Skip to content
safemode.space
All incidents
2008-07-25 (approximate)
malware deployment
space

W32.Gammima.AG worm on International Space Station laptops (2008)

Confidence in this reading:
moderate

What happened

In August 2008 NASA confirmed that laptops aboard the International Space Station were infected with W32.Gammima.AG, a Windows worm first detected terrestrially in 2007 that spreads by copying itself to removable media and steals credentials for online games. The affected machines were crew support laptops used for purposes such as nutritional tracking and email, not the station's command and control computers. The ISS has no direct internet connection and ground-to-station traffic is scanned before transmission. NASA characterised the infection as a nuisance, said viruses had reached station laptops on several previous occasions, and indicated that the likely route was a personal flash drive or USB storage device carried up by a crew member. Contemporaneous reporting noted that some ISS laptops lacked antivirus software. NASA said it was reviewing the incident and might make procedural recommendations.

The malware is not the point: Gammima.AG is a low-risk credential stealer aimed at online games and it had no mission function aboard the station. Three structural facts carry the record, each stated by a source. An air gap is not a control against carried media, which is why the absence of a direct internet connection makes the infection more interesting rather than less. Recurrence was normal, on NASA's own account, so the acknowledged pattern is more informative than the single event. And endpoint hygiene on the crewed segment was incomplete, with some laptops reported to lack antivirus, which is the kind of control gap NIS2's technical and organisational measures duties address. Note that all three techniques SPARTA's bibliography associates with this event are rejected here, including IMP-0006: the worm's purpose is credential theft, but no source reports exfiltration and the station has no direct internet path for it. A technique's purpose is not its effect.

Attack vector

Commodity Windows worm propagating via removable media, reaching the station on a personal flash drive or USB storage device carried up by a crew member. The route is NASA's stated hypothesis, not a confirmed finding.

Operational impact

None reported. NASA characterised the infection as a nuisance; the command and control computers were not affected.

Affected segments

space

Disclosed

2008-08-26

SPARTA techniques evidenced

Each row is a technique this record evidences, with the reasoning and the source that attests to it.

What relationship, confidence, and evidence mean on the rows below
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

  • EX-0010's subject is executable logic introduced so that it runs on the vehicle. A Windows worm executing on laptops aboard the station is that, and it is described by the sources rather than inferred from them. The technique's usual delivery examples, update paths, file transfer services and table loaders, do not match here, but the technique is defined by the execution on the vehicle, not by the delivery route.

    https://nasawatch.com/iss-news/more-on-iss-virus/

  • IA-0011 covers peripherals and removable media that the spacecraft or its support equipment ingests during development, integration and test, or on-orbit operations, and names removable storage explicitly. NASA's stated hypothesis for how the worm reached orbit is a personal flash card or USB storage device brought aboard by a crew member. The edge is derived because that route is a hypothesis rather than an established finding, and NASA did not confirm it.

    https://nasawatch.com/iss-news/more-on-iss-virus/

Considered and not mapped

These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.

  • Also in the bibliography here. No source says any ground system was compromised. The stated hypothesis is a personal device carried up; where the infection originated before that is not established by anyone.

  • NASA's characterisation is nuisance. No source reports any operational effect.

  • In SPARTA's bibliography against the SpaceRef article. Gammima.AG steals online-game credentials, and that is what it is for. But no source reports that anything was exfiltrated from the station, and the station has no direct internet connection for the malware's exfiltration channel to use. A technique's purpose is not its effect.

  • Also in the bibliography here, and the natural-looking fit for "how did it get up there". Rejected because RD-0004.02 describes an adversary deliberately pre-positioning packages on compromised or leased infrastructure for fast execution. Nothing here is deliberate: this is commodity malware travelling on an item of personal kit. IA-0011 is the honest mapping and it is made.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

  • SpaceRef · 2008-08-26

    Tier 2: The canonical first report and the article SPARTA's bibliography cites against EXF-0007, IMP-0006 and RD-0004.02, all three of which are rejected in this record. Space-trade reporting rather than a NASA publication. Its migrated URL returned no readable body on retrieval; the content used reaches the record through NASA Watch and Schneier, both read directly.

  • Virus Infects the Space Station
    Researcher blog
    supporting

    Schneier on Security · Bruce Schneier · 2008-08-27

    Tier 3: A digest quoting SpaceRef, Wired and the BBC rather than independent reporting. Tier 3 on that basis, despite the author's standing.

  • The Guardian · 2008-08-28

    Tier 3: General newspaper reporting. Tier 3 as general news; it is one of the two URLs SPARTA's bibliography carries for the ISS Gammima infection.

  • More on ISS Virus
    Researcher blog
    corroborating

    NASA Watch · 2008-08-28

    Tier 2: Long-running specialist NASA-watching site with direct access to agency statements. Read directly in this session; both technique edges rest on it.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.