APT28 intrusion at a US satellite communications provider (disclosed 2022)
What happened
At CYBERWARCON in 2022 MJ Emanuel, an incident response analyst at the US Cybersecurity and Infrastructure Security Agency, described an intrusion the agency had worked earlier that year at a satellite communications provider whose customers include US critical infrastructure operators. The entry point was a virtual private network left unpatched against a 2018 vulnerability, which allowed the intruders to scrape credentials from every active session. Movement inside the network was made easier by the provider's practice of using the same credentials for emergency accounts as for ordinary ones, so the stolen material worked in more places than it should have. Emanuel is reported as saying the group appeared to have been in the networks for months. CISA also found supervisory control and data acquisition traffic crossing the network unencrypted. The activity was attributed to APT28, Russian military intelligence. Neither the provider nor any exfiltrated data has been named publicly, and CISA published no advisory on this case.
The account is a government incident responder's, which is the strongest kind of source for this corpus, but it reaches the public only through one trade-press report of a conference talk: CISA issued no advisory, the provider is unnamed, and there is no document to check the reporting against. Every edge is therefore derived. Note also what is absent: all three techniques SPARTA's bibliography cites for this incident (downlink exfiltration, exfiltration via a compromised ground system, and theft) assert data loss, and the source reports none.
Attack vector
Exploitation of a 2018 vulnerability in an unpatched VPN appliance to scrape credentials from active sessions, followed by reuse of those credentials, including for emergency accounts sharing credentials with ordinary ones, to move through the network.
Operational impact
None reported. No source states any service outage, any effect on a spacecraft, or any manipulation of the SCADA traffic that was found crossing the network in the clear.
Data compromised
Not stated. The only data described is credentials scraped from VPN sessions.
Affected segments
ground
Disclosed
2022-12-16
SPARTA techniques evidenced
Each row is a technique this record evidences, with the reasoning and the source that attests to it.
What relationship, confidence, and evidence mean on the rows below
- Relationship
What kind of link this is between the technique and the target.
Mitigates: the target actively prevents, detects, or recovers from the technique.
Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.
Triggers obligation: the technique occurring is what triggers the duty the target imposes.
Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.
- Confidence
How strongly the source supports this mapping, not how severe the technique is.
High: the source supports the mapping squarely.
Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.
Low: the source reaches the technique only in part.
- Evidence
How close to the source text the mapping was made.
Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.
Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.
Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.
The compromised entity is a satellite communications provider, and IA-0007's scope covers the ground infrastructure such a provider runs, including identity providers and gateways. The edge is derived rather than direct because the source describes an enterprise perimeter (a VPN appliance) and lateral movement inside a corporate network, and does not state that mission control software, antenna control, modems or any commanding path was reached.
The reported mechanism of movement is credential reuse across a trust boundary that was supposed to be separate: emergency accounts carried the same credentials as ordinary ones, so material harvested once opened more of the network. That is LM-0007's subject, crossing boundaries that rely on trust rather than isolation by reusing legitimate credentials. Derived because LM-0007's worked examples are spacecraft and constellation boundaries (C&DH to payload, crosslink routers) and the traversal here is between enterprise enclaves.
PER-0005 is the use of acquired valid credentials to sustain access over extended periods without triggering access alarms. The source reports both halves: credentials scraped from active VPN sessions, and an actor that appeared to have been in the networks for months. This edge and the LM-0007 edge rest on adjacent but distinct statements, the dwell time and the credential reuse, rather than on one fact counted twice. Derived because no source states that credentials were the mechanism by which the months of access were maintained.
Considered and not mapped
These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.
Recording spacecraft-to-ground traffic: telemetry, recorder playbacks, payload products. Nothing in the source describes any RF collection at all.
The exfiltration technique, requiring that data was siphoned. The source names no exfiltrated data and no exfiltration tooling. Compare the Thrip record, where this edge is mapped, at moderate, because an infostealer and a file-transfer client were named.
Same problem, and IMP-0006 additionally requires the stolen data to be the spacecraft's mission product.
Sources
The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.
A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.
Tier 3: Named security trade outlet reporting a named government incident responder's conference presentation. The underlying account is a government agency's, but CISA published no advisory on this case, so the trade report is the only public record and cannot be checked against a primary document.
Every source SafeMode Space reproduces, and on what terms: sources and attribution.