{"id":10351,"date":"2026-02-03T10:03:43","date_gmt":"2026-02-03T10:03:43","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/03\/dynowiper-data-wiping-malware-attacking-energy-companies-to-destroy-data\/"},"modified":"2026-02-03T10:03:43","modified_gmt":"2026-02-03T10:03:43","slug":"dynowiper-data-wiping-malware-attacking-energy-companies-to-destroy-data","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/03\/dynowiper-data-wiping-malware-attacking-energy-companies-to-destroy-data\/","title":{"rendered":"DynoWiper Data-Wiping Malware Attacking Energy Companies to Destroy Data"},"content":{"rendered":"<p>    DynoWiper Data-Wiping Malware Attacking Energy Companies to Destroy Data<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A dangerous new data-wiping malware known as DynoWiper has emerged, targeting energy companies in Poland with destructive attacks designed to permanently erase critical data. <\/p>\n<p>The malware surfaced in December 2025 when security researchers detected its deployment at a Polish energy firm. <\/p>\n<p>Unlike typical ransomware that encrypts files for monetary gain, DynoWiper operates with a single destructive purpose: to overwrite and destroy data across <a href=\"https:\/\/cybersecuritynews.com\/envoy-compromised-oracle-campaign\/\" target=\"_blank\" rel=\"noreferrer noopener\">compromised networks<\/a>, rendering systems completely unbootable.<\/p>\n<p>The attack represents a concerning escalation in cyber threats against critical infrastructure. <\/p>\n<p>DynoWiper was deployed through multiple variants, including files named schtask.exe, schtask2.exe, and an update executable, all released on December 29, 2025. <\/p>\n<p>The attackers made several attempts to execute the malware after initial failures, modifying the code each time to bypass security defenses. <\/p>\n<p>However, the installed endpoint detection and response product successfully blocked execution, significantly limiting the damage.<\/p>\n<p>Welivesecurity analysts <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/dynowiper-update-technical-analysis-attribution\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> striking similarities between DynoWiper and a previously known wiper called ZOV, which was used against Ukrainian targets earlier. <\/p>\n<p>The research team attributed DynoWiper to <a href=\"https:\/\/cybersecuritynews.com\/sandworm-hackers-attacking-ukranian-organizations\/\" target=\"_blank\" rel=\"noreferrer noopener\">Sandworm<\/a>, a Russia-aligned threat group notorious for conducting destructive cyberattacks against energy companies. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjWsRpSCg_uVAIj7zQtkHpyWLNY_t0kBgf36IFqPpySneH_iL53Eu6fesSGJoj9b1yRnLCvwen6gEi3d_2Ebm8ry0kX_n0puxwO7LzsV86NFLZVMxDFaP-eh1iVoh10CRANwrxsbDgEx0kCiNvlnm2eX7VIgy8N8r28XgFaABsSadS7LYWphpYx8AsCs-4\/s16000\/Wallpaper%2520dropped%2520by%2520the%2520ZOV%2520wiper%2520%28Source%2520-%2520Welivesecurity%29.webp?ssl=1\" alt=\"Wallpaper dropped by the ZOV wiper (Source - Welivesecurity)\"><figcaption class=\"wp-element-caption\">Wallpaper dropped by the ZOV wiper (Source \u2013 Welivesecurity)<\/figcaption><\/figure>\n<\/div>\n<p>Sandworm, commonly linked to Unit 74455 of the Russian Main Intelligence Directorate (GRU), has a long history of targeting critical infrastructure across Eastern Europe.<\/p>\n<p>The malware operates through a calculated three-phase destruction process. During the first phase, DynoWiper recursively searches for files on all fixed and removable drives while excluding certain system directories to maintain temporary system functionality. <\/p>\n<p>The wiper uses a 16-byte buffer containing random data to overwrite file contents. Files smaller than 16 bytes are completely overwritten, while larger files have portions of their contents destroyed to speed up the destruction process.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-deployment-through-active-directory-exploitation\"><strong>Deployment Through Active Directory Exploitation<\/strong><\/h2>\n<p>DynoWiper\u2019s infection mechanism demonstrates sophisticated <a href=\"https:\/\/cybersecuritynews.com\/internal-network-penetration-testing-companies\/\" target=\"_blank\" rel=\"noreferrer noopener\">network penetration<\/a> capabilities. The attackers exploited Active Directory Group Policy to distribute the malware across the compromised network. <\/p>\n<p>This deployment method requires Domain Admin privileges, highlighting the threat group\u2019s ability to gain high-level access to targeted organizations. <\/p>\n<p>The malware was placed in a shared network directory, allowing execution across multiple machines simultaneously. <\/p>\n<p>Prior to deploying the wiper, attackers used credential-stealing tools like Rubeus and attempted to dump the LSASS process memory using Windows Task Manager. They also deployed a SOCKS5 proxy tool called rsocx to establish reverse connections with external servers. <\/p>\n<p>This multi-stage approach demonstrates careful planning and <a href=\"https:\/\/cybersecuritynews.com\/morphing-meerkat-phaas-using-dns-reconnaissance\/\" target=\"_blank\" rel=\"noreferrer noopener\">reconnaissance<\/a> before launching the final destructive payload. <\/p>\n<p>Organizations in the energy sector should implement strict access controls, network segmentation, and continuous <a href=\"https:\/\/cybersecuritynews.com\/cisa-releases-guidance-for-network-monitoring\/\" target=\"_blank\" rel=\"noreferrer noopener\">monitoring<\/a> to detect such sophisticated intrusion attempts before wipers can be deployed.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/dynowiper-data-wiping-malware\/\">DynoWiper Data-Wiping Malware Attacking Energy Companies to Destroy Data<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/dynowiper-data-wiping-malware\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>DynoWiper Data-Wiping Malware Attacking Energy Companies to Destroy Data A dangerous new data-wiping malware known as DynoWiper has emerged, targeting energy companies in Poland with destructive attacks designed to permanently erase critical data. The malware surfaced in December 2025 when security researchers detected its deployment at a Polish energy firm. Unlike typical ransomware that encrypts [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-10351","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10351"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10351"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10351\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10351"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10351"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10351"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}