Static Tundra ICS Attacks on Polish Energy Infrastructure with DynoWiper

Static Tundra ICS Attacks on Polish Energy Infrastructure (TL-2026-0014), also tracked as Static Tundra, is a critical-severity campaign scored CVSS 9.8, first published 2026-02-02. It is attributed to Static Tundra (Russia) with high confidence, affects Fortinet FortiGate, maps to 50 MITRE ATT&CK techniques (T1003, T1005, T1021), and is covered by 23 detection rules and 45 indicators of compromise.

Key facts for TL-2026-0014

Threat ID
TL-2026-0014
Also known as
Static Tundra, Berserk Bear, Blue Kraken, Crouching Yeti, Dragonfly, Energetic Bear
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
MONITORING
Category
CAMPAIGN
First published
2026-02-02
Last reviewed
2026-02-02
Attribution
Static Tundra
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
DISRUPTION
Target sectors
Energy, Electrical Utilities, Industrial Control Systems, Critical Infrastructure, Government, Defense
Target regions
Poland, Eastern Europe, NATO Member States, Ukraine, Baltic States
Detection rules
23
Indicators of compromise
45

Malware and tooling in Static Tundra ICS Attacks on Polish Energy Infrastructure

Malware and tooling: DynoWiper - S9038, LazyWiper

Static Tundra is a Russian GRU-aligned threat actor (overlapping with APT44/Sandworm and Dragonfly/Energetic Bear) conducting destructive ICS attacks against Polish energy infrastructure using DynoWiper — a purpose-built wiper malware designed for operational technology (OT) environments. The campaign represents an extension of Russia's decade-long cyber operations against European energy infrastructure, now escalating beyond Ukraine to NATO member state Poland. DynoWiper targets SCADA/HMI systems, engineering workstations, and historian servers in electrical utility environments, overwriting firmware on PLCs and RTUs while simultaneously deploying CaddyWiper variants on IT infrastructure. The attack chain follows the GRU's documented five-phase disruptive playbook: Living on the Edge (compromised VPN/firewall), Living off the Land (native SCADA binaries, MicroSCADA scilc.exe), Going for the GPO (TANKTRAP PowerShell wiper deployment), Disrupt and Deny (DynoWiper on OT + CaddyWiper on IT), and Telegraphing Success (hacktivist persona amplification via Telegram). The Polish campaign specifically targets Polskie Sieci Elektroenergetyczne (PSE) transmission infrastructure and regional distribution operators, exploiting IEC 61850/MMS protocols and legacy SCADA systems. DynoWiper extends the Sandworm wiper lineage: BlackEnergy (2015) → Industroyer (2016) → NotPetya (2017) → Industroyer.V2 (2022) → CaddyWiper (2022) → AcidRain (2022) → DynoWiper (2025), representing the 8th+ generation of Russian ICS-targeted destructive malware.

How Static Tundra ICS Attacks on Polish Energy Infrastructure works

Static Tundra represents Russia's escalation of destructive cyber operations against NATO member state energy infrastructure, specifically targeting Polish electrical utilities. The campaign is attributed to a subunit within Russia's GRU Main Intelligence Directorate (Military Unit 74455 / GTsST / Main Center for Special Technologies), operating under the broader APT44/Sandworm umbrella with distinct tactical overlaps with Dragonfly/Energetic Bear (MITRE G0035) — the group that has targeted Western energy sectors since 2011.

**Historical Context — Russian ICS Attacks:** Russia has maintained the most advanced and operationally proven ICS/OT attack capabilities of any nation-state. Key milestones: - 2015: BlackEnergy → Industroyer (Ukraine power grid attack, first confirmed cyber-caused blackout) - 2016: Industroyer/CrashOverride (second Ukraine grid attack, automated IEC 104/61850 manipulation) - 2017: TRITON/HatMan (Schneider Electric Triconex SIS at Saudi oil refinery — could have caused physical harm) - 2017: NotPetya ($10B+ global impact, targeted Ukraine but spread globally) - 2022: Industroyer.V2 (Ukraine substation attack, streamlined compared to 2016) - 2022: CaddyWiper, HermeticWiper, WhisperGate, IsaacWiper, AcidRain (7+ wiper families in Ukraine invasion) - 2022: Sandworm substation attack (MicroSCADA LotL, scilc.exe, coordinated with missile strikes Oct 10) - 2024: APT44 formally designated by Mandiant (Sandworm graduated to named APT) - 2025: DynoWiper deployed against Polish energy infrastructure

