Malicious DYNOWIPER PowerShell Loader Execution (via ps_script)

PremiumReviewedSigma · High · v1
Product
windows
Category
ps_script
Author
HuntRule
Published
2026-09-19
Updated
2026-09-19

ATT&CK techniques

Execution → Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

What it detects

This rule detects execution of the DYNOWIPER PowerShell loader scripts that stage and launch the destructive wiper against Poland's energy sector. Observed in Elastic Security Labs telemetry where dynacon_update.ps1 or exp.ps1 orchestrate dropping and running the wiper binary, indicating imminent data destruction.

Related detections9 linkedT1059.001 — drag to rearrange
Windows Process Command-Line Indicators of BlackByte Ransomware Activity
Malicious ClickFix Clipboard Command Execution via PowerShell
Suspicious PowerShell AMSI or ETW Tampering
Suspicious Batch Fake Installer Spawning PowerShell Downloader via OXLoader
Malicious Renamed PowerShell as wt.exe in ProgramData via Axios Compromise
Suspicious ClickFix PowerShell Execution with Hidden Window (via process_creation)
Suspicious Encoded PowerShell Execution with No Profile
Suspicious PowerShell Encoded Command Execution
Suspicious PowerShell BITS Transfer of DLL Payload via process_creation
Malicious DYNOWIPER PowerShell Loader Execution (via ps_script)
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.