Researchers: an allegedly Russia-tied wiper malware, AcidRain, which shares similarities with the malware VPNFilter, was behind the attack on Viasat in February
AcidRain is the seventh wiper associated with the Russian invasion of Ukraine — Viasat—the high-speed-satellite-broadband …
Context & Ripple Effects
The Viasat outage was already under investigation by NSA and other agencies after it disabled satellite internet service in Europe as Russia invaded Ukraine. It also extended beyond Ukraine: the earlier coverage reported 27,000 affected European users, with thousands still offline weeks later.
Researchers now add a malware identification to that incident, linking AcidRain to the Viasat attack and noting similarities to the earlier Russia-tied VPNFilter malware. That moves the episode from an unexplained service disruption toward a more legible destructive-malware campaign.
First-order effects
- Viasat and affected KA-SAT customers gain a specific suspected wiper malware to investigate, while the researchers' findings strengthen the technical connection between the February disruption and AcidRain.
- The reported VPNFilter similarities give defenders a concrete prior malware family to compare against when examining compromised satellite-network equipment.
Second-order effects
- Satellite operators and their customers face added pressure to treat broadband infrastructure as a destructive-attack target, rather than solely a connectivity dependency; later coverage says the incident prompted countries and the industry to rethink satellite cybersecurity.
- Government investigators examining the Viasat disruption can use the AcidRain attribution and its reported code similarities to focus cross-agency analysis on a potentially related Russian-linked malware lineage.
Third-order effects
- The incident points to satellite connectivity becoming part of the cyberwar attack surface: disruptions aimed at one network can impose costs on civilian users across Europe as well as actors in the conflict zone.
- If destructive malware continues to be paired with attacks on communications infrastructure, satellite providers' security posture will increasingly be judged by resilience and recovery for distributed customers, not only by network availability.
The trend: Cyber conflict around Ukraine is expanding from espionage and information operations to destructive attacks on shared communications infrastructure with cross-border civilian fallout.