Framework mapping
MITRE ATT&CK® Enterprise mapping
Relationship: Canonical Enterprise ATT&CK campaign record
Open the official ATT&CK object ↗Canonical ATT&CK entity profile. Identifier, name, associated-name context, and public-reporting scope were reconciled to the official Enterprise ATT&CK directory; the official object page remains controlling for complete and current relationships.
What this ATT&CK campaign record represents
2025 Poland Wiper Attacks (C0063) is an Enterprise ATT&CK campaign record. ATT&CK uses Campaign for a grouping of intrusion activity conducted over a specific period with common targets and objectives. A campaign can be attributed, unattributed, or involve more than one participating cluster.
The official directory summarizes public reporting that describes destructive December 2025 attacks against Polish energy infrastructure involving Windows and PowerShell wipers. This BMC page focuses on how to analyze that record defensibly rather than reproducing harmful operational detail.
The public campaign name is a reporting label. Other sources may use overlapping names or define the activity window differently.
Separate the campaign from the actor
A campaign is a time-bounded activity set; a group is an analytic cluster that may participate in many campaigns. Treating those objects as interchangeable can erase chronology, hide changes in tooling, and overstate attribution.
For 2025 Poland Wiper Attacks, record which source makes each actor, software, infrastructure, target, and technique association. Preserve disagreements instead of forcing every report into one narrative.
- Record the observed start and end dates or the source’s stated uncertainty.
- Distinguish direct attribution from similarity, overlap, or speculation.
- Track each organization’s campaign and group definitions separately.
- Note where multiple actors may have performed different operational roles.
Build a campaign timeline
Chronology is the backbone of campaign analysis. Place public-reporting events and local observations on the same time axis, but label the source and confidence of every event.
Use phases that support defensive decisions: preparation, initial access, foothold, privilege or identity expansion, discovery, lateral movement, collection, impact, response, and post-incident activity. Do not infer a missing phase merely because it appears in another campaign.
- Use normalized UTC timestamps while retaining original time-zone context.
- Link each timeline event to a source passage or telemetry record.
- Mark first seen, last seen, publication date, and discovery date separately.
- Identify collection gaps that could make activity appear to stop or start artificially.
Map behaviors without turning ATT&CK into a checklist
Campaign-to-technique relationships in ATT&CK reflect publicly reported observations. They represent a subset of known activity and can change as new reporting is added.
For 2025 Poland Wiper Attacks, map only behaviors supported by evidence. For every mapping, capture the observable action, affected technology, data source, time window, confidence, and alternative interpretation.
A missing technique does not prove the behavior did not occur, and a mapped technique does not prove it occurred in a different victim environment.
Defensive lessons and coverage questions
Campaign analysis should produce decisions: telemetry improvements, exposed-service review, identity hardening, detection tests, segmentation changes, recovery validation, supplier assurance, or intelligence-collection priorities.
- Which campaign behaviors are relevant to technologies and trust boundaries actually used by the organization?
- Which behaviors would create high-consequence outcomes even if they are unlikely?
- Can the organization reconstruct the sequence with current log coverage and retention?
- Which controls were preventive, detective, investigative, containment, or recovery measures?
- What evidence would distinguish this campaign from commodity or unrelated activity?
Investigation and threat-hunting workflow
Use 2025 Poland Wiper Attacks as a structured hypothesis, not as a keyword hunt. Begin with the most reliable observable, define a time and asset scope, test for related behaviors, and document both confirming and disconfirming evidence.
Threat hunting should not introduce unsafe tools or live adversary infrastructure. Use approved indicators, passive historical data, synthetic tests, and isolated lab material.
- Validate source reliability and indicator freshness.
- Search for behavior sequences, not only isolated hashes or domains.
- Compare affected assets with the campaign’s reported target and technology scope.
- Escalate based on local evidence and consequence, not the fame of the campaign name.
- Retire or revise the hypothesis when evidence no longer supports it.
Lessons-learned and resilience review
After analysis, convert the campaign into a small set of reusable control and intelligence requirements. Record what the organization could see, what it could not see, which controls were tested, and what recovery dependencies remain.
Revisit the record when ATT&CK, the underlying public reports, or your environment changes. Versioning keeps a historical assessment from silently becoming a current claim.
Safe practitioner exercise
Using the official C0063 page and one underlying public source, create a campaign timeline with five evidence-backed events. Map no more than three techniques and include one alternative explanation for each mapping.
Finish with one telemetry improvement, one detection test, one containment consideration, and one recovery question. Use only public, synthetic, or sanitized information.
Version, attribution, and independence
This page was reviewed against Enterprise ATT&CK v19.2. Verify the official C0063 record for current dates, associated campaigns, groups, software, techniques, and references.
© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation. Bare Metal Cyber is not affiliated with or endorsed by MITRE. The instructional analysis on this page is original Bare Metal Cyber content.
Certification relevance
This subject appears in or supports the following certification bodies of knowledge: