惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hugging Face - Blog
Hugging Face - Blog
腾讯CDC
阮一峰的网络日志
阮一峰的网络日志
博客园_首页
Last Week in AI
Last Week in AI
月光博客
月光博客
D
DataBreaches.Net
WordPress大学
WordPress大学
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - 叶小钗
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
U
Unit 42
Recent Announcements
Recent Announcements
宝玉的分享
宝玉的分享
MyScale Blog
MyScale Blog
C
Check Point Blog
F
Fortinet All Blogs
B
Blog
小众软件
小众软件
Vercel News
Vercel News
罗磊的独立博客
有赞技术团队
有赞技术团队

RSS

Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Vietnam-aligned OceanLotus pivots to spy on domestic targets as it takes a more selective approach abroad, ESET Research finds Events and conferences Canon Canada Partners with ESET to Expand Cybersecurity Services ESET releases 2026 SMB Cyber Readiness Index showing growing confidence but also concerns about AI ESET has been named the only Challenger in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection ESET Research APT Report: China-aligned groups spy in Venezuela and the Gulf, target AI robotics in S. Korea Events and conferences ESET uncovers the expanded arsenal of China-aligned Webworm; European governments targeted ESET reaffirms its global market presence with new European and Asian offices ESET supercharges AI innovation with investment to address rapidly expanding attack surface ESET joins the Agentic AI Foundation to help shape safe, human‑led agentic AI ESET’s Tony Anscombe to Co-Chair NetDiligence Cyber Risk Summit Belarus-aligned FrostyNeighbor attacks Ukrainian government, again — ESET Research discovers ESET Research uncovers CallPhantom scam on Google Play: Fake logs for real money North Korea-aligned APT group ScarCruft compromises gaming platform in supply‑chain espionage attack, ESET Research finds ESET Research discovers new China-aligned group, GopherWhisper: It abuses messaging services Discord, Slack, and Outlook to spy ESET Research: New NGate hides in NFC payment app, possibly built with AI
Russian Sandworm group attacks energy company in Poland w...
2026-01-30 · via RSS
  • ESET researchers identified new data-wiping malware that ESET named DynoWiper, used against an energy company in Poland.
  • The TTPs observed during the DynoWiper incident closely resemble those seen previously in an incident involving another data wiper, ZOV, in Ukraine.
  • ESET Research attributes DynoWiper to the Russia-aligned threat group Sandworm with medium confidence.
  • The incident is a rare and unreported case in which a Russia-aligned threat actor deployed destructive, data-wiping malware against an energy company in Poland.

BRATISLAVAJanuary 30, 2026 — ESET researchers identified new data-wiping malware that they named DynoWiper, used against an energy company in Poland. The tactics, techniques, and procedures (TTPs) observed during the DynoWiper incident closely resembles the previous one involving the ZOV wiper in Ukraine: Z, O, and V are Russian military symbols. ESET Research attributes DynoWiper to Russia-aligned threat group Sandworm with medium confidence.

This incident represents a rare and previously undocumented case in which a Russia-aligned threat actor deployed destructive, data-wiping malware against an energy company in Poland. In 2025, ESET investigated more than 10 incidents involving destructive malware attributed to Sandworm, almost all of them occurring in Ukraine.

The installed EDR/XDR product, ESET PROTECT, blocked execution of the wiper, significantly limiting its impact in the environment. CERT Polska did an excellent job investigating the incident and published a detailed analysis in a report available on its website.

On December 29th, 2025, DynoWiper samples were deployed to what probably is a shared directory in the victim’s domain. It is possible that Sandworm operators first tested the operation on virtual machines before deploying the malware in the target organization. Three distinct samples were deployed and all attempts failed. The wiper overwrites files using a 16-byte buffer that contains random data generated  at a single instance  at the start of the wiper’s execution. On an unprotected machine, files of size 16 bytes or fewer are fully overwritten. To speed up the destruction process, files larger than 16 bytes have only some parts of their contents overwritten. DynoWiper wipes files on all removable and fixed drives and finally forces the system to reboot, completing the destruction of the system.

Unlike other Sandworm malware including Industroyer and Industroyer2, the newly discovered DynoWiper samples focus solely on the IT environment, with no observed functionality targeting operational technology industrial components. However, this does not exclude the possibility that such capabilities were present elsewhere in the attack chain.

ESET Research identified several similarities to previously known destructive malware, specifically to the wiper ZOV, which ESET attributes to Sandworm with high confidence. DynoWiper operates in a broadly similar fashion to the ZOV wiper. Notably, the exclusion of certain directories and especially the clear separate logic present in the code for wiping smaller and larger files can also be found in the ZOV wiper. ZOV is destructive malware that we detected being deployed against a financial institution in Ukraine in November 2025. Once executed, the ZOV wiper iterates over files on all fixed drives and wipes them by overwriting their contents. There was another ZOV wiper case at an energy company in Ukraine, where the attackers deployed the wiper on January 25th, 2024. 

Sandworm is a Russia-aligned threat group that performs destructive attacks, targeting a wide range of entities including government agencies, logistics companies, transportation firms, energy providers, media organizations, grain sector companies, and telecommunications companies. These attacks typically involve the deployment of wiper malware – malicious software designed to delete files, erase data, and render systems unbootable.

Besides Ukraine, the group has a decade-long history of targeting companies in Poland, including those in the energy sector. In October 2022, it carried out a destructive attack against logistics companies in both Ukraine and Poland, disguising the operation as a Prestige ransomware incident. Because the majority of Sandworm’s cyberattacks currently target Ukraine, we collaborate closely with our Ukrainian partners, including the Computer Emergency Response Team of Ukraine (CERT-UA), to support both prevention and remediation efforts.

For a more detailed analysis of DynoWiper and Sandworm, check out the latest ESET Research blogpost “DynoWiper update: Technical analysis and attribution” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

Wallpaper dropped by the ZOV wiper

About ESET

ESET® provides cutting-edge cybersecurity to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown—securing businesses, critical infrastructure, and individuals. Whether it’s endpoint, cloud, or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit www.eset.com or follow our social media, podcasts, and blogs.