Satellite attacks went from TV pranks to wiper malware

Attacks on space systems have gone from a satellite TV dealer hijacking an HBO movie broadcast in 1986 to wiper malware bricking satellite modems across Europe. The ground and user equipment tying those systems together, meanwhile, is frequently sitting on the open internet.

That is the arc traced in a retrospective published by Kaspersky ICS CERT researchers Semen Kort, Alexander Nikolaev and Ekaterina Rudina, covering roughly 65 years of incidents involving spacecraft, ground stations and subscriber terminals. Their count, drawn from open sources, is a little over a hundred recorded attacks between 1957 and the early 2020s, with the caveat that recent tallies reach the thousands or tens of thousands per year depending on what you agree to call a space system and what you agree to call a cyberattack.

Why this is critical infrastructure

NATO formally recognized space as an operational domain in November 2019, alongside land, sea, air and cyberspace. The researchers spell out what a sustained satellite outage would cost: disrupted telephone, internet and television service, degraded navigation for aircraft, shipping and road transport, weaker severe weather forecasting, and a direct hit to military surveillance. That dependency is what makes the segment worth attacking.

The finding that keeps repeating

Across the early decades the report's recurring conclusion is that people, not code, caused most of the damage. In 1982 an error in an update command sequence made the American Viking 1 lower its antenna, permanently ending communication. In September 1988 the Soviet station Phobos 1 was lost after an operator omitted a single hyphen from a command and sent it without waiting for the verification computer, which was broken that day; the malformed command activated an unused test sequence and disabled the attitude control thrusters. The following week the crew of Soyuz TM-5 survived only by reprogramming their control module in flight to work around an outdated docking software load.

Pure software bugs did their share. The first Space Shuttle launch was scrubbed minutes before liftoff in 1981 by a scheduler defect that, with a probability of about 1 in 67, desynchronized the primary and backup computers.

From TV piracy to state operations

The first widely known act of satellite hacktivism was commercial. In April 1986 John MacDougall, a Florida uplink engineer who had lost his satellite dish dealership to HBO's signal scrambling, pointed an antenna at an HBO transponder and overrode the movie playing to roughly 14.6 million viewers with a message signed Captain Midnight. He used coordinates and frequencies taken from public manuals, and drew a year of probation and a 5,000 dollar fine.

Motives politicized from there: activists overriding CCTV broadcasts on SinoSat in 2002, the LTTE using an Intelsat transponder in 2007, Iranian jamming of BBC Persian in 2009, and insurgents in Iraq intercepting unencrypted Predator drone video with 26 dollars of shareware. Ground segments were no better defended; an audit of NOAA's JPSS ground system counted more than 9,100 vulnerabilities and over 3,600 security policy violations.

By the 2010s state groups treated satellites as both target and tool. Turla compromised DVB-S providers and rode their unencrypted downstream links as command and control infrastructure, hiding the true location of its servers. The Thrip campaign in 2018 went after satellite communications operators with an interest in operational control systems.

The modern era

The February 2022 attack on Viasat's KA-SAT network is the reference case: a misconfigured VPN opened the door, and the AcidRain wiper overwrote modem flash memory, knocking out remote monitoring of more than 5,800 wind turbines across Europe totalling over 11 GW. A successor wiper, AcidPour, appeared in 2024 aimed at Linux routers, satellite modems and storage arrays, and was linked to Sandworm.

Signal attacks scaled alongside. GNSS spoofing over the Black Sea region in 2023 compromised aircraft navigation, in the worst cases taking inertial systems down with it, while the hacktivist groups SiegedSec and GhostSec reached satellite and GNSS receivers in Colombia, Romania, Russia, Israel and the United States. Kaspersky's own scan, run with 70 vendors, found more than 3,000 GNSS receivers exposed and vulnerable over the internet.

The gap

The researchers are candid that governance has not kept up: there is no single comprehensive treaty covering cybersecurity in space, and protection rests on fragmented space law, UN resolutions and emerging soft law. The current effort aims at consensus norms of responsible behavior rather than new treaties, which they note is unlikely on its own to deter a motivated attacker. For defenders the practical items are the ordinary ones that keep failing here: get receivers and ground equipment off the public internet, enforce change verification instead of letting operators bypass it, and treat the supply chain behind a terminal as part of your attack surface. Kaspersky ICS CERT telemetry also underpinned our earlier report that attacks on industrial control systems fell to a three-year low.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions