Kaspersky warned that the security of space systems is no longer limited to protecting satellites in orbit, after an audit conducted by the company revealed that more than 3,000 receivers for global navigation satellite systems (GNSS) had been subjected to direct attacks over the internet. These vulnerabilities could affect sectors that rely on navigation and timing signals, such as maritime and air transport and land-based logistics services.
Kaspersky presented the findings of a report prepared by the Industrial Control Systems Emergency Response Team (ICS CERT) at GISEC 2026. The report presents the space ecosystem as an interconnected network comprising satellites, ground control stations, communication channels, user devices, and software provided by third parties, rather than as an isolated orbital infrastructure.
Internet-Connected Ground Devices
The report was based on more than 100 cyber incidents targeting space systems from 1957 through the beginning of the 2020s. Kaspersky considers internet-connected ground devices and signal receivers to be practical pathways for accessing more sensitive parts of the ecosystem.
The company audited internet-connected GNSS receivers in cooperation with 70 global equipment suppliers, following the sharp increase in GPS and GNSS signal-spoofing incidents in the Black Sea region in 2023. Based on the audit findings, it recommended restricting external access to these devices and strengthening authentication and identity verification when internet connectivity is required.
Satellites as a Covert Channel
Adversarial use of space systems is not limited to disrupting their infrastructure; the report noted that unencrypted data traffic over satellites has been exploited to conceal communications by attack groups. It cited the Turla and Whitebear groups as examples of entities that exploited these channels during the second decade of the twenty-first century, and referred to incidents since 2009 that enabled the interception of unencrypted military video streams using low-cost commercial tools.
The report also linked the Thrip group to targeting satellite operators and geospatial mapping databases, with the aim of monitoring or disrupting critical space infrastructure.
What Does the KA-SAT Attack Change?
Kaspersky cited the 2022 attack on Viasat's KA-SAT network. The attackers exploited a misconfigured VPN device to deploy the AcidRain destructive malware, disrupting approximately 30,000 satellite communication terminals across Europe and indirectly causing the remote operation of more than 5,800 wind turbines to stop.
In 2024, AcidPour, which is associated with the Sandworm group, was disclosed. The malware targets a broader range of devices, including Linux-based routers, satellite signal modems, and data storage systems.
What Should Organizations Review?
- Conduct regular audits of GNSS receivers, ground control devices, and user devices.
- Update internet-connected devices and restrict external access to their management interfaces.
- Encrypt data traffic and space communication links to limit espionage and spoofing.
- Apply strong protection to endpoint devices at ground communication stations and enforce strict controls on internal management networks.
certi.news reading: The actual change lies in the shift of the point of risk from the satellite alone to an entire operational chain, beginning with a receiver or VPN configuration and ending with a vital service such as energy or navigation. However, the figures and facts presented here are based on Kaspersky's report as conveyed by the article, without independent verification or full technical details about the devices covered by the audit; therefore, the findings should be read as an institutional warning that requires review of the original report before being generalized to all environments.