Threat Intelligence, Critical Infrastructure Security

CERT Polska: Static Tundra behind coordinated Poland critical infrastructure hack

Magnifying glass found the Russia map among computer binary code

More than 30 solar and wind farms across Poland, along with a major combined heat and power plant and a manufacturing firm, were noted by CERT Polska to have been targeted by the Russian state-sponsored threat operation Static Tundra, also known as Berserk Bear, Ghost Blizzard, and Dragonfly, in coordinated cyberattacks in late December, reports Security Affairs.

Neither electricity nor heat supply had been disrupted by the destructive intrusions, which involved the compromise of renewable energy substations with tampered firmware and the DynoWiper malware, according to CERT Polska. After targeting misconfigured Fortinet FortiGate devices for admin access, Static Tundra proceeded to reset devices, corrupt Hitachi RTU firmware, erase Mikronika controllers, and inject DynoWiper into HMI computers, resulting in compromised communications.

"The attack affected the GCP substation, which serves not only as the physical grid interconnection point but also as the location through which the DSO performs remote monitoring and supervisory control. Such substations are typically remotely managed and unmanned, with remote access capabilities commonly employed for operations and maintenance," said the report, which comes after the campaign was linked to the Sandworm hacking group.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds