logo

Russian APT Releases More Deadly Variant of AcidRain Wiper Malware

ID: 1b998c76-5232-5d57-8316-e6e067defe54

STIX ID: report--1b998c76-5232-5d57-8316-e6e067defe54

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2024-03-22

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

SentinelOne researchers identified AcidPour, an X86-compiled wiper linked to the same Russian Sandworm actor behind AcidRain; AcidPour broadens destructive reach (including UBI, Device Mapper, IOCTL-based wiping) to SAN/NAS/RAID, IoT, networking and some ICS devices and includes a self-delete capability. The sample shares reboot, recursive-wipe, and IOCTL wiping logic with AcidRain and VPNFilter and is attributed by Ukraine CERT to UAC-0165; researchers have not yet observed its use in the wild but warn of high destructive potential and recommend backups, network segmentation, and incident response readiness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.