AcidRain

S1125

Malware.View on attack.mitre.org

About this malware

AcidRain is an ELF binary targeting modems and routers using MIPS architecture. AcidRain is associated with the ViaSat KA-SAT communication outage that took place during the initial phases of the 2022 full-scale invasion of Ukraine. Analysis indicates overlap with another network device-targeting malware, VPNFilter, associated with Sandworm Team. US and European government sources linked AcidRain to Russian government entities, while Ukrainian government sources linked AcidRain specifically to Sandworm Team.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1083
File and Directory Discovery

AcidRain identifies specific files and directories in the Linux operating system associated with storage devices.

T1485
Data Destruction

AcidRain performs an in-depth wipe of the target filesystem and various attached storage devices through either a data overwrite or calling various IOCTLS to erase it.

T1529
System Shutdown/Reboot

AcidRain reboots the target system once the various wiping processes are complete.

T1561.001
Disk Content Wipe

AcidRain iterates over device file identifiers on the target, opens the device file, and either overwrites the file or calls various IOCTLS commands to erase it.

Groups that use it1

Campaigns0

None recorded.

References3

  1. AcidRain JAGS 2022 Open source
    Juan Andres Guerrero-Saade and Max van Amerongen, SentinelOne. (2022, March 31). AcidRain | A Modem Wiper Rains Down on Europe. Retrieved March 25, 2024.
  2. AcidRain State Department 2022 Open source
    Antony J. Blinken, US Department of State. (2022, May 10). Attribution of Russia’s Malicious Cyber Activity Against Ukraine. Retrieved March 25, 2024.
  3. Vincens AcidPour 2024 Open source
    A.J. Vincens, CyberScoop. (2024, March 18). Researchers spot updated version of malware that hit Viasat. Retrieved March 25, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.