News
Critical Marimo RCE Vulnerability Exploited Rapidly Critical Marimo RCE Vulnerability Exploited Rapidly The Hacker News
Apple Patches Zero-Day Vulnerability in Devices Apple Patches Zero-Day Vulnerability in Devices The Hacker News
Germany Shuts Down eXch Over .9B Laundering, Seizes €34M in Crypto and 8TB of Data Germany Shuts Down eXch Over $1.9B Laundering, Seizes €34M in Crypto and 8TB of Data The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Adobe ColdFusion Flaws Pose Severe Security Risks
  • WhatsApp Introduces Scam Alert to Enhance Security
  • Enterprise Security Shows Strength at Edge, Weakness Within
  • Chrome 151 Update Fixes Five Critical Security Flaws
  • SharePoint Exploit Emerges Following PoC Release

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Adobe ColdFusion Flaws Pose Severe Security Risks
  • WhatsApp Introduces Scam Alert to Enhance Security
  • Enterprise Security Shows Strength at Edge, Weakness Within
  • Chrome 151 Update Fixes Five Critical Security Flaws
  • SharePoint Exploit Emerges Following PoC Release

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark