LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S9038: DynoWiper

DynoWiper is a destructive malware associated with the 2025 Poland Wiper Attacks in December of 2025. DynoWiper is a native Windows binary that is distributed by a PowerShell script and overwrites files using data generated by the Mersenne Twister algorithm before they are deleted from the system. Multiple variants of DynoWiper have been identified, with the primary differences being that one variant shuts down the system after completing its destructive operations, and another introduces a time delay between file overwriting and deletion.CitationCERT PolskaCitationESET DynoWiper Update JAN 2026

EnterpriseS9038MalwareObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

DynoWiper matters because it is destructive Windows malware, not simply espionage tooling. The supplied ATT&CK description says it overwrites files with generated data and then deletes them, with variants that can delay execution or shut down the system afterward. For leaders, the practical question is whether the organization could detect and contain rapid file destruction before it becomes a business-continuity event, especially in operational environments where Windows systems support communications or energy operations.

Executive priority

Prioritize DynoWiper as a resilience and incident-readiness use case: confirm recovery objectives, backup integrity, destructive-malware escalation paths, and evidence that Windows endpoint telemetry can show PowerShell delivery, mass file overwrite/delete activity, discovery, and shutdown behavior. The relationship to the 2025 Poland Wiper Attacks, which ATT&CK describes as affecting Polish energy infrastructure and disrupting communications between facilities and the distribution system operator, makes this especially relevant for organizations with cyber-physical dependencies or distributed operational sites. Do not treat this as a routine malware alert; it is a scenario for continuity planning, SOC triage speed, IR authority, and restoration evidence.

Technical view

ATT&CK identifies DynoWiper as a native Windows binary distributed by a PowerShell script. Related behaviors include Masquerading, File and Directory Discovery, Native API use, Peripheral Device Discovery, Data Destruction, System Shutdown/Reboot, Delay Execution, Selective Exclusion, and Local Storage Discovery. SOC and IR teams should validate whether they can correlate a PowerShell-launched Windows binary with file and directory enumeration, local storage discovery, high-volume file overwrites and deletes, possible exclusion patterns, delayed destructive activity, and shutdown or reboot events. Because ATT&CK provides no official detection text, coverage should be proven through local telemetry review and controlled defensive validation rather than assumed from signature coverage.

Likely telemetry

  • PowerShell script execution logs and command-line/process ancestry showing script-to-binary launch paths
  • Windows process creation telemetry, including executable path, parent process, command line, hash, and user context
  • Endpoint file activity showing rapid overwrite, rename, delete, or high-volume write/delete sequences across directories or volumes
  • File and directory enumeration events where available from EDR, Sysmon-style telemetry, or operating system auditing
  • Local drive, disk, volume, and peripheral discovery indicators collected by endpoint or system management telemetry

Detection direction

  • Build correlation around PowerShell spawning or staging an unusual native Windows binary followed by discovery and high-volume file overwrite/delete behavior.
  • Tune for destructive sequences rather than single events: enumeration of files or storage followed by bulk writes, deletes, and possible shutdown/reboot is more meaningful than any one behavior alone.
  • Account for variant behavior described by ATT&CK: one variant shuts down after destructive operations, and another introduces a time delay between overwriting and deletion.
  • Look for selective exclusion patterns, such as files, folders, or components avoided during tampering, while recognizing exclusions alone may be benign without destructive context.
  • Review masquerading coverage for suspicious executable names, paths, or metadata that appear legitimate but do not match expected software inventory.

Mitigation priorities

  • Validate offline, immutable, or otherwise tamper-resistant backups and perform restore testing for critical Windows systems and operational dependencies.
  • Harden PowerShell use with appropriate logging, script control, and administrative restrictions consistent with business operations.
  • Use application control or allowlisting where feasible to limit execution of unapproved native binaries, especially from user-writable or script-staging locations.
  • Ensure least-privilege access to file shares, local administrative rights, and systems that support operational communications or critical services.
  • Prepare incident response runbooks for destructive malware, including rapid isolation, evidence preservation, shutdown/reboot handling, and restoration decision points.
Additional notes and limits

This take is based on the supplied ATT&CK S9038 object and relationships. The most decision-relevant facts are that DynoWiper is described as a Windows destructive malware distributed by PowerShell, associated with the 2025 Poland Wiper Attacks campaign, and mapped to discovery, stealth, execution, and impact behaviors. The relationship context supports cyber-physical risk discussion because the related campaign description names Polish energy infrastructure and disrupted communications, but local exposure depends on each organization’s architecture and telemetry.

ATT&CK provides no official detection section for DynoWiper in the supplied object. The object lists Windows as the platform, but several related technique platform lists are broader or do not include Windows; defensive planning here is therefore anchored to the malware description and the explicit Windows platform field. No claim is made that DynoWiper is currently active in any customer environment, that any control guarantees detection, or that any organization is exposed without local evidence.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

DynoWiper

DynoWiper is a destructive malware associated with the 2025 Poland Wiper Attacks in December of 2025. DynoWiper is a native Windows binary that is distributed by a PowerShell script and overwrites files using data generated by the Mersenne Twister algorithm before they are deleted from the system. Multiple variants of DynoWiper have been identified, with the primary differences being that one variant shuts down the system after completing its destructive operations, and another introduces a time delay between file overwriting and deletion.CitationCERT PolskaCitationESET DynoWiper Update JAN 2026

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
d7b3b82962cded49...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.