Static Tundra Attacks on Polish Energy Infrastructure - 30+ Wind and Solar Farms
Static Tundra Attacks on Polish Energy Infrastructure (TL-2026-0037), also tracked as Static Tundra, is a critical-severity ICS/SCADA threat scored CVSS 9, first published 2026-02-03. It is attributed to Static Tundra (Russia) with high confidence, affects Multiple Wind Farm SCADA/Control Systems, maps to 32 MITRE ATT&CK techniques (T0800, T0809, T0814), and is covered by 12 detection rules and 39 indicators of compromise.
Key facts for TL-2026-0037
- Threat ID
- TL-2026-0037
- Also known as
- Static Tundra, Energetic Bear, Dragonfly, Berserk Bear, Blue Kraken, Crouching Yeti
- Severity
- CRITICAL
- CVSS
- 9 (N/A - ICS/SCADA Campaign)
- Status
- MONITORING
- Category
- ICS_SCADA
- First published
- 2026-02-03
- Last reviewed
- 2026-02-03
- Attribution
- Static Tundra
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- STATE_SPONSORED
- Target sectors
- Energy, Renewable Energy, Critical Infrastructure, Utilities
- Target regions
- Poland, Central Europe, NATO Eastern Flank
- Detection rules
- 12
- Indicators of compromise
- 39
Malware and tooling in Static Tundra Attacks on Polish Energy Infrastructure
Malware and tooling: DynoWiper — ICS-specific destructive malware targeting historian databases (.pid), HMI projects (.prj/.hmi), TIA Portal files (.tia), PLC archives (.zap), DynoWiper: ICS-specific wiper targeting .pid, .prj, .hmi, .tia, .zap files via GPO deployment
Static Tundra, a GRU-affiliated threat group operating as a subunit of Sandworm (APT44/IRIDIUM/Voodoo Bear), conducted targeted cyber-physical attacks against 30+ wind and solar farm SCADA/ICS systems across Polish energy infrastructure in 2025-2026, deploying the DynoWiper destructive malware specifically designed to corrupt ICS historian databases, HMI configurations, and PLC firmware. This campaign represents a strategic escalation: Russia targeting NATO member renewable energy infrastructure as a geopolitical weapon — undermining Poland's energy transition while demonstrating capability to disrupt the European ENTSO-E interconnected grid. The attacks exploited ICS-specific protocols (Modbus TCP, IEC 60870-5-104, DNP3) to manipulate SCADA systems controlling wind turbine pitch controllers, solar inverter arrays, and substation protection relays. Static Tundra's operational methodology combines initial IT network compromise (spearphishing → Active Directory → engineering workstation lateral movement) with OT-specific tradecraft: exploitation of unsegmented IT/OT networks, abuse of legitimate engineering tools (TIA Portal, EcoStruxure), and deployment of DynoWiper to corrupt ICS data integrity while avoiding safety instrumented system (SIS) triggers that would cause immediate physical damage. The campaign targets Poland specifically due to its role as the largest Central European energy market, its aggressive renewable energy expansion (target: 50% by 2030), its strategic importance as a NATO eastern flank transit corridor for energy and military logistics, and its position as a key node in ENTSO-E cross-border electricity trading. This is cyber-physical warfare disguised as data destruction — corrupting SCADA historian databases causes operators to lose situational awareness, leading to manual errors that can cascade into physical equipment damage.
How Static Tundra Attacks on Polish Energy Infrastructure works
Static Tundra emerged as a distinct operational cluster within the broader Sandworm/APT44 ecosystem, tracked by Dragos as a subset of the ELECTRUM activity group. While Sandworm (GRU Unit 74455) is Russia's primary ICS/OT attack capability — responsible for Ukraine's 2015/2016 power grid attacks, NotPetya, Industroyer/CrashOverride, Industroyer2, and the PIPEDREAM/INCONTROLLER modular ICS attack framework — Static Tundra represents a specialization: targeting RENEWABLE energy infrastructure in NATO member states.
