AcidPour | New Embedded Wiper Variant of AcidRain Appears in Ukraine [Thursday, March 21, 2024]

SentinelLabs discovered a new Linux wiper named AcidPour, a variant of AcidRain used in attacks against Ukraine. AcidPour expands on AcidRain's cap...
AcidPour | New Embedded Wiper Variant of AcidRain Appears in Ukraine [Thursday, March 21, 2024]
AcidPour | New Embedded Wiper Variant of AcidRain Appears in Ukraine

AcidPour | New Embedded Wiper Variant of AcidRain Appears in Ukraine

Description :
SentinelLabs discovered a new Linux wiper named AcidPour, a variant of AcidRain used in attacks against Ukraine. AcidPour expands on AcidRain's capabilities to better target Linux devices like networking gear, IoT, RAIDs, and possibly ICS. Its discovery coincides with telecoms disruptions in Ukraine claimed by a GRU hacktivist persona. Technical analysis confirms similarities between AcidPour and AcidRain, linking it to clusters attributed to Russian intelligence.

Published Created Modified
2024-03-21 19:58:33 2024-03-21 19:58:33 2024-03-21 20:10:55

Tags

Indicators

IPv4s : Domains : Malwares :
  • AcidPour
  • AcidRain
Hashes :
  • 6a8824048417abe156a16455b8e29170f8347312894fde2aabe644c4995d7728
Intrusion set :
  • Sandworm
Location :
  • Ukraine
MITRE ATT&CK Techniques : Other observables :
  • Telecommunications

External References

You can download the txt file containing the indicators by clicking on the button below:

About the author
Julien B.

Securitricks

Up-to-Date Cybersecurity Insights & Malware Reports

Securitricks

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to Securitricks.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.