Malware.View on attack.mitre.org
AcidRain is an ELF binary targeting modems and routers using MIPS architecture. AcidRain is associated with the ViaSat KA-SAT communication outage that took place during the initial phases of the 2022 full-scale invasion of Ukraine. Analysis indicates overlap with another network device-targeting malware, VPNFilter, associated with Sandworm Team. US and European government sources linked AcidRain to Russian government entities, while Ukrainian government sources linked AcidRain specifically to Sandworm Team.
| Technique | Procedure example |
|---|---|
| T1083 File and Directory Discovery |
AcidRain identifies specific files and directories in the Linux operating system associated with storage devices. |
| T1485 Data Destruction |
AcidRain performs an in-depth wipe of the target filesystem and various attached storage devices through either a data overwrite or calling various IOCTLS to erase it. |
| T1529 System Shutdown/Reboot |
AcidRain reboots the target system once the various wiping processes are complete. |
| T1561.001 Disk Content Wipe |
AcidRain iterates over device file identifiers on the target, opens the device file, and either overwrites the file or calls various IOCTLS commands to erase it. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.