Hack.lu 2026

Satellites in the Sandbox: Hands-On Component Collusion and Aerospace C2 Evasion

As space infrastructure increasingly relies on Commercial Off-The-Shelf (COTS) hardware, the satellite supply chain has become a premier target for sophisticated adversaries. Traditional security reviews focus heavily on monolithic flight software, leaving a massive blind spot: malicious peripheral components that bypass initial testing to strike only when in orbit.
In this 90-minute hands-on workshop, we break out of traditional IT networks and dive straight into the aerospace ecosystem. We will explore the "SpyChain" attack surface—examining how supply chain malware can hide in auxiliary satellite modules, remain dormant using dynamic GNSS/GPS triggers, and evade telemetry baselines via multi-component evasion.
Attendees will get their hands dirty in a virtualized aerospace environment utilizing NASA’s open-source Core Flight Software (cFS) framework. Participants will play the role of both threat actor and defender: analyzing hidden file channels (FIFO pipes) used for component collusion, executing covert telemetry data exfiltration over simulated radio links, and testing the limits of aerospace threat matrices like SPARTA.


This workshop is a practical, simulation-driven exploration of hardware supply chain vulnerabilities and advanced evasion mechanics within small satellite frameworks. Rather than presenting theoretical attack vectors, this session relies on a fully virtualized, open-source aerospace environment to demonstrate Component Collusion—a novel evasion vector recently assigned to the SPARTA matrix (ID: DE-0012).
We will analyze how an adversary can fragment malware logic across seemingly benign, unauthenticated third-party COTS applications inside NASA's Core Flight Software (cFS) ecosystem. By shifting coordination from the highly monitored cFS Software Bus to local Linux operating system file interfaces (hidden named pipes/FIFOs), the threat vector successfully bypasses automated telemetry baselines and flight-readiness reviews.

Munara

security researcher focused on the resilience of critical infrastructure
background in offensive security