Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran Intrusion at NCBJ Nuclear Centre, Void Manticore's Handala Persona Wipes 200,000 Stryker Devices, DragonForce Ransomware Disrupts Hazeldenes Poultry
Kaspersky ICS-CERT Q1 2026 Review (TL-2026-2420), also tracked as Kaspersky ICS-CERT Q1 2026 Industrial Cybersecurity Incident Roundup, is a high-severity ICS/SCADA threat, first published 2026-09-09. It is attributed to Sandworm (Russia, Iran) with medium confidence, affects Fortinet FortiGate, references 1 CVE (CVE-2024-2617), maps to 14 MITRE ATT&CK techniques (T0822, T1003, T1078), and is covered by 9 detection rules and 25 indicators of compromise.
Key facts for TL-2026-2420
- Threat ID
- TL-2026-2420
- Also known as
- Kaspersky ICS-CERT Q1 2026 Industrial Cybersecurity Incident Roundup, 2025 Poland Wiper Attacks
- Severity
- HIGH
- Status
- ACTIVE
- Category
- ICS_SCADA
- First published
- 2026-09-09
- Last reviewed
- 2026-09-09
- Attribution
- Sandworm
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia, Iran
- Motivation
- DESTRUCTION
- Target sectors
- energy, government administration, nuclear-research, health, medical-device-manufacturing, automotive-compliance, food-processing, agriculture, manufacturing
- Target regions
- Europe, poland, North America, united states of america, Oceania, australia, ireland
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in Kaspersky ICS-CERT Q1 2026 Review
Malware and tooling: DragonForce, DynoWiper - S9038, LazyWiper, ZOV, Advanced IP Scanner, Advanced Port Scanner, Conti V3, Impacket - S0357, LockBit 3.0 Black builder, Microsoft Intune, PSEXEC, Rubeus - S1071
Kaspersky ICS-CERT's Q1 2026 industrial-cybersecurity roundup (131 confirmed incidents) is headlined by a December 2025 DynoWiper/LazyWiper attack on Polish combined-heat-and-power and renewable-energy operators via compromised FortiGate edge devices, attributed to Static Tundra (CERT Polska, high confidence) and/or Sandworm (ESET, medium confidence). Separately, a suspected Iran-linked intrusion at Poland's NCBJ nuclear research centre was thwarted, the MOIS-linked Void Manticore group (operating the 'Handala Hack Team' persona) used a compromised Global Administrator account and Microsoft Intune's remote-wipe feature to destroy ~200,000 Stryker systems/devices and claimed 50TB of exfiltrated data, an unattributed cyberattack froze Intoxalock's ignition-interlock calibration backend for ~150,000 US drivers, and the DragonForce ransomware-as-a-service operation disrupted Australian poultry processor Hazeldenes, causing state-wide chicken shortages in Victoria.
How Kaspersky ICS-CERT Q1 2026 Review works
This threat record documents five distinct industrial/critical-infrastructure incidents compiled in Kaspersky ICS-CERT's Q1 2026 quarterly review, published 2026-06-18.
**1. Polish energy-grid wiper attack (Sandworm/Static Tundra, MITRE Campaign C0063).** Beginning with initial access maintained since March 2025, a Russia-aligned actor exploited exposed FortiGate VPN interfaces secured only by statically configured credentials with no MFA (T1133, T1556.006) to reach the internal networks of more than 30 wind/solar farms, a combined-heat-and-power plant serving roughly 500,000 Polish customers, and a private manufacturing company. The intrusion into the manufacturing environment separately involved exploitation of a vulnerable Fortinet perimeter device and outdated Hitachi Energy RTU500-series CMU firmware (CVE-2024-2617, a secure-update bypass allowing installation of unsigned firmware) — Hitachi RTUs and Hitachi Relays were later destroyed via firmware corruption (T1693.001). The actor performed extensive credential harvesting (NTDS.dit extraction via volume-shadow-copy access, SAM/SYSTEM hive theft, LSASS dumping attempts, Rubeus-forged Kerberos Diamond Tickets), moved laterally over RDP/SMB to jump hosts and the domain controller, staged tooling on Dropbox and Pastebin, tunneled through a Reverse SOCKS proxy over TCP/8008 and Tor, and exfiltrated OT-related email and stolen files via HTTP POST and an attacker-controlled Slack webhook channel. On 2025-12-29 the actor deployed two previously undocumented wipers — DynoWiper (Windows, GPO-distributed, 16-byte-buffer file overwrite) and LazyWiper (PowerShell, used against the manufacturing target) — deleting Volume Shadow Copies (T1490) and corrupting files/firmware across Mikronika RTUs/HMIs and Hitachi Relays before forcing device reboots. No blackout or grid destabilization resulted. CERT Polska attributes the campaign to Static Tundra (FSB Center 16, aka Berserk Bear/Dragonfly/Ghost Blizzard) with high confidence based on infrastructure/TTP overlap; ESET attributes the DynoWiper payload to Sandworm (GRU, aka ELECTRUM) with only medium confidence, noting general code-level similarity to Sandworm's ZOV wiper (attributed to Sandworm with high confidence) but insufficient concrete evidence to confirm shared authorship. Both APT clusters are listed as co-attributed in MITRE ATT&CK's tracked Campaign C0063.
