OPS-SAT in-orbit cybersecurity demonstration (Thales Alenia Space, CYSAT 2023)
What happened
For the third edition of CYSAT, held at Station F in Paris on 26-27 April 2023, ESA opened its OPS-SAT nanosatellite to a controlled offensive-security demonstration. A four-person Thales Alenia Space team, working to a scenario designed by CYSEC and supervised throughout by ESA, used ordinary experimenter access to OPS-SAT's payload application environment as its starting point. It uploaded software that appeared harmless and carried a deserialization flaw, exploited that flaw for arbitrary code execution, escalated to root through operating-system weaknesses, crossed the unsegmented CAN bus into subsystems the payload was not designed to reach, and established persistence by injecting malicious bytecode into a Java archive. The demonstrated effects were modification of the satellite's camera imagery with chosen geographic areas masked, alteration of its pointing direction, and concealment of the team's activity from ESA. ESA subsequently updated the security systems at OPS-SAT's SMILE control centre to remove the demonstrated attack path.
A sanctioned, ESA-supervised exercise, not an adversary operation. The deserialization flaw was planted by the team so that the uploaded artefact would not read as malicious to a scanner, so its presence is not a finding about OPS-SAT or about spacecraft generally; The Aerospace Corporation's analysis calls the scenario manufactured and states that with the relevant countermeasures implemented the attack would have failed. What the technique edges record is that the tactics executed against a live spacecraft in orbit and produced the stated effects on its payload output and attitude. Distinct from the existing draft opssat-firmware-exploitation-2023, which records the separate Willbold et al. Space Odyssey analysis of the same spacecraft.
Attack vector
Legitimate experimenter upload to the payload application environment carrying a planted deserialization flaw, exploited for code execution, then privilege escalation to root and lateral movement across an unsegmented CAN bus.
Operational impact
None outside the exercise. OPS-SAT is a flying laboratory ESA offers for software too risky for operational satellites, and ESA states it was fully isolated from operational systems throughout.
Affected segments
space, ground
Disclosed
2023-04-25
SPARTA techniques evidenced
Each row is a technique this record evidences, with the reasoning and the source that attests to it.
What relationship, confidence, and evidence mean on the rows below
- Relationship
What kind of link this is between the technique and the target.
Mitigates: the target actively prevents, detects, or recovers from the technique.
Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.
Triggers obligation: the technique occurring is what triggers the duty the target imposes.
Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.
- Confidence
How strongly the source supports this mapping, not how severe the technique is.
High: the source supports the mapping squarely.
Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.
Low: the source reaches the technique only in part.
- Evidence
How close to the source text the mapping was made.
Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.
Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.
Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.
Thales and ESA both record that the team concealed its activity from ESA while the imagery manipulation was in progress. DE-0003's subject is manipulating the housekeeping and control values operators and autonomy rely on to judge activity and command hygiene. Neither source names the mechanism of concealment, so the edge is derived from the stated outcome rather than from a described action.
The team obtained arbitrary code execution by exploiting a deserialization defect in software running on the vehicle, then used operating-system weaknesses to elevate from the payload application to root. The behaviour is EX-0009.01's and is described rather than inferred. Confidence is moderate rather than high because the deserialization flaw was planted by the team for the exercise: the exploitation is real, the defect is not a finding about OPS-SAT.
ESA states the team accessed the control layer and altered the satellite's pointing direction, and Thales states the team took control of the systems managing the payload's positioning, attitude control and camera. That the attitude was changed is stated. Whether it was changed by modifying the ADCS parameters and control constants EX-0012.08 covers, or by issuing commands through the control layer, is not, so the edge is derived from the stated effect.
The demonstrated effect was falsifying what reached the ground: the satellite's camera images were modified and chosen geographic areas were masked. IMP-0001 is defined as manipulation, distortion or falsification of information to induce a reaction prejudicial to the victim's interests, and the point of masking an area in downlinked imagery is that the operator does not know it was masked.
The demonstration began with standard experimenter rights in OPS-SAT's payload application environment and from there reached subsystems outside it. LM-0001's subject is the pivot through the host-payload boundary via the gateways a hosted payload legitimately uses, which is the path The Aerospace Corporation's analysis describes step by step.
The Aerospace Corporation's analysis names the absence of CAN bus segmentation as the weakness that permitted payload-originated messages to reach components not designed for payload communication. LM-0002 is defined as leveraging exactly that flat-architecture property, so the source names the technique's own mechanism.
Root-level persistence was established by injecting malicious bytecode into a Java archive, which The Aerospace Corporation's analysis calls a software backdoor. PER-0002.02 describes code paths crafted or later inserted to provide privileged functionality on cue, which is what an injected bytecode backdoor in a running JAR is.
Considered and not mapped
These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.
Tempting, because the operator's picture was falsified. But DE-0002's scope is ground-side telemetry reception, processing or display, and the falsification here happened on board before downlink. The ground received an honest copy of dishonest data. Mapping it would repeat the
SI-7scope error the curation rules already name.Persistence was in a Java archive, not in boot memory.
Mapped on the other OPS-SAT record, for the Willbold work, where it belongs. Nothing here operates beneath the software stack.
Imagery was altered, not exfiltrated. No source reports data leaving the mission.
Sources
The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.
A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.
- Thales seizes control of ESA demonstration satellite in first cybersecurity exercise of its kindOther
Tier 2: First-party account by the team that performed the exercise. Authoritative on what was attempted and achieved; a press release, and an interested party on framing.
Tier 2: Named technical analysis by researchers at a federally funded research and development centre with no part in the exercise. Published on a corporate blog rather than peer-reviewed.
Tier 2: First-party account by the spacecraft's operator and the exercise's supervisor. Authoritative on the controls in place and on what was changed afterwards; an interested party on framing.
Every source SafeMode Space reproduces, and on what terms: sources and attribution.