**DynoWiper Malware:** DynoWiper is purpose-built for OT environments with the following capabilities: (1) SCADA/HMI data destruction — targets configuration databases, trending history, alarm logs, and recipe files on SCADA servers and HMI workstations (2) PLC/RTU firmware corruption — sends malformed firmware update commands to connected PLCs via IEC 61850/MMS and Modbus protocols, rendering field devices inoperable (3) Engineering workstation wiping — destroys project files, PLC programs, network configurations on engineering stations (targeting Siemens SIMATIC, ABB, Schneider Electric platforms) (4) Historian server corruption — targets OSIsoft PI, Wonderware, and other historian databases, destroying months of operational data (5) IT infrastructure destruction — deploys CaddyWiper variant on Windows domain infrastructure via GPO, following the documented GRU playbook

**The GRU's Five-Phase Disruptive Playbook (Mandiant):** Phase 1 — Living on the Edge: Compromise edge infrastructure (VPN appliances, firewalls, mail servers) for initial access. Sandworm specifically scanned for Citrix, Exchange, and Fortinet VPN vulnerabilities. Phase 2 — Living off the Land: Use native tools (PowerShell, wmiexec, PortProxy, Impacket, Chisel) and legitimate SCADA binaries (MicroSCADA scilc.exe) to move laterally and avoid detection. Phase 3 — Going for the GPO: Create Group Policy Objects via TANKTRAP PowerShell script to deploy wipers across Active Directory domains. Phase 4 — Disrupt and Deny: Deploy DynoWiper on OT + CaddyWiper on IT simultaneously for maximum disruption. Phase 5 — Telegraph Success: Amplify narrative via hacktivist personas (CyberArmyofRussia_Reborn, Xaknet, Solntsepek) on Telegram.

**Polish Energy Sector Targeting:** Poland is a primary target due to: (1) NATO's eastern flank energy transit hub, (2) host of NATO forward presence, (3) major military/humanitarian supply route to Ukraine, (4) energy interconnectors with Ukraine/Baltic states, (5) legacy SCADA infrastructure in regional distribution companies. Static Tundra specifically targets: 400kV/220kV transmission substations, regional distribution operator control centers, gas compression stations on the Yamal pipeline system, and renewable energy management systems.

**Wiper Malware Lineage — GRU Destructive Arsenal:** BlackEnergy (2015) → Industroyer/CrashOverride (2016) → NotPetya (2017) → Olympic Destroyer (2018) → WhisperGate (2022) → HermeticWiper (2022) → IsaacWiper (2022) → CaddyWiper (2022) → AcidRain (2022) → DoubleZero (2022) → Industroyer.V2 (2022) → CADDYWIPER variants (2022-2023) → DynoWiper (2025). At least 15+ distinct wiper variants deployed since 2022, demonstrating massive operational investment in destructive capabilities.

**ICS-Specific Malware (7+ known families):** 1. Stuxnet (2010, US/Israel), 2. BlackEnergy/KillDisk (2015, Russia), 3. Industroyer/CrashOverride (2016, Russia), 4. TRITON/HatMan (2017, Russia), 5. Industroyer.V2 (2022, Russia), 6. PIPEDREAM/Incontroller (2022, unknown — possibly Russia), 7. COSMICENERGY (2023, possible Russian training tool), 8. DynoWiper (2025, Russia/Static Tundra). Russia is responsible for at least 5 of 8 known ICS-specific malware families.

MITRE ATT&CK techniques used in TL-2026-0014

credential-access

T1003 OS Credential Dumping; T1110 Brute Force; T1187 Forced Authentication

collection

T1005 Data from Local System; T1113 Screen Capture; T1114 Email Collection; T1213.002 Sharepoint; T1560 Archive Collected Data

lateral-movement

T1021 Remote Services; T1021.002 SMB/Windows Admin Shares; T1210 Exploitation of Remote Services; T1570 Lateral Tool Transfer

defense-evasion

T1036 Masquerading; T1070 Indicator Removal; T1078 Valid Accounts; T1550 Use Alternate Authentication Material

execution

T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1059.001 PowerShell

discovery

T1069 Permission Groups Discovery; T1083 File and Directory Discovery; T1087 Account Discovery; T1135 Network Share Discovery

command-and-control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling

persistence

T1133 External Remote Services; T1136 Create Account; T1505 Server Software Component; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution

initial-access

T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1566 Phishing

impact

T1485 Data Destruction; T1489 Service Stop; T1490 Inhibit System Recovery; T1491 Defacement; T1495 Firmware Corruption; T1561 Disk Wipe; T1561.001 Disk Content Wipe

defense-impairment

T1553 Subvert Trust Controls; T1685 Disable or Modify Tools

resource-development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1588 Obtain Capabilities

reconnaissance

T1590 Gather Victim Network Information; T1591 Gather Victim Org Information; T1595 Active Scanning

