Article Details

Scrape Timestamp (UTC): 2024-03-19 10:04:04.467

Source: https://thehackernews.com/2024/03/suspected-russian-data-wiping-acidpour.html

Original Article Text

Click to Toggle View

Suspected Russian Data-Wiping 'AcidPour' Malware Targeting Linux x86 Devices. A new variant of a data wiping malware called AcidRain has been detected in the wild that's specifically designed for targeting Linux x86 devices. The malware, dubbed AcidPour, is compiled for Linux x86 devices, SentinelOne's Juan Andres Guerrero-Saade said in a series of posts on X. "The new variant [...] is an ELF binary compiled for x86 (not MIPS) and while it refers to similar devices/strings, it's a largely different codebase," Guerrero-Saade noted. AcidRain first came to light in the early days of the Russo-Ukrainian war, with the malware deployed against KA-SAT modems from U.S. satellite company Viasat. An ELF binary compiled for MIPS architectures is capable of wiping the filesystem and different known storage device files by recursively iterating over common directories for most Linux distributions. The cyber attack was subsequently attributed to Russia by the Five Eyes nations, along with Ukraine and the European Union. AcidPour, as the new variant is called, is designed to erase content from RAID arrays and Unsorted Block Image (UBI) file systems through the addition of file paths like "/dev/dm-XX" and "/dev/ubiXX," respectively. It's currently not clear who the intended victims are, although SentinelOne said it notified Ukrainian agencies. The exact scale of the attacks is presently unknown. The discovery once again underscores the use of wiper malware to cripple targets, even as threat actors are diversifying their attack methods for maximum impact. Goodbye, Atlassian Server. Goodbye… Backups? Protect your data on Atlassian Cloud from disaster with Rewind's daily backups and on-demand restores. Take Action Fast with Censys Search for Security Teams Stay ahead of advanced threat actors with best-in-class threat intelligence from Censys Search.

Daily Brief Summary

MALWARE // AcidPour Malware Targets Linux Devices, Linked to Russian Activity

A new data wiping malware variant named AcidPour, targeting Linux x86 devices, has been identified by SentinelOne.

AcidPour is a progression from the previously discovered AcidRain malware, known to have been used against Viasat’s KA-SAT modems during the Russo-Ukrainian conflict.

This variant is distinctive for being an ELF binary compiled for x86 architecture, with significant codebase differences from its predecessor.

Five Eyes nations, along with Ukraine and the EU, attributed the earlier AcidRain attacks to Russia.

AcidPour aims to delete data from RAID arrays and UBI file systems by targeting specific file paths, indicating a shift in the threat vectors used by attackers.

The specific targets and the extent of the AcidPour malware's deployment are not yet clear; however, Ukrainian agencies have been alerted.

The emergence of AcidPour emphasizes the ongoing trend of using wiper malware to severely disrupt targets and escalate the severity of cyberattacks.