AcidPour is a destructive Linux wiper assessed as a newer variant of AcidRain and associated with attacks against Ukrainian telecommunications targets in 2024. It is an ELF binary compiled for x86 systems and is designed to irreversibly destroy data and render targeted devices inoperable. Public reporting links the broader activity to Russian state-aligned operations, including Sandworm-related tracking such as UAC-0165, although some attribution details remain assessed rather than conclusively proven.
The malware performs deep wiping of victim filesystems and attached storage by recursively deleting or overwriting data and by issuing device-level erase operations through IOCTLs. Compared with AcidRain, AcidPour expands destructive coverage to additional Linux storage abstractions, notably UBI flash storage and Device Mapper devices, improving its ability to impact embedded Linux systems, RAID-backed storage, large disks, and other mapped storage configurations. Reported behavior also includes recursive wiping of boot-related content, overwriting raw device content with a fixed buffer, rebooting the host after destruction, delaying execution before the wipe begins, and overwriting or deleting its own executable to hinder recovery and analysis.
AcidPour has been described as particularly relevant to Linux-based network equipment, storage appliances, embedded devices, IoT systems, and potentially OT- or ICS-adjacent Linux x86 systems. Its tradecraft and destructive logic make it suitable for disruptive operations intended to deny service and prolong restoration rather than for espionage or financial extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ELECTRUM ... специализируется на OT-impact - ей атрибутируется применение вайпера AcidPour в 2024 году.
SentinelLABS has discovered a novel malware variant of AcidRain... The new malware, which we call AcidPour, expands upon AcidRain’s capabilities and destructive potential to now include Linux Unsorted Block Image (UBI) and Device Mapper (DM) logic, better targeting RAID arrays and large storage devices.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."
If it is a regular file (“DT_REG”) or a symbolic link (“DT_LNK”), the file is wiped. If it is a directory (“DT_DIR”), the recursive wipe function is called with the newly discovered directory as its argument, thus traversing all directories within each directory, starting at the provided directory.
In two recent major geopolitical conflicts, in Ukraine and in Israel, wipers - malware used to destroy access to files and commonly used to halt telecom operations - were used to destroy digital infrastructure.
The references include multiple wiper campaigns and destructive malware operations such as NotPetya, SwiftSlicer, AcidRain, AcidPour, and DynoWiper associated with Sandworm/APT44.
IoT wipers often rewrite important parts of the firmware of an IoT device, rendering that device useless, so they are also known as 'brickers'.
SentinelLABS has discovered a novel malware variant of AcidRain... The new malware, which we call AcidPour, expands upon AcidRain’s capabilities and destructive potential to now include Linux Unsorted Block Image (UBI) and Device Mapper (DM) logic, better targeting RAID arrays and large storage devices.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Wiper attributed in the article to ELECTRUM/Sandworm activity for OT-impact operations in 2024.
Linux-based wiper malware closely resembling AcidRain, with added capabilities including self-overwrite, configurable delay before wiping, recursive wiping of /boot, expanded device targeting, and reboot after destruction. The report assesses with medium confidence that it likely uses AcidRain’s source code as a basis.
Embedded-device wiper assessed as a variant of AcidRain and observed in Ukraine.
A destructive malware/wiper referenced in the analytic story context for Linux init daemon script deletion and data destruction activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.