Malware News • 5d
Post-Incident Analysis: Private APN Exploitation in the Polish Energy Sector
A three-month forensic investigation by CERT Polska and IOActive into the December 2025 cyberattack on the Polish energy sector has confirmed a multi-target campaign impacting at least two Combined Heat and Power (CHP) plants. The investigation identified a novel exploitation of private Access Point Names (APNs) used for cellular-based industrial connectivity. By leveraging these cellular-to-OT bridges, threat actors successfully bypassed traditional network perimeter defenses to access critical ICS/OT control systems. The incident involved the deployment of specialized ICS/OT malware, highlighting a sophisticated pivot from mobile telecommunications infrastructure directly into critical national infrastructure environments.
Links:Malware News, Security Affairs, feeds.feedburner.com, cybersecurity.pk, Industrial Cyber, techjacksolutions.com, Cert, Thehackernews, Cisa, Industrialcyber, Reddit, Ioactive, Ceenergynews, 4m4, The Record by Recorded Future, Helpnetsecurity, Daily, Indurex, Dev, Omicroncybersecurity, bleepingcomputer.com, helpnetsecurity.com, gbhackers.com, Securityweek, Infosecurity-magazine, Cyberpress •