Static Tundra destructive campaign against Polish energy and manufacturing targets
Campaign
Summary
Hide ▲
Show ▼
The Static Tundra campaign is a destructive cyber activity tied to FSB Center 16 that targeted more than 30 wind and photovoltaic farms, a manufacturing company, and a CHP plant in Poland. The operation used vulnerable Fortinet/FortiGate devices, wiper malware such as DynoWiper and LazyWiper, and access paths including SSL‑VPN portal service exposure and Active Directory. Public reporting now also links the broader threat actor to router scanning worldwide for weak SNMP passwords and community strings and to exploitation of CVE-2018-0171 on Cisco devices. The same source says the late-2025 Poland energy-infrastructure attacks were officially attributed to FSB Centre 16 by the UK and EU.
Related Happenings
Cybersecurity agencies from 12 countries fresh warning / joint advisory for published on 2026-07-13
Public Sector Action
H score53
First: 13.07.2026 13:40
Last: 13.07.2026 13:40
Sources 1
How related:
Cybersecurity agencies from 12 countries have issued a fresh warning that a Russian state-sponsored cyber unit is actively targeting vulnerable routers worldwide.
About this happening:
Cybersecurity agencies from 12 countries issued a fresh advisory urging defenders to harden vulnerable routers amid active targeting by a Russian state-sponsored cyber u...
Cybersecurity agencies from 12 countries fresh warning / joint advisory for published on 2026-07-13
Public Sector ActionHow related: Cybersecurity agencies from 12 countries have issued a fresh warning that a Russian state-sponsored cyber unit is actively targeting vulnerable routers worldwide.
About this happening: Cybersecurity agencies from 12 countries issued a fresh advisory urging defenders to harden vulnerable routers amid active targeting by a Russian state-sponsored cyber u...
FSB 16th Centre yearslong cyber espionage campaign against European governments and critical infrastructure
Campaign
H score42
First: 13.07.2026 13:00
Last: 13.07.2026 13:00
Sources 1
About this happening:
FSB 16th Centre is tied to a yearslong cyberespionage campaign against European governments and critical infrastructure across at least nine countries. The C...
FSB 16th Centre yearslong cyber espionage campaign against European governments and critical infrastructure
CampaignAbout this happening: FSB 16th Centre is tied to a yearslong cyberespionage campaign against European governments and critical infrastructure across at least nine countries. The C...
Russian FSB Center 16 router intrusion campaign
Campaign
H score40
First: 13.07.2026 12:32
Last: 13.07.2026 12:32
Sources 1
About this happening:
A Russian FSB Center 16 campaign is targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks, raising the risk of device takeo...
Russian FSB Center 16 router intrusion campaign
CampaignAbout this happening: A Russian FSB Center 16 campaign is targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks, raising the risk of device takeo...
Initial access broker (IAB) campaign expands across multiple victims
Campaign
H score89
First: 22.06.2026 23:01
Last: 22.06.2026 23:01
Sources 1
About this happening:
The FortiBleed campaign is a live credential-harvesting activity targeting Fortinet FortiGate devices worldwide. It has been active since at least February 2026 an...
Initial access broker (IAB) campaign expands across multiple victims
CampaignAbout this happening: The FortiBleed campaign is a live credential-harvesting activity targeting Fortinet FortiGate devices worldwide. It has been active since at least February 2026 an...
Latest development: 23.06.2026 13:30
On June 15, attackers behind FortiBleed successfully cracked Kerberos hashes and immediately exfiltrated DFS backup data from a NATO-aligned defense contractor, extending the campaign from credential harvesting into direct data theft.
FortigateSniffer FortiOS packet-sniffer credential-harvesting tool
Malware Activity
H score72
First: 22.06.2026 23:01
Last: 22.06.2026 23:01
Sources 1
About this happening:
FortigateSniffer is a Golang-based credential-harvesting tool used in the FortiBleed operation against FortiGate firewalls. It abuses FortiOS packet-sniffing f...
FortigateSniffer FortiOS packet-sniffer credential-harvesting tool
Malware ActivityAbout this happening: FortigateSniffer is a Golang-based credential-harvesting tool used in the FortiBleed operation against FortiGate firewalls. It abuses FortiOS packet-sniffing f...
Timeline
-
31.01.2026 09:05 1 articles · 5mo ago
Destructive intrusion on Polish energy and industrial targets
Exploitation ObservedOn December 29, 2025, coordinated destructive activity targeted more than 30 wind and photovoltaic farms, a private manufacturing company, and a large combined heat and power plant in Poland. The attackers gained access through vulnerable Fortinet and FortiGate devices, moved through power-substation and Active Directory environments, and deployed wiper malware including DynoWiper and LazyWiper, while attempts to detonate the wipers were unsuccessful.
Show sources
- CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms — thehackernews.com — 31.01.2026 09:05
-
31.01.2026 09:05 1 articles · 5mo ago
Communications disruption without power or heat outage
Victim Impact UpdateOn December 29, 2025, destructive activity against Polish renewable-energy infrastructure disrupted communication between affected facilities and the distribution system operator, but electricity production continued. The combined heat and power plant did not lose heat supply to end users, so the operational impact remained limited to communications and attempted sabotage rather than achieved service outages.
Show sources
- CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms — thehackernews.com — 31.01.2026 09:05
-
31.01.2026 09:05 3 articles · 5mo ago
CERT Polska disclosure and attribution update
Initial DisclosureOn January 31, 2026, CERT Polska publicly disclosed the coordinated campaign against Polish energy and industrial targets, attributed it to Static Tundra linked to Russia's FSB Center 16 unit, and noted that ESET and Dragos had associated the activity with Sandworm at moderate confidence. The disclosure also described long-term data theft in the combined heat and power plant case dating back to March 2025, use of credentials from on-premises systems to access M365 services such as Exchange, Teams, and SharePoint, and the deployment of DynoWiper and LazyWiper through FortiGate, SSL-VPN, and Active Directory paths.
Show sources
- CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms — thehackernews.com — 31.01.2026 09:05
- CERT Polska Details Coordinated Cyber Attacks on 30+ Wind and Solar Farms — thehackernews.com — 31.01.2026 09:05
- Russian State Hackers Target Vulnerable Routers Worldwide, Joint Advisory Warns — www.infosecurity-magazine.com — 13.07.2026 13:40