Polish Critical Infrastructure Cyberattack Followup

CERT Polska released a follow up analysis of the cyberattack on power infrastructure at the end of December last year. The entire report is available here but I’ve included some sections that stood out to me and I would like to add some context to.

Page 5 Paragraph 2

The report did not give us an indication of how close this event was to being missed/written off entirely. It is possible that this is just a coincidence that the attack happened during maintenance, but it also may be that this was planned as the report also details steps taken to remove forensic evidence.

Page 5 Paragraph 3

The PLC device that was used as a staging ground had multiple network connections which allowed the attacker to jump through the power operator’s network into the Combined Heat and Power (CHP) powerplant. These dual-homed devices (with multiple network connections) have been used in other cyberattacks. In 2016 dual-homed devices were used to bridge the Information Technology (IT) and Operational Technology (OT) networks of a Ukrainian power substation to deliver the infamous INDUSTROYER malware.[1,2] Also in 2022, attackers again used this technique to jump through the networks of organizations in adjacent buildings.[3] Once a dual-homed laptop was identified, the attackers would use it’s wireless card to jump into the network of an organization located in an adjacent building.[3] This was performed 2 times to jump into their target network to steal files and documents related to individuals that were focusing on Ukraine.[3]

Page 6 Paragraph 1

This reminds me of the February 2022 Viasat KA-SAT disruption where a network provider in Italy was breached, allowing attackers to send commands over the satellite network to remotely wipe Modems.[4,5]

Page 10 Paragraph 1

A “specific username” implies that the attackers had knowledge of the renewable energy facility ecosystem including contract/repair companies and had obtained their credentials in some way.

Page 11

This is a tradeoff that incident response teams must make for each individual incident. Resetting and repairing systems frequently removes any forensic traces that may be analyzed later. For critical infrastructure (such as this CHP plant) that uses embedded devices that are not easily replaceable, the negative effects of downtime likely outweigh the benefit of preserving evidence. For more than a decade, high-end malware implants have been designed to run entirely in non-volatile RAM memory. A reboot of these infected device would erase the malware unless persistence methods were used to ensure re-infection.

This also highlights the critical importance of having robust, tested backup systems and procedures for restoration. In 2025 during the Twelve-day Israel-Iran war, The Iranian Sepah Bank was forced to rebuild their systems from partial offline backups when it’s computer systems were destroyed by a cyberattack.[6] A portable data center “Samsonite” was available to other banks affected by the attack (The Pasargad Bank) which allowed them to restore core functionality, but the Sepah Bank, which had not integrated this system, causing longer disruptions in operations.[6]

Page 14 Paragraph 1

A partition table tells the computer where important software elements of the operating system are stored in the hard drive. If this is corrupted or destroyed, the computer does not know where the starting address of operating system data is rendering the entire system unreadable. This technique is commonly used in wiper malware, including Iran-linked groups like HANDALA.[7]

Page 16 Paragraph 1

I think this is correct, but incomplete. An APN is simply a private cellular network, and in some of the comments above I’ve detailed other incidents where attackers moved from a private network into OT devices. It is likely that this is the first observed instance of a utility with this particular APN configuration being breached to access the critical infrastructure, even though the general process of jumping to the OT systems from another system seems to be common.

Conclusion

Along with my previous writings on this incident, this new report gives us some more information about how malicious groups disrupt critical infrastructure and shows us how to secure other similar systems. The end of the report gives actions that other organizations can take to eliminate risks in systems that also use APNs for secondary access to remote sites.

Sources

[1] K. O’Meara and B. Livingston, “ELECTRUM and KAMACITE: Ten Years of Adversary Tradecraft in ICS Operations.” Dragos, Jan. 2026. [Online]. Available: https://5943619.hs-sites.com/hubfs/Reports/electrum-kamacite-ten-years-adversary-tradecraft-intel-report-01-26.pdf?hsCtaAttrib=202871233975

[2] A. Kaushik, “The War on Ukraine: A Look at (Underemphasised) Russian Cyber Operations.” GLOBSEC, Oct. 02, 2023. [Online]. Available: https://www.globsec.org/what-we-do/publications/war-ukraine-look-underemphasised-russian-cyber-operations

[3] “The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access,” Dec. 05, 2024. [Online]. Available: https://www.youtube.com/watch?v=OmrzQ2dfaGY

[4] C. Vasquez and E. Groll, “Satellite hack on eve of Ukraine war was a coordinated, multi-pronged assault.” [Online]. Available: https://cyberscoop.com/viasat-ka-sat-hack-black-hat/

[5] J. Guerrero-Saade, “AcidRain | A Modem Wiper Rains Down on Europe.” [Online]. Available: https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/

[6] “Wartime cyberattack wiped data from two major Iranian banks, expert says,” Jul. 19, 2025. [Online]. Available: https://www.iranintl.com/en/202507192001

[7] “‘Handala Hack’ – Unveiling Group’s Modus Operandi.” [Online]. Available: https://research.checkpoint.com/2026/handala-hack-unveiling-groups-modus-operandi/