Affected products and versions in Static Tundra ICS Attacks on Polish Energy Infrastructure

  • Fortinet — FortiGate
    Vulnerable versions: Unpatched versions
  • Mikronika — HMI Computers
    Vulnerable versions: All
  • Various — ICS/SCADA Systems
    Vulnerable versions: Wind/Solar farms, CHP plants

Remediation for Static Tundra ICS Attacks on Polish Energy Infrastructure

Patches

  • Citrix CVE-2019-19781: Apply Citrix ADC and Gateway patch (Sandworm initial access vector)
  • Microsoft Exchange CVE-2020-0688: Apply Exchange CU patch (Sandworm initial access vector)
  • Fortinet CVE-2018-13379: Update FortiOS to patched version (Sandworm VPN exploitation)
  • ABB MicroSCADA: Apply latest security updates, restrict SCIL execution environment
  • Schneider Electric Triconex: Physical key-switch to PROGRAM mode only during maintenance

Immediate actions

  • Verify IT/OT network segmentation — no direct IP connectivity between corporate IT and SCADA/OT networks. Deploy unidirectional security gateways (data diodes) at IT/OT boundaries
  • Audit all VPN and edge infrastructure (Citrix, Fortinet, MS Exchange) for compromise indicators — Static Tundra/Sandworm exploits CVE-2019-19781, CVE-2020-0688, CVE-2018-13379
  • Restrict MicroSCADA scilc.exe execution to authorized operators only — implement application whitelisting on SCADA servers
  • Deploy file integrity monitoring on OT engineering workstations — alert on PLC project file modifications, new ISO mounts, and SCIL script changes
  • Disable SMBv1 across all OT and IT networks — Sandworm uses SMB for lateral movement and credential harvesting

Workarounds

  • If full IT/OT segmentation cannot be achieved immediately: deploy jump servers with MFA for all OT access, disable RDP on OT systems, restrict PowerShell execution to signed scripts only
  • For MicroSCADA environments: remove or rename scilc.exe on systems where SCIL command-line execution is not required operationally
  • Block ISO mount capability on SCADA servers via Group Policy — Sandworm's 2022 Ukraine substation attack used a.iso to deliver malicious SCIL commands
  • Deploy ASR rules on Windows OT systems to block process creation from ISO/IMG mounted images

Longer-term hardening

  • Implement IEC 62443 security architecture — industrial DMZ with defense-in-depth zones and conduits
  • Deploy OT-specific network monitoring (Dragos Platform, Claroty, Nozomi Networks) for protocol-aware ICS anomaly detection
  • Establish dedicated OT Active Directory forest — no trust relationship with corporate IT AD. Implement credential tiering (Tier 0 for OT domain controllers)
  • Conduct regular Sandworm/APT44 TTPs tabletop exercises with utility SOC teams — practice detecting LotL techniques in OT environments
  • Implement IEC 61850 monitoring — detect unauthorized MMS commands to substation relays and IEDs
  • Deploy honeypots mimicking SCADA/HMI systems at network boundaries to detect reconnaissance

