According to publicly available data, over 100 cyber incidents targeting space systems were recorded between 1957 and the early 2020s. Kaspersky ICS CERT’s recent report highlights that modern space security is no longer just about guarding physical satellites in orbit. Today’s "space system" consists of an interconnected web of ground control stations, terrestrial communication links, user terminals, and third-party software – with attackers frequently exploiting the most accessible and least secure links in this chain.
Specifically, Kaspersky’s past reports highlight a critical risk to Global Navigation Satellite Systems (GNSS). Following a sharp spike in GPS/GNSS signal spoofing in the Black Sea region in 2023, Kaspersky researchers audited internet-exposed GNSS hardware in collaboration with 70 global equipment vendors. They discovered that more than 3,000 GNSS receivers are actively vulnerable to attacks directly over the internet, presenting severe risks to maritime, aviation, and land logistics. To protect their systems from internet-based attacks, organizations should keep GNSS receivers unreachable from the outside. If internet access is a necessity, Kaspersky recommends protecting your devices with robust authentication mechanisms.
Threat actors often abuse satellite infrastructure to conceal their malicious activities. Throughout the 2010s, Advanced Persistent Threat (APT) groups like Turla and Whitebear hijacked unencrypted downstream satellite traffic to route their server communications, achieving an unprecedented level of anonymity. This issue is compounded by the low barrier to entry for interception; as early as 2009, militants in the Middle East demonstrated that commercially available, low-cost software could be used to intercept unencrypted, downstream video feeds from military systems. Today, sophisticated APT groups like Thrip continue to target satellite operators and geospatial mapping databases to monitor or directly disrupt critical space infrastructure.
Kaspersky ICS CERT’s report also points to the critical secondary impacts of space-oriented cyberattacks. In 2022, a major cyberattack hit satellite operator Viasat's KA-SAT network. Initiated via a misconfigured VPN device, the threat actors deployed the AcidRain wiper, disabling approximately 30,000 satellite terminals across Europe and indirectly halting the remote operations of more than 5,800 wind turbines.
This trend has only been intensifying, with the 2024 discovery of AcidPour, a highly destructive successor associated with the Sandworm APT group. Unlike its predecessor, AcidPour targets a much wider array of Linux routers, satellite modems, and data storage systems.
"A space system comprises far more than what is launched into orbit; the ground-based control networks, communication channels, and subscriber receivers represent the true, and often fragile, operational foundation of the entire system. As satellite technology becomes deeper integrated into civilian life – from navigation systems to energy grids – securing these connections, enforcing encryption on downstream links, and patching vulnerable internet-exposed receivers is of highest importance," commented Ekaterina Rudina, Security Analysis Expert at Kaspersky.
To reduce the risk of exploitation, Kaspersky recommends that organizations:
· Regularly audit and patch vulnerable, internet-facing ground control and user-subscriber hardware, particularly GNSS receivers
· Ensure satellite communication links are fully encrypted to prevent unauthorized traffic snooping and spoofing
· Implement robust endpoint protection on ground station terminals and enforce strict access controls on internal management networks
Read the full report on Kaspersky ICS CERT’s website.
Tracy