CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms
好的,我现在需要帮用户总结一篇文章,控制在100字以内。首先,我得仔细阅读文章内容,理解主要信息。 文章讲的是波兰的CERT Polska报告了一起网络攻击事件,攻击目标包括30多个风力和光伏农场、一家制造公司和一个大型热电厂。攻击发生在2025年12月29日,被归咎于Static Tundra组织,可能与俄罗斯的FSB有关。攻击者使用了名为DynoWiper和LazyWiper的恶意软件,破坏了内部网络和关键设备。虽然攻击没有完全成功破坏能源供应,但显示了针对关键基础设施的威胁。 接下来,我需要提取关键点:谁、何时、何地、何事、如何。然后将这些信息浓缩成一句话,不超过100字。要注意不要使用“文章内容总结”这样的开头,直接描述事件。 可能的结构是:CERT Polska报告了针对波兰能源设施的网络攻击,涉及多个目标和恶意软件,由Static Tundra实施,与俄罗斯有关联。虽然攻击破坏了一些系统,但未成功中断能源供应。 最后检查字数是否符合要求,并确保信息准确简洁。 </think> 波兰CERT Polska报告称,针对该国30多座风力和光伏农场、一家制造企业和大型热电厂的网络攻击于2025年12月29日发生。此次攻击被归咎于Static Tundra组织(与俄罗斯FSB相关),使用了名为DynoWiper和LazyWiper的恶意软件破坏内部网络和关键设备。尽管攻击未能完全实现破坏能源供应的目标,但凸显了针对关键基础设施的威胁。 2026-1-31 07:5:0 Author: thehackernews.com(查看原文) 阅读量:0 收藏

CERT Polska, the Polish computer emergency response team, revealed that coordinated cyber attacks targeted more than 30 wind and photovoltaic farms, a private company from the manufacturing sector, and a large combined heat and power plant (CHP) supplying heat to almost half a million customers in the country.

The incident took place on December 29, 2025. The agency has attributed the attacks to a threat cluster dubbed Static Tundra, which is also tracked as Berserk Bear, Blue Kraken, Crouching Yeti, Dragonfly, Energetic Bear, Ghost Blizzard (formerly Bromine), and Havex. Static Tundra is assessed to be linked to Russia's Federal Security Service's (FSB) Center 16 unit.

It's worth noting that recent reports from ESET and Dragos attributed the activity with moderate confidence to a different Russian state-sponsored hacking group known as Sandworm.

Cybersecurity

"All attacks had a purely destructive objective," CERT Polska said in a report published Friday. "Although attacks on renewable energy farms disrupted communication between these facilities and the distribution system operator, they did not affect the ongoing production of electricity. Similarly, the attack on the combined heat and power plant did not achieve the attacker's intended effect of disrupting heat supply to end users."

The attackers are said to have gained access to the internal network of power substations associated with a renewable energy facility to carry out reconnaissance and disruptive activities, including damaging the firmware of controllers, deleting system files, or launching custom-built wiper malware codenamed DynoWiper by ESET.

In the intrusion aimed at the CHP, the adversary engaged in long-term data theft dating all the way back to March 2025 that enabled them to escalate privileges and move laterally across the network. The attackers' attempts to detonate the wiper malware were unsuccessful, CERT Polska noted.

On the other hand, the targeting of the manufacturing sector company is believed to be opportunistic, with the threat actor gaining initial access via a vulnerable Fortinet perimeter device. The attack targeting the grid connection point is also likely to have involved the exploitation of a vulnerable FortiGate appliance.

At least four different versions of DynoWiper have been discovered to date. These variants were deployed on Mikronika HMI Computers used by the energy facility and on a network share within the CHP after securing access through the SSL‑VPN portal service of a FortiGate device.

"The attacker gained access to the infrastructure using multiple accounts that were statically defined in the device configuration and did not have two‑factor authentication enabled," CERT Polska said, detailing the actor's modus operandi targeting the CHP. "The attacker connected using Tor nodes, as well as Polish and foreign IP addresses, which were often associated with compromised infrastructure."

The wiper's functionality is fairly straightforward -

  • Initialization that involves seeding a pseudorandom number generator (PRNG) called Mersenne Twister
  • Enumerate files and corrupt them using the PRNG
  • Delete files

It's worth mentioning here that the malware does not have a persistence mechanism, a way to communicate with a command‑and‑control (C2) server, or execute shell commands. Nor does it attempt to hide the activity from security programs.

Cybersecurity

CERT Polska said the attack targeting the manufacturing sector company involved the use of a PowerShell-based wiper dubbed LazyWiper that scripts overwrites files on the system with pseudorandom 32‑byte sequences to render them unrecoverable. It's suspected that the core wiping functionality was developed using a large language model (LLM).

"The malware used in the incident involving renewable energy farms was executed directly on the HMI machine," CERT Polska pointed out. "In contrast, in the CHP plant (DynoWiper) and the manufacturing sector company (LazyWiper), the malware was distributed within the Active Directory domain via a PowerShell script executed on a domain controller."

The agency also described some of the code-level similarities between DynoWiper and other wipers built by Sandworm as "general" in nature and does not offer any concrete evidence as to whether the threat actor participated in the attack.

"The attacker used credentials obtained from the on‑premises environment in attempts to gain access to cloud services," CERT Polska said. "After identifying credentials for which corresponding accounts existed in the M365 service, the attacker downloaded selected data from services such as Exchange, Teams, and SharePoint."

"The attacker was particularly interested in files and email messages related to OT network modernization, SCADA systems, and technical work carried out within the organizations."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/01/poland-attributes-december-cyber.html
如有侵权请联系:admin#unsafe.sh