AcidPour

MITRE ATT&CK: S1167 View on attack.mitre.org

Aliases: AcidPour

First seen
2023-01-01 00:00:00
Malware type
wiper
Family
Malware family
Operating systems
linux
Related IoCs
1 (1 malicious)
Last IoC activity
2026-08-27 17:37:07
Profile updated
2026-07-07 13:09:58

Targeted industries: technology-and-telecommunications government-and-public-sector

Targeted regions: country_code:ua

Context

AcidPour is a variant of AcidRain designed to impact a wider range of x86 architecture Linux devices. AcidPour is an x86 ELF binary that expands on the targeted devices and locations in AcidRain by including items such as Unsorted Block Image (UBI), Deice Mapper (DM), and various flash memory references. Based on this expanded targeting, AcidPour can impact a variety of device types including IoT, networking, and ICS embedded device types. AcidPour is a wiping payload associated with the Sandworm Team threat actor, and potentially linked to attacks against Ukrainian internet service providers (ISPs) in 2023.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to AcidPour (S1167). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample 6a8824048417abe156a16455b8e29170f8347312894fde2aabe644c4995d7728.zip 2026-08-27 1

Detection coverage

  • 96 Sigma rules

Malware & tools used

  • System Shutdown/Reboot (attack-pattern)
  • Peripheral Device Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Disk Content Wipe (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • File Deletion (attack-pattern)
  • Data Destruction (attack-pattern)

Used by threat actors

Reports & references

  • CERT-UA — 6123309 (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Acidpour (report)
  • twitter.com — 1769726024600768959 (report)
  • trellix.com — Pouring Acid Rain (report)
  • MITRE ATT&CK — S1167 (report)
  • sentinelone.com — Acidpour New Embedded Wiper Variant Of Acidrain Appears In Ukraine (report)

External references