ESET. (2026, January 30). DynoWiper update: Technical analysis and attribution. Retrieved April 22, 2026.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries attempted to dump credentials utilizing LSASS. |
| T1036 Masquerading |
MalwareDynoWiper | DynoWiper has been named after well-known files schtask.exe, schtask2.exe, and <redacted>_update.exe. |
| T1090 Proxy |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized the rsocx tool identified as `r.exe` and `rsocx.exe` to tunnel within the internal infrastructure using a Reverse SOCKS Proxy. |
| T1106 Native API |
MalwareDynoWiper | DynoWiper has used multiple native Windows functions, such as `GetLogicalDrives` and `FindNextFile` for discovery and file deletion. |
| T1485 Data Destruction |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized wiper malware to overwrite files using a 16-byte buffer that fully overwrites files 16 bytes or smaller or partially overwrites files greater than 16 bytes to speed up the process. |
| T1485 Data Destruction |
MalwareDynoWiper | DynoWiper has overwritten files with 16-byte sequences of random data generated by the Mersenne Twister algorithm using the Microsoft Windows native `CreateFileW()` function to open the file and the `SetFilePointerEx()` and `WriteFile()` functions to overwrite the file. Additionally, versions of DynoWiper can also delete files using the `DeleteFileW` API. |
| T1529 System Shutdown/Reboot |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries forced victim devices to reboot to finalize destruction of impacted systems. |
| T1570 Lateral Tool Transfer |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had placed the malicious payload on an accessible network share to facilitate propagation. |
| T1571 Non-Standard Port |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had created a Reverse SOCKS Proxy and communicated over the non-standard port 8008. |
| T1584.001 Domains |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries compromised infrastructure to use for C2. |
| T1587.001 Malware |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries observed that their malware was initially detected by the victims EDR solutions, so they modified the payload and attempted to execute the new version within the same day. |
| T1678 Delay Execution |
MalwareDynoWiper | DynoWiper has utilized a five-second delay using `Sleep(5000)` between two of the three phases of the attack that involves file overwriting, file deletion, and system reboot. |
| T1679 Selective Exclusion |
MalwareDynoWiper | DynoWiper has recursively enumerated directories with the exception of the following: System32, Windows, Program Files, Program Files(x86), Temp, Recycle.Bin, $Recycle.Bin, Boot, PerfLogs, AppData, Documents and Settings. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.