A coalition of 12 countries led by the UK and US has issued a joint advisory warning that Russian state-backed Advanced Persistent Threat groups are actively compromising poorly secured routers and network devices worldwide, including those used by satellite ground stations and space operations centers.
The advisory, jointly published by cybersecurity agencies from the Five Eyes nations and allied countries, details how threat actors affiliated with Russian military intelligence are exploiting weak SNMP credentials, default passwords, and unpatched firmware to gain persistent access to edge network devices. These compromised routers serve as stealthy footholds for espionage, data exfiltration, and potential disruptive operations against critical infrastructure — including space sector networks.
Satellite ground stations and space operations centers are particularly vulnerable because they often rely on remote-site routers with limited security monitoring. A compromised router at a ground station could allow attackers to intercept telemetry, disrupt satellite command-and-control links, or pivot deeper into space agency and commercial satellite operator networks. The advisory specifically notes that the targeting extends across critical infrastructure sectors, of which space communications infrastructure is a key component.
Organizations in the space sector should immediately audit router configurations, disable SNMP where not required, enforce strong unique credentials, and ensure all network equipment firmware is up to date. The joint advisory includes indicators of compromise and detection guidance for space operators to identify potential router compromises before they escalate into larger breaches.