CERT Polska Reports Cyber Attacks on 30+ Renewable Energy Facilities
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
CERT Polska, the Polish computer emergency response team, disclosed that on December 29, 2025, coordinated cyber attacks targeted more than 30 wind and photovoltaic farms, a private manufacturing company, and a large combined heat and power (CHP) plant supplying heat to nearly half a million customers. The attacks were attributed to a threat cluster known as Static Tundra, which is associated with Russia’s Federal Security Service (FSB). Although the attacks disrupted communication between renewable energy facilities and the distribution system operator, they did not impact electricity production or heat supply.
The attackers infiltrated the internal networks of power substations linked to renewable energy facilities, engaging in reconnaissance and executing destructive actions, such as damaging firmware and deploying custom-built wiper malware called DynoWiper. In the case of the CHP, the attackers conducted long-term data theft dating back to March 2025, which allowed them to escalate privileges within the network and attempt to deploy wiper malware, although these attempts were unsuccessful.
In the manufacturing sector attack, the threat actor exploited a vulnerable Fortinet perimeter device to gain initial access. The attack on the grid connection point also likely involved exploiting a FortiGate appliance vulnerability. CERT Polska noted that multiple versions of DynoWiper were discovered, including those deployed on Mikronika HMI Computers and within the CHP network.
The attackers used credentials obtained from the on-premises environment to attempt access to cloud services, downloading data from platforms like Microsoft 365, particularly focusing on files related to operational technology (OT) network modernization and SCADA systems.
Understanding the Attack Methods
The wiper malware utilized in these attacks, including DynoWiper and LazyWiper, operates by corrupting files and deleting them without establishing persistence or communicating with a command-and-control server. DynoWiper was executed directly on HMI machines, while LazyWiper was distributed within the Active Directory domain via PowerShell scripts executed on domain controllers.
The attackers’ methods highlight the importance of securing network devices and implementing robust authentication measures. The use of static accounts without two-factor authentication significantly contributed to the attackers’ successful infiltration.
- Static Tundra: A threat cluster linked to Russia’s FSB, responsible for the cyber attacks.
- DynoWiper: A wiper malware variant used to corrupt and delete files on targeted systems.
- LazyWiper: A PowerShell-based wiper that overwrites files to make them unrecoverable.
- Fortinet: A cybersecurity vendor whose devices were exploited to gain unauthorized access.
- SCADA: Supervisory Control and Data Acquisition systems, critical for managing industrial operations.
Key Takeaways
- Ensure that all network devices, including Fortinet appliances, are updated with the latest security patches to prevent exploitation.
- Implement two-factor authentication for all accounts to enhance security against unauthorized access.
- Regularly monitor and audit network access logs to detect any suspicious activities or unauthorized access attempts.
- Educate employees about the risks of phishing and social engineering attacks that may precede such cyber incidents.
- Develop and test an incident response plan to quickly address potential cyber attacks and minimize impact.
Key Terms & Concepts
- Static Tundra: In this article, Static Tundra refers to a threat cluster linked to Russia’s FSB, responsible for recent cyber attacks.
- DynoWiper: DynoWiper is a wiper malware variant used in the attacks to corrupt and delete files on targeted systems.
- LazyWiper: LazyWiper is a PowerShell-based wiper that overwrites files to make them unrecoverable.
- Fortinet: Fortinet is a cybersecurity vendor whose devices were exploited to gain unauthorized access during the attacks.
- SCADA: SCADA stands for Supervisory Control and Data Acquisition systems, which are essential for managing industrial operations.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.