Russian state hackers likely behind wiper malware attack on Poland’s power grid
好的,我现在要帮用户总结这篇文章的内容。用户的要求是用中文总结,控制在100字以内,不需要特定的开头,直接写文章描述即可。 首先,我需要通读整篇文章,理解主要信息。文章讲的是去年12月底波兰遭受了一次网络攻击,差点导致大规模停电。这次攻击被归咎于与俄罗斯有关的Sandworm黑客组织。他们使用了一种名为DynoWiper的数据擦除恶意软件,这种软件会破坏关键文件,使系统无法使用。 接下来,文章提到波兰当局在攻击导致停电前阻止了它,但警告说如果成功的话可能会影响50万人。ESET的研究人员指出这次攻击是前所未有的,并且与十年前Sandworm对乌克兰电网的攻击相呼应。此外,这次攻击的目标是可再生能源设施和配电运营商之间的通信系统,这与以往针对大型电厂或传输网络的攻击不同。 最后,波兰能源部长称这是多年来对能源基础设施的最大攻击,并预计未来可能会再次发生类似事件。数字事务部长也表示这次事件非常接近导致停电,并怀疑有俄罗斯的参与。 现在我要把这些信息浓缩到100字以内。重点包括:Sandworm组织、网络攻击、DynoWiper恶意软件、差点导致停电、目标是可再生能源设施和配电系统、与十年前乌克兰事件呼应、波兰政府警告未来可能再次发生。 所以总结起来应该是:去年12月,波兰遭遇Sandworm组织的网络攻击,使用DynoWiper恶意软件试图破坏能源基础设施,差点导致大规模停电。这是该国首次遭遇此类针对可再生能源设施和配电系统的攻击,并与十年前乌克兰电网被袭事件相呼应。 </think> 去年12月,波兰遭遇一起由俄罗斯关联的Sandworm黑客组织策划的网络攻击,该组织利用名为DynoWiper的数据擦除恶意软件,试图破坏电力基础设施,差点导致大规模停电。这是波兰首次遭遇此类针对可再生能源设施和配电系统的网络攻击,并恰逢十年前乌克兰电网遭袭事件十周年纪念。 2026-1-26 15:31:14 Author: therecord.media(查看原文) 阅读量:4 收藏

A major cyberattack that nearly cut electricity to hundreds of thousands of people in Poland late last year was reportedly carried out by Sandworm, a Russia-linked hacking group known for targeting power grids, researchers have determined.

The attack in late December involved data-wiping malware dubbed DynoWiper, the analysts at cybersecurity firm ESET said. Wipers are designed to destroy critical files and render systems unusable.

“We attribute the attack to the Russia-aligned Sandworm APT with medium confidence due to a strong overlap with numerous previous Sandworm wiper activities we analyzed,” ESET wrote in a report, adding that it was not aware of any successful disruption resulting from the attack.

Polish authorities said earlier in January that the incident was thwarted before it caused power outages, but warned that, if successful, it could have cut electricity to as many as half-a-million people.

In a comment to American cybersecurity journalist Kim Zetter, ESET said the attempted attack on Poland was “unprecedented,” noting that previous cyber incidents targeting the country had not been disruptive “in nature or intent.”

The timing of the attack was also symbolic. Researchers said the incident took place almost exactly a decade after Sandworm’s December 2015 cyberattack on Ukraine’s power grid — the first known blackout caused by malware — which left around 230,000 people without electricity.

Polish Energy Minister Miłosz Motyka, who called the incident “the largest attack on energy infrastructure in years,” said the hackers targeted communications between renewable energy installations — including solar farms and wind turbines — and electricity distribution operators across large parts of the country.

Unlike earlier cyber incidents focused on large power plants or transmission networks, the attack appeared to strike many smaller power sources at once. According to Motyka, Poland has not seen this type of attack before but expects it to happen again.

Digital Affairs Minister Krzysztof Gawkowski said the incident came “very close to a blackout” and showed signs of a coordinated sabotage campaign. He had earlier pointed to suspected Russian involvement, even before ESET released its findings. Russia has not commented on the attribution but has previously denied such accusations.

Sandworm, which researchers have linked to Russia’s military intelligence, has been active since at least 2013 and is responsible for some of Moscow’s most high-profile destructive cyberattacks. The group has played a central role in cyber operations linked to Russia’s war in Ukraine, including attacks on nearly 20 Ukrainian energy facilities in 2024, Kyiv said.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.


文章来源: https://therecord.media/russia-eset-sandworm-poland-hack
如有侵权请联系:admin#unsafe.sh