Kaspersky has warned of growing cyber risks targeting space systems, confirming that more than 3,000 GNSS receivers are exposed to direct online attacks, threatening maritime, aviation, and land logistics sectors.

According to a recent report by the Industrial Control Systems Cyber Emergency Response Team (ICS CERT) presented at GISEC 2026, the security of space systems is no longer limited to protecting satellites in orbit. It now includes an interconnected network of ground control stations, communication channels, user devices, and software from third parties.

Over 100 Cyber Incidents Targeting Space Systems

Publicly available data recorded more than 100 cyber incidents targeting space systems from 1957 to the early 2020s, according to the report.

Kaspersky noted that attackers exploit vulnerabilities in space system components, especially ground equipment and internet-connected receivers, as potential paths to access critical systems.

In this context, the company’s researchers audited internet-connected GNSS receivers in collaboration with 70 global equipment suppliers, following a sharp increase in GPS and GNSS spoofing incidents in the Black Sea region in 2023.

The audit revealed that more than 3,000 receivers were exposed to direct cyberattacks via the internet, necessitating restrictions on external access and enhanced authentication and identity verification mechanisms when internet connectivity is required.

Satellites as a Tool to Hide Attacks

The risks are not limited to targeting space infrastructure. Attackers sometimes exploit satellite networks to hide their malicious activities.

The report mentioned that advanced persistent threat (APT) groups, such as Turla and Whitebear, exploited unencrypted satellite data traffic during the 2010s to route their server communications, enhancing their ability to hide.

Incidents since 2009 have shown the possibility of intercepting unencrypted military video streams using low-cost commercial tools.

Currently, advanced groups like Thrip continue to target satellite operators and geospatial map databases, aiming to monitor or disrupt critical space infrastructure.

KA-SAT Attack Disrupted 30,000 Communication Terminals

Kaspersky’s report reviewed the repercussions that can extend beyond space systems to affect other vital sectors, citing the cyberattack that targeted Viasat’s KA-SAT network in 2022.

Attackers exploited a misconfigured VPN appliance to deploy the AcidRain destructive malware, disrupting approximately 30,000 satellite communication terminals across Europe.

The attack’s repercussions extended to the energy sector, indirectly causing remote shutdown of more than 5,800 wind turbines.

In 2024, AcidPour malware was discovered, linked to the Sandworm APT group, targeting a wider range of devices, including Linux-based routers, satellite signal modulators, and data storage systems.

Recommendations to Protect Space Infrastructure

Ekaterina Rudina, security analysis expert at Kaspersky, said that ground control networks, communication channels, and user receivers form the operational foundation of the space system, but they often lack adequate protection.

She added that the growing reliance on satellite technology in navigation systems and power grids necessitates securing communications, encrypting incoming data traffic, and updating internet-connected receivers.

To mitigate attack risks, Kaspersky recommended that organizations conduct regular audits and updates of ground control and user devices, especially GNSS receivers, in addition to fully encrypting space communication links to prevent data espionage and spoofing.

It also called for implementing strong endpoint protection solutions at ground communication stations and enforcing strict controls on access to internal management networks.

The full report can be found on the Kaspersky ICS CERT website.

By Ryan

Leave a Reply

Your email address will not be published. Required fields are marked *