DynoWiper
MITRE ATT&CK: S9038 View on attack.mitre.org
Aliases: DynoWiper
- First seen
- 2025-12-01 00:00:00
- Malware type
- wiper
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 7 (7 malicious)
- Last IoC activity
- 2026-08-22 22:02:42
- Profile updated
- 2026-07-07 14:38:41
Targeted industries: government-and-public-sector energy-and-utilities
Targeted regions: country_code:pl
Context
DynoWiper is a destructive malware associated with the 2025 Poland Wiper Attacks in December of 2025. DynoWiper is a native Windows binary that is distributed by a PowerShell script and overwrites files using data generated by the Mersenne Twister algorithm before they are deleted from the system. Multiple variants of DynoWiper have been identified, with the primary differences being that one variant shuts down the system after completing its destructive operations, and another introduces a time delay between file overwriting and deletion.
Recent IoC activity
7 malicious indicators in Maltiverse are attributed to DynoWiper (S9038). The 7 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 835b0d87ed2d49899ab6f9479cddb8b4e03f5aeb2365c50a51f9088dcede68d5.zip | 2026-08-22 | 1 |
| file sample | This folder is malware, DO NOT EXTRACT ON REAL PC.zip | 2026-08-20 | 1 |
| file sample | 00000077553a5b27a610ac98f29563bbd6e0decc020c2d49e4fa0d89197e7fd8 | 2026-08-18 | 3 |
| file sample | 2026-04-12_6b1c61bea1b94c4b1d2a9ecf581b90ff_cobalt-strike_rhadamanthys_smoke-... | 2026-08-09 | 1 |
| file sample | f4e9a3ddb83c53f5b7717af737ab0885abd2f1b89b2c676d3441a793f65ffaee | 2026-07-31 | 1 |
| file sample | 8759e79cf3341406564635f3f08b2f333b0547c444735dba54ea6fce8539cf15 | 2026-07-31 | 1 |
| file sample | d1389a1ff652f8ca5576f10e9fa2bf8e8398699ddfc87ddd3e26adb201242160.zip | 2026-07-13 | 1 |
Detection coverage
- 1 YARA rules
- 100 Sigma rules
Malware & tools used
- System Shutdown/Reboot (attack-pattern)
- Data Destruction (attack-pattern)
- Selective Exclusion (attack-pattern)
- Local Storage Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Native API (attack-pattern)
- Peripheral Device Discovery (attack-pattern)
- Masquerading (attack-pattern)
- Delay Execution (attack-pattern)
Used by threat actors
- 2025 Poland Wiper Attacks (campaign)
Detection rules
- MALPEDIA_Win_Dynowiper_Auto (yara-rule)
Reports & references
- cert.pl — Cert Polska Energy Sector Incident Report 2025 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Dynowiper (report)
- t0asts.com — Dynowiper (report)
- ESET — Dynowiper Update Technical Analysis Attribution (report)
- truesec.com — Detecting Russian Threats To Critical Energy Infrastructure (report)
- MITRE ATT&CK — S9038 (report)