Weaknesses (CWE) in Static Tundra ICS Attacks on Polish Energy Infrastructure

CWE-284, CWE-306, CWE-522

Timeline of Static Tundra ICS Attacks on Polish Energy Infrastructure

  • FSB/GRU-aligned Dragonfly (Energetic Bear) begins multi-year intrusion campaign against international energy sector, deploying Havex RAT via supply chain compromise of ICS vendor websites and spearphishing. Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-083a
  • First confirmed cyber-caused power outage. BlackEnergy/KillDisk deployed against three Ukrainian power distribution companies, affecting 230,000 customers for 1-6 hours. Coordinated with telephone DDoS. Source: CISA/ICS-CERT
  • Industroyer/CrashOverride attacks Ukrenergo transmission substation. First malware to directly interact with ICS protocols (IEC 104, IEC 61850, OPC DA). Automated grid manipulation capability. Source: ESET/Dragos
  • NotPetya wiper deployed via M.E.Doc supply chain targeting Ukraine. Spreads globally via EternalBlue/EternalRomance. $10B+ total damage. GRU Military Unit 74455 indicted. Source: DOJ indictment
  • TRITON/HatMan malware targets Schneider Electric Triconex safety systems at Saudi oil refinery. First malware targeting Safety Instrumented Systems — could have caused physical harm. TsNIIKhM employee indicted. Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-083a
  • Russia invades Ukraine. 7+ wiper families deployed: WhisperGate, WhisperKill, HermeticWiper, IsaacWiper, CaddyWiper, DoubleZero, AcidRain. AcidRain targets Viasat KA-SAT satellite modems, spills over to 5,800 Enercon wind turbines in Germany. Source: https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/
  • DOJ unseals indictments of 3 FSB officers and 1 TsNIIKhM employee for energy sector hacking campaigns (2011-2018). Rewards for Justice offers $10M for information. Source: https://www.justice.gov/opa/pr/four-russian-government-employees-charged-two-historical-hacking-campaigns-targeting-critical
  • CISA/Dragos disclose PIPEDREAM/Incontroller — 7th known ICS-specific malware targeting Omron and Schneider Electric PLCs via CODESYS, Modbus, OPC UA. Capable of 38% of known ICS attack techniques. Attributed to CHERNOVITE. Source: https://www.dragos.com/blog/detecting-chernovites-pipedream-with-the-dragos-platform
  • Sandworm (APT44) disrupts Ukrainian power substation using MicroSCADA Living-off-the-Land technique (scilc.exe via ISO mount). OT attack coordinated with mass Russian missile strikes on infrastructure. CaddyWiper deployed on IT 2 days later. Source: https://cloud.google.com/blog/topics/threat-intelligence/sandworm-disrupts-power-ukraine-operational-technology/
  • Mandiant publishes 'The GRU's Disruptive Playbook' documenting the five-phase operational model (Edge→LotL→GPO→Disrupt→Telegraph) used by Sandworm/UNC3810 across 15+ wiper variants. Source: https://cloud.google.com/blog/topics/threat-intelligence/gru-disruptive-playbook
  • Mandiant graduates Sandworm to APT44 named designation. Report documents integration of espionage, attack, and influence operations. Confirms GRU Military Unit 74455 (GTsST). Ongoing wartime operations against Ukraine with spillover risk to NATO allies. Source: https://services.google.com/fh/files/misc/apt44-unearthing-sandworm.pdf
  • Static Tundra campaign identified targeting Polish energy infrastructure. DynoWiper malware deployed against SCADA systems in Polish electrical utilities. Campaign follows GRU five-phase playbook adapted for Polish OT environments. First confirmed destructive ICS operation against a NATO member state energy grid.
  • First Exploitation
  • DynoWiper technical analysis reveals purpose-built OT wiper targeting MicroSCADA, Siemens SIMATIC, and ABB platforms. Capability to corrupt PLC firmware via IEC 61850/MMS and Modbus. Extends Sandworm wiper lineage as 8th+ generation destructive ICS malware.
  • Discovered
  • Disclosed
  • Threadlinqs Intelligence revalidates TL-2026-0014 (Static Tundra/DynoWiper ICS Attacks on Polish Energy). Comprehensive analysis mapping full Russian ICS attack lineage, GRU disruptive playbook, and escalation to NATO member state critical infrastructure.
  • As of 2026-05-29, this specific campaign (MITRE C0063, Mar-Dec 2025) concluded and was thwarted: DynoWiper/LazyWiper began overwriting files but alerts halted it, with no disruption to Poland's power generation or heat supply (ESET/CERT Polska, Jan 2026). The responsible Russian actors (Sandworm/APT44, Static Tundra/FSB) remain fully active in 2026, so monitoring is warranted rather than ACTIVE or RESOLVED.

Sources cited for Static Tundra ICS Attacks on Polish Energy Infrastructure

Threats related to Static Tundra ICS Attacks on Polish Energy Infrastructure

Detection coverage for TL-2026-0014

As of 2026-02-02, Threadlinqs Intelligence publishes 23 detection rule(s) for TL-2026-0014 across Splunk SPL, Microsoft KQL and Sigma, covering 45 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats