AcidPour Malware Wiping Out Linux Data Storage Devices
ID: 05894afc-992c-52fe-bc19-6982633c8c78
STIX ID: report--05894afc-992c-52fe-bc19-6982633c8c78
Feed Name: Cyber Press
SentinelOne discovered AcidPour, a sophisticated Linux wiper active in March 2024 that irreversibly destroys data by overwriting files and raw storage (SCSI, MTD, MMC, DMSETUP, UBI and more), erases critical directories including /boot, and uses two destruction methods (repeated 256KB block overwrites and IOCTL-driven memory manipulation). The analysis highlights evasion techniques—overwriting its executable, process isolation, descriptor redirection, and time-based delays—and notes the malware's focus on rendering compromised systems inoperable rather than exfiltrating data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
