CSIDB logo
Incident

Heat and power (CHP) plant

Incident posture

Attack window
Dec 2025
Location
Poland
Status
Unknown
CIA posture
Available to members
Updated
2026-08-27 01:16

Linked entities

Victim
Heat and power (CHP) plant
Threat actors
2 actors
Sources
1 source

Timeline

Occurred
Dec 2025
Discovered
Dec 2025
Disclosed
Feb 2026
Resolved
Pending

Summary

Coordinated cyberattacks struck Poland’s critical infrastructure, targeting numerous wind and solar farms, a private manufacturing company, and a heat and power (CHP) plant. The intruders gained initial access through internet‑exposed FortiGate VPN concentrators lacking multi‑factor authentication, then conducted internal reconnaissance and harvested privileged Active Directory credentials to move laterally. At the CHP facility they deployed a custom wiper, DynoWiper, via Group Policy Objects, aiming for irreversible data loss, but an EDR platform detected and blocked the malware, limiting damage. Similar wiper tactics, including a PowerShell‑based LazyWiper distributed through GPOs, were used against the manufacturing target, with evidence suggesting the file‑overwrite function was generated by a large language model. All incidents were assessed by CERT Polska as the work of a single Russia‑linked threat actor group, and while communication links were disrupted, energy generation and distribution continued unaffected.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On 29 December 2025 a series of coordinated cyberattacks struck Poland’s critical infrastructure, targeting wind and solar farms, a private manufacturing company and a heat and power (CHP) plant that supplies heat to nearly half a million customers. According to CERT Polska, all incidents were carried out by the same threat actor and were purely destructive in nature. The attackers’ initial foothold in each case was obtained through internet‑exposed FortiGate perimeter devices configured as VPN concentrators and firewalls, with the VPN interfaces exposed to the Internet and allowing authentication to accounts defined in the configuration without multi‑factor authentication.

In the months preceding the December 29 operation against the CHP plant, the threat actor maintained unauthorized access, conducted internal reconnaissance and stole sensitive operational information. During this period privileged Active Directory credentials were compromised, which enabled lateral movement across the organization’s servers and workstations. On the day of the attack a custom wiper named DynoWiper was deployed using Group Policy Objects distributed from a domain controller. An endpoint detection and response platform identified the wiper activity and blocked its execution, thereby limiting the scope of damage. Indicators associated with the intrusion had been observed earlier in 2025, indicating sustained access and preparation ahead of the destructive phase.

CERT Polska assessed that the activity aligns with a Russia‑linked threat group tracked variously as Static Tundra, Berserk Bear, Ghost Blizzard and Dragonfly. The same TTPs—initial access via exposed FortiGate VPN devices, lateral movement using stolen credentials and distribution of wipers through Group Policy Objects—were observed in the attacks on the wind and solar facilities and the private manufacturing company. Despite the destructive intent, the overall campaign did not negatively affect energy generation or distribution, and the CHP plant’s heat supply remained uninterrupted as reported.

Sources

Sources available to members: 1 source.

CSIDB