China-Singapore security team claims breakthrough in hacking Starlink terminals


A team of cybersecurity experts has announced they successfully compromised the latest Starlink user terminals, crossing the security boundaries of the world’s largest satellite constellation.

In a post on its social media account on Tuesday, Darknavy, an independent cybersecurity research institute headquartered in Singapore and Shanghai, said it had used sophisticated hardware attacks to gain full administrative control over the terminals, allowing it to run any custom code on the devices.

This gives researchers unprecedented freedom, according to the pot, by reopening a long-missing entry point for in-depth security studies of the Starlink satellite system.

Starlink, SpaceX’s low-Earth-orbit satellite internet service, works by connecting user terminals to satellites in near-Earth orbit, which then relay data through ground gateways to the wider internet.

As newer satellites are gradually equipped with laser links, some satellites can also communicate directly with one another via laser, reducing reliance on ground stations while improving transmission speeds and expanding global coverage.

In battlefield conditions like those in Ukraine, where no local ground gateways exist, Starlink terminals can still gain access to the internet by routing signals through satellites that connect to gateways in neighbouring countries.

The terminal acts as both an antenna and a router, making it a critical node for direct communication with the satellites.

Until now, research into the satellite system’s security had largely stalled because the terminals could not be hacked.

At the Black Hat USA conference in 2022, Lennert Wouters of KU Leuven showed an attack on the first-generation Starlink antenna using voltage fault injection – an advanced hardware attack method.

SpaceX later added targeted defences into its models, and for years, multiple top international research teams failed to breach the updated terminals.

Last March, Darknavy bought a Starlink Standard Actuated terminal in Singapore, disassembled its antenna, and began analysing its firmware.

At the time, the company noted in a blog post that “developers and hackers contend not only in the digital realm but also against the constraints of cosmic physics”.

Now, by taking control of the terminal, researchers might be able to legally explore the interaction between Starlink satellites and ground equipment – simulating, injecting, intercepting, and analysing communication protocols to uncover vulnerabilities across the entire satellite network.

Darknavy’s case shows that even under the latest and strongest protections, systems can still have weaknesses.

The firm said on Tuesday that further details of the research could not be disclosed at this stage and the official website would serve as the main source of information.

The South China Morning Post has contacted SpaceX for comment about the findings. -- SOUTH CHINA MORNING POST

 

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Next In Aseanplus News

US university to pay US$2.1mil settlement over claims it didn’t disclose China ties
Four teens drown in Johor: Body of last victim found after four days
Can Chinese sleeper hit 'Dear You' conquer the US box office next?
Hong Kong Nepalese man searches for cousin missing in flood: ‘I cannot sleep’
US targets China’s global trade surplus at G20 meeting ahead of Xi-Trump summit
Zahid's no-show at PAS muktamar doesn't signal end of alliance in Melaka polls, says Takiyuddin
Pang Ron gets another shot at China Masters glory with new partner Pei Jing
No haze deaths reported nationwide, illness cases drop
Philippines Vice President Duterte posts bail after arrest order for alleged threats against Marcos
Mass poisonings cast doubt on free meals reforms

Others Also Read