DynoWiper has been named after well-known files schtask.exe, schtask2.exe, and <redacted>_update.exe.34
tool
DynoWiper S9038
- Type
- malware
- Platform
- Windows
- Created
- 22 April 2026
- Last modified
- 23 April 2026
DynoWiper is a destructive malware associated with the 2025 Poland Wiper Attacks in December of 2025. DynoWiper is a native Windows binary that is distributed by a PowerShell script and overwrites files using data generated by the Mersenne Twister algorithm before they are deleted from the system. Multiple variants of DynoWiper have been identified, with the primary differences being that one variant shuts down the system after completing its destructive operations, and another introduces a time delay between file overwriting and deletion.[1][2]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S9038
DynoWiper has used the Microsoft Windows native FindFirstFile() and FindNextFile() to recursively enumerate directories and files on the system.5
DynoWiper has used multiple native Windows functions, such as GetLogicalDrives and FindNextFile for discovery and file deletion.67
DynoWiper has enumerated and overwritten files on all removeable and fixed drives.8
DynoWiper has overwritten files with 16-byte sequences of random data generated by the Mersenne Twister algorithm using the Microsoft Windows native CreateFileW() function to open the file and the SetFilePointerEx() and WriteFile() functions to overwrite the file.9 Additionally, versions of DynoWiper can also delete files using the DeleteFileW API.10
DynoWiper has used the Microsoft Windows native ExitWindowsEx() function to log off the interactive user and shutdown the system.11
Standing S9038
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
44th percentile · 56% of 825 ATT&CK software entries have more Enterprise techniques.
32nd percentile · 68% of 825 ATT&CK software entries have more tactics spanned.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
29th percentile · 71% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S9038
170 distinct rules cover the 9 techniques recorded for this tool. 109 Sigma · 61 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org