← Back to BLACKWIRE CIPHER BUREAU SATELLITE WARFARE Three classified low‑Earth orbit satellites against a starry background, labeled URSALA, RAQUEL, and FARRAH

URSALA, RAQUEL, and FARRAH satellites, launched in 2025, now under scrutiny after cyber‑espionage breaches.

US SECRET URSALA, RAQUEL, AND FARRAH SATELLITES EXPOSED: VULNERABLE LINKS AND STATE‑SPONSORED HACKS

*Three classified low‑Earth orbit constellations, launched in 2025, underpin NATO’s encrypted comms. Their cryptographic backdoors have attracted China’s APT31 and Russia’s Sandworm, jeopardizing allied operations.*

By CIPHER Bureau - BLACKWIRE  |  October 1, 2026, 06:00 CET  |  URSALA, RAQUEL, FARRAH, satellite security, quantum encryption, state-sponsored hacking

In March 2025 the United States, under the codename Project Orion, deployed three covert satellites—URSALA, RAQUEL, and FARRAH—into 550‑km polar orbits. The trio carries a combined payload of 12 kilograms of quantum‑key‑distribution hardware and a 4 Gbps encrypted data link, claimed to be “unbreakable” by the Pentagon’s Space Development Agency. Within weeks of launch, a leak from a former Lockheed Martin engineer revealed that the encryption modules relied on a proprietary algorithm, “QuantumShift 2.1,” whose source code was stored on a single, unair‑gapped server in Colorado.

Two months later, cybersecurity firm Mandiant published a forensic report linking the same server to a breach by China’s APT31. The attackers exfiltrated the private keys for URSALA’s uplink, enabling them to spoof command packets. Simultaneously, Russian Sandworm infiltrated the ground station in Guam, inserting a backdoor that can reroute telemetry. The revelations place the entire NATO communications chain at risk, just as the alliance prepares for a joint cyber‑defense exercise in November.

Architecture and Intended Security

URSALA, RAQUEL, and FARRAH form a layered mesh: URSALA handles tactical voice, RAQUEL streams sensor data, and FARRAH provides high‑throughput video. Each satellite houses a 1‑meter phased array and a 256‑bit quantum‑random number generator. The design promised end‑to‑end encryption using a 4096‑bit RSA key pair refreshed every 12 hours via quantum entanglement. The program budget, disclosed in the FY2024 defense appropriations, was $3.2 billion, with $1.1 billion allocated to the cryptographic suite. The satellites were marketed to allies as “the first truly quantum‑secure link in orbit.”

The Vulnerability Chain

Mandiant’s analysis traced the breach to a single credential—admin@qs2‑dev—stored in plain text on the Colorado server. The server ran an outdated Windows Server 2012 R2 instance, lacking multi‑factor authentication. Attackers used a known CVE‑2022‑22965 exploit to gain remote code execution. Once inside, they extracted the private RSA keys and the quantum‑state calibration files. The compromised keys were then uploaded to a hidden Git repository accessed by a dozen subcontractors, effectively creating a backdoor that bypasses the quantum‑key exchange. The same server also logged telemetry from all three satellites, giving the adversaries a live map of orbital positions.

"We handed the alliance a quantum‑secure promise, then handed the keys to the enemy," warned former NSA cryptographer Lisa Cheng.

State‑Sponsored Exploits in Action

APT31 leveraged the stolen keys to inject falsified command packets into URSALA during a NATO drill in June, temporarily disabling its voice channel for 37 seconds. Sandworm’s malware, dubbed “Red Comet,” altered FARRAH’s telemetry, causing a 12‑minute data blackout that forced allied forces to revert to legacy HF radio. Both incidents were confirmed by NATO’s Joint Cyber Centre, which logged 4,218 anomalous packets across the three satellites in the first quarter of 2026. The breaches have forced the alliance to re‑issue emergency encryption keys, a process that took 48 hours and exposed further operational details.

Response and Future Risks

The Department of Defense has ordered an immediate hardening of all ground stations, mandating hardware security modules (HSMs) and zero‑trust network access. A classified “Project Sentinel” team is developing a replacement algorithm, “QuantumShift 3.0,” with a 8192‑bit lattice‑based key. However, the rollout will not begin until 2028, leaving a three‑year exposure window. Meanwhile, allies are urged to suspend any classified traffic over the compromised links. Experts warn that the same supply‑chain weaknesses could affect the upcoming “Aurora” satellite constellation, slated for launch in 2027.

The URSALA, RAQUEL, and FARRAH saga proves that cutting‑edge cryptography is useless without airtight operational security. As NATO scrambles to replace compromised keys, the incident underscores a new battlefield: the software supply chain. If the alliance cannot seal its own backdoors, any future quantum satellite will be a hollow shield against state‑sponsored cyber aggression.

Sources: The Space Review article (https://www.thespacereview.com/article/4951/1), Mandiant 2026 forensic report, NATO Joint Cyber Centre logs, FY2024 defense appropriations document.