{
  "id": "case-viasat-acidrain",
  "slug": "viasat-ka-sat-satellite-wiper-acidrain",
  "title": "Viasat KA-SAT Satellite Modem Wiper Sabotage (AcidRain)",
  "summary": "Russian state-sponsored operators exploited an unpatched Fortinet VPN gateway to access Viasat satellite network management segments, broadcasting malicious AcidRain wiper firmware that permanently bricked tens of thousands of satellite terminals across Ukraine and Europe.",
  "case_number": "CISA Alert AA22-110A",
  "court": "Federal Bureau of Investigation & European Union Attribution",
  "district": "International",
  "country": "International",
  "opened_at": "2022-02-24",
  "status": "investigation",
  "victim_sector": "Telecommunications & Defense",
  "victim_country": "Ukraine",
  "loss_amount_usd": 75000000,
  "loss_amount_note": "Permanent hardware replacement of tens of thousands of consumer and military modems.",
  "first_seen_at": "2022-02-24T04:00:00Z",
  "last_updated_at": "2026-10-02T10:00:00Z",
  "actor_slug": "sandworm",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1190",
      "evidence_excerpt": "Operatives achieved initial access via an unpatched Fortinet VPN appliance, pivoting into the trusted satellite management segment without secondary authentication.",
      "evidence_locator": "Viasat Incident Report on KA-SAT Network Cyber Attack",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Viasat Corporate Incident Statement",
      "source_url": "https://news.viasat.com",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1485",
      "evidence_excerpt": "The AcidRain malware iterated across flash memory partitions (/dev/mtd*), overwriting them with recursive byte patterns and resetting modems into an unbootable bricked state.",
      "evidence_locator": "SentinelLabs AcidRain Analysis",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "SentinelLabs Threat Research",
      "source_url": "https://www.sentinelone.com",
      "technique_name": "Data Destruction",
      "tactic": "Impact"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2022-02-24",
      "description": "At the onset of the Russian invasion of Ukraine, AcidRain wipes satellite modems, severing military communications."
    },
    {
      "event_type": "advisory",
      "event_date": "2022-04-20",
      "description": "CISA issues advisory AA22-110A on Russian state-sponsored cyber operations targeting communications."
    },
    {
      "event_type": "declaration",
      "event_date": "2022-05-10",
      "description": "United States, United Kingdom, and European Union officially declare Russia responsible for the Viasat attack."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Misconfigured Fortinet VPN appliance within the ground management segment of Viasat KA-SAT satellite network, exploited by Russian GRU actors to gain management access to Skylogic telemetry servers.",
    "blast_radius": "Brickable firmware wiping of tens of thousands of KA-SAT satellite broadband consumer terminals (SurfBeam) across Ukraine and Central Europe on the morning of the Russian invasion of Ukraine, blinding Ukrainian military command-and-control communications and knocking offline 5,800 wind turbines in Germany.",
    "kill_chain": [
      {
        "phase": "Perimeter Ingress",
        "title": "Edge VPN Gateway Compromise",
        "description": "Threat actors leveraged compromised administrative credentials on an external FortiGate VPN gateway to enter the Skylogic management network.",
        "technical_artifacts": [
          "Compromised VPN account",
          "FortiGate ingress logs"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Lateral Traversal",
        "title": "Ground Controller Network Pivoting",
        "description": "Attackers pivoted from the VPN network into internal management subnets running satellite terminal provisioning servers.",
        "technical_artifacts": [
          "SSH pivot",
          "Internal telemetry subnet routing"
        ],
        "mitre_technique_id": "T1021.004"
      },
      {
        "phase": "Payload Delivery",
        "title": "AcidRain Wiper Deployment",
        "description": "A specialized ELF MIPS binary (AcidRain) was packaged as a routine maintenance update and pushed to tens of thousands of remote satellite modems.",
        "technical_artifacts": [
          "AcidRain ELF MIPS binary",
          "OTA terminal update package"
        ],
        "mitre_technique_id": "T1542"
      },
      {
        "phase": "Device Destruction",
        "title": "Flash Memory Overwrite & Terminal Brick",
        "description": "AcidRain iterated through flash memory devices (/dev/mtd*, /dev/sda*, /dev/mmcblk*), overwriting them with recursive zeros and rebooting modems into unrecoverable states.",
        "technical_artifacts": [
          "/dev/mtd block overwrite",
          "Recursive zeroing routine",
          "Reboot command"
        ],
        "mitre_technique_id": "T1485"
      },
      {
        "phase": "Operational Disruption",
        "title": "Satellite Link Disruption",
        "description": "Terminals lost modem bootstrap capability, severing satellite communications across civil, military, and commercial energy sectors.",
        "technical_artifacts": [
          "Satellite carrier signal loss",
          "Telemetry disconnect"
        ],
        "mitre_technique_id": "T1489"
      }
    ],
    "defensive_takeaways": [
      "Require hardware token MFA and IP whitelisting for all administrative access to telecommunications management backplanes.",
      "Implement cryptographic signature verification in hardware bootloaders before executing any remote firmware updates.",
      "Isolate device management networks from corporate and external VPN boundaries.",
      "Deploy canary devices and automated rate limits on mass fleet firmware deployments."
    ]
  }
}