Static Tundra ICS Attacks on Polish Energy Infrastructure with DynoWiper — Threadlinqs Intelligence
As of 2026-05-30, Static Tundra ICS Attacks on Polish Energy Infrastructure with DynoWiper is a critical-severity campaign threat attributed to Static Tundra (Russia), tracked by Threadlinqs Intelligence with 23 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 45 indicators of compromise.
Threat ID: TL-2026-0014 · Severity: CRITICAL · CVSS: 9.8 · Status: MONITORING · Category: CAMPAIGN
Attribution: Static Tundra · Russia · DISRUPTION
Static Tundra is a Russian GRU-aligned threat actor (overlapping with APT44/Sandworm and Dragonfly/Energetic Bear) conducting destructive ICS attacks against Polish energy infrastructure using
Static Tundra represents Russia's escalation of destructive cyber operations against NATO member state energy infrastructure, specifically targeting Polish electrical utilities. The campaign is attributed to a subunit within Russia's GRU Main Intelligence Directorate (Military Unit 74455 / GTsST / Main Center for Special Technologies), operating under the broader APT44/Sandworm umbrella with distinct tactical overlaps with Dragonfly/Energetic Bear (MITRE G0035) — the group that has targeted Western energy sectors since 2011.
**Historical Context — Russian ICS Attacks:**
Russia has maintained the most advanced and operationally proven ICS/OT attack capabilities of any nation-state. Key milestones:
- 2015: BlackEnergy → Industroyer (Ukraine power grid attack, first confirmed cyber-caused blackout)
- 2016: Industroyer/CrashOverride (second Ukraine grid attack, automated IEC 104/61850 manipulation)
- 2017: TRITON/HatMan (Schneider Electric Triconex SIS at Saudi oil refinery — could have caused physical harm)
- 2017: NotPetya ($10B+ global impact, targeted Ukraine but spread globally)
- 2022: Industroyer.V2 (Ukraine substation attack, streamlined compared to 2016)
- 2022: CaddyWiper, HermeticWiper, WhisperGate, IsaacWiper, AcidRain (7+ wiper families in Ukraine invasion)
- 2022: Sandworm substation attack (MicroSCADA LotL, scilc.exe, coordinated with missile strikes Oct 10)
- 2024: APT44 formally designated by Mandiant (Sandworm graduated to named APT)
- 2025: DynoWiper deployed against Polish energy infrastructure
**DynoWiper Malware:**
DynoWiper is purpose-built for OT environments with the following capabilities:
(1) SCADA/HMI data destruction — targets configuration databases, trending history, alarm logs, and recipe files on SCADA servers and HMI workstations
(2) PLC/RTU firmware corruption — sends malformed firmware update commands to connected PLCs via IEC 61850/MMS and Modbus protocols, rendering field devices inoperable
(3) Engineering workstation wiping — destroys project files, PLC programs, network configurations on engineering stations (targeting Siemens SIMATIC, ABB, Schneider Electric platforms)
(4) Historian server corruption — targets OSIsoft PI, Wonderware, and other historian databases, destroying months of operational data
(5) IT infrastructure destruction — deploys CaddyWiper variant on Windows domain infrastructure via GPO, following the documented GRU playbook
**The GRU's Five-Phase Disruptive Playbook (Mandiant):**
Phase 1 — Living on the Edge: Compromise edge infrastructure (VPN appliances, firewalls, mail servers) for initial access. Sandworm specifically scanned for Citrix, Exchange, and Fortinet VPN vulnerabilities.
Phase 2 — Living off the Land: Use native tools (PowerShell, wmiexec, PortProxy, Impacket, Chisel) and legitimate SCADA binaries (MicroSCADA scilc.exe) to move laterally and avoid detection.
Phase 3 — Going for the GPO: Create Group Policy Objects via TANKTRAP PowerShell script to deploy wipers across Active Directory domains.
Phase 4 — Disrupt and Deny: Deploy DynoWiper on OT + CaddyWiper on IT simultaneously for maximum disruption.
Phase 5 — Telegraph Success: Amplify narrative via hacktivist personas (CyberArmyofRussia_Reborn, Xaknet, Solntsepek) on Telegram.
**Polish Energy Sector Targeting:**
Poland is a primary target due to: (1) NATO's eastern flank energy transit hub, (2) host of NATO forward presence, (3) major military/humanitarian supply route to Ukraine, (4) energy interconnectors with Ukraine/Baltic states, (5) legacy SCADA infrastructure in regional distribution companies. Static Tundra specifically targets: 400kV/220kV transmission substations, regional distribution operator control centers, gas compression stations on the Yamal pipeline system, and renewable energy management systems.
**Wiper Malware Lineage — GRU Destructive Arsenal:**
BlackEnergy (2015) → Industroyer/CrashOverride (2016) → NotPetya (2017) → Olympic Destroyer (2018) → WhisperGate (2022) → HermeticWiper (
Weaknesses (CWE)
CWE-284, CWE-306, CWE-522
Target sectors: Energy, Electrical Utilities, Industrial Control Systems, Critical Infrastructure, Government, Defense
Target regions: Poland, Eastern Europe, NATO Member States, Ukraine, Baltic States
Detections & IOCs
As of 2026-07-28, this threat has 23 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 45 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
CAMPAIGN, CRITICAL, threat intelligence, cybersecurity, T1190, T1133, T1059.001, T1021.002, T1485, T1561.001, T1213.002, T1566, T1189, T1059