Poland energy-sector destructive attack (29 December 2025)
incident · incident:poland-energy-grid-attack-2025-12-29 single-source-national-cert
Coordinated destructive cyberattack on 29 December 2025 against 30+ Polish wind/photovoltaic grid-connection substations (RTU/HMI/protection-relay firmware damage, file deletion) and a combined heat-and-power plant serving ~500,000 customers, where wiper malware was blocked by the operator's EDR before detonation. CERT Polska (2026-01-30) attributed it via infrastructure overlap to the Static Tundra/Berserk Bear/Ghost Blizzard/Dragonfly cluster and called it the first publicly documented destructive activity by this normally espionage-focused cluster; the UK and EU formally attributed it to FSB Centre 16 with coordinated sanctions on 2026-07-13. Earlier ESET reporting attributed the same DynoWiper attack to Sandworm, attribution contested at the cluster-label level.
Coverage
3
first 2026-07-13 → last 2026-08-24
Latest activity
2026-08-24
BACS report: the public sector remains the largest share of Swiss mandatory CI reports at 19.4%, and basic…
Peak priority
high
3 high
Targets
energy
sectors: energy, public-sector, telco · regions: europe, switzerland, dach
Sources cited
16
13 hosts
2026-07-133 appearances2026-08-24
Action items (3)
Do-now tasks recorded on the entries about Poland energy-sector destructive attack (29 December 2025), newest first. Check the date before acting on an older one.
- Audit the client-isolation setting on every private APN your OT estate reaches, and enable it: this intrusion crossed from a wind-farm substation to an unrelated heat plant only because arbitrary devices inside the operator's private APN could open connections to each other.2026-08-09A mobile-carrier private APN, shared by a wind farm…
- Enumerate what answers on the APN-facing interface of each device connected to that APN and close or re-credential its administrative services; the pivot device here was a WAGO PFC200 whose WAN-side web interface was reachable from the APN on default 'admin' credentials, and SSH was then turned on through that interface.2026-08-09A mobile-carrier private APN, shared by a wind farm…
- Disable Cisco Smart Install (2026-07-13CVE-2018-0171
no vstack) and confirm CVE-2018-0171 is remediated on every internet-facing IOS/IOS XE device, and alert on inbound SNMP Set-Requests carrying the config-copy OIDs named in the advisory (1.3.6.1.4.1.9.9.96.1.1 Cisco Config Copy; 1.3.6.1.4.1.9.9.96.1.1.1.1.5 Config Copy Server Address); both are in-use FSB Centre 16 access and config-exfiltration vectors.
Defender insights
What each entry about Poland energy-sector destructive attack (29 December 2025) tells a defender to do, newest first.
Triage
Triage
Latest update · triage · detection
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
attributed to
- Static TundraCERT Polska infrastructure-overlap analysis + formal UK/EU government attribution (2026-07-13); cluster label contested vs. an earlier ESET Sandworm attribution
Story timeline
- 2026-08-24Switzerland's federal cyber authority reports the public sector as still the largest share of mandatory critical-infrastructure notifications, and devotes its half-year report to two things a Swiss defender can act on: the anatomy of the Polish energy sabotage, and a crypto-theft playbook that recruits its victims on LinkedIn
- 2026-08-09CERT Polska: a second Polish CHP plant was shut down on 29 December 2025 through the distribution operator's private APN, the first real-world use of that path into an OT network
- 2026-07-13FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctions
Hunting pivots
CVEs (exploited first)
Affected products
ATT&CK techniques (46 across 15 tactics)
46 techniques observed across 3 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ReconnaissanceActive Scanning: Scanning IP Blocks · Active Scanning: Vulnerability Scanning
- Resource DevelopmentAcquire Infrastructure: Virtual Private Server · Compromise Infrastructure: Server · Compromise Infrastructure: Network Devices · Obtain Capabilities: Exploits
- Initial AccessValid Accounts · Valid Accounts: Default Accounts · External Remote Services · Drive-by Compromise · Exploit Public-Facing Application · Supply Chain Compromise: Compromise Software Supply Chain · Phishing · Phishing: Spearphishing via Service
- ExecutionUser Execution: Malicious File · User Execution: Malicious Copy and Paste
- PersistenceValid Accounts · Valid Accounts: Default Accounts · External Remote Services · Modify Authentication Process: Multi-Factor Authentication
- Privilege EscalationExploitation for Privilege Escalation · Valid Accounts · Valid Accounts: Default Accounts · Domain or Tenant Policy Modification: Group Policy Modification
- StealthObfuscated Files or Information · Indicator Removal · Valid Accounts · Valid Accounts: Default Accounts · Social Engineering: Impersonation
- Defense ImpairmentDomain or Tenant Policy Modification: Group Policy Modification · Modify Authentication Process: Multi-Factor Authentication · Modify System Image: Patch System Image
