The Telecommunication Sabotage Strategy in the Russia-Ukraine War

Immediately following the outbreak of the Russia-Ukraine War in 2022, Sandworm—a hacking group operating under the Russian Main Intelligence Directorate (GRU)—targeted Ukraine’s critical infrastructure through state-sponsored cyber warfare. Having a notorious track record of state-backed operations, such as previous attacks on the Ukrainian power grid, they deployed two prominent destructive tools, AcidRain and IsaacWiper, to paralyze communication networks and core systems. Unlike ransomware, these two malware strains do not seek financial gain; instead, they focus exclusively on wiping systems and destroying data to inflict catastrophic, irreversible damage.
AcidRain
A Destructive Attack Beyond Satellite Comms, Paralyzing Society at Large
On February 24, 2022, precisely at the onset of the Russian invasion of Ukraine, AcidRain was deployed to cripple the Viasat KA-SAT network, a satellite internet service heavily relied upon across Europe and Ukraine. This attack went far beyond simple data deletion—it completely corrupted the firmware of thousands of modems and routers, effectively bricking the hardware. This caused severe disruptions in early Ukrainian military command-and-control communications and triggered widespread socio-economic ripple effects, leaving civilians without internet access and causing massive service outages.
AcidRain specifically targeted Linux-based embedded systems, executing the notorious rm -rf /* command to wipe all data from storage media. Running autonomously without setting up backdoors for recovery or initiating outbound communications with external servers, it left victims with no choice but to physically replace the compromised hardware. The impact cascaded past Ukraine's borders, disrupting wind farms and energy facilities in several European nations, including Germany, France, and Poland, serving as a stark demonstration of how geopolitical cyber warfare can trigger cross-border fallout.
IsaacWiper
A Precision Tool for Covert System Destruction
While AcidRain aimed for broad, hardware-level devastation, IsaacWiper was deployed as a precision scalpel targeting Windows-based servers and workstations to systematically wipe data. This malware was covertly distributed in late February 2022, infiltrating Ukrainian government agencies, financial networks, and energy infrastructure.

IsaacWiper operates by intentionally corrupting the structural file system. Rather than just deleting files, it repeatedly overwrites storage sectors to thoroughly eliminate any possibility of data recovery. Deviating from ransomware models, it issues no financial demands, focusing purely on neutralizing systems. It evaded detection over extended periods by acting as a malicious DLL (a library required for running Windows OS applications) and injecting itself into legitimate, running processes. Crucially, it was architected to run completely offline without communicating with an external Command & Control (C2) server—the infrastructure typically used by attackers to remotely control infected systems. This design choice made tracing the origin and defending against the attack exceptionally difficult, proving that the threat actors had already penetrated deep into the internal networks, allowing them to pull the trigger covertly without triggering suspicious outbound traffic.
The Paradigm of Modern Cyber Warfare
The deployment of AcidRain and IsaacWiper transcends conventional cybercrime. It stands as a pivotal case study illustrating the mechanics of modern hybrid warfare, where kinetic military actions are tightly synchronized with cyber operations. Throughout the conflict, Russia has paired physical strikes with digital onslaughts to maximize systemic national chaos. AcidRain played a decisive role in undermining Ukraine's initial military response by blinding its communication infrastructure, while IsaacWiper sought to paralyze state administration by wiping data across government and key institutional networks. This underscores that cyber attacks have matured into core strategic assets in modern warfare, possessing a destructive payload that rivals conventional weaponry.
An Ongoing Threat
Sandworm continues to iterate on these destructive wiper variants, engineering new strains to target Ukraine and Western allies. This indicates that these types of cyber operations are not isolated, one-off events, but rather persistent, long-term threats. Consequently, defending against them demands a defense-in-depth posture that looks far beyond routine data backups. Safeguarding critical infrastructure now requires a combination of technical protocols—such as offline backups, physical air-gapping, and real-time behavioral monitoring—alongside robust international intelligence cooperation. The invisible war in cyberspace has long been underway, and its capacity to compromise national security and societal foundations is just as devastating as physical combat.