Skip to content
Breaking
Latest technical intelligence from Northeast India • Infrastructure, AI, Cloud & Security Analysis • Precision Analysis | Raw Intelligence | Your North Star of Tech Latest technical intelligence from Northeast India • Infrastructure, AI, Cloud & Security Analysis • Precision Analysis | Raw Intelligence | Your North Star of Tech
SECURITY

Analysis: Sandworm hackers linked to failed wiper attack on Polands energy systems

Sandworm Hackers Linked to Poland's Failed Energy Wiper Attack: Implications for North East India and Beyond

A Cyberattack Threatens Poland's Energy Systems: What Happened and Why It Matters

In late December 2025, Poland's power grid faced a cyberattack that targeted its energy infrastructure. The attack, which used a destructive data-wiping malware known as DynoWiper, has been linked to the Russian state-sponsored hacking group Sandworm.

Who is Sandworm, and Why Should We Care?

Sandworm, also known as UAC-0113, APT44, and Seashell Blizzard, is a Russian nation-state hacking group that has been active since 2009. Believed to be part of Russia's Military Unit 74455 of the Main Intelligence Directorate (GRU), the group is known for carrying out disruptive and destructive attacks. Sandworm's most notorious attack occurred in 2015, when it launched a destructive data-wiping attack on Ukraine's energy grid, leaving approximately 230,000 people without power.

Sandworm's Connections to the North East Region and India

While Sandworm's attacks have primarily targeted Eastern European countries, the group's activities pose a potential threat to countries worldwide, including those in North East India. Cybersecurity experts warn that state-sponsored hacking groups like Sandworm may seek to exploit vulnerabilities in critical infrastructure systems, such as power grids, water utilities, and financial institutions, to cause disruption or harm.

DynoWiper: A New Destructive Malware on the Block

DynoWiper is a data-wiping malware that Sandworm is believed to have used in the December 2025 attack on Poland's energy infrastructure. When executed, data wipers iterate through a filesystem, deleting files. When finished, the operating system is left unusable and must be rebuilt from backups or reinstalled.

The Fallout: How Poland Responded and What We Know About DynoWiper

In a press statement, Polish officials stated that the attack targeted two combined heat and power plants as well as a management system used to control electricity generated from renewable sources such as wind turbines and photovoltaic farms. Poland's Prime Minister Donald Tusk said, "Everything indicates that these attacks were prepared by groups directly linked to the Russian services." ESET, the antivirus company that discovered DynoWiper, has not shared many technical details about the malware, only stating that it detects it as Win32/KillFiles and has a SHA-1 hash of 4EC3C90846AF6B79EE1A5188EEFA3FD21F6D4CF6.

Implications and Lessons for Defenders

While it is unclear how long the threat actors remained within Poland's systems or how they were breached, cybersecurity experts recommend that defenders read Microsoft's February 2025 report on Sandworm to better understand the group's tactics, techniques, and procedures (TTPs). As Sandworm continues to evolve and develop new tools, it is essential for organizations to stay vigilant and implement best practices to protect against these types of attacks.