ATT&CKReferencesSentinelOne AcidPour 2024

SentinelOne AcidPour 2024

Juan Andrés Guerrero-Saade & Tom Hegel. (2024, March 21). AcidPour | New Embedded Wiper Variant of AcidRain Appears in Ukraine. Retrieved November 25, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1070.004
File Deletion
MalwareAcidPour

AcidPour includes a self-delete function where the malware deletes itself from disk after execution and program load into memory.

T1082
System Information Discovery
MalwareAcidPour

AcidPour can identify various system locations and mapped devices on Linux systems as a precursor to wiping activity.

T1083
File and Directory Discovery
MalwareAcidPour

AcidPour can identify specific files and directories within the Linux operating system corresponding with storage devices for follow-on wiping activity, similar to AcidRain.

T1120
Peripheral Device Discovery
MalwareAcidPour

AcidPour includes functionality to identify MMC and SD cards connected to the victim device.

T1485
Data Destruction
MalwareAcidPour

AcidPour can perform an in-depth wipe of victim filesystems and attached storage devices through either data overwrite or calling various IOCTLS to erase them, similar to AcidRain.

T1529
System Shutdown/Reboot
MalwareAcidPour

AcidPour includes functionality to reboot the victim system following wiping actions, similar to AcidRain.

T1561.001
Disk Content Wipe
MalwareAcidPour

AcidPour includes functionality to overwrite victim devices with the content of a buffer to wipe disk content.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.