Issue 45

Viasat Releases Details of Cyber Attack

30 Mar 2022: Viasat believes the cyberattack on its KA-SAT network last month that affected modems across Ukraine and Europe was “deliberate” and intended to interrupt service, the company said in a report on the attack.

30 Mar 2022: Viasat believes the cyberattack on its KA-SAT network last month that affected modems across Ukraine and Europe was “deliberate” and intended to interrupt service, the company said in a report on the attack.

– Viasat called the cyberattack on 24 Feb as “multifaceted and deliberate.” It caused a partial interruption of KA-SAT’s consumer satellite broadband service.

– KA-SAT covers Europe and the Mediterranean region, and Viasat purchased the satellite, formerly owned by Eutelsat, last year when it purchased Eutelsat’s share of Euro Broadband Infrastructure.

– The attacker exploited a misconfiguration in a VPN appliance to gain remote access to the trusted management segment of the KA-SAT network. It’s still unclear how the threat actors gained access to the VPN.

– The attacker moved laterally through this trusted management network to a specific network segment used to manage and operate the network. They used this network access to execute legitimate, targeted management commands on a large number of residential modems simultaneously.

– Viasat concluded that an attacker had breached their management network for this subset of users and issued a command to wipe a key part of these modems

– A separate investigation from SentinelOne claimed to have discovered a new type of modem wiper software, called AcidRain.

– AcidRain is an executable that “performs an in-depth filesystem wipe and various known storage device files,” researchers Juan Andres Guerrero-Saade and Max van Amerongen said. “If the code is running as root, AcidRain performs an initial recursive overwrite and delete of non-standard files in the filesystem.”

– SentinelOne also noticed an interesting (but not conclusive) code overlap between AcidRain and another piece of malware, VPNFilter, that has been attributed by the FBI to Russia’s GRU (military intelligence service).

– Viasat said there is no evidence that the KA-SAT satellite or its ground infrastructure were directly involved, impaired or compromised.

– This very effective cyber attack was done through the ground network/Internet.

– To restore service to customers, Viasat said some modems received over-the-air updates, and Viasat has shipped nearly 30,000 modems to distributors in cases when the updates were not sufficient.

KA-SAT Coverage.

AcidRain modem-wiper code analysis.

KA-SAT Groundtrack.

KA-SAT Undergoing Testing in 2011.

KA-SAT network diagram associated with the cyberattack analysis.