SATCOM terminals under attack in Europe: a plausible analysis
1–10 of 79 posts
Re: SATCOM terminals under attack in Europe: a plausible analysis
#2Re: SATCOM terminals under attack in Europe: a plausible analysis
#3Is there a plausible explanation for who would do this, besides Russia?
Is Viasat/Eutelsat a particularly good target for this for some reason (seems more like Iridium is used in these scenarios).
Re: SATCOM terminals under attack in Europe: a plausible analysis
#4Seems entirely plausible to me that someone pushed a firmware update which corrupted the firmware (even maybe at the fpga/bootcode level) and effectively bricked the devices. Not horribly complicated to do and once you've done it it would require physical access to recover each device individually. Is there a plausible explanation for who would do this, besides Russia? Is Viasat/Eutelsat a particularly good target fo…
Not sure at all if this was the intended/primary target, but Europe is certainly scrambling for every Watt at the moment...
Also note that KA-SAT/Viasat and Eutelsat seem to be different platforms. I've seen reports of services based on the former being affected (e.g. SkyDSL [2]), but not the latter (Konnect), so far.
I was also surprised to learn that Ka-band based stationary consumer satellite internet services seem to be using (mostly) plain DOCSIS as the protocol. That possibly introduces its own share of vulnerabilities due to OTA updates/provisioning.
[1] https://thestack.technology/viasat-ka-sat-outage-cyber/
[2] https://www.connexionfrance.com/French-news/Thousands-in-Fra...
Re: SATCOM terminals under attack in Europe: a plausible analysis
#5What I think happened is that they breached the control infrastructure which gives them access to an "internal" VLAN that the satellite terminals use to communicate with the mothership for firmware updates, configuration changes, etc, and from there were able to attack these as if they were locally connected (or worse - since that network segment is presumed "internal" and may expose services not normally available - think whatever is the TR-069 equivalent for BGAN terminals), either just pushing an incorrect configuration that prevents the terminal from connecting (essentially bricking it until you can get out-of-band access and reconfigure it properly) or obtaining root (via exploit or pushing a specially-crafted firmware update) and overwriting /dev/mtd* to completely kill the terminal.
"Cyberattack on satellite network" sounds so serious but I very much doubt it's got anything to do with the satellite part of it. They've done the equivalent of breaching into the management network at a terrestrial, wired ISP and sent garbage configuration over TR-069 to brick the modems. Attacking the satellite layer would require much more effort for essentially the same gain (and if your objective was to get into the satellite layer, why waste that access on breaking everything in a highly-visible way when you're better off silently sitting there and using the access to eavesdrop on everything, especially when it's used for SCADA traffic of critical systems that's itself unencrypted and vulnerable to tampering?).
Re: SATCOM terminals under attack in Europe: a plausible analysis
#6Seems entirely plausible to me that someone pushed a firmware update which corrupted the firmware (even maybe at the fpga/bootcode level) and effectively bricked the devices. Not horribly complicated to do and once you've done it it would require physical access to recover each device individually. Is there a plausible explanation for who would do this, besides Russia? Is Viasat/Eutelsat a particularly good target fo…
Re: SATCOM terminals under attack in Europe: a plausible analysis
#7Seems entirely plausible to me that someone pushed a firmware update which corrupted the firmware (even maybe at the fpga/bootcode level) and effectively bricked the devices. Not horribly complicated to do and once you've done it it would require physical access to recover each device individually. Is there a plausible explanation for who would do this, besides Russia? Is Viasat/Eutelsat a particularly good target fo…
KA-SAT seems to be used for SCADA control of 11 Gigawatt worth of wind turbines in Germany, among other things [1]. Not sure at all if this was the intended/primary target, but Europe is certainly scrambling for every Watt at the moment... Also note that KA-SAT/Viasat and Eutelsat seem to be different platforms. I've seen reports of services based on the former being affected (e.g. SkyDSL [2]), but not the latter (Ko…
Re: SATCOM terminals under attack in Europe: a plausible analysis
#8Seems entirely plausible to me that someone pushed a firmware update which corrupted the firmware (even maybe at the fpga/bootcode level) and effectively bricked the devices. Not horribly complicated to do and once you've done it it would require physical access to recover each device individually. Is there a plausible explanation for who would do this, besides Russia? Is Viasat/Eutelsat a particularly good target fo…
KA-SAT seems to be used for SCADA control of 11 Gigawatt worth of wind turbines in Germany, among other things [1]. Not sure at all if this was the intended/primary target, but Europe is certainly scrambling for every Watt at the moment... Also note that KA-SAT/Viasat and Eutelsat seem to be different platforms. I've seen reports of services based on the former being affected (e.g. SkyDSL [2]), but not the latter (Ko…
"The [turbines] affected remain in operation and are producing clean renewable energy. ... they will operate in automatic mode and are fundamentally capable of self-contained and independent regulation."
Re: SATCOM terminals under attack in Europe: a plausible analysis
#9Earlier quoted context omitted.
KA-SAT seems to be used for SCADA control of 11 Gigawatt worth of wind turbines in Germany, among other things [1]. Not sure at all if this was the intended/primary target, but Europe is certainly scrambling for every Watt at the moment... Also note that KA-SAT/Viasat and Eutelsat seem to be different platforms. I've seen reports of services based on the former being affected (e.g. SkyDSL [2]), but not the latter (Ko…
Taking a country's infrastructure through a cyberattack is considered an act of war. Same as if you bombed the power generation infrastructure.
Re: SATCOM terminals under attack in Europe: a plausible analysis
#10Does the best-known approach just boil down to weighing the cost/benefit of (acting | not acting) x P(most likely aggressor | some other cause)? Or has someone figured out a better approach?