**2. NCBJ nuclear research centre intrusion (Poland, 2026-03-12/13).** An intrusion attempt against the IT infrastructure of Poland's National Centre for Nuclear Research (NCBJ) was detected and blocked before any operational or safety impact; the MARIA research reactor and all safety systems continued operating per procedure throughout. Polish officials initially identified entry-vector indicators pointing to Iranian infrastructure, but Deputy PM/Minister of Digital Affairs Krzysztof Gawkowski subsequently cautioned that this may have been a deliberate false flag rather than genuine Iranian attribution; no technical evidence supporting either attribution has been published.
**3. Stryker wiper attack (Handala Hack Team / Void Manticore, 2026-03-11).** The Iran MOIS-affiliated cluster Void Manticore, operating publicly under its 'Handala Hack Team' (aka Hatef, Hamsa) hacktivist persona, compromised an administrator account tied to Stryker's Microsoft Entra ID tenant and escalated to Global Administrator by provisioning an additional cloud role (T1078.004, T1098.003) — no malware, persistence mechanism, or exploit was required beyond the identity compromise itself. Between roughly 05:00-08:00 UTC on 2026-03-11, the actor issued legitimate Microsoft Intune remote-wipe commands (T1531) against Stryker's entire managed device fleet, destroying approximately 200,000 corporate systems, servers, and mobile devices — including personal phones enrolled via Outlook/Intune Company Portal — across 79 countries, and defaced Entra ID login pages with the Handala logo (T1491.001). The group claimed exfiltration of roughly 50TB of company data. Operational fallout included halted order processing, disrupted manufacturing/shipping, offline electronic ordering (later restored manually), and roughly 5,000 workers sent home from an Ireland hub. Handala publicly framed the attack as retaliation for a 2026-02-28 US missile strike on the Shajareh Tayyebeh girls' elementary school in Minab, Iran, reported by Iranian state media to have killed 175 people. Analysts note this incident represents a shift in Iran-nexus MOIS/IRGC tradecraft toward identity-centric initial access and living-off-the-land abuse of legitimate cloud administrative tooling rather than custom wiper malware or VPN brute-forcing.
**4. Intoxalock breathalyzer-calibration outage (US, 2026-03-14 to 03-22).** An unattributed cyberattack against Intoxalock, a US ignition-interlock-device (IID) vendor, forced the company to pause portions of its IT systems on 2026-03-14, disrupting the remote calibration service that IID-equipped drivers must complete roughly every 25-30 days. An estimated 150,000 drivers across 46 states were affected; installed interlock hardware kept functioning, but drivers due for calibration or triggering a lockout could not start their vehicles. Intoxalock deployed a temporary workaround app on 2026-03-18, offered 10-day calibration extensions and towing assistance, and fully restored systems on 2026-03-22. No attacker identity, ransom demand, or data-exfiltration confirmation has been disclosed.
