Turla satellite downlink hijacking for command-and-control (2015 disclosure)
What happened
Kaspersky published in September 2015 an account of how the Turla espionage group hid its command-and-control infrastructure behind commercial satellite internet links. Downstream-only DVB-S satellite internet is one-way and unencrypted: the provider's broadcast reaches every receiver inside the beam, and it is only the receiving equipment that decides which packets it keeps. Turla assembled its own receive chain, a dish, a low-noise block downconverter, a DVB-S tuner card and a Linux PC, for under a thousand dollars, picked IP addresses in the provider's range that were unassigned or lightly used, and then had infected machines send C2 traffic to those addresses. The traffic went up over ordinary internet lines to the provider, came back down over the satellite beam, and Turla read it off the air. Replies were spoofed from a conventional line using the same source address, which the subscriber whose address had been borrowed would drop as traffic to a closed port. The effect is that the true location of the C2 endpoint cannot be determined from the address. Kaspersky reported abuse of downstream providers across the Middle East and Africa and dated the earliest indication of use to a sample compiled in November 2007.
The victim here is not a space mission. The satellite segment is the adversary's infrastructure, not the target, and the parties whose links are abused are commercial broadband providers and their subscribers. That inverts the usual reading of a space-incident record and is the reason three of SPARTA's six cited techniques are rejected: they describe an adversary acting on a spacecraft, and nothing here touches one. What the record does establish, with an unusually specific equipment list, is that a downlink's broadcast property is directly usable by anyone inside the footprint who buys a receive chain.
Attack vector
Passive reception of a commercial downstream-only DVB-S satellite internet beam using the adversary's own receive chain, combined with source-address spoofing of replies over conventional internet lines.
Operational impact
None to any spacecraft or to the satellite operator's own systems. The abuse is of the broadcast property of the downlink; no source reports the provider's infrastructure being compromised, and the subscribers whose addresses were borrowed are described as dropping the traffic rather than being affected by it.
Data compromised
None from the satellite operator. The link carries Turla's own C2 traffic to and from victims compromised elsewhere.
Affected segments
link, ground
Disclosed
2015-09-09
SPARTA techniques evidenced
Each row is a technique this record evidences, with the reasoning and the source that attests to it.
What relationship, confidence, and evidence mean on the rows below
- Relationship
What kind of link this is between the technique and the target.
Mitigates: the target actively prevents, detects, or recovers from the technique.
Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.
Triggers obligation: the technique occurring is what triggers the duty the target imposes.
Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.
- Confidence
How strongly the source supports this mapping, not how severe the technique is.
High: the source supports the mapping squarely.
Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.
Low: the source reaches the technique only in part.
- Evidence
How close to the source text the mapping was made.
Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.
Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.
Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.
Kaspersky describes Turla answering from a conventional internet line while forging the borrowed subscriber's address, so that the C2 endpoint presents to the victim as a legitimate host at a legitimate address and the true location cannot be determined. DE-0004's subject is presenting as an authorised origin across protocol and organisational boundaries so activity is processed without scrutiny. Moderate rather than high because DE-0004's worked examples are telecommand frames and station fingerprints, not IP headers.
RD-0001.01 opens by distinguishing itself from compromising an existing station: the adversary acquires or assembles its own RF receive stack, and with that kit can passively collect. Kaspersky itemises exactly such a stack, a satellite dish, a low-noise block downconverter, a DVB-S tuner card and a Linux PC, at a stated cost, and describes it being used for passive collection off the beam. The technique's own text and the source's description are the same activity.
The mechanism is downlink interception in the literal sense: traffic addressed to other parties is recovered by receiving the satellite-to-ground broadcast. But SPARTA writes REC-0005.02 with spacecraft telemetry, ephemerides and payload products as the content, and the content here is commercial subscriber IP traffic that the spacecraft is merely relaying. The behaviour matches and the subject matter does not, which is why the edge is derived and moderate. This is the same endpoint-mismatch question flagged on IA-0007.02 in the Viasat record and it needs one editorial ruling covering both.
Considered and not mapped
These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.
EX-0014 is forging inputs that onboard logic treats as truth: sensor measurements, bus messages, navigation signals. Turla forges an IP source address on the terrestrial internet.
Explicitly internal spacecraft command/data paths: 1553, SpaceWire, CAN. Not remotely applicable. Mapping it would be the clearest scope error available here.
Tempting, because a secondary link is co-opted as a covert data path. But EXF-0004's links are the spacecraft's own secondary channels, rekeying, emergency commanding, beacons, used to move data off the spacecraft. Re-evaluated under decision 67 and held. The ruling removes the off-the-spacecraft half, but the other half is a channel-role distinction that survives it: what Turla rides is a commercial provider's primary broadcast downlink, exploited for being unencrypted and receivable by anyone in the beam, not a sparsely-supervised secondary channel co-opted out of its intended function.
Turla buys and operates its own DVB-S tuner. It compromises nobody's radio. The technique is about manipulating a radio's pipeline, bitstreams or update channels; none of that happens.
Nothing of the provider's is compromised. The provider's beam is used exactly as designed; the design is the vulnerability.
Sources
The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.
A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.
- Satellite Turla: APT Command and Control in the SkyVendor threat intelligence
Tier 2: Named vendor research with the receive-chain hardware itemised, the cost stated, and the abused provider regions listed. The most technically specific public account of the technique.
- Satellite Turla: APT Command and Control in the Sky (solution paper)Vendor threat intelligencecorroborating
Tier 2: Same vendor, same research, packaged as a customer-facing paper. Listed because SPARTA's bibliography cites it, not because it adds evidence.
Every source SafeMode Space reproduces, and on what terms: sources and attribution.