Viasat KA-SAT Satellite Modem Wiper Sabotage (AcidRain)
Key Facts
- Legal Status: INVESTIGATION in Federal Bureau of Investigation & European Union Attribution.
- Primary Target Sector: Telecommunications & Defense.
- Documented Financial Loss: $75.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Misconfigured Fortinet VPN appliance within the ground management segment of Viasat KA-SAT satellite network, exploited by Russian GRU actors to gain management access to Skylogic telemetry servers.
Operational & Financial Fallout
Brickable firmware wiping of tens of thousands of KA-SAT satellite broadband consumer terminals (SurfBeam) across Ukraine and Central Europe on the morning of the Russian invasion of Ukraine, blinding Ukrainian military command-and-control communications and knocking offline 5,800 wind turbines in Germany.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Misconfigured Fortinet VPN appliance within the ground management segment of Viasat KA-SAT satellite network, exploited by Russian GRU actors to gain management access to Skylogic telemetry servers.
Adversary Kill Chain Flow
5 Documented PhasesThreat actors leveraged compromised administrative credentials on an external FortiGate VPN gateway to enter the Skylogic management network.
Attackers pivoted from the VPN network into internal management subnets running satellite terminal provisioning servers.
A specialized ELF MIPS binary (AcidRain) was packaged as a routine maintenance update and pushed to tens of thousands of remote satellite modems.
AcidRain iterated through flash memory devices (/dev/mtd*, /dev/sda*, /dev/mmcblk*), overwriting them with recursive zeros and rebooting modems into unrecoverable states.
Terminals lost modem bootstrap capability, severing satellite communications across civil, military, and commercial energy sectors.
Brickable firmware wiping of tens of thousands of KA-SAT satellite broadband consumer terminals (SurfBeam) across Ukraine and Central Europe on the morning of the Russian invasion of Ukraine, blinding Ukrainian military command-and-control communications and knocking offline 5,800 wind turbines in Germany.
Procedural & Incident Timeline
At the onset of the Russian invasion of Ukraine, AcidRain wipes satellite modems, severing military communications.
CISA issues advisory AA22-110A on Russian state-sponsored cyber operations targeting communications.
United States, United Kingdom, and European Union officially declare Russia responsible for the Viasat attack.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1190 | Exploit Public-Facing Application Initial Access | "Operatives achieved initial access via an unpatched Fortinet VPN appliance, pivoting into the trusted satellite management segment without secondary authentication." | Viasat Incident Report on KA-SAT Network Cyber Attack | reviewed |
| T1485 | Data Destruction Impact | "The AcidRain malware iterated across flash memory partitions (/dev/mtd*), overwriting them with recursive byte patterns and resetting modems into an unbootable bricked state." | SentinelLabs AcidRain Analysis | reviewed |