logo

AcidPour Malware Wiping Out Linux Data Storage Devices

ID: 05894afc-992c-52fe-bc19-6982633c8c78

STIX ID: report--05894afc-992c-52fe-bc19-6982633c8c78

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2024-07-29

Date Updated: 2026-04-13

Author: Kaaviya

...
...

SentinelOne discovered AcidPour, a sophisticated Linux wiper active in March 2024 that irreversibly destroys data by overwriting files and raw storage (SCSI, MTD, MMC, DMSETUP, UBI and more), erases critical directories including /boot, and uses two destruction methods (repeated 256KB block overwrites and IOCTL-driven memory manipulation). The analysis highlights evasion techniques—overwriting its executable, process isolation, descriptor redirection, and time-based delays—and notes the malware's focus on rendering compromised systems inoperable rather than exfiltrating data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.