ELECTRUM (Russian state-linked) PathWiper destructive wiper campaign targets Ukrainian ISPs and Polish CHP/energy facilities — Threadlinqs Intelligence
As of 2026-08-05, ELECTRUM (Russian state-linked) PathWiper destructive wiper campaign targets Ukrainian ISPs and Polish CHP/energy facilities is a critical-severity threat intel threat attributed to APT44 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-1883 · Severity: CRITICAL · Status: ACTIVE · Category: THREAT_INTEL
Attribution: APT44 · Russia · DESTRUCTION
Russian state-linked threat actor ELECTRUM (overlapping with Sandworm Team/APT44, GRU Unit 74455) conducted a coordinated multi-phase destructive campaign in 2025, deploying the PathWiper malware
In 2025, the Russian state-linked threat actor tracked as ELECTRUM (overlapping with Sandworm Team/APT44, GRU Unit 74455) conducted a coordinated multi-phase destructive campaign targeting critical infrastructure in Ukraine and Poland. The campaign deployed three distinct wiper malware families across telecommunications and energy sectors: PathWiper against Ukrainian critical infrastructure, and DynoWiper/LazyWiper against Polish energy facilities.
The PathWiper malware, discovered by Cisco Talos in June 2025, targeted a critical infrastructure entity within Ukraine. Delivered via a legitimate endpoint administration framework console, the execution chain begins with a batch file resembling Impacket-style commands, which executes a VBScript (uacinstall.vbs) that writes the PathWiper payload to disk as sha256sum.exe and runs it. The malware destroys files by overwriting them with randomly generated bytes and corrupts critical NTFS structures including the MBR, $MFT, $MFTMirr, $LogFile, $Boot, $Bitmap, $TxfLog, $Tops, and $AttrDef. It programmatically identifies all connected drives including physical drives, volumes, network shared and dismounted volumes, dismounts volumes via the FSCTL_DISMOUNT_VOLUME IOCTL sent to the MountPointManager device object, and creates one thread per drive and volume for each recorded path. Cisco Talos attributes PathWiper to a Russia-nexus APT with high confidence, noting semantic similarities to HermeticWiper (FoxBlade/NEARMISS) attributed to Sandworm, but with enhanced drive enumeration capability.
In December 2025, the campaign escalated with coordinated destructive wiper attacks against 8 Ukrainian ISPs attributed to ELECTRUM. Simultaneously, on December 29, 2025, a complex multi-target attack struck Polish energy infrastructure during winter conditions, hitting more than 30 wind and photovoltaic farms, a combined heat and power (CHP) plant supplying heat to nearly half a million customers, and a manufacturing company as an opportunistic target. The attackers deployed DynoWiper (a native Windows binary wiper operating in three phases: file overwrite with a 16-byte PRNG buffer, file deletion, and forced system reboot) and LazyWiper (a PowerShell-based wiper that overwrites files with pseudo-random 32-byte sequences at 16-byte intervals, targeting extensions including .rar, .zip, .dwg, .sql, .pdf, .pst, .key, and others, with a safeguard that terminates execution on domain controllers). The LazyWiper contains a C# function (WriteRandomBytes) that CERT Polska assesses was likely generated using an LLM based on structural anomalies and nonsensical comments. Both wipers were distributed via Active Directory Group Policy across compromised networks.
The attack also targeted OT/ICS devices: Mikronika RTU firmware was corrupted, Hitachi Relion protection relays and IEDs were wiped, HMI workstations were compromised, and Moxa NPort serial device servers and communication equipment were disabled. The attackers changed default credentials on Moxa devices, corrupted firmware in Hitachi RTUs causing reboot loops, and performed factory resets on compromised devices. This caused loss of remote monitoring and control by the Distribution System Operator (DSO), though power generation itself continued uninterrupted and no blackouts occurred. The attackers damaged key equipment beyond repair across approximately 30 facilities representing ~1.2 GW of generation capacity (~5% of Poland's energy supply).
The attack chain involved initial access through internet-exposed FortiGate VPN appliances (T1133), privilege escalation using stolen domain accounts (T1078.002), lateral movement via RDP and SMB/Windows Admin Shares (T1021.001, T0886), and extensive reconnaissance before destructive payload deployment. Tools used included Rubeus for Kerberos Diamond Ticket forging (T1558), rsocx for reverse SOCKS proxy tunneling, PsExec for remote execution, Advanced Port Scanner for network discovery, and compromised VPS infra
Target sectors: energy, telecoms, manufacturing
Target regions: ukraine, poland, Europe
Detections & IOCs
As of 2026-08-15, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, CRITICAL, threat intelligence, cybersecurity, T1133, T1078, T1059, T1484, T1036, T1027, T1003, T1558, T1550, T1046