AcidRain is a destructive Linux wiper targeting satellite modems, routers, and similar embedded network devices. Identified by SentinelLabs in March 2022, its analyzed implementation is a 32-bit MIPS ELF executable. With root privileges, it recursively overwrites and deletes filesystem contents and attacks flash memory, SD/MMC storage, and block devices. It iterates through possible storage-device identifiers rather than relying exclusively on device-specific configurations, uses direct writes and flash-memory IOCTL erase operations, commits destructive writes to storage, and reboots the system, leaving affected devices inoperable.
AcidRain was used in the February 24, 2022 attack against Viasat’s KA-SAT satellite broadband network at the outset of Russia’s full-scale invasion of Ukraine. Attackers compromised the network’s trusted management infrastructure and used legitimate management commands to execute the destructive payload on customer modems. The operation disrupted thousands of subscribers in Ukraine and tens of thousands elsewhere in Europe, including satellite connectivity supporting remote monitoring and control of approximately 5,800 Enercon wind turbines in Germany; the turbines themselves were not physically disabled. The KA-SAT operation has been publicly attributed to Russia, including its military intelligence agency, the GRU. AcidRain’s primary purpose is destructive sabotage of communications infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
AcidRain was designed to remotely erase vulnerable modems and routers, including terminals used by the Armed Forces of Ukraine for command and control at exactly the moment that control matters most.
Researchers from cybersecurity vendor SentinelOne uncovered a wiper malware called AcidRain designed for MIPS firmware used by the SATCOM modems that was potentially used in the KA-SAT attack.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
As noted in our report: "the attacker moved laterally through this trusted management network to a specific network segment used to manage and operate the network, and then used this network access to execute legitimate, targeted management commands on a large number of residential modems simultaneously."
As noted in our report: "the attacker moved laterally through this trusted management network to a specific network segment used to manage and operate the network, and then used this network access to execute legitimate, targeted management commands on a large number of residential modems simultaneously."
As noted in our report: "the attacker moved laterally through this trusted management network to a specific network segment used to manage and operate the network, and then used this network access to execute legitimate, targeted management commands on a large number of residential modems simultaneously."
Destroys infected equipment (Wipes flash memory, sd, memory card, and block devices)
If during enumeration it found a regular file (DT_REG) or symbolic link (DT_LNK) it will overwrite it... If it is another directory, it will traverse all the files on that folder path, wipe it, then delete that directory using rmdir() function.
As noted in our report: "the attacker moved laterally through this trusted management network to a specific network segment used to manage and operate the network, and then used this network access to execute legitimate, targeted management commands on a large number of residential modems simultaneously."
the user manual suggests retrieving firmware updates via FTP from a Telnet or SSH shell on the serial converter itself... The iRZ RUH2 3G is similarly Linux-based and has the ability to push firmware updates via its web interface, though SSH shell access is possible too... FuxNet malware over either SSH or a proprietary sensor management protocol
Many entries concern “CaddyWiper”, “new data wiper hits Ukraine”, “destructive wiper malware”, and Sandworm operations using CADDYWIPER alongside INDUSTROYER2.
Prior to the start of the conflict, it was strongly believed that a cyber operation, specifically against energy and communication sectors, would act as a precursor to kinetic action. While a WannaCry or NotPetya-scale attack did not occur, the AcidRain attack against the Viasat satellite communication network and other attacks targeting Ukraine’s energy sector highlight that cyber operations of varying effectiveness will play a role in the lead up to a military conflict.
IoT wipers often rewrite important parts of the firmware of an IoT device, rendering that device useless, so they are also known as 'brickers'.
Once all the processes of the malware are executed, it initiates a reboot of the device.
From there, the attackers executed commands to flash the memory of the modems, rendering them unusable.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
41 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive malware used in the February 24, 2022 Viasat KA-SAT attack to erase modems and routers and disrupt satellite communications. The operation sought to degrade Ukrainian military command and control before the invasion, but Ukrainian officials reported no tactical impact because alternative communications were available. Civilian internet services across Europe and remote monitoring of German wind turbines were also disrupted.
Referenced as historical comparison for destructive malware focused on immediate operational impact.
Linux-based wiper malware that destroys data by overwriting files and storage devices, including flash and block devices, then reboots the device. It was used to disrupt Viasat KA-SAT satellite modems in the context of the Russo-Ukrainian conflict.
A wiper targeting Viasat KA-SAT modems rather than typical enterprise Windows systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.