Imagine a cyberattack so audacious it targets an entire nation's power grid, leaving experts scrambling to understand its origins and implications. That's exactly what happened to Poland in late 2025, and now, ESET Research has uncovered a chilling truth: the notorious Russia-aligned APT group Sandworm was behind the attack. But here's where it gets even more intriguing—this wasn't just any cyberattack; it involved a sophisticated data-wiping malware that ESET researchers have dubbed DynoWiper.
On January 23, 2026, ESET revealed that Poland’s energy system had faced what was described as the “largest cyberattack” in years, targeting the country’s critical infrastructure. After a thorough analysis, researchers attributed the attack to Sandworm with medium confidence, citing a strong overlap with the group’s previous wiper activities, particularly those targeting Ukraine. And this is the part most people miss: the attack occurred on the 10th anniversary of Sandworm’s infamous 2015 assault on Ukraine’s power grid, which caused the world’s first malware-induced blackout. Coincidence? Likely not.
Sandworm’s history of disruptive cyberattacks, especially against Ukraine’s critical infrastructure, is well-documented. In 2015, they used the BlackEnergy malware to compromise electrical substations, plunging 230,000 people into darkness for hours. Fast forward to 2025, and Sandworm’s tactics remain as relentless as ever. ESET’s latest APT Activity Report highlights regular wiper attacks against Ukrainian targets, underscoring the group’s persistent threat to critical infrastructure worldwide.
Now, let’s talk about DynoWiper. This malware, detected by ESET as Win32/KillFiles.NMO, was designed to erase data, though researchers note no successful disruptions occurred during the Poland attack. But the question remains: What was the intended impact? Was it a test run, a symbolic strike, or a prelude to something larger? This ambiguity only adds to the controversy surrounding Sandworm’s motives and capabilities.
Here’s where it gets even more thought-provoking: Is Sandworm’s focus on critical infrastructure a strategic move to destabilize nations, or a calculated effort to send a geopolitical message? As cyberattacks become increasingly sophisticated, the line between warfare and digital sabotage blurs. What does this mean for global cybersecurity, and how prepared are we to defend against such threats?
For those eager to dive deeper, ESET Research offers private APT intelligence reports and data feeds. For inquiries, visit their Threat Intelligence page. And if you’re curious about the technical details, here’s the Indicator of Compromise (IoC) for DynoWiper:
SHA-1: 4EC3C90846AF6B79EE1A5188EEFA3FD21F6D4CF6
Detection: Win32/KillFiles.NMO
As we navigate this era of escalating cyber threats, one thing is clear: staying informed is our best defense. What do you think about Sandworm’s latest move? Is it a harbinger of more aggressive cyber warfare, or a calculated act of intimidation? Share your thoughts in the comments—let’s spark a conversation that matters.