Skip to content
safemode.space
All incidents
cyber espionage

German Aerospace Center (DLR) espionage intrusion (disclosed 2014)

Confidence in this reading:
moderate

What happened

In April 2014 Der Spiegel reported that computers at the German Aerospace Center's Cologne site had been infiltrated by espionage programs over a period of months. Reporting relayed from that account describes the operation as coordinated and systematic, affecting several computers used by researchers and system administrators, with some trojans built to destroy themselves on discovery and others staying dormant for months before activating. The German government is reported to have treated the case as extremely serious because it reached armament and rocket technology work, and DLR is reported to have called in the National Cyber Defence Centre in Bonn. Federal forensic examiners are reported to have found Chinese characters and repeated typographical patterns in the malicious code, but the same reporting carries an explicit caution that this may be camouflage and that another intelligence service could be responsible. No attribution was ever established publicly.

Everything public about this incident is one German news magazine's reporting, relayed by others. There is no vendor analysis, no sample hash, no government report, no named investigator, and no confirmed attribution: the Chinese-character evidence is reported together with the caution that it may be planted. The record is kept because DLR is a European space agency and the case is one of the few European ones SPARTA's bibliography cites, but it carries three technique edges: EX-0010 Malicious Code at direct/moderate, and PER-0003 Ground System Presence and REC-0001 Gather Spacecraft Design Information at derived/moderate. Three of SPARTA's five cited techniques are mapped and two are rejected. Note in particular that DLR operates spacecraft from the German Space Operations Center at Oberpfaffenhofen and this intrusion is at the Cologne site: no source links the two, which is why PER-0003 is graded derived rather than direct. It is mapped: it was recovered under decision 67, which retired the requirement of end-to-end reach to a spacecraft that had been the only ground for refusing it.

Attack vector

Not stated. The reporting describes the malware's behaviour on the compromised hosts but names no initial access vector.

Operational impact

None reported. No source connects the intrusion to DLR's spacecraft operations, to the German Space Operations Center, or to any mission.

Data compromised

Not established. The reporting states that the targeting reached armament and rocket technology work but identifies no document, dataset or system as taken.

Disclosed

2014-04-13

SPARTA techniques evidenced

Each row is a technique this record evidences, with the reasoning and the source that attests to it.

What relationship, confidence, and evidence mean on the rows below
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

  • Der Spiegel's account, relayed by AFP, describes espionage programs on researcher and system-administrator computers at DLR's Cologne site over a period of months, with some trojans built to destroy themselves on discovery and others staying dormant for months before activating. That is adversary-introduced executable logic running on victim systems. Moderate rather than high because everything public rests on one magazine's reporting, with no sample, no hash and no vendor analysis. Recovered per decision 67: previously rejected only because SPARTA scopes EX-0010 to the vehicle and the malware ran on office computers.

    https://phys.org/news/2014-04-german-space-centre-espionage.html

  • The intrusion is reported as coordinated and systematic across several computers over a period of months, with trojans staying dormant before activating: long-lived covert residence in a space organisation's ground-side systems, which is PER-0003's behaviour. Derived because no source names a mission system, and DLR's mission-operations centre at Oberpfaffenhofen is a different site from the compromised one at Cologne. Recovered per decision 67: the end-to-end-reach-to-a-spacecraft requirement that previously blocked this edge is the segment restriction the ruling retires.

    https://phys.org/news/2014-04-german-space-centre-espionage.html

  • The reporting states that what made the German government treat the case as extremely serious was that it was aimed at armament and rocket technologies, and that the compromised machines belonged to researchers and system administrators at a space research centre. REC-0001's subject is collection of the design picture of a spacecraft and its supporting ecosystem, including propulsion and the artefacts research staff hold. The edge is derived because no source names a document, a programme or a dataset, and because rocket technology is launch-vehicle rather than spacecraft design, which REC-0001 does not literally cover.

    https://phys.org/news/2014-04-german-space-centre-espionage.html

Considered and not mapped

These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.

  • Pre-positioning packages in provider portals, scheduler queues or ground station file drops. Not described.

  • Nothing in the reporting describes the actor mapping manufacturers, lots, custody handoffs or promotion gates. The victim being a research institute does not make the intrusion supply-chain reconnaissance.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.