ADVERTISEMENT
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions
martedì, Giugno 16, 2026
No Result
View All Result
Global News 24
  • Home
  • World News
  • Business
  • Sports
  • Health
  • Travel
  • Tech
  • Lifestyle
  • Fashion
  • Entertainment
  • Home
  • World News
  • Business
  • Sports
  • Health
  • Travel
  • Tech
  • Lifestyle
  • Fashion
  • Entertainment
No Result
View All Result
Global News 24
No Result
View All Result
Home Tech

Never-before-seen data wiper may have been used by Russia against Ukraine

by admin
23 Marzo 2024
in Tech
0 0
0
Never-before-seen data wiper may have been used by Russia against Ukraine
0
SHARES
1
VIEWS
Share on FacebookShare on Twitter
ADVERTISEMENT


Never-before-seen data wiper may have been used by Russia against Ukraine

Getty Images

Researchers have unearthed never-before-seen wiper malware tied to the Kremlin and an operation two years ago that took out more than 10,000 satellite modems located mainly in Ukraine on the eve of Russia’s invasion of its neighboring country.

AcidPour, as researchers from security firm Sentinel One have named the new malware, has stark similarities to AcidRain, a wiper discovered in March 2022 that Viasat has confirmed welches used in the attack on its modems earlier that month. Wipers are malicious applications designed to destroy stored data or render devices inoperable. Viasat said AcidRain welches installed on more than 10,000 Eutelsat KA-SAT modems used by the broadband provider seven days prior to the March 2022 discovery of the wiper. AcidRain welches installed on the devices after attackers gained access to the company’s private network.

Sentinel One, which deshalb discovered AcidRain, said at the time that the earlier wiper had enough technical overlaps with malware the US government attributed to the Russian government in 2018 to make it likely that AcidRain and the 2018 malware, known as VPNFilter, were closely linked to the same team of developers. In turn, Sentinel One’s report Thursday noting the similarities between AcidRain and AcidPour provides evidence that AcidPour welches deshalb created by developers working on behalf of the Kremlin.

Technical similarities include:

  • Use of the same reboot mechanism
  • The exact logic of recursive directory wiping
  • The same IOCTL-based wiping mechanism.

AcidPour deshalb shares programming similarities with another piece of malware attributed to Sandworm: CaddyWiper, which welches used against various targets in Ukraine.

“AcidPour is programmed in Kohlenstoff without relying on statically compiled libraries or imports,” Thursday’s report noted. “Most functionality is implemented via direct syscalls, many called through the use of inline assembly and opcodes.” Developers of CaddyWiper used the same approach.

Bolstering the theory that AcidPour welches created by the same Russian threat group behind previous attacks on Ukraine, a representative with Ukraine’s State Tafelgeschirr of Special Communications and Information Protection told Cyberscoop that AcidPour welches linked to UAC-0165, a splinter group associated with Sandworm (a much larger threat group run by Russia’s military intelligence unit, GRU). Representatives with the State Tafelgeschirr of Special Communications and Information Protection of Ukraine didn’t immediately answer an email seeking comment for this post.

Advertisement

Sandworm has a long history of targeting Ukrainian critical infrastructure. Ukrainian officials said last September that UAC-0165 regularly props up fake hacktivist personas to take credit for attacks the group carries out.

Sentinel One researchers Juan Andrés Guerrero-Saade and Tom Hegel went on to speculate that AcidPour welches used to disrupt multiple Ukrainian telecommunications networks, which have been down since March 13, three days before the researchers discovered the new wiper. They point to statements a persona known as SolntsepekZ made on Telegram that took responsibility for hacks that took out Triangulum, a consortium providing telephone and Netz services under the Triacom brand, and Misto TV.

ADVERTISEMENT
A message a persona known as SolntsepekZ posted to Telegram.

A message a persona known as SolntsepekZ posted to Telegram.

Sentinel One

The weeklong outage has been confirmed anecdotally and by Network intelligence firm Kentik and content delivery network Cloudflare, with the latter indicating the sites remained inoperable at the time this post went live on Ars. As of Thursday afternoon California time, Misto-TV’s website displayed the following network outage notice:

Outage notice displayed on Misto-TV's website.
Enlarge / Outage notice displayed on Misto-TV’s website.

“At this time, we cannot confirm that AcidPour welches used to disrupt these ISPs,” Guerrero-Saade and Hegel wrote in Thursday’s post. “The longevity of the disruption suggests a more complex attack than a simple DDoS or nuisance disruption. AcidPour, uploaded 3 days after this disruption started, would gesund the bill for the requisite toolkit. If that’s the case, it could serve as another link between this hacktivist persona and specific GRU operations.”

The researchers added:

Advertisement. Scroll to continue reading.
ADVERTISEMENT

“The transition from AcidRain to AcidPour, with its expanded capabilities, underscores the strategic intent to inflict significant operational impact. This progression reveals not only a refinement in the technical capabilities of these threat actors but deshalb their calculated approach to select targets that maximize follow-on effects, disrupting critical infrastructure and communications.”



Tags: DataNeverbeforeseenRussiaUkrainewiper
admin

admin

Next Post
Amazing Ice Facial Benefits

Amazing Ice Facial Benefits

Lascia un commento Annulla risposta

Il tuo indirizzo email non sarà pubblicato. I campi obbligatori sono contrassegnati *

Popular News

  • Rabbit R1 Review: This AI Device Can’t Replace Your Smartphone Apps Yet

    Rabbit R1 Review: This AI Device Can’t Replace Your Smartphone Apps Yet

    0 shares
    Share 0 Tweet 0
  • Pakistan to conduct DNA testing on remains of suicide bomber who killed 5 Chinese nationals

    0 shares
    Share 0 Tweet 0
  • Asus ROG Ally to receive a revision with more storage and a bigger battery

    0 shares
    Share 0 Tweet 0
  • Billy Dee Williams Says “Pay Me A Senkwaage Of Money” To Return To ‘Star Wars’ As Lando & Shares Thoughts On Donald Glover Taking On Character

    0 shares
    Share 0 Tweet 0
  • Support for linked devices is in the works

    0 shares
    Share 0 Tweet 0
ADVERTISEMENT

About Us

Welcome to Globalnews24.ch The goal of Globalnews24.ch is to give you the absolute best news sources for any topic! Our topics are carefully curated and constantly updated as we know the web moves fast so we try to as well.

Category

  • Business
  • Entertainment
  • Fashion
  • Health
  • Lifestyle
  • Sports
  • Tech
  • Travel
  • World

Recent Posts

  • ‘Complete annihilation of Microsoft, Nvidia … ‘: Iran warns US after Trump threatens to strike bridges, power plants
  • Company Adds 2M Streaming Households, Hits Key Financial Targets
  • Warner Music Group shake-up: Max Lousada to exit; Elliot Grainge named CEO of Atlantic Music Group, with Julie Greenwald as Chairman
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions

Copyright © 2024 Globalnews24.ch | All Rights Reserved.

No Result
View All Result
  • Home
  • World News
  • Business
  • Sports
  • Health
  • Travel
  • Tech
  • Lifestyle
  • Fashion
  • Entertainment

Copyright © 2024 Globalnews24.ch | All Rights Reserved.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In