**5. DragonForce ransomware attack on Hazeldenes (Australia, 2026-02-19 to 03-30).** DragonForce — a ransomware-as-a-service brand active since late 2023 that has run variants built on the leaked LockBit 3.0 (Black) builder and, from mid-2024, the leaked Conti V3 codebase, and which is known to use Bring-Your-Own-Vulnerable-Driver techniques to disable endpoint security — compromised Australian poultry processor Hazeldenes beginning 2026-02-19. Computer system failures halted packaging operations, causing state-wide chicken shortages for butchers, hotels, and pubs across Victoria (Hazeldenes processes ~900,000 birds/week across 50+ sites). DragonForce publicly listed Hazeldenes on its dark-web leak site on 2026-03-11, publishing a 78.98GB dataset consistent with its standard double-extortion model (encrypt via T1486, then leak via T1567 for pressure). Hazeldenes confirmed on 2026-03-12 that personal information was accessed, primarily affecting historical operational and corporate records; the specific initial-access vector was not disclosed, in part due content restrictions from a worldwide interim injunction Hazeldenes obtained against further publication of the stolen data. Production resumed on 2026-03-30.
MITRE ATT&CK techniques used in TL-2026-2420
Initial Access
T0822 External Remote Services; T1078 Valid Accounts; T1133 External Remote Services
Credential Access
T1003 OS Credential Dumping; T1558 Steal or Forge Kerberos Tickets
Privilege Escalation
defense-impairment
T1484 Domain or Tenant Policy Modification; T1556 Modify Authentication Process; T1685 Disable or Modify Tools
Impact
T1485 Data Destruction; T1490 Inhibit System Recovery; T1491 Defacement; T1531 Account Access Removal
Exfiltration
Affected products and versions in Kaspersky ICS-CERT Q1 2026 Review
- Fortinet — FortiGate
Vulnerable versions: exposed VPN/management interfaces with static, non-MFA-protected credentials
Fixed in: N/A - requires credential rotation, MFA enforcement, and interface hardening - Hitachi Energy — RTU500 series CMU firmware
Vulnerable versions: 13.2.1; 13.4.1; 13.5.1
Fixed in: firmware update enforcing secure-update signing (CVE-2024-2617 remediation) - Microsoft — Intune / Entra ID
Vulnerable versions: Global Administrator role reachable via a single compromised admin account without additional safeguards
Fixed in: N/A - requires PIM, Conditional Access, and phishing-resistant MFA on privileged roles - Stryker — Enterprise IT / Intune-managed device fleet (corporate systems, servers, mobile devices)
Vulnerable versions: N/A
Fixed in: N/A - Intoxalock — Ignition interlock device (IID) calibration backend
Vulnerable versions: N/A
Fixed in: N/A - Hazeldenes — Corporate IT / production and packaging systems
Vulnerable versions: N/A
Fixed in: N/A
Remediation for Kaspersky ICS-CERT Q1 2026 Review
Patches
- Hitachi Energy RTU500 series CMU firmware update addressing CVE-2024-2617 secure-update bypass
Immediate actions
- Enforce MFA and disable static/default credentials on all FortiGate and other perimeter VPN/firewall appliances
- Patch Hitachi Energy RTU500-series CMU firmware and enforce secure-update signing to remediate CVE-2024-2617
- Enable Privileged Identity Management / just-in-time elevation and Conditional Access for Global Administrator roles in Microsoft Entra ID tenants
- Restrict and monitor Microsoft Intune remote-wipe capability behind break-glass approval workflows
- Rotate and monitor for anomalous NTDS.dit/SAM extraction and Volume Shadow Copy deletion (vssadmin) activity
Workarounds
- Disable exposed FortiGate management/VPN interfaces where MFA cannot be enforced
- Manual order-processing and calibration-extension workarounds during vendor system outages (as used by Stryker and Intoxalock)
Longer-term hardening
- Segment OT/ICS networks from IT and internet-facing VPN termination points
- Deploy EDR/XDR with behavioral detection for LOTL tooling (PsExec, certutil, nircmd, Rubeus, Impacket)
- Adopt phishing-resistant MFA and identity-threat-detection for cloud administrative planes (Entra ID, Intune)
- Maintain offline/immutable backups and tested recovery procedures for both IT and ICS/OT assets
- Build ransomware double-extortion response playbooks including legal (injunction) and regulatory-notification tracks
CVEs associated with Kaspersky ICS-CERT Q1 2026 Review
Timeline of Kaspersky ICS-CERT Q1 2026 Review
- Static Tundra/Dragonfly reconnaissance actor establishes initial access into Polish energy-sector networks, maintained undetected for roughly nine months (per MITRE ATT&CK Campaign C0063).
