Skip to content
safemode.space
All incidents
2023-04-25 (approximate)
security research
space

OPS-SAT in-orbit cybersecurity demonstration (Thales Alenia Space, CYSAT 2023)

Confidence in this reading:
high

What happened

For the third edition of CYSAT, held at Station F in Paris on 26-27 April 2023, ESA opened its OPS-SAT nanosatellite to a controlled offensive-security demonstration. A four-person Thales Alenia Space team, working to a scenario designed by CYSEC and supervised throughout by ESA, used ordinary experimenter access to OPS-SAT's payload application environment as its starting point. It uploaded software that appeared harmless and carried a deserialization flaw, exploited that flaw for arbitrary code execution, escalated to root through operating-system weaknesses, crossed the unsegmented CAN bus into subsystems the payload was not designed to reach, and established persistence by injecting malicious bytecode into a Java archive. The demonstrated effects were modification of the satellite's camera imagery with chosen geographic areas masked, alteration of its pointing direction, and concealment of the team's activity from ESA. ESA subsequently updated the security systems at OPS-SAT's SMILE control centre to remove the demonstrated attack path.

A sanctioned, ESA-supervised exercise, not an adversary operation. The deserialization flaw was planted by the team so that the uploaded artefact would not read as malicious to a scanner, so its presence is not a finding about OPS-SAT or about spacecraft generally; The Aerospace Corporation's analysis calls the scenario manufactured and states that with the relevant countermeasures implemented the attack would have failed. What the technique edges record is that the tactics executed against a live spacecraft in orbit and produced the stated effects on its payload output and attitude. Distinct from the existing draft opssat-firmware-exploitation-2023, which records the separate Willbold et al. Space Odyssey analysis of the same spacecraft.

Attack vector

Legitimate experimenter upload to the payload application environment carrying a planted deserialization flaw, exploited for code execution, then privilege escalation to root and lateral movement across an unsegmented CAN bus.

Operational impact

None outside the exercise. OPS-SAT is a flying laboratory ESA offers for software too risky for operational satellites, and ESA states it was fully isolated from operational systems throughout.

Affected segments

space, ground

Disclosed

2023-04-25

SPARTA techniques evidenced

Each row is a technique this record evidences, with the reasoning and the source that attests to it.

What relationship, confidence, and evidence mean on the rows below
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

Considered and not mapped

These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.

  • Tempting, because the operator's picture was falsified. But DE-0002's scope is ground-side telemetry reception, processing or display, and the falsification here happened on board before downlink. The ground received an honest copy of dishonest data. Mapping it would repeat the SI-7 scope error the curation rules already name.

  • Persistence was in a Java archive, not in boot memory.

  • Mapped on the other OPS-SAT record, for the Willbold work, where it belongs. Nothing here operates beneath the software stack.

  • Imagery was altered, not exfiltrated. No source reports data leaving the mission.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.