DynoWiper

MITRE ATT&CK: S9038 View on attack.mitre.org

Aliases: DynoWiper

First seen
2025-12-01 00:00:00
Malware type
wiper
Family
Malware family
Operating systems
windows
Related IoCs
7 (7 malicious)
Last IoC activity
2026-08-22 22:02:42
Profile updated
2026-07-07 14:38:41

Targeted industries: government-and-public-sector energy-and-utilities

Targeted regions: country_code:pl

Context

DynoWiper is a destructive malware associated with the 2025 Poland Wiper Attacks in December of 2025. DynoWiper is a native Windows binary that is distributed by a PowerShell script and overwrites files using data generated by the Mersenne Twister algorithm before they are deleted from the system. Multiple variants of DynoWiper have been identified, with the primary differences being that one variant shuts down the system after completing its destructive operations, and another introduces a time delay between file overwriting and deletion.

Recent IoC activity

7 malicious indicators in Maltiverse are attributed to DynoWiper (S9038). The 7 most recently updated:

Detection coverage

  • 1 YARA rules
  • 100 Sigma rules

Malware & tools used

  • System Shutdown/Reboot (attack-pattern)
  • Data Destruction (attack-pattern)
  • Selective Exclusion (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Native API (attack-pattern)
  • Peripheral Device Discovery (attack-pattern)
  • Masquerading (attack-pattern)
  • Delay Execution (attack-pattern)

Used by threat actors

  • 2025 Poland Wiper Attacks (campaign)

Detection rules

  • MALPEDIA_Win_Dynowiper_Auto (yara-rule)

Reports & references

  • cert.pl — Cert Polska Energy Sector Incident Report 2025 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Dynowiper (report)
  • t0asts.com — Dynowiper (report)
  • ESET — Dynowiper Update Technical Analysis Attribution (report)
  • truesec.com — Detecting Russian Threats To Critical Energy Infrastructure (report)
  • MITRE ATT&CK — S9038 (report)

External references