Live data from Hacker News

SATCOM terminals under attack in Europe: a plausible analysis

reversemode.com

11–20 of 79 posts

Re: SATCOM terminals under attack in Europe: a plausible analysis

#12
post #4

Seems entirely plausible to me that someone pushed a firmware update which corrupted the firmware (even maybe at the fpga/bootcode level) and effectively bricked the devices. Not horribly complicated to do and once you've done it it would require physical access to recover each device individually. Is there a plausible explanation for who would do this, besides Russia? Is Viasat/Eutelsat a particularly good target fo…

KA-SAT seems to be used for SCADA control of 11 Gigawatt worth of wind turbines in Germany, among other things [1]. Not sure at all if this was the intended/primary target, but Europe is certainly scrambling for every Watt at the moment... Also note that KA-SAT/Viasat and Eutelsat seem to be different platforms. I've seen reports of services based on the former being affected (e.g. SkyDSL [2]), but not the latter (Ko…

[1] above: "This article was published on: 02/28/22".

Re: SATCOM terminals under attack in Europe: a plausible analysis

#13

Seems entirely plausible to me that someone pushed a firmware update which corrupted the firmware (even maybe at the fpga/bootcode level) and effectively bricked the devices. Not horribly complicated to do and once you've done it it would require physical access to recover each device individually. Is there a plausible explanation for who would do this, besides Russia? Is Viasat/Eutelsat a particularly good target fo…

Dumb Question here but my thoughts were - why not push the corrupted update to the sats? AKA hack the sat firmware? I'm fairly certain that they aren't wide open doors but still - I would guess that it would be a lot easier doing it that way. Perhaps it was both, or someting else entirely. It will make for an interesting read one day.

The satellite layer is probably very custom and requires specific skills and initial recon work which could be visible and risky. In contrast, getting access to the management network and sending intentionally-malformed configurations or firmware updates to the terminals is much easier and doesn't require any satellite-specific knowledge. The satellite terminals (at least the router part of it) are just standard Linux embedded devices, so no special skills required.

If your objective is to disable the devices like they've done, attacking the "easy" layer is enough so why waste time on unnecessary complexity? Of course they might well have also done recon on the satellite side and collected valuable data they can use in the next round.

Re: SATCOM terminals under attack in Europe: a plausible analysis

#14
post #9
post #7

Earlier quoted context omitted.

Taking a country's infrastructure through a cyberattack is considered an act of war. Same as if you bombed the power generation infrastructure.

Sure, but can you prove it to the public in enough certainty to declare war? No. Suppose it was Russian flag, they could very easily just claim they were framed - and they very likely could’ve been.

> Sure, but can you prove it to the public in enough certainty to declare war?

This is not a court of law, proof is not what is missing to declare a war against Russia. They have a credible nuclear deterent, that is why war is not declared against them by other countries.

It is in fact a very sweet idea to think that a war declaration depends on meeting or not meeting some evidentiary standard.

Re: SATCOM terminals under attack in Europe: a plausible analysis

#15
post #11

Any other sources on this yet? This, if real, is big enough there should be multiple news articles.

The outage itself has already been widely reported (at least in EU media), especially the (potential) impact on wind electricity generation capacities:

https://www.reuters.com/business/energy/satellite-outage-kno...

Re: SATCOM terminals under attack in Europe: a plausible analysis

#16

Seems entirely plausible to me that someone pushed a firmware update which corrupted the firmware (even maybe at the fpga/bootcode level) and effectively bricked the devices. Not horribly complicated to do and once you've done it it would require physical access to recover each device individually. Is there a plausible explanation for who would do this, besides Russia? Is Viasat/Eutelsat a particularly good target fo…

Dumb Question here but my thoughts were - why not push the corrupted update to the sats? AKA hack the sat firmware? I'm fairly certain that they aren't wide open doors but still - I would guess that it would be a lot easier doing it that way. Perhaps it was both, or someting else entirely. It will make for an interesting read one day.

It's easy to buy an end-user terminal and tear it apart on your workbench to develop an understanding of how it works. I don't know about you, but I haven't seen any satellites on eBay recently.

Also, most satellites are intentionally as dumb as possible, just a "bent pipe" transponder, putting all the complexity on the ground stations which are easier to service if something goes wrong. There might not be much to do on the satellite itself.

Re: SATCOM terminals under attack in Europe: a plausible analysis

#17

Can someone versed in military doctrine / strategy talk about dealing with the uncertainty of a false-flag attack? Does the best-known approach just boil down to weighing the cost/benefit of (acting | not acting) x P(most likely aggressor | some other cause)? Or has someone figured out a better approach?

The purpose of a false flag is to drive a certain narrative, so it's always accompanied by incessant media coverage. That is not the case here, the attack is likely for genuine tactical purposes.

Re: SATCOM terminals under attack in Europe: a plausible analysis

#18
post #5

I've investigated network equipment before, my findings were that you shouldn't trust any of it and use a standard Linux box whenever possible. The worst was consumer-grade modems/routers with low-hanging fruits such as backdoors, "forgotten" telnet servers left enabled, shell command injection in the web UI, etc but even enterprise stuff had its problems (thankfully, at least on enterprise stuff you can disable the…

> why waste that access on breaking everything in a highly-visible way when you're better off silently sitting there and using the access to eavesdrop on everything

The subtle approach takes more time.

Take the PoV of the hypothetical Russian decision maker.. you can either take all them down now with something quick & dirty while the tanks are rolling, or inject a stealthy targeted piece of malware you haven't finished yet next week after Kiev is already in the hands of a puppet government....

Re: SATCOM terminals under attack in Europe: a plausible analysis

#19
post #7
post #4

Earlier quoted context omitted.

KA-SAT seems to be used for SCADA control of 11 Gigawatt worth of wind turbines in Germany, among other things [1]. Not sure at all if this was the intended/primary target, but Europe is certainly scrambling for every Watt at the moment... Also note that KA-SAT/Viasat and Eutelsat seem to be different platforms. I've seen reports of services based on the former being affected (e.g. SkyDSL [2]), but not the latter (Ko…

Taking a country's infrastructure through a cyberattack is considered an act of war. Same as if you bombed the power generation infrastructure.

If this was true and practical, there would be so many wars... pretty much every country has had some infrastructure hacked, most more than once, some by random groups, some by government sponsored hacking, some by exploiting outdated installation of services and some using very advanced techniques (eg stuxnet).

Re: SATCOM terminals under attack in Europe: a plausible analysis

#20

Earlier quoted context omitted.

Dumb Question here but my thoughts were - why not push the corrupted update to the sats? AKA hack the sat firmware? I'm fairly certain that they aren't wide open doors but still - I would guess that it would be a lot easier doing it that way. Perhaps it was both, or someting else entirely. It will make for an interesting read one day.

It's easy to buy an end-user terminal and tear it apart on your workbench to develop an understanding of how it works. I don't know about you, but I haven't seen any satellites on eBay recently. Also, most satellites are intentionally as dumb as possible, just a "bent pipe" transponder, putting all the complexity on the ground stations which are easier to service if something goes wrong. There might not be much to do…

With the right commands, you could flip the satellite by 180 degrees, move it from Europe to the pacific ocean, or crash it into one of its neighbors.

All geostationary satellites need to be capable of at least some station-keeping to correct for drift, move them to other service areas, or move them to a graveyard orbit at their end of life. (Unlike LEO, GEO satellites don't carry enough fuel for de-orbiting, and friction is essentially nonexistent at that altitude.)

That layer of commands is hopefully very well protected.

Post reply on HN