Viasat KA-SAT Wiper Attack Knocked Out Satellite Broadband at the Start of the Ukraine Invasion
Minutes before Russia's invasion on 24 February 2022, a wiper attack against Viasat's KA-SAT ground infrastructure took roughly 45,000 modems offline across Ukraine and Central Europe — the first major cyber-physical attack on a civilian satellite network during wartime.
02Deep-Dive Technical Analysis
The attack used legitimate remote-management access (VPN with compromised credentials, no MFA) to reach the KA-SAT network management segment, then deployed a destructive wiper targeting the modems themselves: a malicious firmware overwrite (later attributed to the "AcidRain" wiper) bricked SurfBeam2 modems en masse, overwhelming recovery because the devices could not be restored over the air. Viasat isolated the KA-SAT segment from other services, and traffic mixing between the consumer broadband network and other managed services prevented broader propagation. Attribution was later made by US, UK, and EU partners to Russian military intelligence (GRU) acting in support of the invasion, with the UK NCSC tying it to Sandworm-team infrastructure.
03Vulnerability & Exploit Flow
Credential compromise of ground-segment management VPN, followed by destructive modem firmware wipe (AcidRain-class wiper).
04Recommended Defense & Mitigation Protocol
Enforce MFA and PAM on satellite NOC remote management, segment modem fleets so a wiper cannot reach the whole estate, support signed and rollback-capable modem firmware, rehearse mass-replacement logistics, and share satellite ground-segment telemetry with national CSIRTs.
05Security Impact & Geopolitical Consequence
The incident was a watershed for satellite security: it demonstrated that geostationary broadband ground segments are strategic cyber-physical targets, that modem fleets are a single point of wiper failure, and that space assets require the same zero-trust segmentation as terrestrial core networks. It directly informed EU space-security policy, prompted EASA/CISA guidance on satellite communications resilience, and joined undersea cables and SS7 roaming exchanges on the list of critical telecom infrastructure targeted in hybrid warfare.
06Authoritative Standards & External References
07Related Topic Cluster Records
Master 5G Core, SS7 Defense & Subsea Cable Auditing
Ready to turn your historical knowledge into certified hands-on expertise? Register free on TelcoSec Academy to access interactive lab challenges, or consult our enterprise team for carrier-grade signaling assessments and portable BTS hardware.