Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Campaigns/C0063
MITRE ATT&CK Campaign · 2025–2025

2025 Poland Wiper Attacks (C0063)

ShareXLinkedInRedditHN

[2025 Poland Wiper Attacks](https://attack.mitre.org/campaigns/C0063) is a Russian state-sponsored campaign that conducted destructive cyberattacks against Polish energy infrastructure in December 2025. Targets included more than 30 wind and photovoltaic farms, a combined heat and power (CHP) plant, and a manufacturing sector company. The attacks on the distributed energy resources (DER) disrupted communications between affected facilities and the distribution system operator, but did not impact electricity generation or heat supply. Across the campaign, threat actors deployed two previously undocumented wiper tools, [DynoWiper](https://attack.mitre.org/software/S9038), a Windows-based wiper and [LazyWiper](https://attack.mitre.org/software/S9039), a PowerShell wiper, distributed via malicious Group Policy Objects. At the CHP plant, threat actors had maintained access since at least March 2025, using that foothold to obtain credentials and move laterally before attempting wiper deployment. Some reporting has assessed the activity to be consistent with Russian Federal Security Service (FSB) threat activity group [Dragonfly](https://attack.mitre.org/groups/G0035), also tracked as STATIC TUNDRA, while other reporting attributes the destructive wiper activities to the Russian General Staff Main Intelligence Directorate (GRU) threat activity group ELECTRUM, also tracked as [Sandworm Team](https://attack.mitre.org/groups/G0034).(Citation: CERT Polska)(Citation: Dragos ELECTRUM JAN 2026)(Citation: ESET DynoWiper JAN 2026)(Citation: ESET DynoWiper Update JAN 2026)

▪Techniques used (73)

T1529System Shutdown/RebootT1053Scheduled Task/JobT1484.001Group Policy ModificationT1059.008Network Device CLIT1048.003Exfiltration Over Unencrypted Non-C2 ProtocolT1006Direct Volume AccessT1090.003Multi-hop ProxyT1571Non-Standard PortT1567.004Exfiltration Over WebhookT1584.001DomainsT1049System Network Connections DiscoveryT1558Steal or Forge Kerberos TicketsT1027.013Encrypted/Encoded FileT1602.002Network Device Configuration DumpT1140Deobfuscate/Decode Files or InformationT1587.001MalwareT1560.001Archive via UtilityT1090ProxyT1530Data from Cloud StorageT1555Credentials from Password StoresT1570Lateral Tool TransferT1102.002Bidirectional CommunicationT1550.002Pass the HashT1584.008Network DevicesT1016System Network Configuration DiscoveryT1105Ingress Tool TransferT1110.002Password CrackingT1059.004Unix ShellT1057Process DiscoveryT1556.006Multi-Factor AuthenticationT1078.002Domain AccountsT1133External Remote ServicesT1078.004Cloud AccountsT1495Firmware CorruptionT1584.003Virtual Private ServerT1490Inhibit System RecoveryT1583.006Web ServicesT1074.001Local Data StagingT1003.001LSASS MemoryT1113Screen CaptureT1485Data DestructionT1114.002Remote Email CollectionT1046Network Service DiscoveryT1021.001Remote Desktop ProtocolT1083File and Directory DiscoveryT1036.005Match Legitimate Resource Name or LocationT1003.002Security Account ManagerT1588.007Artificial IntelligenceT1059.003Windows Command ShellT1608.002Upload ToolT1590.006Network Security AppliancesT1003.003NTDST1686.002Network Device FirewallT0892Change CredentialT0829Loss of ViewT0816Device Restart/ShutdownT0846.001Port ScanT0840Network Connection EnumerationT0885Commonly Used PortT0852Screen CaptureT0809Data DestructionT1693.001System FirmwareT0807Command-Line InterfaceT0859Valid AccountsT1694.001Default CredentialsT0827Loss of ControlT0823Graphical User InterfaceT0846.002Broadcast DiscoveryT0882Theft of Operational InformationT0846Remote System DiscoveryT0822External Remote ServicesT0886Remote ServicesT0888Remote System Information Discovery

▪Software used (11)

S0160certutiltoolS1071RubeustoolS0029PsExectoolS0183TortoolS0099ArptoolS0097PingtoolS9039LazyWipermalwareS0057TasklisttoolS9038DynoWipermalwareS0104netstattoolS0357Impackettool
C0063on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.