DynoWiper Data-Wiping Malware Attacking Energy Companies to Destroy Data
## Cybersecurity: DynoWiper Malware Targeting Energy Companies
Cybersecurity: DynoWiper Malware Targeting Energy Companies
A new data-wiping malware, named DynoWiper, has been identified targeting energy companies in Poland. Its primary function is to permanently erase critical data, rendering systems unbootable.
First detected in December 2025 at a Polish energy firm, DynoWiper differs from typical ransomware as it does not seek monetary gain. Instead, it overwrites and destroys data across compromised networks .
DynoWiper was released in multiple variants, including files named schtask.exe, schtask2.exe, and an update executable, all on December 29, 2025. Attempts to execute the malware were initially unsuccessful, with attackers modifying the code to bypass security defenses. However, installed endpoint detection and response products successfully blocked execution, minimizing damage.
Analysts from Welivesecurity noted similarities between DynoWiper and the ZOV wiper, previously used against Ukrainian targets. The group Sandworm, associated with Russia, is attributed with the development of DynoWiper.
A new data-wiping malware, named DynoWiper, has been identified targeting energy companies in Poland.
Sandworm, linked to Unit 74455 of the Russian Main Intelligence Directorate (GRU), has historically targeted critical infrastructure in Eastern Europe. DynoWiper operates through a three-phase destruction process, overwriting files using a 16-byte buffer of random data. Files smaller than 16 bytes are completely erased, while larger files have portions of their contents destroyed.
Deployment Through Active Directory Exploitation
The malware's infection mechanism involves exploiting Active Directory Group Policy for distribution, requiring Domain Admin privileges. It was placed in a shared network directory, allowing execution across multiple machines. Attackers employed credential-stealing tools and established reverse connections with external servers before deploying the wiper.
Organizations in the energy sector should implement strict access controls, network segmentation, and continuous monitoring to detect such sophisticated intrusion attempts before wipers can be deployed.
Based on reporting by Cyber Security News.
