Principal Malware Researcher, ESET
Anton Cherepanov is a Principal Malware Researcher at ESET, responsible for analyzing and hunting the most complex cyber threats. He has conducted extensive research on the Sandworm APT group. His professional interests include detection engineering, reverse engineering, and hunting for previously unknown threats.
On 29 December 2025, a coordinated destructive cyberattack targeted more than thirty renewable energy plants and a combined heat and power plant in Poland – the most significant, albeit unsuccessful, attempt at cybersabotage against NATO territory to date.
The talk goes over technical details of the attack, from initial access through vulnerable FortiGate perimeter devices, credential harvesting, and months long reconnaissance, ultimately culminating in the deployment of the destructive payload: DynoWiper.
We also tackle the question of attribution: our analysis points to Sandworm, primarily based on TTPs revolving around the way DynoWiper was deployed, while CERT Polska links the activity based on network infrastructure to a different Russia-aligned APT group: Berserk Bear.
Combining insights from ESET’s first hand telemetry as well as from CERT Polska’s incident response, participants will gain a comprehensive understanding of Russia’s most escalatory cybersabotage operation outside Ukraine.