Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on Polish Energy Infrastructure — Threadlinqs Intelligence
As of 2026-05-30, Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on Polish Energy Infrastructure is a critical-severity apt threat attributed to Static Tundra (Russia), tracked by Threadlinqs Intelligence with 15 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 71 indicators of compromise.
Threat ID: TL-2026-0004 · Severity: CRITICAL · CVSS: 9.1 · Status: ACTIVE · Category: APT
Attribution: Static Tundra · Russia · DESTRUCTION
Static Tundra (Dragonfly/Energetic Bear/Berserk Bear/DYMALLOY/TEMP.Isotope/Crouching Yeti/IRON LIBERTY/Ghost Blizzard/BROMINE — MITRE G0035) is a Russian state-sponsored APT group conducting sustained
The Static Tundra campaign represents the convergence of 15 years of Russian state-sponsored ICS targeting with the current geopolitical reality of NATO's Eastern European defense posture. This is not a new group — it is the MOST PERSISTENT state-sponsored ICS threat actor in documented history, now deploying DESTRUCTIVE capabilities against a NATO ally.
**The Threat Actor — Dragonfly (MITRE G0035):**
Dragonfly is one of the most extensively documented state-sponsored threat groups operating globally:
- **Aliases**: Energetic Bear, Berserk Bear, TEMP.Isotope, DYMALLOY (Dragos), Crouching Yeti, IRON LIBERTY (SecureWorks), Ghost Blizzard (Microsoft), BROMINE, TG-4192, TeamSpy, Koala, Havex
- **Attribution**: Russian state-sponsored (FBI/CISA joint assessment, CISA AA20-296A)
- **Active since**: 2011 (15-year operational history)
- **Primary targets**: Energy sector (power generation, transmission, distribution), ICS/SCADA systems, government networks, aviation
- **Target regions**: US, Europe (Poland, Turkey, Germany, France, Spain, Italy, UK), North America
- **Motivation**: Intelligence gathering, pre-positioning for disruption/destruction, coercive signaling
**Phase 1 — Dragonfly 1.0 (2011-2014):**
Initial operations focused on ICS reconnaissance and intelligence gathering:
- Supply chain compromise: infected ICS vendor update websites (trojanized legitimate ICS software downloads)
- Deployed Havex RAT — specifically designed to scan for OPC (OLE for Process Control) servers on victim networks
- OPC scanning = mapping ICS/SCADA architecture without active exploitation of control systems
- Targeted energy companies in US, Western and Eastern Europe
- Primarily intelligence gathering: understanding ICS architectures, identifying HMI workstations, mapping SCADA networks
**Phase 2 — Dragonfly 2.0 / DYMALLOY (2015-2018):**
Escalated to direct network penetration and credential theft:
- Spearphishing campaigns targeting energy sector employees
- Watering hole attacks on industrial-related websites
- Deployed Goodor, DorShel, and Karagany backdoors (commodity malware assembled as unique toolkit)
- Used Mimikatz, CrackMapExec, PsExec, SecretsDump for credential harvesting
- Successfully penetrated ICS networks in Turkey, Europe, and North America
- Stole confidential ICS documentation including SCADA configurations and network diagrams
- US-CERT TA18-074A (March 2018): attributed to Russian government actors
- Accessed SCADA/HMI screens — demonstrated ability to interact with control systems
- Key evidence: screenshots of HMI interfaces taken by operators indicated CAPABILITY to manipulate industrial processes
**Phase 3 — Current Operations (2020-2026):**
- CISA AA20-296A (October 2020): Dragonfly targeting US SLTT government and aviation networks
- Exploited CVE-2019-19781 (Citrix), CVE-2020-0688 (Exchange), CVE-2018-13379 (Fortinet), CVE-2020-1472 (Zerologon)
- Compromised O365 accounts, exfiltrated data from government servers
- Used Turkish IP addresses and registered look-alike domains (microsoftonline[.]host)
- 2025-2026 Static Tundra campaign: ESCALATION to Polish energy infrastructure with DynoWiper deployment
**DynoWiper — Destructive ICS Malware:**
DynoWiper represents Dragonfly's evolution from reconnaissance/pre-positioning to DESTRUCTIVE CAPABILITY:
- Purpose-built wiper targeting ICS/SCADA environments
- Designed to corrupt or destroy SCADA configurations, HMI databases, and PLC programming
- Targets specific ICS protocols (OPC, Modbus, IEC 61850, IEC 104)
- Can wipe historian databases — destroying operational records needed for forensics and recovery
- Can corrupt PLC firmware — requiring physical replacement of industrial controllers
- Includes time-delay and condition-triggered execution — allowing pre-positioning before activation
- Parallels to previous ICS wipers: Industroyer/CrashOverride (2016, Ukraine), Industroyer2 (2022, Ukraine), Triton/TRISIS (2017, Saudi Arabia)
**The Polish Energy Grid Target:
Weaknesses (CWE)
CWE-358, CWE-798, CWE-287, CWE-1188, CWE-521
Target sectors: Energy, Government, Critical Infrastructure, Aviation, ICS/SCADA, Defense, Water
Target regions: Poland, Europe, North America, Turkey
Detections & IOCs
As of 2026-07-20, this threat has 15 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 71 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, CVE-2024-2617, T1190, T1078.001, T1133, T1053.005, T1059.001, T1078, T1078.002, T1222, T1550, T1003.001