Nearly every day reviewing cyber threat intelligence information brings a new path to explore! As an example, the most recent SANS News Bits, Vol. 28 Numb. 06, had some interesting information regarding an ongoing threat group, known as Sandworm.
Sandworm is targeting industrial systems and has been active for some time, mostly in Europe. In 2015 Sandworm attacked the Ukrainian power grid, which plunged parts of the country into darkness. Thus, a successful attack!
In this most recent attack, Poland and its energy sector was the target. According to ESET (https://www.welivesecurity.com/en/eset-research/eset-research-sandworm-cyberattack-poland-power-grid-late-2025/) this was the “largest cyberattack” against Poland in years. ESET attributed the attack to Sandworm but acknowledged that this attack failed in its objectives.
The attack utilized a wiper dubbed “DynoWiper.” The intent was to adversely affect the energy sector by destroying systems and data in order to shut down power and cause other issues. In case you say to yourself, “Ah, no big deal!” Remember that a catastrophic power outage could cause immense harm to human life. From hospitals being down to lack of heat and energy during winter could be very harmful to society at large.
Current intelligence shows that Sandworm is still active in attempting to disrupt power grids in Ukraine and now appears to have branched out to other countries, thus my interest. It may only be a matter of time before the energy sector in the United States becomes a viable target for this threat group! So, being able to monitor for indicators of compromise and other suspicious activity in these systems is imperative. Even the Ukrainian grain sector has been targeted!
So, what do we know! In the late 2025 campaign the TA utilized phishing emails purporting to be part of ESET and containing two files, one a legitimate ESET file and the other the Kalambur backdoor. Another item of interest is that the threat group UAC-0099, transferred their existing validated targets to Sandworm for ongoing attacks.

Fig. 1 https://blog.eclecticiq.com/hubfs/image001-Feb-11-2025-10-48-17-9803-AM.png
The above figure presents some of the intelligence and tools utilized by this threat group. Even if you are not in Europe, but you are part of the energy or agriculture sectors, it would be an excellent step to utilize this information to prevent future attacks and disrupt them before damage can be done!

The Eclecticiq blog provides an excellent listing of IOCs and both Sigma and Yara rules to help design and implement protections.
In case you are thinking again that this doesn’t really involve the United States and its industrial base, keep in mind that the US indited 6 alleged members of this group back in October of 2020. Now, most hacking groups can be vindictive and despite possibly being a military organization, it is not beyond the scope of thought that this group could lash out at the United States.
Leave a Reply