Energy Sector Incident Report – 29 December
ID: c88ed961-dae8-4785-a214-dec566514b19
STIX ID: report--c88ed961-dae8-4785-a214-dec566514b19
Threat Score
90/100
Uploaded: 2026-08-11
Published Date: 2026-01-30
Last Modified Date: 2026-01-30
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
CERT Polska documents coordinated, destructive cyber-sabotage on 29 December 2025 against Polish critical infrastructure and an opportunistic manufacturing target: intrusions via Internet-exposed FortiGate devices and reused/default credentials enabled long-term access, credential theft (LSASS, ntds.dit, SAM), and lateral movement; the attacker distributed wiper malware (DynoWiper native binary and PowerShell-based LazyWiper) via GPOs and executed direct destructive actions against industrial controllers (RTUs, IEDs, serial device servers), causing loss of supervisory/control communications and attempted disk/RAID destruction. The report includes detailed malware analysis, MITRE ATT&CK mappings, IoCs (hashes, IPs), detection rules, and discussion of attribution to an activity cluster overlapping with infrastructure linked to the “Static Tundra”/“Berserk Bear” cluster, while noting that code similarity is insufficient for definitive attribution.
