Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
critical-infrastructure-threatstate-sponsored-disruptionindustrial-control-system-vulnerabilityoperational-disruption

Static Tundra Sabotage Attempts Against Poland’s Energy Sector Using DynoWiper

Updated 3mo agoFirst seen Feb 3, 20262 sources

CERT Polska reported late-2025 sabotage activity against Poland’s energy sector attributed to the threat actor Static Tundra, including coordinated intrusions affecting renewable energy facilities, a large combined heat and power (CHP) plant, and an energy-linked manufacturer. The activity showed a shift from espionage to disruption, including an operational technology (OT) incident in which attackers reached a renewable facility’s Grid Control Point (GCP) and executed a shutdown of industrial automation devices. Investigators also observed targeting of Moxa NPort serial-to-Ethernet devices, including password changes to lock out operators and deployment of corrupted firmware that could prevent controller startup and require manual recovery.

The same reporting described two destructive malware families, DynoWiper and LazyWiper, used to render systems and data unrecoverable; DynoWiper was documented deleting files from Mikronika RTU controllers, while LazyWiper appeared to provide redundant destructive capability. Separately, an opinion piece highlighted that attempted disruption of the Polish distribution grid was rebuffed and reported, and used the Poland case (alongside speculative discussion of Venezuela) to argue that energy infrastructure attacks are becoming more common; it provided limited additional technical detail beyond noting ambiguity around attribution and the broader trend toward “democratized” attack tooling.

Share:
Static Tundra Sabotage Attempts Against Poland’s Energy Sector Using DynoWiper
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Feb 3, 20265mo ago

Analysts attribute Poland energy attacks primarily to Static Tundra

Analysis published with the CERT Polska reporting linked the campaign's infrastructure primarily to the state-sponsored cluster Static Tundra, also known as Berserk Bear, Ghost Blizzard, and Dragonfly. Researchers also noted possible but inconclusive similarities to Sandworm-associated tooling.

CERT Polska publicly reports destructive attacks on energy infrastructure

By February 2026, CERT Polska disclosed that the late-2025 campaign against Poland's energy infrastructure involved destructive malware and operational disruption affecting OT systems. The report identified DynoWiper and LazyWiper and described damage to industrial controller environments.

Feb 2, 20265mo ago

Attempted disruption of Poland's distribution grid is reportedly rebuffed

In early 2026, Poland reportedly faced an attempted disruption of its distribution grid, but the effort was said to have been successfully resisted. The incident was cited as an example of stronger resilience in power infrastructure defense.

Jan 3, 20266mo ago

Operation Absolute Resolve linked to Caracas power outage

On January 3, 2026, a Caracas power outage was associated in reporting with 'Operation Absolute Resolve,' described as a US operation aimed at abducting Venezuelan President Nicolás Maduro. Public attribution and the exact method of disruption remained unclear.

Dec 1, 20257mo ago

Attackers disrupt Polish grid operations and damage OT devices

During the campaign, the attackers reportedly took control of a Grid Control Point, shut down industrial automation devices, and damaged RTU controllers to disrupt communications with the Distribution System Operator. They also targeted Moxa NPort devices by changing passwords and installing corrupted firmware that required manual recovery.

Static Tundra launches coordinated attacks on Poland's energy sector

In late 2025, attackers conducted sustained cyberattacks against Polish energy-sector critical infrastructure, including renewable energy facilities and a large combined heat and power plant. The activity extended from IT into OT environments and marked an escalation from espionage toward disruptive operations.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

9 LINKEDOpen in app
Threat actors
3 linked
Malware
2 linked
Affected products
1 linked
Google Search
Organizations
1 linked
Google
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.