POLISH ENERGY INFRASTRUCTURE CONTEXT:
Poland operates one of Central Europe's largest and most strategically important energy grids:
- TSO: Polskie Sieci Elektroenergetyczne (PSE S.A.) — Transmission System Operator - ENTSO-E: Member of the European Network of Transmission System Operators, interconnected with Germany, Czech Republic, Slovakia, Lithuania, Sweden - Renewable expansion: National Energy and Climate Plan targets 50% renewable energy by 2030 - Wind capacity: 10+ GW installed (2025), concentrated in northern Poland (Pomerania, West Pomerania, Warmia-Masuria) - Solar capacity: 15+ GW installed (2025), distributed across agricultural regions - Strategic importance: NATO eastern flank energy backbone, transit corridor for LNG terminals (Świnoujście), and interconnector pipelines
SCADA/ICS SYSTEMS TARGETED:
Static Tundra targeted the specific ICS components controlling wind and solar farm operations:
1. WIND FARM SCADA: - Wind turbine controllers: Siemens SIMATIC S7-1500, Vestas/Siemens Gamesa proprietary PLCs - Pitch control systems: regulate blade angle for power output and storm protection - Yaw control systems: orient nacelle into wind direction - SCADA platforms: Siemens WinCC OA, GE iFIX, Schneider Electric ClearSCADA - Meteorological data systems: wind speed/direction sensors feeding turbine optimization - Grid interconnection: substation protection relays (ABB REL670, Siemens SIPROTEC 5)
2. SOLAR FARM SCADA: - Central inverters: SMA Sunny Central, Huawei SUN2000, ABB/FIMER PVS-175 - String monitoring: per-panel current/voltage monitoring for fault detection - Tracker controllers: single-axis solar tracker PLCs (NEXTracker, Array Technologies) - Weather stations: irradiance sensors, temperature monitors - Grid tie protection: anti-islanding relays, frequency/voltage ride-through controllers
3. SUBSTATION SYSTEMS: - Protection relays: ABB REL670, Siemens SIPROTEC 5 - RTUs: ABB RTU560, Schneider Electric SAITEL DP - Protocol gateways: Modbus TCP ↔ IEC 60870-5-104 ↔ DNP3 translators - ENTSO-E SCADA interface: IEC 60870-5-104 to PSE national dispatch center
ICS PROTOCOL EXPLOITATION:
Static Tundra exploited three primary ICS protocols:
1. MODBUS TCP (Port 502): - No authentication, no encryption in base protocol - Static Tundra sent malicious function codes: FC6 (Write Single Register) to alter setpoints, FC15/16 (Write Multiple Coils/Registers) for bulk parameter manipulation - Target: wind turbine pitch angle limits, solar inverter power factor settings - Impact: altered setpoints cause equipment to operate outside safe parameters
2. IEC 60870-5-104 (Port 2404): - Standard SCADA telecontrol protocol for substation communication - Static Tundra injected ASDU (Application Service Data Unit) commands: single/double commands to operate circuit breakers, setpoint commands to alter protection relay thresholds - Target: substation protection relay trip settings, ENTSO-E dispatch signaling - Impact: modified protection settings can cause relay misoperation — either nuisance tripping (disconnecting generation) or failure to trip (equipment damage)
3. DNP3 (Port 20000): - Distributed Network Protocol used for RTU communication - Static Tundra exploited DNP3 broadcast addressing to send commands to all RTUs simultaneously - Target: RTU configurations, time synchronization (time manipulation causes event correlation failure) - Impact: RTU configuration corruption causes loss of visibility for operators
DYNOWIPER MALWARE:
DynoWiper is Static Tundra's purpose-built ICS destructive malware:
- Function: Corrupts ICS historian databases (OSIsoft PI, Wonderware Historian), HMI project files (WinCC OA, iFIX), PLC program backups, and engineering workstation configurations - Method: Targeted file overwrite — not encryption (not ransomware). Overwrites specific file types: .pid (PI data), .prj/.hmi (SCADA projects), .tia (TIA Portal projects), .zap (PLC program archives) - Persistence: Deploys via Group Policy Object (GPO) in Active Directory environments - Wiper logic: Checks for ICS-related file extensions and process names before activating — avoids general-purpose file destruction to maximize ICS-specific impact while minimizing detection by IT-focused security tools - Safety system awareness: DynoWiper explicitly avoids corrupting Safety Instrumented System (SIS) configurations — preventing immediate physical hazard but causing data integrity loss that leads to operational errors - Impact chain: Corrupted historian data → operators lose historical trends → manual operation required → human error probability increases → physical equipment damage through incorrect operator actions
ATTRIBUTION:
