Skip to content

Hide Navigation Hide TOC

DynoWiper - S9038 (34057cb6-0a56-48a3-92e5-3af1357808da)

DynoWiper is a destructive malware associated with the 2025 Poland Wiper Attacks in December of 2025. DynoWiper is a native Windows binary that is distributed by a PowerShell script and overwrites files using data generated by the Mersenne Twister algorithm before they are deleted from the system. Multiple variants of DynoWiper have been identified, with the primary differences being that one variant shuts down the system after completing its destructive operations, and another introduces a time delay between file overwriting and deletion.(Citation: CERT Polska)(Citation: ESET DynoWiper Update JAN 2026)

Cluster A Galaxy A Cluster B Galaxy B Level
DynoWiper - S9038 (34057cb6-0a56-48a3-92e5-3af1357808da) Malware Selective Exclusion - T1679 (9b00925a-7c4b-4e53-bfc8-9a6a806fde03) Attack Pattern 1
DynoWiper - S9038 (34057cb6-0a56-48a3-92e5-3af1357808da) Malware Masquerading - T1036 (42e8de7b-37b2-4258-905a-6897815e58e0) Attack Pattern 1
DynoWiper - S9038 (34057cb6-0a56-48a3-92e5-3af1357808da) Malware Local Storage Discovery - T1680 (f2514ae4-4e9b-4f26-a5ba-c4ae85fe93c3) Attack Pattern 1
DynoWiper - S9038 (34057cb6-0a56-48a3-92e5-3af1357808da) Malware System Shutdown/Reboot - T1529 (ff73aa03-0090-4464-83ac-f89e233c02bc) Attack Pattern 1
DynoWiper - S9038 (34057cb6-0a56-48a3-92e5-3af1357808da) Malware Native API - T1106 (391d824f-0ef1-47a0-b0ee-c59a75e27670) Attack Pattern 1
DynoWiper - S9038 (34057cb6-0a56-48a3-92e5-3af1357808da) Malware File and Directory Discovery - T1083 (7bc57495-ea59-4380-be31-a64af124ef18) Attack Pattern 1
DynoWiper - S9038 (34057cb6-0a56-48a3-92e5-3af1357808da) Malware Peripheral Device Discovery - T1120 (348f1eef-964b-4eb6-bb53-69b3dcb0c643) Attack Pattern 1
DynoWiper - S9038 (34057cb6-0a56-48a3-92e5-3af1357808da) Malware Data Destruction - T1485 (d45a3d09-b3cf-48f4-9f0f-f521ee5cb05c) Attack Pattern 1
DynoWiper - S9038 (34057cb6-0a56-48a3-92e5-3af1357808da) Malware Delay Execution - T1678 (a1df809c-7d0e-459f-8fe5-25474bab770b) Attack Pattern 1