logo

Energy Sector Incident Report – 29 December

ID: c88ed961-dae8-4785-a214-dec566514b19

STIX ID: report--c88ed961-dae8-4785-a214-dec566514b19

Threat Score

90/100

Uploaded: 2026-08-11

Published Date: 2026-01-30

Last Modified Date: 2026-01-30

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
CERT Polska documents coordinated, destructive cyber-sabotage on 29 December 2025 against Polish critical infrastructure and an opportunistic manufacturing target: intrusions via Internet-exposed FortiGate devices and reused/default credentials enabled long-term access, credential theft (LSASS, ntds.dit, SAM), and lateral movement; the attacker distributed wiper malware (DynoWiper native binary and PowerShell-based LazyWiper) via GPOs and executed direct destructive actions against industrial controllers (RTUs, IEDs, serial device servers), causing loss of supervisory/control communications and attempted disk/RAID destruction. The report includes detailed malware analysis, MITRE ATT&CK mappings, IoCs (hashes, IPs), detection rules, and discussion of attribution to an activity cluster overlapping with infrastructure linked to the “Static Tundra”/“Berserk Bear” cluster, while noting that code similarity is insufficient for definitive attribution.