Desk live·
ForensicPost
Nation-state/Infrastructure/File 22-0224

A Wiper Aimed at Ukraine Took 5,800 German Wind Turbines off Monitoring

AcidRain bricked Viasat KA-SAT modems on the morning of the invasion. The modems it reached included thousands in countries nobody was invading — the clearest case in this corpus of blast radius crossing a border the attacker did not draw.

Constructed geometry · not a chart of case data
JurisdictionUkrainethe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetViasat KA-SAT users
ActorSandworm
S. Rosler12 min readConfidence: high3 sources reviewed

On 24 February 2022, the morning Russia invaded Ukraine, modems on the Viasat KA-SAT network stopped working. Researchers at SentinelOne subsequently identified the cause as AcidRain, a wiper built for MIPS-based modems and routers that brute-forces device file names and destroys everything it can reach.

Viasat confirmed the wiper’s use. Analysis found code overlap with a plugin from VPNFilter, malware attributed to the Sandworm cluster.

The Wind Turbines Are The Case

Spillover from the attack left roughly 5,800 Enercon wind turbines in Germany unable to communicate for remote monitoring and control.

Germany was not the target. The turbines were not the target. They were on the same satellite network, and the wiper did not distinguish. This is the cleanest instance the corpus holds of a weapon whose effective radius is set by shared infrastructure rather than by intent — the property the desk describes at 26-0704 for shared airport IT and at 24-1121 for a supply-chain platform, arriving here through a satellite footprint.

Availability Was The Whole Harm

Nothing was stolen. No record was published, no individual was notified, and no breach regime anywhere counted this. A wiper does not exfiltrate; it removes the ability to operate.

The corpus files availability harm separately from data harm for exactly this reason, at 24-1231. A turbine that cannot be monitored remotely is not a privacy incident and it is not nothing, and the disclosure apparatus this database spends most of its time reading has no field for it.

Replacement, Not Recovery

The wiper destroyed firmware on the devices themselves. Restoring service meant getting working modems to the places the broken ones were, which is a logistics problem rather than an IT one, and it does not go faster because the incident is urgent.

The corpus records the same distinction at 23-0518, where Barracuda concluded that patching an appliance was insufficient and told customers to replace the hardware. Once the damage is to the device, the response leaves the network and enters a van.

How we reported this

Built on SentinelOne’s AcidRain analysis and on contemporaneous reporting of Viasat’s confirmation. The 24 February 2022 timing, the character of the malware, the ~5,800 Enercon turbines losing remote monitoring, and the VPNFilter code overlap are as reported. Attribution to the Sandworm cluster is reported by researchers on a code-overlap basis and is carried here as attribution, not as established fact — this desk does not present attribution as proven. No count of affected modems is asserted: figures circulated at the time varied and no authoritative total was published. Graded high on the event and the spillover, which are well established. No indicators are reproduced. Corrections: corrections@forensicpost.com.

Sources
  1. AcidRain | A Modem Wiper Rains Down on EuropeSentinelOne
  2. Viasat confirms satellite modems were wiped with AcidRain malwareBleepingComputer
  3. Viasat confirms report of wiper malware used in Ukraine cyberattackThe Record
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary