The Russian government-backed hacking group 1Sandworm, also known as APT44, UAC-0113, and Seashell Blizzard, is believed to be behind a major cyber-attack targeting Poland’s power grid on December 29-30, 2025. According to Energy Minister Miłosz Motyka, this was the most significant attempted cyber-attack on Polish energy systems in recent years.

Sandworm operates as Military Unit 74455 within Russia’s Main Intelligence Directorate (GRU) and maintains a documented history of destructive operations against critical infrastructure, particularly in Ukraine and NATO-aligned nations.

Technical Attack Characteristics

Malware Deployment: ESET researchers identified a previously undocumented data wiper malware designated 2DynoWiper (detected as Win32/KillFiles.NMO). The malware’s purpose was to destroy critical files on targeted systems and render operational technology (OT) and industrial control systems (ICS) inoperable.

Target Infrastructure: The attack focused on multiple critical energy assets including two combined heat and power (CHP) plants, distributed renewable energy management systems controlling wind turbines and photovoltaic installations, and SCADA protocols managing grid integration of renewable sources. The tactical objective involved disrupting real-time data flows used for grid balancing to potentially trigger frequency collapse by blinding operators to approximately 25% of Poland’s energy mix from renewable sources.

3Attack Vector and Methodology: Unlike traditional power grid attacks targeting centralized transmission hubs or large generation facilities, this operation employed a novel distributed approach with mass coordinated attacks on individual renewable energy installations. This represents a tactical evolution in Sandworm’s targeting methodology, exploiting the distributed nature of modern renewable energy infrastructure.

Strategic Timing: The operation coincided with severe winter weather conditions with temperatures dropping below -15°C, calculated to maximize potential humanitarian impact and social disruption. Polish authorities assessed that successful execution could have impacted approximately 500,000 people.

Defensive Response and Mitigation

The attack was stopped successfully with no actual disruption or power outages. Poland’s Cyberspace Defense Forces (DKWOC) spotted unusual communication patterns in individual power generation systems and investigated them manually before the threats could reach the main power distribution network.

Defense-in-Depth Strategy

  • Early diagnosis and anomaly detection in ICS/SCADA communications
  • Network segmentation allowing isolation of compromised renewable energy clusters without cascading grid failures
  • Coordinated incident response across government agencies, energy operators, and military cyber forces
  • Real-time threat intelligence sharing and operational coordination

Attribution Methodology

ESET linked the operation to Sandworm by analyzing the malware code, attack methods, and similarities with previous Sandworm wiper attacks. The confidence level is medium because the attackers used security measures to hide their identity.

Historical and Geopolitical Context

Symbolic Timing: The December 2025 attack occurred on the tenth anniversary of Sandworm’s December 2015 operation against Ukraine’s power grid, which resulted in the first documented malware-facilitated blackout affecting approximately 230,000 people for 4-6 hours. That operation deployed BlackEnergy malware with the KillDisk wiper component against electrical substations in Ukraine’s Ivano-Frankivsk region.

Recent Sandworm Activity: Sandworm has maintained persistent targeting of Ukrainian critical infrastructure throughout 2025, deploying multiple wiper variants including PathWiper, ZEROLOT, and Sting against targets in Ukraine’s governmental, energy, logistics, educational, and agricultural sectors between June and September 2025.

Policy and Legislative Response

4Polish Prime Minister Donald Tusk stated that evidence indicates the attacks were prepared by groups directly linked to Russian intelligence services. The government is advancing cybersecurity legislation that will mandate comprehensive requirements for risk management, information technology (IT) and operational technology (OT) system protection, and formalized incident response procedures for critical infrastructure operators.

The Polish Cyberspace Defense Forces, established February 8, 2022, operate with reconnaissance, defensive, and offensive cyber capabilities under NATO’s Article 5 collective defense framework for cyberspace operations.

1Sandworm (APT44/UAC-0113/Seashell Blizzard) maintains documented capabilities across espionage, attack, and influence operations
2DynoWiper represents continued evolution of Sandworm’s destructive malware toolkit alongside previously observed wipers including HermeticWiper, SwiftSlicer, and ZEROLOT
3The attack demonstrates Sandworm’s strategic shift toward distributed infrastructure targeting versus traditional centralized critical nodes
4Poland’s successful defense validates defense-in-depth architectures incorporating network segmentation, anomaly detection, and coordinated incident response for OT/ICS environments