Publicly available data shows that more than 100 cyber incidents targeting space systems have been recorded from 1957 to the early 2020s. A recent report published by Kaspersky ICS CERT emphasizes that modern space security is no longer limited to physically protecting satellites in orbit.
Today, a “space system” refers to a complex and interconnected network structure consisting of ground control stations, terrestrial communication lines, user terminals, and third-party software. Attackers often target the most accessible and weakest links in this chain.
Kaspersky’s previous reports highlight critical risks, particularly to Global Navigation Satellite Systems (GNSS). Following a sharp increase in GPS/GNSS spoofing incidents in the Black Sea region in 2023, Kaspersky researchers collaborated with 70 hardware manufacturers worldwide to audit internet-connected GNSS devices . The investigations revealed that over 3,000 GNSS receivers were vulnerable to attacks originating directly from the internet. This poses significant risks to maritime, aviation, and land logistics. Organizations are advised to protect their systems from internet-based threats by keeping GNSS receivers inaccessible to external networks and, in scenarios where internet connectivity is essential, by securing devices with robust authentication mechanisms.
Threat actors frequently use satellite infrastructure as a cover to conceal their malicious activities. Throughout the 2010s, Advanced Persistent Threat (APT) groups like Turla and Whitebear achieved an unprecedented level of anonymity by routing server communications through unencrypted satellite downstream traffic. The low technical threshold for intercepting satellite signals further exacerbates this problem. Indeed, as early as 2009, militia groups in the Middle East were able to intercept unencrypted video streams from military systems using inexpensive, commercially available software. Today, sophisticated APT groups like Thrip continue to target satellite operators and geographic information/mapping databases in order to monitor or directly disrupt critical space infrastructure.
The Kaspersky ICS CERT report also highlights the critical secondary impacts of space-focused cyberattacks. In 2022, a large-scale cyberattack was carried out against the KA-SAT network of satellite operator Viasat. Launched via a misconfigured VPN device, the attack deployed the “AcidRain” data wiper malware, disabling approximately 30,000 satellite terminals across Europe and indirectly halting the remote operation of more than 5,800 wind turbines.
The discovery in 2024 of “AcidPour,” a highly destructive sequel software associated with the Sandworm APT group, proves that this dangerous trend is escalating. Unlike its predecessor, AcidPour targets a much wider range of Linux routers, satellite modems, and data storage systems.
Kaspersky Security Analysis Expert Ekaterina Rudina stated: “ A space system is not just comprised of elements sent into orbit. Ground-based control networks, communication channels, and subscriber receivers form the core and often the most sensitive operational infrastructure of the entire system. As satellite technologies become more integrated into civilian life, from navigation systems to energy grids, securing these connections, implementing encryption on downstream connections, and updating vulnerable receivers connected to the internet are of paramount importance .”
Kaspersky recommends that organizations take the following measures to reduce the risk of exploitation:
• Regularly check for security vulnerabilities in internet-connected location control and user/subscriber equipment, especially GNSS receivers, and apply necessary patches.
• Ensure satellite communication links are fully encrypted to prevent unauthorized individuals from monitoring traffic and performing signal spoofing.
• Use robust endpoint protection at ground station terminals and implement strict access controls on internal management networks.
You can read the full report on the Kaspersky ICS CERT website .





