Kaspersky Exposes Vulnerable Satellite Ground Terminals

Over Hundred Cyber Attacks Strike Global Space Systems

  • Kaspersky documents over one hundred cyber strikes against space architectures since nineteen fifty-seven
  • Vulnerable GNSS hardware poses critical operational hazards to civil aviation and maritime logistics
  • Experts demand robust cryptographic protocols across interconnected ground stations and consumer receivers

Over Hundred Cyber Attacks Strike Global Space Systems
Sep 30, 2026 15:53

Targeting interconnected orbital assets, radio transmission relays, and mission-critical telemetry, malicious threat actors have directed over one hundred documented cyber intrusions against space systems between 1957 and the early 2020s. A technical investigation released by international cybersecurity entity Kaspersky ICS CERT on Wednesday, September 30, 2026, details how threat surfaces expand far beyond orbiting satellites. Ground mission command infrastructures, telemetry transport protocols, end-user terminal equipment, and proprietary third-party software supply chains represent equally exploitable vectors within modern space environments.

According to industrial security data, systemic operational vulnerability heavily concentrates around the Global Navigation Satellite System (GNSS). Following heightened GPS and GNSS spoofing anomalies across the Black Sea basin in 2023, Kaspersky security researchers audited over 3,000 exposed GNSS receivers integrated with equipment from 70 major aerospace manufacturers. Left exposed directly to the public internet without perimeter isolation, these network interfaces introduce critical system vulnerabilities across international airspace routing, maritime operations, and automated terrestrial freight transport.

Relevant industry sources revealed that advanced cyber threat groups deliberately weaponize satellite backbones to obscure adversarial intrusion pathways. In 2022, the deployment of the 'AcidRain' wiper malware against Viasat's KA-SAT satellite broadband constellation instantly bricked nearly 30,000 ground terminals, abruptly severing telemetry links for over 5,800 remotely monitored wind turbines. The technical evolution observed in the 2024 discovery of 'AcidPour'—a specialized ELF firmware malware—confirmed targeted capabilities against network routing appliances, satellite transceiver modems, and enterprise SAN/RAID storage arrays.

Synthesizing aerospace defense guidelines, Kaspersky Security Analysis Expert Ekaterina Rudina told media professionals: "A space system encompasses far more than satellites in orbit. Ground control facilities, communication channels, and end-user receiving hardware form indivisible operational components. Systemic vulnerabilities at any point threaten the integrity of the whole architecture. As societal dependence on satellite technology deepens from civil navigation to power grid coordination, engineering teams must deploy robust end-to-end cryptographic encryption across all signal paths and enforce disciplined patching cycles across internet-facing telemetry equipment."

//DBTech/SSCP/SME/DPO//