A Flare study identified 437 distinct Hughes Multimedia VSAT terminals exposed through SNMP across 15 countries, along with five publicly discoverable satellite network-management servers running end-of-life enterprise Linux. The findings indicate that SNMP banners tied to confirmed device instances provide a substantially more reliable means of identifying exposed satellite ground-segment infrastructure than generic vendor-name searches over HTTP.
HTTP-based searches produced more than 5,000 results across 11 queries but yielded only about nine genuine devices; most results were replicated cloud-hosted static content, marketing platforms, demonstrations, or laboratory systems. Organizations operating satellite infrastructure should validate internet-exposure findings using unique identity fields, response-body comparison, network context, and plausible service exposure, and should restrict public SNMP access while remediating unsupported management-server operating systems.

Map this exposure pattern across your cloud, code, and identities.
5 events from the most recent confirmed update back to the earliest known activity.
The subsequent enterprise Linux major release later observed on three exposed satellite network-management servers reached end of life. The servers were reported to have kernels dated from 2016 through 2019.
An enterprise Linux release later observed on two publicly discoverable satellite network-management servers reached end of life. The servers were reported to have kernels built in 2013.
Across 11 HTTP queries, more than 5,000 results yielded roughly nine genuine devices; one mission-control product query returned 1,776 records, all but 18 sharing an identical cloud-hosted response body. The study concluded these results largely represented replicated web assets rather than deployed satellite systems.
The study passively identified five publicly discoverable satellite network-management servers, characterized as control-plane systems capable of operating remote terminals. Two ran an enterprise Linux release end-of-life since March 2017 and three ran a release end-of-life since November 2020.
A passive internet-exposure study identified 437 distinct Hughes Network Systems Multimedia VSAT terminals responding on UDP port 161. The terminals had distinct IP addresses and system-name identifiers and were associated with 13 networks, 28 organizations, and 15 countries.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.