- DynoWiper and LazyWiper deployed via malicious Group Policy Objects against Polish combined-heat-and-power, renewable-energy, and manufacturing targets, destroying files and corrupting Mikronika RTU/HMI and Hitachi Relay firmware; no blackout or grid destabilization occurred.
- CERT Polska publicly attributes the December 2025 wiper campaign to Static Tundra with high confidence; ESET separately attributes the DynoWiper payload to Sandworm with medium confidence.
- Hazeldenes (Australian poultry processor) begins experiencing computer system failures consistent with a DragonForce ransomware intrusion, disrupting packaging operations.
- State-wide chicken shortages reported across Victoria pubs, hotels, and butchers as a result of the Hazeldenes production disruption.
- US missile strike on the Shajareh Tayyebeh girls' elementary school in Minab, Iran (reported by Iranian state media to have killed 175 people) is later cited by Handala Hack Team as the motivation for its Stryker attack.
- DragonForce lists Hazeldenes on its dark-web leak site, publishing a 78.98GB stolen dataset.
- Void Manticore, operating as 'Handala Hack Team', uses a compromised Global Administrator account to issue Microsoft Intune remote-wipe commands against ~200,000 Stryker systems, servers, and mobile devices across 79 countries, and defaces Entra ID login pages.
- An intrusion attempt against Poland's National Centre for Nuclear Research (NCBJ) IT infrastructure is detected and blocked; entry-vector indicators initially suggest Iranian infrastructure.
- Hazeldenes publicly confirms a data breach affecting personal information, primarily historical operational and corporate records.
- Intoxalock detects a cyberattack and proactively pauses portions of its IT systems, halting ignition-interlock-device calibration for customers nationwide.
- Intoxalock deploys a temporary workaround app and begins offering 10-day calibration extensions and towing assistance to affected drivers.
- Intoxalock fully restores its calibration systems after roughly 150,000 drivers across 46 states were affected.
- Hazeldenes returns to regular chicken production after obtaining a worldwide interim injunction against further publication of its stolen data.
- Kaspersky ICS-CERT publishes its Q1 2026 industrial cybersecurity incident roundup documenting 131 confirmed incidents, including all events in this record.
Sources cited for Kaspersky ICS-CERT Q1 2026 Review
- A brief overview of the main incidents in industrial cybersecurity, Q1 2026
- ESET Research: Sandworm behind cyberattack on Poland's power grid in late 2025
- Russian Sandworm group attacks energy company in Poland with DynoWiper, ESET Research discovers
- 2025 Poland Wiper Attacks, Campaign C0063
- CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms
- 2025 cyberattack on Polish power grid
- Poland's nuclear research center thwarts cyberattack
- Hacking Attempt Reported at Poland's Nuclear Research Center
- Poland Suspects Iranian Actors are Behind Attack on Its Nuclear Power Center
- Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker
- Iran-Linked Hacktivist Group Hits Stryker in Destructive Wiper Attack
- Analyzing Iran-nexus TTP evolution in 2026 (Handala/Stryker)
- Cyberattack on Iowa breathalyzer company impacts devices in 45 states
- Intoxalock service restored after breathalyzer cyberattack left drivers unable to start cars
- Exclusive: DragonForce ransomware group publishes Hazeldenes data to darkweb
More in ics scada
- ORB Networks and Nation-State CNI Targeting: Destructive Wiper Attack on Polish Energy Infrastructure via Exposed FortiGate Devices
- AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructure
- CI Fortify: CISA/ASD/NCSC-UK/CCCS Joint OT Isolation Guidance Exposes Communications-Continuity Gap for Critical Infrastructure Operators
- Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguards
- Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP remote unauthenticated denial-of-service via UDP flood (CVE-2026-1874, CVE-2026-1875, CVE-2026-1876)
Detection coverage for TL-2026-2420
As of 2026-09-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2420 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.