Netskope Threat Labs

AcidRain

ATP Sandbox Adv. Heuristics

AcidRain is an ELF wiper targeting modems and routers on MIPS architecture, associated with the ViaSat KA-SAT communication outage at the start of the 2022 invasion of Ukraine. Researchers noted overlap with the VPNFilter network device malware, and US and European government sources linked it to Russian government entities.

First seen
May 2022
Last seen
September 2026
Acidrain

4 techniques across 2 tactics.

TA0007 Discovery

  • T1083File and Directory Discovery

TA0040 Impact

Alert Name
Linux.Trojan.Acidrain
Linux.Trojan.AcidRain