AcidRain is a destructive Linux-based wiper targeting embedded customer-premises equipment, especially satellite modems and routers. It is a 32-bit MIPS ELF malware family associated with the February 2022 disruption of the KA-SAT satellite communications network at the outset of Russia’s invasion of Ukraine, where it rendered large numbers of modems inoperable and caused spillover connectivity outages across Europe. Public reporting and government statements have linked the broader operation to Russian military intelligence, and multiple analyses discuss technical similarities between AcidRain and the destructive plugin of VPNFilter, although they remain distinct malware families.
AcidRain is designed to brick devices by recursively overwriting and deleting filesystem contents and by directly erasing storage devices commonly used in embedded Linux systems. When executed with sufficient privileges, it traverses directories, wipes regular files and symbolic links, removes directories, and targets flash and block storage associated with routers and modems, including MTD, MMC, loop, and other device-backed storage. Its device-wiping logic uses Linux flash-memory control operations to unlock and erase memory regions and commit destructive writes, after which it reboots the device. The malware’s broad, brute-force handling of device names indicates it was built to operate across varying firmware layouts rather than a single exact hardware profile.
AcidRain is notable as one of the clearest examples of an IoT or embedded-device wiper used for operational disruption in a geopolitical conflict. It has been repeatedly cited alongside other destructive malware used against Ukrainian targets and critical communications infrastructure. The malware’s purpose is sabotage rather than espionage or monetization, with limited post-compromise functionality beyond destruction and forced rebooting of the target device.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Researchers from cybersecurity vendor SentinelOne uncovered a wiper malware called AcidRain designed for MIPS firmware used by the SATCOM modems that was potentially used in the KA-SAT attack.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
As noted in our report: "the attacker moved laterally through this trusted management network to a specific network segment used to manage and operate the network, and then used this network access to execute legitimate, targeted management commands on a large number of residential modems simultaneously."
As noted in our report: "the attacker moved laterally through this trusted management network to a specific network segment used to manage and operate the network, and then used this network access to execute legitimate, targeted management commands on a large number of residential modems simultaneously."
As noted in our report: "the attacker moved laterally through this trusted management network to a specific network segment used to manage and operate the network, and then used this network access to execute legitimate, targeted management commands on a large number of residential modems simultaneously."
Destroys infected equipment (Wipes flash memory, sd, memory card, and block devices)
If during enumeration it found a regular file (DT_REG) or symbolic link (DT_LNK) it will overwrite it... If it is another directory, it will traverse all the files on that folder path, wipe it, then delete that directory using rmdir() function.
As noted in our report: "the attacker moved laterally through this trusted management network to a specific network segment used to manage and operate the network, and then used this network access to execute legitimate, targeted management commands on a large number of residential modems simultaneously."
the user manual suggests retrieving firmware updates via FTP from a Telnet or SSH shell on the serial converter itself... The iRZ RUH2 3G is similarly Linux-based and has the ability to push firmware updates via its web interface, though SSH shell access is possible too... FuxNet malware over either SSH or a proprietary sensor management protocol
Many entries concern “CaddyWiper”, “new data wiper hits Ukraine”, “destructive wiper malware”, and Sandworm operations using CADDYWIPER alongside INDUSTROYER2.
Prior to the start of the conflict, it was strongly believed that a cyber operation, specifically against energy and communication sectors, would act as a precursor to kinetic action. While a WannaCry or NotPetya-scale attack did not occur, the AcidRain attack against the Viasat satellite communication network and other attacks targeting Ukraine’s energy sector highlight that cyber operations of varying effectiveness will play a role in the lead up to a military conflict.
IoT wipers often rewrite important parts of the firmware of an IoT device, rendering that device useless, so they are also known as 'brickers'.
Once all the processes of the malware are executed, it initiates a reboot of the device.
From there, the attackers executed commands to flash the memory of the modems, rendering them unusable.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
39 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as historical comparison for destructive malware focused on immediate operational impact.
Linux-based wiper malware that destroys data by overwriting files and storage devices, including flash and block devices, then reboots the device. It was used to disrupt Viasat KA-SAT satellite modems in the context of the Russo-Ukrainian conflict.
A wiper targeting Viasat KA-SAT modems rather than typical enterprise Windows systems.
Destructive modem and embedded-device wiper associated with Sandworm disruptive operations in Europe and Ukraine-related activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.