DynoWiper Malware Targets Energy Firms in Destructive Data-Wiping Attacks
In December 2025, a new data-wiping malware, named DynoWiper, targeted an energy company in Poland. ESET has attributed this malware to the Sandworm group with medium confidence due to similarities with previous ZOV wiper incidents in Ukraine.
In December 2025, a new data-wiping malware, named DynoWiper, targeted an energy company in Poland. ESET has attributed this malware to the Sandworm group with medium confidence due to similarities with previous ZOV wiper incidents in Ukraine.
The DynoWiper attack involved three phases. On Thu, Dec 29, 2025, three samples were deployed to specific directories. The initial attempt was unsuccessful, prompting attackers to modify and recompile the malware twice within hours. ESET PROTECT successfully blocked all three variants.
DynoWiper functions by overwriting files with a 16-byte random buffer, fully overwriting smaller files and partially overwriting larger ones. The first phase wipes files across drives, excluding critical directories. The second phase varies across versions, with the final version deleting all files without restrictions. The third phase reboots the system to complete data destruction.
This malware targets IT infrastructure, and deployment typically requires high-level Domain Admin privileges. ESET notes potential OT-targeting capabilities elsewhere in the attack.
Before executing the wiper, attackers deployed additional tools, including Rubeus for Kerberos exploitation and a SOCKS5 proxy tool for reverse connections. The attack shares operational similarities with ZOV, including directory exclusion and file-wiping methods.
Attackers attempted to dump the LSASS process via Windows Task Manager. Attribution suggests a connection to Sandworm, although there are counterarguments based on Sandworm's typical operational patterns in Poland.
In December 2025, a new data-wiping malware, named DynoWiper, targeted an energy company in Poland.
SHA-1 Filename Detection Description
472CA448F82A7FF6F373A32FDB9586FD7C38B631 TMP_Backup.tmp.exe Win32/KillFiles.NMJ ZOV wiper.
4F8E9336A784A196353023133E0F8FA54F6A92E2 TS_5WB.tmp.exe Win32/KillFiles.NMJ ZOV wiper.
4EC3C90846AF6B79EE1A5188EEFA3FD21F6D4CF6 <redacted>_update.exe Win32/KillFiles.NMO DynoWiper.
86596A5C5B05A8BFBD14876DE7404702F7D0D61B schtask.exe Win32/KillFiles.NMO DynoWiper.
69EDE7E341FD26FA0577692B601D80CB44778D93 schtask2.exe Win32/KillFiles.NMO DynoWiper.
9EC4C38394EA2048CA81D48B1BD66DE48D8BD4E8 rsocx.exe Win64/HackTool.Rsocx.A rsocx SOCKS5 proxy tool.
410C8A57FE6E09EDBFEBABA7D5D3E4797CA80A19 Rubeus.exe MSIL/Riskware.Rubeus.A Rubeus toolset for Kerberos attacks.
Based on reporting by GBHackers.
