AcidRain is a destructive embedded-device wiper associated with the February 2022 disruption of the Viasat KA-SAT satellite communications network at the outset of Russia’s full-scale invasion of Ukraine. It is an ELF MIPS malware built for Linux-based modems, routers, and similar embedded systems, and has been publicly linked to the large-scale disabling of KA-SAT customer modems in Ukraine with spillover disruption elsewhere in Europe, including loss of remote connectivity for thousands of wind turbines in Germany. Public reporting and later reference material have also linked AcidRain to Sandworm, the Russian GRU-linked sabotage actor, although some technical lineage assessments remain medium-confidence rather than definitive.
The malware’s purpose is data destruction and device disablement rather than espionage or extortion. When executed with sufficient privileges, AcidRain recursively deletes files from the target filesystem and performs low-level wiping of attached storage and flash-backed device media. It generically iterates through device identifiers, opens device files, and either overwrites them directly or invokes erase-related IOCTL operations commonly used against flash memory. It then forces a reboot after destructive actions complete, leaving the device unable to function normally. This broad, generic wiping logic distinguishes it from more narrowly tailored destructive modules and makes it suitable for damaging multiple classes of embedded Linux equipment.
In the KA-SAT incident, attackers reportedly gained access to the satellite network’s management environment through a misconfigured VPN appliance, moved laterally into the trust-management segment, and used legitimate management mechanisms to push destructive actions to large numbers of residential modems simultaneously. Independent analysis of affected terminal firmware identified weak management-plane security and plausible remote deployment paths, including application installation and command-execution functionality, but those specific mechanisms were not conclusively established as the exact intrusion path used in the operation.
AcidRain has also been discussed in connection with developmental similarities to the destructive component of VPNFilter, another malware family attributed by U.S. authorities to the Russian government. A later variant, AcidPour, expanded the same destructive model to additional Linux storage abstractions and architectures, reinforcing the view that AcidRain represents a reusable embedded wiper design for operational disruption against communications and potentially other OT-adjacent Linux devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
AcidRain, a wiper that rendered Eutelsat KA-SAT modems inoperative in Ukraine and caused additional disruptions throughout Europe at the onset of the Russian invasion.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
After obtaining initial access via a VPN gateway to the management plane of the ViaSat KA-SAT core ground network, the attackers deployed the AcidRain wiper to the satellite modems via SSH using compromised credentials.
Scalable disruption is more plausibly achieved by pushing an update, script, or executable.
A deeper look at the 'ut_app_execute_operation' function revealed that it is implementing a functionality that enables the ACS to install (upload and run) arbitrary binaries on the modem... This functionality seems to match both the Viasat statement as well as the approach to deploy the 'AcidRain' wiper described by SentinelOne.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
the user manual suggests retrieving firmware updates via FTP from a Telnet or SSH shell on the serial converter itself... The iRZ RUH2 3G is similarly Linux-based and has the ability to push firmware updates via its web interface, though SSH shell access is possible too... FuxNet malware over either SSH or a proprietary sensor management protocol
The references include multiple wiper campaigns and destructive malware operations such as NotPetya, SwiftSlicer, AcidRain, AcidPour, and DynoWiper associated with Sandworm/APT44.
A destructive pattern, that corrupted the flash memory rendering the SATCOM modems inoperable, can be observed on the left...
Notable similarities include the use of the same reboot mechanism, the exact logic of the recursive directory wiping, and most importantly the use of the same IOCTL-based wiping mechanism used by both AcidRain and the VPNFilter plugin ‘dstr’.
SentinelLABS has discovered a novel malware variant of AcidRain... The new malware, which we call AcidPour, expands upon AcidRain’s capabilities and destructive potential to now include Linux Unsorted Block Image (UBI) and Device Mapper (DM) logic, better targeting RAID arrays and large storage devices.
Destructive TTPs such as wiping or even bricking are not novel... CIH virus... overwriting a hard drive's partition table... BrickerBot destroyed more than 10 million IoT devices by writing random data to various block devices... AcidRain's wiper functionality consists of recursive file deletion combined with either overwriting raw block devices or erasing them through dedicated IOCTLs.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as historical comparison for destructive malware focused on immediate operational impact.
Destructive modem and embedded-device wiper associated with Sandworm disruptive operations in Europe and Ukraine-related activity.
A destructive malware/wiper associated here with data destruction behavior, specifically deletion of init daemon scripts on Linux systems.
AcidRain is a wiper malware designed to erase data on modems and routers, causing widespread disruption to satellite communications and critical infrastructure. It was used in the 2022 attack on Viasat's KA-SAT satellite network, impacting thousands of users and critical systems such as wind turbines.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.