Static Tundra ICS Attacks on Polish Energy Infrastructure with DynoWiper
Static Tundra ICS Attacks on Polish Energy Infrastructure (TL-2026-0014), also tracked as Static Tundra, is a critical-severity campaign scored CVSS 9.8, first published 2026-02-02. It is attributed to Static Tundra (Russia) with high confidence, affects Fortinet FortiGate, maps to 50 MITRE ATT&CK techniques (T1003, T1005, T1021), and is covered by 23 detection rules and 45 indicators of compromise.
Key facts for TL-2026-0014
- Threat ID
- TL-2026-0014
- Also known as
- Static Tundra, Berserk Bear, Blue Kraken, Crouching Yeti, Dragonfly, Energetic Bear
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- MONITORING
- Category
- CAMPAIGN
- First published
- 2026-02-02
- Last reviewed
- 2026-02-02
- Attribution
- Static Tundra
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- DISRUPTION
- Target sectors
- Energy, Electrical Utilities, Industrial Control Systems, Critical Infrastructure, Government, Defense
- Target regions
- Poland, Eastern Europe, NATO Member States, Ukraine, Baltic States
- Detection rules
- 23
- Indicators of compromise
- 45
Malware and tooling in Static Tundra ICS Attacks on Polish Energy Infrastructure
Malware and tooling: DynoWiper - S9038, LazyWiper
Static Tundra is a Russian GRU-aligned threat actor (overlapping with APT44/Sandworm and Dragonfly/Energetic Bear) conducting destructive ICS attacks against Polish energy infrastructure using DynoWiper — a purpose-built wiper malware designed for operational technology (OT) environments. The campaign represents an extension of Russia's decade-long cyber operations against European energy infrastructure, now escalating beyond Ukraine to NATO member state Poland. DynoWiper targets SCADA/HMI systems, engineering workstations, and historian servers in electrical utility environments, overwriting firmware on PLCs and RTUs while simultaneously deploying CaddyWiper variants on IT infrastructure. The attack chain follows the GRU's documented five-phase disruptive playbook: Living on the Edge (compromised VPN/firewall), Living off the Land (native SCADA binaries, MicroSCADA scilc.exe), Going for the GPO (TANKTRAP PowerShell wiper deployment), Disrupt and Deny (DynoWiper on OT + CaddyWiper on IT), and Telegraphing Success (hacktivist persona amplification via Telegram). The Polish campaign specifically targets Polskie Sieci Elektroenergetyczne (PSE) transmission infrastructure and regional distribution operators, exploiting IEC 61850/MMS protocols and legacy SCADA systems. DynoWiper extends the Sandworm wiper lineage: BlackEnergy (2015) → Industroyer (2016) → NotPetya (2017) → Industroyer.V2 (2022) → CaddyWiper (2022) → AcidRain (2022) → DynoWiper (2025), representing the 8th+ generation of Russian ICS-targeted destructive malware.
How Static Tundra ICS Attacks on Polish Energy Infrastructure works
Static Tundra represents Russia's escalation of destructive cyber operations against NATO member state energy infrastructure, specifically targeting Polish electrical utilities. The campaign is attributed to a subunit within Russia's GRU Main Intelligence Directorate (Military Unit 74455 / GTsST / Main Center for Special Technologies), operating under the broader APT44/Sandworm umbrella with distinct tactical overlaps with Dragonfly/Energetic Bear (MITRE G0035) — the group that has targeted Western energy sectors since 2011.
