DynoWiper

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[DynoWiper](https://attack.mitre.org/software/S9038) is a destructive malware associated with the [2025 Poland Wiper Attacks](https://attack.mitre.org/campaigns/C0063) in December of 2025. [DynoWiper](https://attack.mitre.org/software/S9038) is a native Windows binary that is distributed by a PowerShell script and overwrites files using data generated by the Mersenne Twister algorithm before they are deleted from the system. Multiple variants of [DynoWiper](https://attack.mitre.org/software/S9038) have been identified, with the primary differences being that one variant shuts down the system after completing its destructive operations, and another introduces a time delay between file overwriting and deletion.(Citation: CERT Polska)(Citation: ESET DynoWiper Update JAN 2026)

Associated Techniques (9)
ID ATT&CK Tactics
T1036 Masquerading -
T1083 File and Directory Discovery -
T1106 Native API -
T1120 Peripheral Device Discovery -
T1485 Data Destruction -
T1529 System Shutdown/Reboot -
T1678 Delay Execution -
T1679 Selective Exclusion -
T1680 Local Storage Discovery -
Metadata
ID: 164208
Created: 28/04/2026 16:00
Updated: 09/05/2026 16:00