VYPR
breachPublished Aug 10, 2026· 1 source

Sandworm APT Uses Novel Private APN Attack Vector to Sabotage Polish Energy Facility

Russian state-sponsored APT Sandworm exploited a private APN to sabotage a Polish energy facility, marking the first documented use of this attack vector against critical infrastructure.

A sophisticated cyberattack targeting Poland's energy sector has revealed a novel exploitation technique, with threat actors leveraging a private Access Point Name (APN) network to sabotage industrial control systems (ICS) at a combined heat and power (CHP) plant. This incident, attributed to the Russian state-sponsored Advanced Persistent Threat (APT) group Sandworm, marks the first documented instance of a private APN being used as a direct attack vector.

The attack, which occurred in late December 2025, was part of a broader campaign that also targeted other energy facilities, including wind and solar power dispatch centers. While a previous attack on December 2025 focused on grid safety and monitoring systems with limited destructive impact, this second, parallel attack was aimed at a smaller CHP plant supplying heat to approximately 50,000 residents, with the objective of causing "purely destructive" damage.

The intrusion began with threat actors compromising a Fortinet VPN and firewall device connected to the internet at a wind farm. From there, they identified and accessed the administrative interface of a Teltonika cellular router. Utilizing an SSH service on this router, the attackers established a tunnel that granted them access to a private APN network. These private APN networks are typically used by Distribution System Operators (DSOs) to facilitate communication between their SCADA systems and the ICS installed at substations.

Once inside the private APN, the attackers scanned the network and located a Wago programmable logic controller (PLC) at the target CHP plant. An SSH service enabled on this PLC provided the attackers with a gateway into the plant's Operational Technology (OT) networks. After a week of reconnaissance within the OT environment, the threat actor directly targeted Siemens PLCs, switching them to a 'stop' mode and setting passwords to prevent operators from altering their operating state or control logic. This action successfully caused the shutdown of a steam turbine and a water treatment system, disrupting the cogeneration process.

In addition to the Siemens PLCs, the attackers also targeted Moxa serial device servers and network switches, configuring them to block legitimate operator access. Variable frequency drives from ABB and Schneider Electric were also identified as targets, though the specific actions taken against them are less clear, and some connection attempts were unsuccessful. Similar to the earlier attack, some of the compromised ICS devices were permanently damaged, with the attackers corrupting the partition table of the Wago controller used as the initial gateway, rendering it unbootable even after a factory reset and preventing log recovery.

While the attack caused a disruption to the cogeneration process, plant operators were able to restore systems quickly by resetting the affected PLCs to factory settings and reloading logic from backups. Crucially, the incident did not result in any interruption to the heat and electricity supply for the local population. The attack was initially mistaken for an engineering error due to its occurrence during maintenance work, but the Polish CERT's investigation quickly identified it as a deliberate cyberattack.

The Polish CERT has warned that the vulnerable configuration involving private APN networks is commonly encountered not only in Poland but also globally, highlighting a significant and previously underutilized threat vector for critical infrastructure. The incident underscores the evolving tactics of APT groups like Sandworm and the critical need for enhanced security measures in OT environments, particularly concerning network segmentation and access controls for remote and private network infrastructure.

Synthesized by Vypr AI