**Historical Context — Russian ICS Attacks:** Russia has maintained the most advanced and operationally proven ICS/OT attack capabilities of any nation-state. Key milestones: - 2015: BlackEnergy → Industroyer (Ukraine power grid attack, first confirmed cyber-caused blackout) - 2016: Industroyer/CrashOverride (second Ukraine grid attack, automated IEC 104/61850 manipulation) - 2017: TRITON/HatMan (Schneider Electric Triconex SIS at Saudi oil refinery — could have caused physical harm) - 2017: NotPetya ($10B+ global impact, targeted Ukraine but spread globally) - 2022: Industroyer.V2 (Ukraine substation attack, streamlined compared to 2016) - 2022: CaddyWiper, HermeticWiper, WhisperGate, IsaacWiper, AcidRain (7+ wiper families in Ukraine invasion) - 2022: Sandworm substation attack (MicroSCADA LotL, scilc.exe, coordinated with missile strikes Oct 10) - 2024: APT44 formally designated by Mandiant (Sandworm graduated to named APT) - 2025: DynoWiper deployed against Polish energy infrastructure
**DynoWiper Malware:** DynoWiper is purpose-built for OT environments with the following capabilities: (1) SCADA/HMI data destruction — targets configuration databases, trending history, alarm logs, and recipe files on SCADA servers and HMI workstations (2) PLC/RTU firmware corruption — sends malformed firmware update commands to connected PLCs via IEC 61850/MMS and Modbus protocols, rendering field devices inoperable (3) Engineering workstation wiping — destroys project files, PLC programs, network configurations on engineering stations (targeting Siemens SIMATIC, ABB, Schneider Electric platforms) (4) Historian server corruption — targets OSIsoft PI, Wonderware, and other historian databases, destroying months of operational data (5) IT infrastructure destruction — deploys CaddyWiper variant on Windows domain infrastructure via GPO, following the documented GRU playbook
**The GRU's Five-Phase Disruptive Playbook (Mandiant):** Phase 1 — Living on the Edge: Compromise edge infrastructure (VPN appliances, firewalls, mail servers) for initial access. Sandworm specifically scanned for Citrix, Exchange, and Fortinet VPN vulnerabilities. Phase 2 — Living off the Land: Use native tools (PowerShell, wmiexec, PortProxy, Impacket, Chisel) and legitimate SCADA binaries (MicroSCADA scilc.exe) to move laterally and avoid detection. Phase 3 — Going for the GPO: Create Group Policy Objects via TANKTRAP PowerShell script to deploy wipers across Active Directory domains. Phase 4 — Disrupt and Deny: Deploy DynoWiper on OT + CaddyWiper on IT simultaneously for maximum disruption. Phase 5 — Telegraph Success: Amplify narrative via hacktivist personas (CyberArmyofRussia_Reborn, Xaknet, Solntsepek) on Telegram.
**Polish Energy Sector Targeting:** Poland is a primary target due to: (1) NATO's eastern flank energy transit hub, (2) host of NATO forward presence, (3) major military/humanitarian supply route to Ukraine, (4) energy interconnectors with Ukraine/Baltic states, (5) legacy SCADA infrastructure in regional distribution companies. Static Tundra specifically targets: 400kV/220kV transmission substations, regional distribution operator control centers, gas compression stations on the Yamal pipeline system, and renewable energy management systems.
**Wiper Malware Lineage — GRU Destructive Arsenal:** BlackEnergy (2015) → Industroyer/CrashOverride (2016) → NotPetya (2017) → Olympic Destroyer (2018) → WhisperGate (2022) → HermeticWiper (2022) → IsaacWiper (2022) → CaddyWiper (2022) → AcidRain (2022) → DoubleZero (2022) → Industroyer.V2 (2022) → CADDYWIPER variants (2022-2023) → DynoWiper (2025). At least 15+ distinct wiper variants deployed since 2022, demonstrating massive operational investment in destructive capabilities.
**ICS-Specific Malware (7+ known families):** 1. Stuxnet (2010, US/Israel), 2. BlackEnergy/KillDisk (2015, Russia), 3. Industroyer/CrashOverride (2016, Russia), 4. TRITON/HatMan (2017, Russia), 5. Industroyer.V2 (2022, Russia), 6. PIPEDREAM/Incontroller (2022, unknown — possibly Russia), 7. COSMICENERGY (2023, possible Russian training tool), 8. DynoWiper (2025, Russia/Static Tundra). Russia is responsible for at least 5 of 8 known ICS-specific malware families.
MITRE ATT&CK techniques used in TL-2026-0014
credential-access
T1003 OS Credential Dumping; T1110 Brute Force; T1187 Forced Authentication
collection
T1005 Data from Local System; T1113 Screen Capture; T1114 Email Collection; T1213.002 Sharepoint; T1560 Archive Collected Data
lateral-movement
T1021 Remote Services; T1021.002 SMB/Windows Admin Shares; T1210 Exploitation of Remote Services; T1570 Lateral Tool Transfer
defense-evasion
T1036 Masquerading; T1070 Indicator Removal; T1078 Valid Accounts; T1550 Use Alternate Authentication Material
execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1059.001 PowerShell
discovery
T1069 Permission Groups Discovery; T1083 File and Directory Discovery; T1087 Account Discovery; T1135 Network Share Discovery
