Researchers detailed multiple destructive malware families used against Ukrainian targets, linking AcidRain, AcidPour, and CaddyWiper to attacks designed to disable systems and erase data during Russia’s war against Ukraine. Trellix reported that AcidRain was used to disrupt Viasat KA-SAT satellite modems, while the newer Linux wiper AcidPour adds features including self-overwrite, a configurable execution delay, and recursive wiping of /boot. The firm assessed with medium confidence that AcidPour was derived from or closely modeled on AcidRain, and said the activity broadly aligns with a pro-Russian actor, though it did not attribute the attacks to a specific group.
On the Windows side, Morphisec said CaddyWiper struck several dozen systems in a limited number of Ukrainian organizations and was likely deployed through Group Policy Object, indicating prior compromise of an Active Directory server. The malware was built to destroy user files and attached drives, and when executed with administrative privileges it also corrupts physical drive partition information, leaving the operating system unusable. Researchers noted that CaddyWiper selectively avoids damaging non-domain-controller systems and dynamically resolves Windows APIs through the PEB to hinder detection, placing it among a broader run of wipers including WhisperGate, HermeticWiper, and IsaacWiper.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Trellix published an analysis comparing the Linux wipers AcidRain and AcidPour, concluding with medium confidence that AcidPour is based on AcidRain's source code or closely replicates it. The report also notes broader use of wipers in the conflicts in Ukraine and Israel and attributes the related attacks at a broad level to a pro-Russian actor.
A sample of the Linux wiper AcidPour was first submitted to VirusTotal. Trellix identifies the sample as SHA-256 6a8824048417abe156a16455b8e29170f8347312894fde2aabe644c4995d7728.
A sample of the Linux wiper AcidRain was first submitted to VirusTotal. Trellix identifies the sample as SHA-256 9b4dfaca873961174ba935fddaf696145afe7bbf5734509f95feb54f3584fd9a.
CaddyWiper was first detected attacking Ukrainian infrastructure and was observed on several dozen systems across a limited number of organizations. The malware was reportedly deployed via Group Policy Object, implying prior compromise of an Active Directory server.
AcidRain was used to brick Viasat KA-SAT satellite modems, disrupting satellite communications at the start of Russia's invasion of Ukraine. Trellix broadly attributes the attack activity to a pro-Russian actor targeting Ukrainian entities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.