bleeping-computer · Crawled Aug 11, 2026
Hackers breached a small Polish energy plant via private APN last year
3 IoCs 1 Actors
Read original article ↗
AI Summary
In December 2025, a threat actor linked to the Russian Electrum group breached a small Polish combined heat-and-power (CHP) plant by exploiting a misconfigured private Access Point Name (APN) network. The attackers gained initial access through a compromised FortiGate firewall and Teltonika cellular router at a wind farm, then moved laterally through the private APN to reach the CHP plant's operational technology (OT) network. They exploited default credentials on a WAGO PFC200 PLC, used it as a bridge to access Siemens PLCs, and ultimately shut down critical systems including the steam turbine and water treatment system.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 3 extracted
MITRE ATT&CK TTPs 23 techniques
T1012 Query Registry · Discovery T1021.001 Remote Desktop Protocol · Lateral Movement T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol · Exfiltration T1053.005 Scheduled Task · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1069.002 Domain Groups · Discovery T1070.001 Clear Windows Event Logs · Defense Evasion T1071.001 Web Protocols · Command And Control T1078.004 Cloud Accounts · Defense Evasion T1083 File and Directory Discovery · Discovery T1087.002 Domain Account · Discovery T1090 Proxy · Command And Control T1090.002 External Proxy · Command And Control T1129 Shared Modules · Execution T1133 External Remote Services · Persistence T1136.002 Domain Account · Persistence T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1217 Browser Information Discovery · Discovery T1485 Data Destruction · Impact T1490 Inhibit System Recovery · Impact T1566 Phishing · Initial Access