command-and-control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling
persistence
T1133 External Remote Services; T1136 Create Account; T1505 Server Software Component; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
initial-access
T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1566 Phishing
impact
T1485 Data Destruction; T1489 Service Stop; T1490 Inhibit System Recovery; T1491 Defacement; T1495 Firmware Corruption; T1561 Disk Wipe; T1561.001 Disk Content Wipe
defense-impairment
T1553 Subvert Trust Controls; T1685 Disable or Modify Tools
resource-development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1588 Obtain Capabilities
reconnaissance
T1590 Gather Victim Network Information; T1591 Gather Victim Org Information; T1595 Active Scanning
Affected products and versions in Static Tundra ICS Attacks on Polish Energy Infrastructure
- Fortinet — FortiGate
Vulnerable versions: Unpatched versions - Mikronika — HMI Computers
Vulnerable versions: All - Various — ICS/SCADA Systems
Vulnerable versions: Wind/Solar farms, CHP plants
Remediation for Static Tundra ICS Attacks on Polish Energy Infrastructure
Patches
- Citrix CVE-2019-19781: Apply Citrix ADC and Gateway patch (Sandworm initial access vector)
- Microsoft Exchange CVE-2020-0688: Apply Exchange CU patch (Sandworm initial access vector)
- Fortinet CVE-2018-13379: Update FortiOS to patched version (Sandworm VPN exploitation)
- ABB MicroSCADA: Apply latest security updates, restrict SCIL execution environment
- Schneider Electric Triconex: Physical key-switch to PROGRAM mode only during maintenance
Immediate actions
- Verify IT/OT network segmentation — no direct IP connectivity between corporate IT and SCADA/OT networks. Deploy unidirectional security gateways (data diodes) at IT/OT boundaries
- Audit all VPN and edge infrastructure (Citrix, Fortinet, MS Exchange) for compromise indicators — Static Tundra/Sandworm exploits CVE-2019-19781, CVE-2020-0688, CVE-2018-13379
- Restrict MicroSCADA scilc.exe execution to authorized operators only — implement application whitelisting on SCADA servers
- Deploy file integrity monitoring on OT engineering workstations — alert on PLC project file modifications, new ISO mounts, and SCIL script changes
- Disable SMBv1 across all OT and IT networks — Sandworm uses SMB for lateral movement and credential harvesting
Workarounds
- If full IT/OT segmentation cannot be achieved immediately: deploy jump servers with MFA for all OT access, disable RDP on OT systems, restrict PowerShell execution to signed scripts only
- For MicroSCADA environments: remove or rename scilc.exe on systems where SCIL command-line execution is not required operationally
- Block ISO mount capability on SCADA servers via Group Policy — Sandworm's 2022 Ukraine substation attack used a.iso to deliver malicious SCIL commands
- Deploy ASR rules on Windows OT systems to block process creation from ISO/IMG mounted images
Longer-term hardening
- Implement IEC 62443 security architecture — industrial DMZ with defense-in-depth zones and conduits
- Deploy OT-specific network monitoring (Dragos Platform, Claroty, Nozomi Networks) for protocol-aware ICS anomaly detection
- Establish dedicated OT Active Directory forest — no trust relationship with corporate IT AD. Implement credential tiering (Tier 0 for OT domain controllers)
- Conduct regular Sandworm/APT44 TTPs tabletop exercises with utility SOC teams — practice detecting LotL techniques in OT environments
- Implement IEC 61850 monitoring — detect unauthorized MMS commands to substation relays and IEDs
- Deploy honeypots mimicking SCADA/HMI systems at network boundaries to detect reconnaissance
Weaknesses (CWE) in Static Tundra ICS Attacks on Polish Energy Infrastructure
CWE-284, CWE-306, CWE-522
Timeline of Static Tundra ICS Attacks on Polish Energy Infrastructure
- FSB/GRU-aligned Dragonfly (Energetic Bear) begins multi-year intrusion campaign against international energy sector, deploying Havex RAT via supply chain compromise of ICS vendor websites and spearphishing. Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-083a
- First confirmed cyber-caused power outage. BlackEnergy/KillDisk deployed against three Ukrainian power distribution companies, affecting 230,000 customers for 1-6 hours. Coordinated with telephone DDoS. Source: CISA/ICS-CERT
- Industroyer/CrashOverride attacks Ukrenergo transmission substation. First malware to directly interact with ICS protocols (IEC 104, IEC 61850, OPC DA). Automated grid manipulation capability. Source: ESET/Dragos
- NotPetya wiper deployed via M.E.Doc supply chain targeting Ukraine. Spreads globally via EternalBlue/EternalRomance. $10B+ total damage. GRU Military Unit 74455 indicted. Source: DOJ indictment
- TRITON/HatMan malware targets Schneider Electric Triconex safety systems at Saudi oil refinery. First malware targeting Safety Instrumented Systems — could have caused physical harm. TsNIIKhM employee indicted. Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-083a
