Static Tundra Attacks on Polish Energy Infrastructure - 30+ Wind and Solar Farms — Threadlinqs Intelligence
As of 2026-05-30, Static Tundra Attacks on Polish Energy Infrastructure - 30+ Wind and Solar Farms is a critical-severity ics scada threat attributed to Static Tundra (Russia), tracked by Threadlinqs Intelligence with 12 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 39 indicators of compromise.
Threat ID: TL-2026-0037 · Severity: CRITICAL · CVSS: 9 · Status: MONITORING · Category: ICS_SCADA
Attribution: Static Tundra · Russia · STATE_SPONSORED
Static Tundra, a GRU-affiliated threat group operating as a subunit of Sandworm (APT44/IRIDIUM/Voodoo Bear), conducted targeted cyber-physical attacks against 30+ wind and solar farm SCADA/ICS systems
Static Tundra emerged as a distinct operational cluster within the broader Sandworm/APT44 ecosystem, tracked by Dragos as a subset of the ELECTRUM activity group. While Sandworm (GRU Unit 74455) is Russia's primary ICS/OT attack capability — responsible for Ukraine's 2015/2016 power grid attacks, NotPetya, Industroyer/CrashOverride, Industroyer2, and the PIPEDREAM/INCONTROLLER modular ICS attack framework — Static Tundra represents a specialization: targeting RENEWABLE energy infrastructure in NATO member states.
POLISH ENERGY INFRASTRUCTURE CONTEXT:
Poland operates one of Central Europe's largest and most strategically important energy grids:
- TSO: Polskie Sieci Elektroenergetyczne (PSE S.A.) — Transmission System Operator
- ENTSO-E: Member of the European Network of Transmission System Operators, interconnected with Germany, Czech Republic, Slovakia, Lithuania, Sweden
- Renewable expansion: National Energy and Climate Plan targets 50% renewable energy by 2030
- Wind capacity: 10+ GW installed (2025), concentrated in northern Poland (Pomerania, West Pomerania, Warmia-Masuria)
- Solar capacity: 15+ GW installed (2025), distributed across agricultural regions
- Strategic importance: NATO eastern flank energy backbone, transit corridor for LNG terminals (Świnoujście), and interconnector pipelines
SCADA/ICS SYSTEMS TARGETED:
Static Tundra targeted the specific ICS components controlling wind and solar farm operations:
1. WIND FARM SCADA:
- Wind turbine controllers: Siemens SIMATIC S7-1500, Vestas/Siemens Gamesa proprietary PLCs
- Pitch control systems: regulate blade angle for power output and storm protection
- Yaw control systems: orient nacelle into wind direction
- SCADA platforms: Siemens WinCC OA, GE iFIX, Schneider Electric ClearSCADA
- Meteorological data systems: wind speed/direction sensors feeding turbine optimization
- Grid interconnection: substation protection relays (ABB REL670, Siemens SIPROTEC 5)
2. SOLAR FARM SCADA:
- Central inverters: SMA Sunny Central, Huawei SUN2000, ABB/FIMER PVS-175
- String monitoring: per-panel current/voltage monitoring for fault detection
- Tracker controllers: single-axis solar tracker PLCs (NEXTracker, Array Technologies)
- Weather stations: irradiance sensors, temperature monitors
- Grid tie protection: anti-islanding relays, frequency/voltage ride-through controllers
3. SUBSTATION SYSTEMS:
- Protection relays: ABB REL670, Siemens SIPROTEC 5
- RTUs: ABB RTU560, Schneider Electric SAITEL DP
- Protocol gateways: Modbus TCP ↔ IEC 60870-5-104 ↔ DNP3 translators
- ENTSO-E SCADA interface: IEC 60870-5-104 to PSE national dispatch center
ICS PROTOCOL EXPLOITATION:
Static Tundra exploited three primary ICS protocols:
1. MODBUS TCP (Port 502):
- No authentication, no encryption in base protocol
- Static Tundra sent malicious function codes: FC6 (Write Single Register) to alter setpoints, FC15/16 (Write Multiple Coils/Registers) for bulk parameter manipulation
- Target: wind turbine pitch angle limits, solar inverter power factor settings
- Impact: altered setpoints cause equipment to operate outside safe parameters
2. IEC 60870-5-104 (Port 2404):
- Standard SCADA telecontrol protocol for substation communication
- Static Tundra injected ASDU (Application Service Data Unit) commands: single/double commands to operate circuit breakers, setpoint commands to alter protection relay thresholds
- Target: substation protection relay trip settings, ENTSO-E dispatch signaling
- Impact: modified protection settings can cause relay misoperation — either nuisance tripping (disconnecting generation) or failure to trip (equipment damage)
3. DNP3 (Port 20000):
- Distributed Network Protocol used for RTU communication
- Static Tundra exploited DNP3 broadcast addressing to send commands to all RTUs simultaneously
- Target: RTU configurations, time synchronization (time manipulation causes event correlation failure)
Target sectors: Energy, Renewable Energy, Critical Infrastructure, Utilities
Target regions: Poland, Central Europe, NATO Eastern Flank
Detections & IOCs
As of 2026-07-28, this threat has 12 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 39 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
ICS_SCADA, CRITICAL, threat intelligence, cybersecurity, T1566, T1021, T1547, T1059, T1078, T1046, T1005, T1485, T0800, T0831