Static Tundra → Sandworm (APT44) → GRU Unit 74455: - Technical indicators: shared C2 infrastructure with known Sandworm operations, DynoWiper code shares libraries with Industroyer2 wiper component - Operational indicators: targeting aligns with Russian strategic objectives (disrupting NATO energy independence, undermining EU renewable energy transition) - Temporal indicators: attacks intensified during Poland-Ukraine energy cooperation announcements and EU sanctions escalation - OSINT: GRU Unit 74455 (Main Centre for Special Technologies) has documented ICS attack capability dating to 2015 Ukraine grid attacks
GEOPOLITICAL CONTEXT:
Poland's renewable energy infrastructure is a strategic target for Russia: 1. Energy independence: Poland is reducing Russian fossil fuel dependency via renewables and LNG — targeting renewables undermines this transition 2. NATO deterrence: demonstrating capability to disrupt NATO member energy infrastructure serves as coercive signaling 3. ENTSO-E disruption: Polish grid instability can cascade to Germany, Czech Republic, Slovakia via interconnectors 4. Economic impact: damaged wind/solar farms = lost generation revenue + replacement costs + insurance premium increases 5. Precedent: extends Sandworm's Ukraine grid attack methodology to NATO territory, testing alliance response thresholds
MITRE ATT&CK techniques used in TL-2026-0037
inhibit-response-function
T0800 Activate Firmware Update Mode; T0809 Data Destruction; T0814 Denial of Service; T1691.002 Reporting Message
Impact
T0827 Loss of Control; T0829 Loss of View; T0831 Manipulation of Control; T0879 Damage to Property
impact
T0828 Loss of Productivity and Revenue; T0880 Loss of Safety; T1485 Data Destruction
impair-process-control
discovery
T0846 Remote System Discovery; T1046 Network Service Discovery
evasion
T0851 Rootkit; T1692.001 Command Message; T1692.002 Reporting Message
collection
T0861 Point & Tag Identification; T1005 Data from Local System; T1119 Automated Collection
initial-access
T0866 Exploitation of Remote Services; T1566 Phishing
execution
T0875 Change Program State; T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter
persistence
T0889 Modify Program; T1547 Boot or Logon Autostart Execution
credential-access
lateral-movement
defense-evasion
T1036 Masquerading; T1078 Valid Accounts
reconnaissance
Affected products and versions in Static Tundra Attacks on Polish Energy Infrastructure
- Multiple — Wind Farm SCADA/Control Systems
Vulnerable versions: Various ICS platforms - Multiple — Solar Farm Management Systems
Vulnerable versions: Various ICS platforms - Multiple — Combined Heat and Power Plant Controls
Vulnerable versions: Various ICS platforms
Remediation for Static Tundra Attacks on Polish Energy Infrastructure
Immediate actions
- Review all ICS/SCADA access logs for December 29, 2025 and surrounding dates
- Audit remote access to OT networks
- Check for unauthorized accounts or permission changes
- Verify integrity of HMI and SCADA configurations
- Isolate any compromised systems immediately
Workarounds
- Disable remote access during non-business hours when possible
- Implement jump servers for all OT access
- Enable enhanced logging on all ICS components
Longer-term hardening
- Implement strict IT/OT network segmentation
- Deploy OT-specific IDS (Claroty, Nozomi, Dragos)
- Establish 24/7 OT SOC monitoring
- Conduct tabletop exercises for energy sector attacks
- Coordinate with sector ISACs and CISA
Timeline of Static Tundra Attacks on Polish Energy Infrastructure
- Sandworm (GRU Unit 74455) executes first-ever cyber-caused power outage: Ukraine's western grid, 230,000 customers without power for 6 hours. Uses BlackEnergy3 malware + manual SCADA manipulation via IEC-104. Establishes Russia's ICS attack capability. Source: SANS ICS, Dragos
- Sandworm deploys Industroyer/CrashOverride against Ukraine's Ukrenergo transmission grid. Automated ICS attack using IEC-104, IEC 61850, and OPC DA protocols. First malware to directly manipulate power grid protocols. 1-hour blackout in Kyiv. Source: ESET, Dragos
- Sandworm deploys Industroyer2 against Ukrainian energy infrastructure coinciding with Russian military offensive. Targeted IEC-104 protocol manipulation. Discovered and mitigated before causing power outage. Confirmed Sandworm's continued ICS capability development. Source: ESET, CERT-UA
- Dragos and CISA disclose PIPEDREAM/INCONTROLLER: modular ICS attack framework targeting Schneider Electric PLCs (CODESYS) and Omron NX/NJ PLCs. Most capable ICS attack tool ever discovered. Attributed to Sandworm ecosystem. Demonstrates OPC UA, Modbus, and CODESYS exploitation. Source: Dragos, CISA
- Static Tundra identified as distinct operational cluster within Sandworm/ELECTRUM ecosystem. Specialization: targeting renewable energy infrastructure in NATO member states. Uses modified Sandworm tooling adapted for wind/solar farm SCADA systems. First operations targeting Polish wind farms detected.
- Static Tundra conducts initial reconnaissance against Polish wind farm operators in Pomerania and West Pomerania. Spearphishing of energy company employees using Polish-language lures themed around EU renewable energy subsidies. Goal: establish AD foothold for lateral movement to OT.
- DynoWiper malware first observed in Static Tundra operations. Purpose-built ICS destructive malware targeting historian databases (.pid), HMI projects (.prj), TIA Portal projects (.tia), and PLC archives (.zap). Explicitly avoids SIS corruption — causes data integrity loss, not immediate physical hazard.
- Static Tundra campaign escalates: 30+ wind and solar farms across Poland targeted. IT network compromise via AD → lateral movement to engineering workstations → OT pivot via unsegmented networks. DynoWiper deployed via GPO to corrupt historian databases and HMI configurations. Multiple farms lose SCADA visibility.
- Static Tundra exploits ICS protocols: Modbus TCP write commands alter wind turbine pitch setpoints, IEC-104 ASDU commands modify substation protection relay settings, DNP3 broadcast addressing corrupts RTU configurations. Protocol-level attacks demonstrate deep ICS knowledge beyond IT-focused operations.
- ENTSO-E issues advisory on cross-border grid stability risks from ICS attacks on Polish renewable generation. Modified protection relay settings could cause cascade disconnection of Polish generation, stressing German-Polish interconnector capacity. PSE (Polish TSO) activates enhanced grid monitoring.
- Static Tundra expands targeting to solar farms: central inverter control systems (SMA, Huawei, ABB), tracker controller PLCs, and grid-tie protection relays. Solar farm SCADA often uses cloud-connected monitoring — provides additional attack surface via internet-facing management portals.
- Current state: Static Tundra maintains persistent access to multiple Polish energy OT networks. DynoWiper deployments continue. NATO and EU coordinating ICS defense response. Polish CERT (CERT.PL) leading incident response with Dragos support. Campaign demonstrates GRU treats renewable energy targeting as military capability for NATO coercion.
- As of 2026-05-29, the threat remains active: the Dec 2025 DynoWiper attacks on 30+ Polish renewable/CHP sites were confirmed by CERT Polska (Jan 30), ESET/Dragos, and a CISA alert (Feb 10, 2026), with the Russian actor (Berserk Bear/Static Tundra per Poland, Sandworm per ESET) undisrupted and uncharged. The discrete wiper event concluded without blackouts, but no CVE patch, takedown, or successor applies and CISA/CERT-PL still treat it as a standing critical-infrastructure threat, so it warrants
Sources cited for Static Tundra Attacks on Polish Energy Infrastructure
- Dragos — ELECTRUM/Sandworm ICS Threat Profile
- Mandiant — APT44: Russia's Military Sabotage Group
- CISA — Russian ICS/SCADA Threat Advisory
- ESET — Industroyer2 Analysis
- Dragos — PIPEDREAM ICS Attack Framework
- PSE S.A. — Polish TSO
- ENTSO-E — European Grid Security
- MITRE ATT&CK for ICS — Manipulation of Control
- Siemens — SIPROTEC 5 Protection Relays
- ABB — REL670 Protection Relay
- Schneider Electric — ClearSCADA
- AVEVA — PI System Historian
- Recorded Future — GRU Cyber Operations
- Nozomi Networks — ICS Protocol Security
- SANS ICS — Critical Infrastructure Defense
Threats related to Static Tundra Attacks on Polish Energy Infrastructure
Detection coverage for TL-2026-0037
As of 2026-02-03, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0037 across Splunk SPL, Microsoft KQL and Sigma, covering 39 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.