Overview
The 2025 Poland Wiper Attacks (MITRE ATT&CK ID C0063) is a Russian state-sponsored campaign that conducted destructive cyberattacks against Polish energy infrastructure in December 2025, per MITRE’s campaign profile. MITRE documents targets including more than 30 wind and photovoltaic farms, a combined heat and power (CHP) plant, and a manufacturing-sector company. The attacks on distributed energy resources disrupted communications between affected facilities and the distribution system operator but, per MITRE’s data, did not impact electricity generation or heat supply.
Across the campaign, MITRE documents threat actors deploying two previously undocumented wiper tools — DynoWiper (Windows-based) and LazyWiper (PowerShell-based) — distributed via malicious Group Policy Objects. At the CHP plant specifically, MITRE’s data states attackers had maintained access since at least March 2025, using that foothold to obtain credentials and move laterally before attempting wiper deployment.
Attribution: unresolved between two competing assessments
MITRE ATT&CK’s own documentation is explicit that attribution is contested between two sources: some reporting assesses the activity consistent with Russian FSB threat group Dragonfly (also tracked as STATIC TUNDRA), while other reporting attributes the destructive wiper activity to Russian GRU threat group ELECTRUM, also tracked as Sandworm Team. We report both assessments as MITRE documents them rather than resolving the disagreement ourselves.
Timeline
Per MITRE ATT&CK’s ingested data, this campaign’s documented activity window runs from March 2025 to December 2025 — with initial CHP-plant access in March 2025 and the destructive wiper phase in December 2025.
Tools involved (per MITRE ATT&CK relationship data)
MITRE ATT&CK’s relationship data links this campaign to DynoWiper, LazyWiper, Rubeus, certutil, PsExec, Tor, Arp, Ping, Tasklist, netstat, and Impacket.
What we don’t have
Attribution to a specific named group is explicitly unresolved in MITRE’s own data between two competing assessments (Dragonfly vs. Sandworm Team) — we present both rather than picking one. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and given how recent this entry is, no longer-term data on further campaign developments beyond December 2025.
Frequently Asked Questions
What were the 2025 Poland Wiper Attacks? A Russian state-sponsored destructive campaign, per MITRE ATT&CK, against Polish energy infrastructure in December 2025, deploying two new wiper tools (DynoWiper, LazyWiper) against 30+ wind/solar farms and a CHP plant.
Who conducted the 2025 Poland Wiper Attacks? MITRE ATT&CK’s data cites two competing assessments — Russian FSB group Dragonfly (STATIC TUNDRA) or Russian GRU group Sandworm Team (ELECTRUM) — without resolving between them.
Did the attacks disrupt Poland’s power supply? Per MITRE’s data, the attacks disrupted communications between distributed energy facilities and the distribution system operator but did not impact actual electricity generation or heat supply.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), campaign ID C0063, aggregated September 14, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more campaign profiles.