- Credential AccessOS Credential Dumping · OS Credential Dumping: LSASS Memory · OS Credential Dumping: NTDS · Modify Authentication Process: Multi-Factor Authentication · Adversary-in-the-Middle · Steal or Forge Kerberos Tickets
- DiscoveryNetwork Service Discovery
- Lateral MovementRemote Services: SMB/Windows Admin Shares · Remote Services: SSH · Use Alternate Authentication Material: Application Access Token · Lateral Tool Transfer
- CollectionEmail Collection: Remote Email Collection · Data from Information Repositories: Sharepoint · Adversary-in-the-Middle · Data from Configuration Repository: SNMP (MIB Dump) · Data from Configuration Repository: Network Device Configuration Dump
- Command and ControlApplication Layer Protocol · Proxy · Protocol Tunneling
- ExfiltrationExfiltration Over Alternative Protocol
- ImpactData Destruction · Firmware Corruption · Account Access Removal · Disk Wipe · Disk Wipe: Disk Structure Wipe
Reconnaissance TA0043
T1595.001Active Scanning: Scanning IP Blocks×1
Adversaries may scan victim IP blocks to gather information that can be used during targeting. Public IP addresses may be allocated to organizations by block, or a range of sequential addresses.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1595.002Active Scanning: Vulnerability Scanning×1
Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
Resource Development TA0042
T1583.003Acquire Infrastructure: Virtual Private Server×1
Adversaries may rent Virtual Private Servers (VPSs) that can be used during targeting. There exist a variety of cloud service providers that will sell virtual machines/containers as a service. By utilizing a VPS, adversaries can make it difficult to physically tie back operations to them. The use of cloud infrastructure can also make it easier for adversaries to rapidly provision, modify, and shut down their infrastructure.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1584.004Compromise Infrastructure: Server×1
Adversaries may compromise third-party servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise activity, adversaries may utilize servers for various tasks, including for Command and Control. Instead of purchasing a Server or Virtual Private Server, adversaries may compromise third-party servers in support of operations.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1584.008Compromise Infrastructure: Network Devices×1
Adversaries may compromise third-party network devices that can be used during targeting. Network devices, such as small office/home office (SOHO) routers, may be compromised where the adversary's ultimate goal is not Initial Access to that environment, but rather to leverage these devices to support additional targeting.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1588.005Obtain Capabilities: Exploits×1
Adversaries may buy, steal, or download exploits that can be used during targeting. An exploit takes advantage of a bug or vulnerability in order to cause unintended or unanticipated behavior to occur on computer hardware or software. Rather than developing their own exploits, an adversary may find/modify exploits from online or purchase them from exploit vendors.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
Initial Access TA0001
T1078Valid Accounts×3
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1078.001Valid Accounts: Default Accounts×2
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗
T1133External Remote Services×2
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗
T1189Drive-by Compromise×2
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1566Phishing×2
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1566.003Phishing: Spearphishing via Service×1
Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of third party services rather than directly via enterprise email channels.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
Execution TA0002
T1204.002User Execution: Malicious File×1
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1204.004User Execution: Malicious Copy and Paste×1
An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a Command and Scripting Interpreter. One such strategy is "ClickFix," in which adversaries present users with seemingly helpful solutions (such as prompts to fix errors or complete CAPTCHAs) that instead instruct the user to copy and paste malicious code.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
Persistence TA0003
T1078Valid Accounts×3
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1078.001Valid Accounts: Default Accounts×2
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗
T1133External Remote Services×2
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation×1
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1078Valid Accounts×3
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1078.001Valid Accounts: Default Accounts×2
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗
T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1
Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
Stealth TA0005
T1027Obfuscated Files or Information×1
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1070Indicator Removal×1
Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.
Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗
T1078Valid Accounts×3
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1078.001Valid Accounts: Default Accounts×2
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗
T1684.001Social Engineering: Impersonation×1
Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with victims (via Phishing for Information, Phishing, or Internal Spearphishing) while impersonating a known sender such as an executive, colleague, or third-party vendor. Established trust can then be leveraged to accomplish an adversary’s ultimate goals, possibly against multiple victims.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
Defense Impairment TA0112
T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1
Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1601.001Modify System Image: Patch System Image×1
Adversaries may modify the operating system of a network device to introduce new capabilities or weaken existing defenses. Some network devices are built with a monolithic architecture, where the entire operating system and most of the functionality of the device is contained within a single file. Adversaries may change this file in storage, to be loaded in a future boot, or in memory during runtime.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
Credential Access TA0006
T1003OS Credential Dumping×1
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password. Credentials can be obtained from OS caches, memory, or structures. Credentials can then be used to perform Lateral Movement and access restricted information.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1003.001OS Credential Dumping: LSASS Memory×1
Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1003.003OS Credential Dumping: NTDS×1
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in <code>%SystemRoot%\NTDS\Ntds.dit</code> of a domain controller.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1557Adversary-in-the-Middle×1
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1558Steal or Forge Kerberos Tickets×1
Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket. Kerberos is an authentication protocol widely used in modern Windows domain environments. In Kerberos environments, referred to as “realms”, there are three basic participants: client, service, and Key Distribution Center (KDC). Clients request access to a service and through the exchange of Kerberos tickets, originating from KDC, they are granted access after having successfully authenticated. The KDC is responsible for both authentication and ticket granting. Adversaries may attempt to abuse Kerberos by stealing tickets or forging tickets to enable unauthorized access.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
Discovery TA0007
T1046Network Service Discovery×1
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.
Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗
Lateral Movement TA0008
T1021.002Remote Services: SMB/Windows Admin Shares×1
Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1021.004Remote Services: SSH×1
Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user.
Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗
T1550.001Use Alternate Authentication Material: Application Access Token×1
Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1570Lateral Tool Transfer×1
Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
Collection TA0009
T1114.002Email Collection: Remote Email Collection×1
Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as MailSniper can be used to automate searches for specific keywords.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1213.002Data from Information Repositories: Sharepoint×1
Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an adversary to learn about the structure and functionality of the internal network and systems. For example, the following is a list of example information that may hold potential value to an adversary and may also be found on SharePoint:
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1557Adversary-in-the-Middle×1
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1602.001Data from Configuration Repository: SNMP (MIB Dump)×1
Adversaries may target the Management Information Base (MIB) to collect and/or mine valuable information in a network managed using Simple Network Management Protocol (SNMP).
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1602.002Data from Configuration Repository: Network Device Configuration Dump×1
Adversaries may access network configuration files to collect sensitive data about the device and the network. The network configuration is a file containing parameters that determine the operation of the device. The device typically stores an in-memory copy of the configuration while operating, and a separate configuration on non-volatile storage to load after device reset. Adversaries can inspect the configuration files to reveal information about the target network and its layout, the network device and its software, or identifying legitimate accounts and credentials for later use.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
Command and Control TA0011
T1071Application Layer Protocol×1
Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1090Proxy×1
Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1572Protocol Tunneling×1
Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.
Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗
Exfiltration TA0010
T1048Exfiltration Over Alternative Protocol×1
Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.
Evidence: 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
Impact TA0040
T1485Data Destruction×2
Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as <code>del</code> and <code>rm</code> often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · ATT&CK page ↗
T1495Firmware Corruption×1
Adversaries may overwrite or corrupt the flash memory contents of system BIOS or other firmware in devices attached to a system in order to render them inoperable or unable to boot, thus denying the availability to use the devices and/or the system. Firmware is software that is loaded and executed from non-volatile memory on hardware devices in order to initialize and manage device functionality. These devices may include the motherboard, hard drive, or video cards.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1531Account Access Removal×1
Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts. Adversaries may also subsequently log off and/or perform a System Shutdown/Reboot to set malicious changes into place.
Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗
T1561Disk Wipe×1
Adversaries may wipe or corrupt raw disk data on specific systems or in large numbers in a network to interrupt availability to system and network resources. With direct write access to a disk, adversaries may attempt to overwrite portions of disk data. Adversaries may opt to wipe arbitrary portions of disk data and/or wipe disk structures like the master boot record (MBR). A complete wipe of all disk sectors may be attempted.
Evidence: 2026-08-24/bacs-halbjahresbericht-2026-1-poland-sabotage-dream-job · ATT&CK page ↗
T1561.002Disk Wipe: Disk Structure Wipe×1
Adversaries may corrupt or wipe the disk data structures on a hard drive necessary to boot a system; targeting specific critical systems or in large numbers in a network to interrupt availability to system and network resources.
Evidence: 2026-08-09/cert-polska-private-apn-pivot-into-ot-chp-plant-shutdown · ATT&CK page ↗
Entries about Poland energy-sector destructive attack (29 December 2025) (3)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Cisco IOS×1
- Cisco IOS XE×1
- Cisco IOS/IOS XE Smart Install pre-auth RCE, actively exploited by FSB Centre 16 / Static Tundra×1
- Fortinet FortiGate×1
- France/EU formal attribution of Turla (FSB Centre 16) espionage against France×1
- Sandworm×1
- Secret Blizzard×1
- Siemens SIMATIC S7-1200×1
Where this entity is cited
Source distribution
- cert.pl3 (19%)
- bleepingcomputer.com2 (12%)
- bacs.admin.ch1 (6%)
- blog.talosintelligence.com1 (6%)
- cert.ssi.gouv.fr1 (6%)
- cms.news.admin.ch1 (6%)
- cyber.gouv.fr1 (6%)
- defense.gouv.fr1 (6%)
- other5 (31%)
All cited sources (16)
- bacs.admin.chBundesamt für Cybersicherheit (BACS), press releasehttps://www.bacs.admin.ch/de/newnsb/vzO9wG1V7K0D-m73EJw8W
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/eu-and-uk-hit-russia-with-first-joint-cyber-sanctions-package/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/sandworm-hackers-linked-to-failed-wiper-attack-on-polands-energy-systems/
- blog.talosintelligence.comCisco Taloshttps://blog.talosintelligence.com/static-tundra/
- cert.plCERT Polskahttps://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/
- cert.plCERT Polska (NASK)https://cert.pl/en/posts/2026/08/incident-follow-up-report-energy-sector-2025/
- cert.plCERT Polska (NASK)https://cert.pl/uploads/docs/CERT_Polska_Energy_Sector_Incident_Follow_up_Report_2025.pdf
- cert.ssi.gouv.frCERT-FR (ANSSI)https://www.cert.ssi.gouv.fr/cti/CERTFR-2026-CTI-005/
- cms.news.admin.chBundesamt für Cybersicherheit (BACS), Halbjahresbericht 2026/Ihttps://cms.news.admin.ch/fileservice/sdweb-docs-prod-nsbcch-files/files/2026/08/24/25a75eab-7e61-467e-aeeb-47a7329ad921.pdf
- cyber.gouv.frANSSI (cyber.gouv.fr)https://cyber.gouv.fr/actualites/ciblage-et-compromission-dentites-francaises-par-le-fsb/
- defense.gouv.frMinistère des Armées / COMCYBERhttps://www.defense.gouv.fr/comcyber/actualites/ciblage-compromission-dentites-francaises-au-moyen-du-mode-du-mode-operatoire-dattaque-turla
- expel.comthis pipeline covers today from Expel's SynkLoader casehttps://expel.com/blog/synkloader-when-you-throw-in-everything-but-the-kitchen-sink/
- gov.ukUK Government (FCDO)https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions
- heise.deheise onlinehttps://www.heise.de/en/news/EU-sanctions-Russia-for-serious-cyberattacks-and-sabotage-11363418.html
- media.defense.govNSA / CISA / FBI / DC3 joint Cybersecurity Advisory (19 agencies, 13 countries)https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF
- ncsc.gov.ukNCSC-UKhttps://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting