Viasat KA-SAT modem wiper (AcidRain), February 2022
What happened
About an hour before the Russian invasion of Ukraine, an intruder exploited a misconfiguration in a VPN appliance to reach the trusted management segment of the KA-SAT consumer broadband network, moved laterally to the segment used to manage and operate the network, and issued legitimate management commands to tens of thousands of SurfBeam2 subscriber modems at once. The commands installed and ran a destructive MIPS binary, later named AcidRain, which overwrote flash and block storage device files and left the modems unable to connect. Only the consumer partition of KA-SAT was affected; mobility and government users were not, and no effect on the spacecraft is reported. Collateral effects included the loss of the satellite remote-monitoring link for roughly 5,800 Enercon wind turbines in Germany. The EU and its Member States attributed the operation to the Russian Federation on 10 May 2022.
The attack reached the ground and user segments of a satellite broadband service; the spacecraft was not a target and no source reports any effect on it. Mapped accordingly: the technique edges describe ground-system compromise and destructive action on subscriber terminals, not on-orbit effects.
Attack vector
Misconfigured VPN appliance in the KA-SAT ground management segment, followed by lateral movement and mass issuance of authentic modem management commands (TR-069 path) that installed an unsigned destructive binary.
Operational impact
Tens of thousands of consumer terminals disconnected, including the majority of previously active modems in Ukraine and substantial numbers across Europe. Network largely stabilised within hours and fully within days; nearly 30,000 replacement modems shipped. Roughly 5,800 Enercon wind turbines in Germany lost satellite remote monitoring.
Affected segments
ground, user
Disclosed
2022-03-30
SPARTA techniques evidenced
Each row is a technique this record evidences, with the reasoning and the source that attests to it.
What relationship, confidence, and evidence mean on the rows below
- Relationship
What kind of link this is between the technique and the target.
Mitigates: the target actively prevents, detects, or recovers from the technique.
Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.
Triggers obligation: the technique occurring is what triggers the duty the target imposes.
Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.
- Confidence
How strongly the source supports this mapping, not how severe the technique is.
High: the source supports the mapping squarely.
Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.
Low: the source reaches the technique only in part.
- Evidence
How close to the source text the mapping was made.
Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.
Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.
Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.
SentinelOne documents AcidRain as a statically linked 32-bit MIPS ELF wiper that overwrites /dev/sd*, /dev/mtd*, /dev/mtdblock*, /dev/mmcblk* and /dev/loop* on modems and routers. Viasat independently reports that the management commands overwrote key data in flash memory on the modems. SPARTA's own bibliography cites the AcidRain analysis at this technique.
Viasat states the intruder exploited a VPN-appliance misconfiguration to gain remote access to the trusted management segment of the KA-SAT network and then moved laterally to the segment used to manage and operate the network. That is IA-0007's own subject matter, mission ground infrastructure including modem management, described by the operator of the network itself.
Viasat states the intruder used the compromised network access to execute legitimate, targeted management commands on a large number of residential modems simultaneously, so the traffic was indistinguishable from routine operations. SPARTA writes IA-0007.02 with the spacecraft as the commanded endpoint; here the commanded endpoint was the subscriber modem. The behaviour matches the technique and the endpoint does not, which is why this is derived rather than direct. Flagged for an editorial scope decision.
Viasat reports tens of thousands of terminals simultaneously disconnected, including the majority of previously active modems in Ukraine and substantial numbers across Europe, with the network largely stabilised within hours and fully within days. That is temporary impairment of use and access, which is IMP-0002's definition.
Affected terminals did not merely degrade; they lost network function entirely until factory reset or replacement, and Viasat shipped nearly 30,000 replacement modems. The hardware was not permanently damaged, which fits IMP-0003's 'usually without physical damage' qualifier. No source uses the word denial, so the distinction drawn here between IMP-0002 and IMP-0003 is editorial.
The compromised VPN appliance sat in ground infrastructure operated by Skylogic on Eutelsat's behalf rather than by Viasat, and that infrastructure was the stepping stone to Viasat's own customer terminals. The third-party relationship is drawn from the corporate facts of who operated KA-SAT in February 2022; no source frames it as an adversary infrastructure-acquisition step.
A destructive payload built for the target's MIPS modem architecture existed and was deployed. SentinelOne records a medium-confidence assessment of non-trivial developmental similarity to VPNFilter's dstr destructive plugin, which is evidence the payload was obtained or adapted from prior work rather than improvised at the point of use.
Santamarta's analysis of the SurfBeam2 shows the ut_app_execute_operation function permits installing and running arbitrary binaries with no signature verification, which is the staging-and-execution path the wiper required. No source describes the pre-positioning step itself, so the technique is derived from the mechanism rather than from a reported adversary action.
Considered and not mapped
These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.
No source identifies a known defect being exploited. The VPN appliance was misconfigured, and the modem accepted unsigned binaries by design. Neither is a known-vulnerability trigger.
Parent of
EX-0010.02, which is mapped. Mapping both adds no information and inflates the count.The technique's scope is legitimate direct-memory or load commands placing chosen bytes at chosen addresses. AcidRain wrote to device files through the modem's own operating system after achieving execution. Calling that a memory-load command describes the effect and misstates the mechanism.
IA-0009.02 is about obtaining first execution by riding a third party's trusted operational route into the mission. Viasat has first execution obtained by exploiting a misconfigured VPN appliance, so the operator relationship was the setting rather than the access path. That relationship is already recorded twice:
RD-0002.02carries the third-party ground infrastructure, andIA-0007.02carries the legitimate management commands the attacker issued once inside. This differs fromlandsat-7-terra-am-1-interference-2007-2008, where the commercial station operator's own route was the way in.No host–payload boundary was crossed. Nothing in the reporting involves a hosted payload.
LM-0007 requires movement achieved by reusing legitimate credentials or keys, and the mechanism is what the technique discriminates on rather than the fact of movement. Viasat states that the intruder moved laterally to the segment used to manage and operate the network but never says how, and no other held source supplies the mechanism. The refusal is evidentiary rather than a question of family scope:
apt28-satcom-provider-2022carries a live LM-0007 edge for a traversal between enterprise enclaves, so the family reaches ground boundaries when a source names the credential reuse.No source describes reconnaissance of the operator's institutional terrain.
The technique's scope is component sourcing, screening and life-cycle state for pre-delivery manipulation. Nothing of that kind is reported.
The technique's scope is the software factory: repositories, CI/CD, signing services. The attacker plainly knew the modem's architecture and management stack, but that is not the software supply chain this technique describes.
Sources
The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.
A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.
- KA-SAT Network cyber attack overviewOperator statement
Tier 2: First-party operator account of an incident on its own network: authoritative on the intrusion path and the scope of the outage, but an interested party on framing and on what it does not say.
- Strengthening Cybersecurity of SATCOM Network Providers and Customers (AA22-076A)Government reportsupporting
Tier 1: Joint advisory from two national government agencies, updated on 2022-05-10 to record US attribution to Russian state-sponsored actors.
- Russian cyber operations against Ukraine: Declaration by the High Representative on behalf of the European UnionRegulator statementsupporting
Tier 1: Formal attribution statement issued on behalf of the European Union and its Member States.
Tier 3: Personal research blog. Used only as supplementary corroboration of the modem-side mechanism, never as sole support for a claim.
Tier 2: Named vendor threat-intelligence analysis with the sample identified and the wipe behaviour enumerated; not peer-reviewed.
Every source SafeMode Space reproduces, and on what terms: sources and attribution.