TF-MAL-elf.acidrain
📛 Threat Title
Malware family: AcidRain
Description
ThreatFox malware family `elf.acidrain`. Printable name: AcidRain.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.acidrain
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.acidrain
IOC database
- Type
- domain
- Value
elf.acidrain- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.acidrain
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.acidrain
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
AcidRain is an ELF binary targeting modems and routers using MIPS architecture. [1] AcidRain is associated with the ViaSat KA-SAT communication outage that took place during the initial phases of the 2022 full-scale invasion of Ukraine. Analysis indicates overlap with another network device-targeting malware , VPNFilter, associated with Sandworm Team. [1] US and European government sources ...
-
web:cyberscoop.com
Geopolitics Researchers spot updated version of malware that hit Viasat Russian hackers have added new capabilities to the malware used to disable satellite modems at the outset of the invasion of Ukraine.
-
web:eurepoc.eu
Major Cyber Incident: KA-SAT 9A Other incident names: Viasat, AcidRain 4 October 2023 Kerttunen, Mika; Schuck, Kim; Hemmelskamp, Jonas EN About KA-SAT 9A The GEO satellite broadband services of the US communications company Viasat (KA-SAT 9A network) were disrupted in parts of Europe when the Russian military offensive against Ukraine commenced in February 2022. While the attack caused ...
-
web:malpedia.caad.fkie.fraunhofer.de
A MIPS ELF binary with wiper functionality used against Viasat KA-SAT modems.
-
web:www.huntress.com
AcidRain is a data-wiping malware that overwrites critical firmware data in modems and routers, rendering them inoperable. It typically propagates via compromised firmware update mechanisms, exploiting systemic weaknesses to achieve its destructive ends.
-
web:www.researchgate.net
This paper also entails the attack's execution, and how the AcidRain malware was deployed, resulting in widespread disruption of internet access in Ukraine and several parts of Europe.
-
web:www.sentinelone.com
AcidRain is the 7th wiper malware associated with the Russian invasion of Ukraine. Update: In a statement disseminated to journalists, Viasat confirmed the use of the AcidRain wiper in the February 24th attack against their modems.
-
web:www.splunk.com
The Splunk Threat Research Team shares the details on the new malicious payload named AcidRain , designed to wipe modem or router devices (CPEs).
-
web:www.trellix.com
Pouring Acid Rain By Trellix · April 30, 2024 This blog was written by Max Kersten In two recent major geopolitical conflicts, in Ukraine and in Israel, wipers - malware used to destroy access to files and commonly used to halt telecom operations - were used to destroy digital infrastructure.
-
web:www.virusbulletin.com
Both reports agreed that novel malware , named 'AcidRain' by SentinelOne, was responsible for disrupting some KA-SAT customer modems [10] [11] [12]. However, an overview of events indicates that the execution of AcidRain was not the only disruptive event against the KA-SAT network on 24 February 2022.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.