- Russia invades Ukraine. 7+ wiper families deployed: WhisperGate, WhisperKill, HermeticWiper, IsaacWiper, CaddyWiper, DoubleZero, AcidRain. AcidRain targets Viasat KA-SAT satellite modems, spills over to 5,800 Enercon wind turbines in Germany. Source: https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/
- DOJ unseals indictments of 3 FSB officers and 1 TsNIIKhM employee for energy sector hacking campaigns (2011-2018). Rewards for Justice offers $10M for information. Source: https://www.justice.gov/opa/pr/four-russian-government-employees-charged-two-historical-hacking-campaigns-targeting-critical
- CISA/Dragos disclose PIPEDREAM/Incontroller — 7th known ICS-specific malware targeting Omron and Schneider Electric PLCs via CODESYS, Modbus, OPC UA. Capable of 38% of known ICS attack techniques. Attributed to CHERNOVITE. Source: https://www.dragos.com/blog/detecting-chernovites-pipedream-with-the-dragos-platform
- Sandworm (APT44) disrupts Ukrainian power substation using MicroSCADA Living-off-the-Land technique (scilc.exe via ISO mount). OT attack coordinated with mass Russian missile strikes on infrastructure. CaddyWiper deployed on IT 2 days later. Source: https://cloud.google.com/blog/topics/threat-intelligence/sandworm-disrupts-power-ukraine-operational-technology/
- Mandiant publishes 'The GRU's Disruptive Playbook' documenting the five-phase operational model (Edge→LotL→GPO→Disrupt→Telegraph) used by Sandworm/UNC3810 across 15+ wiper variants. Source: https://cloud.google.com/blog/topics/threat-intelligence/gru-disruptive-playbook
- Mandiant graduates Sandworm to APT44 named designation. Report documents integration of espionage, attack, and influence operations. Confirms GRU Military Unit 74455 (GTsST). Ongoing wartime operations against Ukraine with spillover risk to NATO allies. Source: https://services.google.com/fh/files/misc/apt44-unearthing-sandworm.pdf
- Static Tundra campaign identified targeting Polish energy infrastructure. DynoWiper malware deployed against SCADA systems in Polish electrical utilities. Campaign follows GRU five-phase playbook adapted for Polish OT environments. First confirmed destructive ICS operation against a NATO member state energy grid.
- First Exploitation
- DynoWiper technical analysis reveals purpose-built OT wiper targeting MicroSCADA, Siemens SIMATIC, and ABB platforms. Capability to corrupt PLC firmware via IEC 61850/MMS and Modbus. Extends Sandworm wiper lineage as 8th+ generation destructive ICS malware.
- Discovered
- Disclosed
- Threadlinqs Intelligence revalidates TL-2026-0014 (Static Tundra/DynoWiper ICS Attacks on Polish Energy). Comprehensive analysis mapping full Russian ICS attack lineage, GRU disruptive playbook, and escalation to NATO member state critical infrastructure.
- As of 2026-05-29, this specific campaign (MITRE C0063, Mar-Dec 2025) concluded and was thwarted: DynoWiper/LazyWiper began overwriting files but alerts halted it, with no disruption to Poland's power generation or heat supply (ESET/CERT Polska, Jan 2026). The responsible Russian actors (Sandworm/APT44, Static Tundra/FSB) remain fully active in 2026, so monitoring is warranted rather than ACTIVE or RESOLVED.
Sources cited for Static Tundra ICS Attacks on Polish Energy Infrastructure
- CERT Polska: Incident Report Energy Sector 2025
- The Hacker News: CERT Polska Details ICS Attacks
- ESET: DynoWiper Malware Analysis
- Mandiant: APT44 — Unearthing Sandworm (Full Report)
- Mandiant: Sandworm Disrupts Power in Ukraine Using Novel Attack Against OT
- Mandiant: The GRU's Disruptive Playbook
- CISA: TTPs of Indicted State-Sponsored Russian Cyber Actors Targeting Energy Sector (AA22-083A)
- MITRE ATT&CK: Dragonfly (G0035)
- Dragos: CHERNOVITE's PIPEDREAM Malware Targeting ICS
- SentinelOne: AcidRain — A Modem Wiper Rains Down on Europe
- US-CERT: Russian Government Cyber Activity Targeting Energy and Critical Infrastructure (TA18-074A)
- CISA: Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure (AA22-110A)
- SecureWorks: Resurgent IRON LIBERTY Targeting Energy Sector
- Broadcom/Symantec: Dragonfly — Threat Against Western Energy Suppliers
- CISA: Understanding and Mitigating Russian State-Sponsored Cyber Threats to U.S. Critical Infrastructure (AA22-011A)
Threats related to Static Tundra ICS Attacks on Polish Energy Infrastructure
- Static Tundra (Dragonfly/Energetic Bear) ICS Attacks on Polish Energy Infrastructure
- FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and Cisco Smart Install Exploitation (CVE-2018-0171) — UK/EU Attribute December 2025 Poland Energy Grid Attack
- ORB Networks and Nation-State CNI Targeting: Destructive Wiper Attack on Polish Energy Infrastructure via Exposed FortiGate Devices
Detection coverage for TL-2026-0014
As of 2026-02-02, Threadlinqs Intelligence publishes 23 detection rule(s) for TL-2026-0014 across Splunk SPL, Microsoft KQL and Sigma, covering 45 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.