On 24 February 2022, the morning Russia invaded Ukraine, modems on the Viasat KA-SAT network stopped working. Researchers at SentinelOne subsequently identified the cause as AcidRain, a wiper built for MIPS-based modems and routers that brute-forces device file names and destroys everything it can reach.
Viasat confirmed the wiper’s use. Analysis found code overlap with a plugin from VPNFilter, malware attributed to the Sandworm cluster.
The Wind Turbines Are The Case
Spillover from the attack left roughly 5,800 Enercon wind turbines in Germany unable to communicate for remote monitoring and control.
Germany was not the target. The turbines were not the target. They were on the same satellite network, and the wiper did not distinguish. This is the cleanest instance the corpus holds of a weapon whose effective radius is set by shared infrastructure rather than by intent — the property the desk describes at 26-0704 for shared airport IT and at 24-1121 for a supply-chain platform, arriving here through a satellite footprint.
Availability Was The Whole Harm
Nothing was stolen. No record was published, no individual was notified, and no breach regime anywhere counted this. A wiper does not exfiltrate; it removes the ability to operate.
The corpus files availability harm separately from data harm for exactly this reason, at 24-1231. A turbine that cannot be monitored remotely is not a privacy incident and it is not nothing, and the disclosure apparatus this database spends most of its time reading has no field for it.
Replacement, Not Recovery
The wiper destroyed firmware on the devices themselves. Restoring service meant getting working modems to the places the broken ones were, which is a logistics problem rather than an IT one, and it does not go faster because the incident is urgent.
The corpus records the same distinction at 23-0518, where Barracuda concluded that patching an appliance was insufficient and told customers to replace the hardware. Once the damage is to the device, the response leaves the network and enters a van.
Built on SentinelOne’s AcidRain analysis and on contemporaneous reporting of Viasat’s confirmation. The 24 February 2022 timing, the character of the malware, the ~5,800 Enercon turbines losing remote monitoring, and the VPNFilter code overlap are as reported. Attribution to the Sandworm cluster is reported by researchers on a code-overlap basis and is carried here as attribution, not as established fact — this desk does not present attribution as proven. No count of affected modems is asserted: figures circulated at the time varied and no authoritative total was published. Graded high on the event and the spillover, which are well established. No indicators are reproduced. Corrections: corrections@forensicpost.com.