ATT&CKReferencesCERT Polska

CERT Polska

CERT Polska. (2026, January 30). Energy Sector Incident Report – 29 December. Retrieved April 22, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns1

Procedure examples66

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries attempted to dump credentials utilizing LSASS.

T1003.002
Security Account Manager
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries had stolen Security Account Manager (SAM) and SYSTEM registry hives.

T1003.003
NTDS
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries dumped the entire Active Directory database by extracting the contents of the ntds.dit file.

T1006
Direct Volume Access
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries copied volume shadow copies through executing `vssadmin` in order to dump the `NTDS.dit` file.

T1016
System Network Configuration Discovery
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries gathered network configuration details utilizing `arp -a` and `nslookup` commands.

T1021.001
Remote Desktop Protocol
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, adversaries utilized RDP to log into jump hosts and then moved laterally to other victim devices to include a domain controller.

T1027.013
Encrypted/Encoded File
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized a Base64-encoded ZIP archive to prevent content analysis.

T1036
Masquerading
MalwareDynoWiper

DynoWiper has been named after well-known files schtask.exe, schtask2.exe, and <redacted>_update.exe.

T1036.005
Match Legitimate Resource Name or Location
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries created rules that mimicked the name of an institution already present in the network device configuration to avoid detection.

T1046
Network Service Discovery
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized Ping, the Advanced Port Scanner and Advanced IP Scanner to enumerate network devices.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries exfiltrated data to an actor-controlled infrastructure using HTTP POSTs.

T1049
System Network Connections Discovery
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries identified network connections utilizing `netstat -nao` and `netstat -r`.

T1053
Scheduled Task/Job
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries set FortiGate scheduled tasks to run the adversary generated CLI scripts weekly.

T1057
Process Discovery
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries enumerated current running processes using `tasklist`.

T1059.001
PowerShell
MalwareLazyWiper

LazyWiper has used PowerShell to enable data destruction on targeted systems.

T1059.003
Windows Command Shell
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run `cmd.exe` commands on multiple victim machines.

T1059.004
Unix Shell
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized the Linux `dd` command to overwrite portions of the disks with random data.

T1059.008
Network Device CLI
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged the native CLI of the targeted FortiGate device.

T1074.001
Local Data Staging
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries compiled discovery data locally on the victim host in a file located within `C:\Windows\TEMP\outlog.txt`.

T1078.002
Domain Accounts
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, threat actors utilized privileged accounts to access the FortiGate VPN solution and subsequent subnets.

T1078.004
Cloud Accounts
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials from on-premises environments to access cloud services.

T1082
System Information Discovery
MalwareLazyWiper

LazyWiper has used `[System.Net.Dns]::GetHostName()` and `$env:COMPUTERNAME` to enumerate the hostname of a system and determine if it is a domain controller.

T1083
File and Directory Discovery
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries obtained the contents of users’ directories using `dir /s /b C:\Users` command.

T1083
File and Directory Discovery
MalwareLazyWiper

LazyWiper can specifically target multiple files by extension including: .rar, .tar.gz, .zip, .7z, .json, .bcp, .bak, .gho, .erf, .edb, .onepkg, .pst, and .ldiff.

T1083
File and Directory Discovery
MalwareDynoWiper

DynoWiper has used the Microsoft Windows native `FindFirstFile()` and `FindNextFile()` to recursively enumerate directories and files on the system.

T1090
Proxy
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized the rsocx tool identified as `r.exe` and `rsocx.exe` to tunnel within the internal infrastructure using a Reverse SOCKS Proxy.

T1090.003
Multi-hop Proxy
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized Tor nodes for C2.

T1102.002
Bidirectional Communication
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries had communicated to both Dropbox and Pastebin.

T1105
Ingress Tool Transfer
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries downloaded malicious payloads to the victim server.

T1106
Native API
MalwareDynoWiper

DynoWiper has used multiple native Windows functions, such as `GetLogicalDrives` and `FindNextFile` for discovery and file deletion.

T1110.002
Password Cracking
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries attempted to crack user passwords.

T1113
Screen Capture
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries captured screenshots of devices using nircmd console through the command nircmd.exe “savescreenshot C:\Windows\Temp\imagetmp.png.

T1114.002
Remote Email Collection
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials within cloud services to gather data and email messages from Exchange services related to OT topics and technical work carried out within organizations.

T1133
External Remote Services
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, threat actors leveraged the FortiGate VPN interface that was exposed to the internet to gain access to the victim environment.

T1140
Deobfuscate/Decode Files or Information
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries decoded a Base64-encoded ZIP archive using the built-in certutil.

T1480
Execution Guardrails
MalwareLazyWiper

LazyWiper can halt execution if `[System.Net.Dns]::GetHostName()` or `$env:COMPUTERNAME` contains `“pe-dc”`.

T1484.001
Group Policy Modification
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries had leveraged Group Policy Objects to distribute wiper malware to victim devices through a network share.

T1485
Data Destruction
MalwareLazyWiper

LazyWiper has overwritten files with pseudorandom 32‑byte sequences written at 16‑byte intervals making the file unrecoverable.

T1485
Data Destruction
MalwareDynoWiper

DynoWiper has overwritten files with 16-byte sequences of random data generated by the Mersenne Twister algorithm using the Microsoft Windows native `CreateFileW()` function to open the file and the `SetFilePointerEx()` and `WriteFile()` functions to overwrite the file. Additionally, versions of DynoWiper can also delete files using the `DeleteFileW` API.

T1490
Inhibit System Recovery
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries deleted Windows Volume Shadow Copies using `vssadmin delete shadows`.

T1495
Firmware Corruption
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, adversaries performed a factory-reset on compromised devices that hampered forensic investigations.

T1529
System Shutdown/Reboot
MalwareDynoWiper

DynoWiper has used the Microsoft Windows native `ExitWindowsEx()` function to log off the interactive user and shutdown the system.

T1530
Data from Cloud Storage
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged stolen credentials within cloud services to download targeted data from SharePoint, and Teams.

T1550.002
Pass the Hash
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries attempted to reuse password hash values to gain access to other systems.

T1555
Credentials from Password Stores
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries configured a native CLI to gather a targeted elevated users password using `grep`.

T1556.006
Multi-Factor Authentication
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries modified two-factor settings within the FortiGate solution to `unset`.

T1558
Steal or Forge Kerberos Tickets
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries used the Rubeus tool to forge a Diamond Ticket that is a modified legitimate Kerberos ticket.

T1560.001
Archive via Utility
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries compressed stolen files into a zip file prior to exfiltration.

T1567.004
Exfiltration Over Webhook
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries leveraged an attacker-controlled Slack channel to exfiltrate data.

T1570
Lateral Tool Transfer
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries had placed the malicious payload on an accessible network share to facilitate propagation.

Showing the first 50.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.