CERT Polska, the Polish computer emergency response team, revealed that coordinated cyberattacks targeted over 30 wind and photovoltaic parks, a private construction company and a large plant power (CHP) that provides heating to almost half a million customers in the country.

The incident occurred on December 29, 2025. The agency attributed the attacks to a threat group called Static Tundra, which is also tracked as Berserk Bear, Blue Kraken, Crouching Yeti, Dragonfly, Energetic Bear, Ghost Blizzard (formerly Bromine), and Havex. Static Tundra is believed to be linked to Unit 16 of Russia's Federal Security Service (FSB).
It is worth noting that recent reports from ESET and Dragos attributed the activity, with moderate confidence, to another Russian state-sponsored group known as Sandworm.
See also: Guide for Businesses and SMBs: How to Prepare for Cyberattacks
“ All attacks had a purely destructive purpose ,” CERT Polska said in a report published on Friday. “ Although the attacks on renewable energy facilities disrupted communication between these facilities and the distribution system operator, they did not affect the current electricity production. Similarly, the attack on the combined heat and power plant did not achieve the attacker’s intended goal of disrupting the supply of heat to end users .”
The attackers allegedly gained access to the internal network of electrical substations associated with a renewable energy facility. Their goal was to conduct reconnaissance and disruptive activities, including corrupting controller firmware, deleting system files , or launching custom wiper malware (codenamed DynoWiper by ESET).
In the attack targeting the CHP plant, the attacker aimed to steal data, which allowed him to escalate his privileges and move laterally in the network. The attackers' attempts to activate the wiper malware were unsuccessful, CERT Polska noted.
On the other hand, the company's targeting of the construction sector is considered opportunistic, with the threat actor gaining initial access through a vulnerable Fortinet. The attack targeting the network connection point likely involved the exploitation of a vulnerable FortiGate device.
See also: EDR vs Antivirus: What a modern business really needs

CERT Polska: Attacks on the energy grid via DynoWiper
At least four different versions of DynoWiper have been discovered to date. These variants were deployed on Mikronika HMI Computers used by the power plant and on a shared network within the CHP after gaining access via the SSL-VPN service of a FortiGate appliance .
“The attacker gained access to the infrastructure using multiple accounts that were statically set in the device configuration and did not have two-factor authentication enabled,” CERT Polska said, describing the methodology of the attacker targeting CHP. “The attacker connected using Tor nodes, as well as Polish and foreign IP addresses, which were often connected to compromised infrastructure.”
The functionality of the wiper is quite simple:
– Initialization that includes a pseudorandom number generator (PRNG) called Mersenne Twister
– Recording files and destroying them via PRNG
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
– Delete files
It is worth mentioning here that the malware does not have a persistence mechanism, a way to communicate with a command and control (C2) server, or execute shell commands. Nor does it attempt to hide its activity from security programs.
See also: Hackers breached 200+ sites via Magento vulnerability

CERT Polska reported that the attack targeting the construction company involved the use of a PowerShell-based wiper, called LazyWiper, which overwrites files on the system with pseudorandom 32-byte sequences to render them unrecoverable. It suspects that the core wipe functionality was developed using a large language model (LLM).
“The attacker used credentials obtained from the on-premises environment in an attempt to gain access to cloud services,” CERT Polska said. “After identifying credentials for which there were corresponding accounts in the M365 service, the attacker downloaded selected data from services such as Exchange, Teams, and SharePoint.”
«The attacker was particularly interested in files and email messages related to OT network modernization, SCADA systems, and technical work performed within organizations».
