Skip to main content
QUIETLYTIC
Campaign

2025 Poland Wiper Attacks

Russian state-sponsored destructive campaign against Polish energy infrastructure in December 2025, deploying two previously undocumented wiper tools against wind, photovoltaic, and CHP facilities.

Threat Level
CRITICAL
Status
Resolved
Actors Involved
Dragonfly (assessed by some reporting), Sandworm Team (assessed by other reporting)
Targets
Polish wind and photovoltaic farms (30+), Combined heat and power (CHP) plant and a manufacturing company
Also Known As
2025 Poland Wiper Campaign

Overview

The 2025 Poland Wiper Attacks (MITRE ATT&CK ID C0063) is a Russian state-sponsored campaign that conducted destructive cyberattacks against Polish energy infrastructure in December 2025, per MITRE’s campaign profile. MITRE documents targets including more than 30 wind and photovoltaic farms, a combined heat and power (CHP) plant, and a manufacturing-sector company. The attacks on distributed energy resources disrupted communications between affected facilities and the distribution system operator but, per MITRE’s data, did not impact electricity generation or heat supply.

Across the campaign, MITRE documents threat actors deploying two previously undocumented wiper tools — DynoWiper (Windows-based) and LazyWiper (PowerShell-based) — distributed via malicious Group Policy Objects. At the CHP plant specifically, MITRE’s data states attackers had maintained access since at least March 2025, using that foothold to obtain credentials and move laterally before attempting wiper deployment.

Attribution: unresolved between two competing assessments

MITRE ATT&CK’s own documentation is explicit that attribution is contested between two sources: some reporting assesses the activity consistent with Russian FSB threat group Dragonfly (also tracked as STATIC TUNDRA), while other reporting attributes the destructive wiper activity to Russian GRU threat group ELECTRUM, also tracked as Sandworm Team. We report both assessments as MITRE documents them rather than resolving the disagreement ourselves.

Timeline

Per MITRE ATT&CK’s ingested data, this campaign’s documented activity window runs from March 2025 to December 2025 — with initial CHP-plant access in March 2025 and the destructive wiper phase in December 2025.

Tools involved (per MITRE ATT&CK relationship data)

MITRE ATT&CK’s relationship data links this campaign to DynoWiper, LazyWiper, Rubeus, certutil, PsExec, Tor, Arp, Ping, Tasklist, netstat, and Impacket.

What we don’t have

Attribution to a specific named group is explicitly unresolved in MITRE’s own data between two competing assessments (Dragonfly vs. Sandworm Team) — we present both rather than picking one. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and given how recent this entry is, no longer-term data on further campaign developments beyond December 2025.

Frequently Asked Questions

What were the 2025 Poland Wiper Attacks? A Russian state-sponsored destructive campaign, per MITRE ATT&CK, against Polish energy infrastructure in December 2025, deploying two new wiper tools (DynoWiper, LazyWiper) against 30+ wind/solar farms and a CHP plant.

Who conducted the 2025 Poland Wiper Attacks? MITRE ATT&CK’s data cites two competing assessments — Russian FSB group Dragonfly (STATIC TUNDRA) or Russian GRU group Sandworm Team (ELECTRUM) — without resolving between them.

Did the attacks disrupt Poland’s power supply? Per MITRE’s data, the attacks disrupted communications between distributed energy facilities and the distribution system operator but did not impact actual electricity generation or heat supply.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), campaign ID C0063, aggregated September 14, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more campaign profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Cross-referenced intelligence


Analyst tools