ATT&CKReferencesAcidRain JAGS 2022

AcidRain JAGS 2022

Juan Andres Guerrero-Saade and Max van Amerongen, SentinelOne. (2022, March 31). AcidRain | A Modem Wiper Rains Down on Europe. Retrieved March 25, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1083
File and Directory Discovery
MalwareAcidRain

AcidRain identifies specific files and directories in the Linux operating system associated with storage devices.

T1485
Data Destruction
MalwareAcidRain

AcidRain performs an in-depth wipe of the target filesystem and various attached storage devices through either a data overwrite or calling various IOCTLS to erase it.

T1529
System Shutdown/Reboot
MalwareAcidRain

AcidRain reboots the target system once the various wiping processes are complete.

T1561.001
Disk Content Wipe
MalwareAcidRain

AcidRain iterates over device file identifiers on the target, opens the device file, and either overwrites the file or calls various IOCTLS commands to erase it.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.