/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers: an allegedly Russia-tied wiper malware, AcidRain, which shares similarities with the malware VPNFilter, was behind the attack on Viasat in February

AcidRain is the seventh wiper associated with the Russian invasion of Ukraine  —  Viasat—the high-speed-satellite-broadband …

Ars Technica Dan Goodin

Context & Ripple Effects

The Viasat outage was already under investigation by NSA and other agencies after it disabled satellite internet service in Europe as Russia invaded Ukraine. It also extended beyond Ukraine: the earlier coverage reported 27,000 affected European users, with thousands still offline weeks later.

Researchers now add a malware identification to that incident, linking AcidRain to the Viasat attack and noting similarities to the earlier Russia-tied VPNFilter malware. That moves the episode from an unexplained service disruption toward a more legible destructive-malware campaign.

First-order effects

  • Viasat and affected KA-SAT customers gain a specific suspected wiper malware to investigate, while the researchers' findings strengthen the technical connection between the February disruption and AcidRain.
  • The reported VPNFilter similarities give defenders a concrete prior malware family to compare against when examining compromised satellite-network equipment.

Second-order effects

  • Satellite operators and their customers face added pressure to treat broadband infrastructure as a destructive-attack target, rather than solely a connectivity dependency; later coverage says the incident prompted countries and the industry to rethink satellite cybersecurity.
  • Government investigators examining the Viasat disruption can use the AcidRain attribution and its reported code similarities to focus cross-agency analysis on a potentially related Russian-linked malware lineage.

Third-order effects

  • The incident points to satellite connectivity becoming part of the cyberwar attack surface: disruptions aimed at one network can impose costs on civilian users across Europe as well as actors in the conflict zone.
  • If destructive malware continues to be paired with attacks on communications infrastructure, satellite providers' security posture will increasingly be judged by resilience and recovery for distributed customers, not only by network availability.

The trend: Cyber conflict around Ukraine is expanding from espionage and information operations to destructive attacks on shared communications infrastructure with cross-border civilian fallout.

Discussion

  • @780thc @780thc on x
    SentinelLabs researchers assess there are developmental similarities between AcidRain and a VPNFilter stage 3 destructive plugin | In 2018, the FBI and Department of Justice attributed the VPNFilter campaign to the Russian government. https://www.sentinelone.com/ ... @LabsSentine…
  • @sentinelone @sentinelone on x
    👉In @arstechnica: AcidRain is the 7th distinct piece of wiper #malware associated w/ Russia's ongoing invasion of Ukraine. @juanandres_gs & @maxpl0it said its an executable file for MIPS, the hardware architecture for the modems used by Viasat customers. https://arstechnica.com/.…
  • @dangoodin001 Dan Goodin on x
    Viasat confirms that wiper with possible ties to Russia used in modem hack https://arstechnica.com/...