All cases

Viasat KA-SAT (AcidRain)

February 2022

Record reviewed: 2026-07

DestructivePeak: Strategic ImpactAttribution: ConfirmedTelecommunicationsDefenseEnergy
Year
2022
Actor country
Russia
Target regions
Ukraine, Germany, France, Italy, Central Europe
Unpeace score
10

Executive Summary

Destructive cyber attack against Viasat's KA-SAT satellite broadband network, timed to coincide with Russia's invasion of Ukraine on 24 February 2022. AcidRain wiper malware bricked tens of thousands of satellite modems across Europe, disrupting Ukrainian military and government communications and causing collateral outages to wind turbines in Germany and broadband users in multiple EU states.

Why This Matters

Viasat KA-SAT was the clearest example yet of cyber attack as an opening act of war, with cross-border collateral damage that forced NATO and the EU to treat satellite infrastructure as a shared security concern.

Escalation Profile

7-Dimension Profile

Escalation Ladder

Probing
Intrusion
Disruption
Degradation
Destruction
Strategic

Phases

2022-02-24
Intrusion

VPN appliance exploitation

Attackers exploited a misconfigured VPN appliance in the KA-SAT management network to reach modem provisioning infrastructure.

2022-02-24
Destruction

Mass modem wipe

AcidRain wiper pushed to tens of thousands of SurfBeam2 modems, overwriting flash storage and rendering them permanently inoperable.

2022-02-24
Strategic Impact

Collateral disruption across Europe

Beyond Ukraine, the attack disrupted ~5,800 Enercon wind turbines in Germany and broadband for users in France, Italy, and Central Europe.

Threshold Crossings

  • First confirmed cyber attack synchronized with the opening of a conventional military invasion
  • Cross-border collateral impact on NATO-member critical infrastructure

Restraint Factors

  • Attack targeted communications infrastructure, not life-safety systems
  • Physical satellite constellation was not damaged

Attribution Assessment

ConfirmedAttributed by the EU, UK, US, and allied governments to Russia's GRU
Russia
Sandworm
1. Technical

Threat actor mapped to Russia based on infrastructure analysis, malware attribution, and operational patterns.

Evidence: Viasat: KA-SAT Network Cyber Attack Overview; Guerrero-Saade & Chen (SentinelOne Labs): AcidRain — A Modem Wiper Rains Down on Europe

2. Political / Legal
Public AttributionSanctions Imposed
  • EU, UK, and US formal attribution to Russia (May 2022)
  • NATO recognized cyberspace as an operational domain with renewed emphasis
  • Viasat coordinated with NSA and allied agencies on incident response

Sources: Council of the EU: Declaration by the High Representative on Russian cyber operations against Ukraine (Viasat/KA-SAT)

3. Open Source

No dedicated journalistic sources in dataset. See sources section for full references.

Confirmed” reflects available public evidence. All assessments carry inherent uncertainty and should be read alongside source material.

Unpeace Position

10

Unpeace Score

Composite severity rating on the peace–conflict spectrum (1–10)

Stable
Contested
Escalatory
03060100

Unpeace · score breakdown

10/10
Escalation peak6 × 1.2 = +7.2

Peak tier reached (strategic), ranked 1–6.

Threshold crossings2 × 1 = +2

Distinct escalation thresholds the operation crossed.

Governance weight4 × 0.5 = +2

Formal governance responses flagged (attribution, sanctions, indictments…).

Raw sum 11.2 → capped= 10/10

round( escalationPeak×1.2 + crossings×1 + governance×0.5 ), capped at 10. These weights are an interpretive heuristic, not a validated metric — see the scoring methodology for rationale and limits.

Entanglement · score breakdown

10/10
Sectors affected4 × 1 = +4

Distinct critical-infrastructure sectors touched.

Countries / regions5 × 1 = +5

Geographic spread of impact.

Threshold crossings2 × 1 = +2

Escalation thresholds crossed (collateral-spread proxy).

Baseline offset1 × -1 = -1

Constant offset so a single-sector, single-country event floors at 1.

Raw sum 10= 10/10

clamp( sectors + countries + crossings − 1, 1, 10 ). These weights are an interpretive heuristic, not a validated metric — see the scoring methodology for rationale and limits.

Coercive Function

Destructive

Destruction of data or systems, coercive value through denial, punishment, or deterrence signaling.

Observed coercive effects

  • First confirmed cyber attack synchronized with the opening of a conventional military invasion
  • Cross-border collateral impact on NATO-member critical infrastructure

Entanglement Risk

Entanglement score10

Sectors affected

TelecommunicationsDefenseEnergyCritical Infrastructure

Countries / regions

UkraineGermanyFranceItalyCentral Europe

Impact summary

Tens of thousands of satellite modems bricked; disruption to Ukrainian military comms and collateral outages across multiple EU states.

Infrastructure Meaning

Malware / tooling

AcidRain

Capability profile

Tens of thousands of satellite modems bricked; disruption to Ukrainian military comms and collateral outages across multiple EU states.

3 ATT&CK techniques mapped — see ATT&CK mapping below.

Governance Analysis

Governance Flags

!Norm Violation
APublic Attribution
SSanctions Imposed
IIndictment
UUN Discussion
RRegulatory Change
CInternational Cooperation
DDeterrence Signal

Norms invoked

  • UN GGE 2015 norm against attacking critical infrastructure
  • International humanitarian law: proportionality and distinction in armed conflict

Policy responses

  • EU, UK, and US formal attribution to Russia (May 2022)
  • NATO recognized cyberspace as an operational domain with renewed emphasis
  • Viasat coordinated with NSA and allied agencies on incident response

Regulatory changes

  • EU NIS2 Directive implementation accelerated, partly citing Viasat as a motivating case
  • Increased focus on satellite and space-system cybersecurity in US National Cyber Strategy (2023)

Governance impact assessment

Demonstrated that cyber operations are now integrated into conventional military campaigns and that collateral effects readily cross borders, reinforcing momentum behind the EU NIS2 Directive and NATO cyber commitments.

Rules whose application to this operation is debated in the literature. These are analytical questions, not findings — the Atlas records where a case sits in legal debate, it does not adjudicate legality (see methodology §09).

Tallinn Manual 2.0

  • Rule 30, Distinction

    Satellite network serving both Ukrainian military and European civilians challenged distinction principle

UN Charter

  • Article 2(4), Prohibition on the Use of Force

    Synchronized with kinetic military invasion, blurring the line between cyber and conventional use of force

Geneva Conventions / IHL

  • Principle of Distinction

    Collateral effects on civilian broadband and wind turbines across NATO states challenged distinction compliance

Explore the full Legal Mapper

Sources

Sources listed reflect publicly available materials used to construct this case entry. Inclusion does not imply endorsement. Where no URL is provided, the source may be found via its title and date.