NASA (National Aeronautics and Space Administration) revealed information about a hack of its internal infrastructure that went undetected for approximately a year. It's worth noting that the network was isolated from external threats and that the attack was carried out from within using a Raspberry Pi board connected without authorization at the Jet Propulsion Laboratory (JPL).
This board was used by employees as an entry point to the local network. During the hacking of an external user's system with access to the gateway, the attackers were able to access the board and, through it, the entire internal network of the Jet Propulsion Laboratory, which developed the Curiosity rover and space telescopes.
Traces of intruders on the internal network were identified in April 2018. During the attack, unknown individuals were able to intercept 23 files, with a total size of about 500 MB, associated with missions to Mars.
Two of these files contained information subject to the prohibition on exporting dual-use technologies. In addition, the attackers gained access to the network of a Deep Space Network (DSN) satellite dish used to receive and transmit data to the spacecraft used in NASA missions.
Of the reasons that contributed to the implementation of hacking, the late removal of vulnerabilities in internal systems was called.
However, the audit found that the database inventory was incomplete and inaccurate, a situation that jeopardizes JPL's ability to effectively monitor, report, and respond to security incidents.
System administrators do not systematically update the inventory when adding new devices to the network. In particular, some of the current vulnerabilities remained unpatched for more than 180 days.
The division also incorrectly maintained the ITSDB (Information Technology Security Database) inventory database , which should reflect all devices connected to the internal network.
Specifically, it was found that 8 of the 11 system administrators responsible for managing the 13 study sample systems maintain a separate inventory table of their systems, from which they periodically and manually update information in the ITSDB database.
In addition, a systems administrator stated that he did not regularly enter new devices into the ITSDB database because the database update function sometimes failed to work.
The analysis showed that this database was carelessly filled and did not reflect the actual state of the network , including the fact that it did not take into account the Raspberry Pi board used by employees.
The internal network itself was not divided into smaller segments, simplifying the attackers' activities.
Officials feared cyberattacks would laterally cross the bridge into their mission systems, potentially gaining access and sending malicious signals to manned spaceflight missions using these systems.
At the same time, IT security officers stopped using DSN data because they feared it was corrupt and unreliable.
That said, NASA did not mention any names directly related to the April 2018 attack. However, some speculate that this could be related to the actions of the Chinese hacking group known as Advanced Persistent Threat 10, or APT10.
According to the complaint, investigations showed that a phishing campaign allowed spies to steal hundreds of gigabytes of data by accessing at least 90 computers, including computers from seven aviation, space and satellite technology companies, from three companies.
This attack makes it very clear that even organizations with the highest levels of security can suffer this type of event.
Commonly, these types of attackers tend to take advantage of the weakest links in computer security, that is, the users themselves.