CASE DOSSIER investigation

Viasat KA-SAT Satellite Modem Wiper Sabotage (AcidRain)

Docket: CISA Alert AA22-110A Court: Federal Bureau of Investigation & European Union Attribution Opened: 2022-02-24 Sector: Telecommunications & Defense

Key Facts

Status
INVESTIGATION
Legal disposition
Loss Amount
$75.0 million
Permanent hardware replacement of tens of thousands of consumer and military modems.
Techniques
2
Verified mappings
Defendants
0
Named in charges
  • Legal Status: INVESTIGATION in Federal Bureau of Investigation & European Union Attribution.
  • Primary Target Sector: Telecommunications & Defense.
  • Documented Financial Loss: $75.0 million.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Russian state-sponsored operators exploited an unpatched Fortinet VPN gateway to access Viasat satellite network management segments, broadcasting malicious AcidRain wiper firmware that permanently bricked tens of thousands of satellite terminals across Ukraine and Europe.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Misconfigured Fortinet VPN appliance within the ground management segment of Viasat KA-SAT satellite network, exploited by Russian GRU actors to gain management access to Skylogic telemetry servers.

Operational & Financial Fallout

Brickable firmware wiping of tens of thousands of KA-SAT satellite broadband consumer terminals (SurfBeam) across Ukraine and Central Europe on the morning of the Russian invasion of Ukraine, blinding Ukrainian military command-and-control communications and knocking offline 5,800 wind turbines in Germany.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: INVESTIGATION
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Misconfigured Fortinet VPN appliance within the ground management segment of Viasat KA-SAT satellite network, exploited by Russian GRU actors to gain management access to Skylogic telemetry servers.

Adversary Kill Chain Flow

5 Documented Phases
1
Perimeter Ingress Edge VPN Gateway Compromise
MITRE ATT&CK T1078 →

Threat actors leveraged compromised administrative credentials on an external FortiGate VPN gateway to enter the Skylogic management network.

Artifacts & Tooling: Compromised VPN account FortiGate ingress logs
2
Lateral Traversal Ground Controller Network Pivoting
MITRE ATT&CK T1021.004 →

Attackers pivoted from the VPN network into internal management subnets running satellite terminal provisioning servers.

Artifacts & Tooling: SSH pivot Internal telemetry subnet routing
3
Payload Delivery AcidRain Wiper Deployment
MITRE ATT&CK T1542 →

A specialized ELF MIPS binary (AcidRain) was packaged as a routine maintenance update and pushed to tens of thousands of remote satellite modems.

Artifacts & Tooling: AcidRain ELF MIPS binary OTA terminal update package
4
Device Destruction Flash Memory Overwrite & Terminal Brick
MITRE ATT&CK T1485 →

AcidRain iterated through flash memory devices (/dev/mtd*, /dev/sda*, /dev/mmcblk*), overwriting them with recursive zeros and rebooting modems into unrecoverable states.

Artifacts & Tooling: /dev/mtd block overwrite Recursive zeroing routine Reboot command
5
Operational Disruption Satellite Link Disruption
MITRE ATT&CK T1489 →

Terminals lost modem bootstrap capability, severing satellite communications across civil, military, and commercial energy sectors.

Artifacts & Tooling: Satellite carrier signal loss Telemetry disconnect
Real-World Blast Radius & Operational Fallout

Brickable firmware wiping of tens of thousands of KA-SAT satellite broadband consumer terminals (SurfBeam) across Ukraine and Central Europe on the morning of the Russian invasion of Ukraine, blinding Ukrainian military command-and-control communications and knocking offline 5,800 wind turbines in Germany.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Require hardware token MFA and IP whitelisting for all administrative access to telecommunications management backplanes.
✓ Implement cryptographic signature verification in hardware bootloaders before executing any remote firmware updates.
✓ Isolate device management networks from corporate and external VPN boundaries.
✓ Deploy canary devices and automated rate limits on mass fleet firmware deployments.

Procedural & Incident Timeline

2022-02-24 incident

At the onset of the Russian invasion of Ukraine, AcidRain wipes satellite modems, severing military communications.

2022-04-20 advisory

CISA issues advisory AA22-110A on Russian state-sponsored cyber operations targeting communications.

2022-05-10 declaration

United States, United Kingdom, and European Union officially declare Russia responsible for the Viasat attack.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1190 Exploit Public-Facing Application
Initial Access
"Operatives achieved initial access via an unpatched Fortinet VPN appliance, pivoting into the trusted satellite management segment without secondary authentication." Viasat Incident Report on KA-SAT Network Cyber Attack reviewed
T1485 Data Destruction
Impact
"The AcidRain malware iterated across flash memory partitions (/dev/mtd*), overwriting them with recursive byte patterns and resetting modems into an unbootable bricked state." SentinelLabs AcidRain Analysis reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Viasat KA-SAT Satellite Modem Wiper Sabotage (AcidRain), No. CISA Alert AA22-110A (Federal Bureau of Investigation & European Union Attribution 2022), https://cybercaselibrary.com/cases/viasat-ka-sat-satellite-wiper-acidrain/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/viasat-ka-sat-satellite-wiper-acidrain" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>