Hack.lu 2026

Munara

security researcher focused on the resilience of critical infrastructure
background in offensive security


Sessions

10-22
09:30
30min
Satellites in the Sandbox: Hands-On Component Collusion and Aerospace C2 Evasion
Munara

As space infrastructure adopts Commercial Off-The-Shelf (COTS) hardware, satellite supply chains present critical blind spots. Traditional security reviews focus on monolithic flight software, missing malicious peripheral components that activate only in orbit. This session examines attack surface inside NASA’s open-source Core Flight Software (cFS) framework. We demonstrate Component Collusion - evasion vector assigned to the SPARTA matrix (ID: DE-0012), showing how malware logic can be fragmented across benign COTS applications. By routing covert coordination through hidden OS file interfaces (FIFOs) rather than the monitored cFS Software Bus, this threat evades telemetry baselines and flight-readiness reviews. The talk includes a live demonstration of dynamic GNSS triggers, covert telemetry exfiltration over simulated RF links, and targeted detection strategies for satellite frameworks.

topic: hack.lu
Europe
10-23
10:15
90min
Satellites in the Sandbox: Hands-On Component Collusion and Aerospace C2 Evasion
Munara

As space infrastructure increasingly relies on Commercial Off-The-Shelf (COTS) hardware, the satellite supply chain has become a premier target for sophisticated adversaries. Traditional security reviews focus heavily on monolithic flight software, leaving a massive blind spot: malicious peripheral components that bypass initial testing to strike only when in orbit.
In this 90-minute hands-on workshop, we break out of traditional IT networks and dive straight into the aerospace ecosystem. We will explore the "SpyChain" attack surface—examining how supply chain malware can hide in auxiliary satellite modules, remain dormant using dynamic GNSS/GPS triggers, and evade telemetry baselines via multi-component evasion.
Attendees will get their hands dirty in a virtualized aerospace environment utilizing NASA’s open-source Core Flight Software (cFS) framework. Participants will play the role of both threat actor and defender: analyzing hidden file channels (FIFO pipes) used for component collusion, executing covert telemetry data exfiltration over simulated radio links, and testing the limits of aerospace threat matrices like SPARTA.

topic: hack.lu
Schengen 1 & 2