Blogs
The latest cybersecurity trends, best practices, security vulnerabilities, and more
The Cyber Implications of the New Space Race
By Ryan Slaney · September 2, 2026
I’ve always suffered from a bit of a split personality. By night, I’m an unapologetic space nerd, watching rocket launches live-streams and tracking the technical milestones of humanity’s push back to the Moon and toward Mars. By day, I’m a cybersecurity professional, hunting through threat telemetry, tracking advanced persistent threats (APTs), and watching geopolitical conflicts play out in 1s and 0s.
Lately, those two worlds have been colliding.
If you look closely at global launch pads right now, you’ll notice a striking visual phenomenon occurring. China is rolling out rockets—like Space Pioneer’s Tianlong-3, LandSpace’s Zhuque-3, and iSpace’s Hyperbola 3—that look remarkably familiar. They are roughly 70-meter-tall, slender, two-stage medium-lift rockets powered by a cluster of nine engines, utilizing aerodynamic grid fins for a controlled vertical descent. To a casual observer, they look like clones of the SpaceX Falcon 9.
In aerospace engineering, some degree of these similarities can be dismissed as "convergent evolution"—the idea that physics dictates the math, and if you want an optimal reusable rocket, this is just what it has to look like. But as a cyber professional and former intelligence officer, I look at the breakneck speed at which China’s commercial space sector has bypassed a decade’s worth of explosive research and development (R&D), trial-and-error, and I have to ask: Is it physics, or is it espionage?
China’s proven playbook
If the idea of state-sponsored data exfiltration reshaping physical manufacturing sounds like a conspiracy theory, it’s only because you haven't been paying attention to the last twenty years of geopolitical cyber history. We have seen this exact movie play out before, most notably in our skies.
In 2016, a Chinese national named Su Bin pled guilty in a U.S. federal court for his role in a massive, multi-year cyber-espionage conspiracy conducted in tandem with the People’s Liberation Army (PLA). Their targets? Major Western defense contractors. Their haul? Terabytes of highly classified data, including flight test plans and structural blueprints for the C-17 transport plane, the F-22 Raptor, and the F-35 Joint Strike Fighter.
In an intercepted email to his military handlers entered into court evidence, Bin explicitly bragged that the stolen files would allow China to "rapidly catch up with U.S. levels…”
The physical manifestations of that hack are now flying missions. Shortly after the breaches, China’s flagship stealth fighter, the Chengdu J-20, suddenly underwent radical, overnight aerodynamic design overhauls. Today, China's carrier-based stealth fighter, the Shenyang J-35, looks so structurally identical to the American F-35 that defense analysts openly refer to it as a twin-engine clone.
This "fast-follower" playbook isn’t reserved for the military, either. In the civilian sector, Chinese wind turbine giant Sinovel was criminally convicted in 2018 for the multi-million-dollar theft of proprietary software source code from American Superconductor (AMSC), nearly bankrupting the U.S. firm while cloning their product. From high-speed bullet trains to heavy hydraulic machinery, the strategy remains unvaried: bypass the agonizingly slow, multi-billion-dollar R&D failure phase by letting the West invent the technology, steal the data, and jump straight to manufacturing.
The identical silhouettes of China's newest rockets are simply the latest chapter of this playbook, adapted for the cislunar age.
China’s 15th five-year plan: Marching orders for cyber hunters
In threat intelligence, we know that Chinese industrial policy directly dictates state cyber-espionage operations. China’s formal policy documents are not vague manifestos—they serve as explicit, highly coordinated collection mandates. When Beijing formalizes an economic milestone, it acts as a corporate task list for state-owned enterprises (SOEs) and a target list for its intelligence services and their cyber espionage teams.
China’s newly ratified 15th Five-Year Plan (2026–2030) puts a massive bullseye directly on Western aerospace. Transitioning from the raw breakthroughs of the previous five years, this new national plan mandates absolute integration, industrial scaling, and cost-reduction across three distinct pillars:
- The reusable launch mandate: The plan explicitly orders the aerospace sector to "develop lighter launch vehicles with reusable capabilities similar to aircraft" to drastically depress payload-to-orbit costs.
- Integrated mass production: Moving away from bespoke, state-directed launch projects, the plan demands a unified, commercialized manufacturing ecosystem capable of turning out standard-diameter rockets and satellites on an assembly line.
- Low Earth orbit (LEO) real estate: Recognizing that LEO slots and radio frequencies are finite resources, the plan mandates a frantic sprint to build out the sovereign, 15,000-satellite Qianfan (Spacesail) megaconstellation to achieve phased parity with Western infrastructure.
The geopolitical pressure of this plan creates an immense burden of velocity. The leadership teams of state agencies and commercial NewSpace startups have their careers and funding directly tied to hitting these unyielding 2030 deadlines. If you are a Chinese cyber unit tasked with helping your nation dominate space, you don't wait for domestic engineers to slowly solve complex vertical landing code or thermal metallurgy over a decade. You hack the supply chain of the company that already perfected it.
China is no longer just "catching up"
The average layman still views the space race through a nostalgic, Cold War lens: NASA is the undisputed leader, and everyone else is just trying to mimic Apollo-era achievements.
That assumption is dangerously outdated.
While the West has been distracted by political debates and supply chain delays, Beijing has quietly built a world-class, independent space infrastructure. Consider what the general public often misses:
- The Tiangong Space Station: While the International Space Station (ISS) approaches its retirement, China’s fully operational Tiangong ("Heavenly Palace") space station is permanently crewed, hosting long-duration astronaut rotations and advanced orbital research.
- Unprecedented lunar firsts: China’s robotic Chang'e-6 mission accomplished something no nation — including the United States — had ever done. It successfully landed on the Moon’s uncharted far side and returned pristine soil samples back to Earth.
- The 2030 Moon rush: China's upcoming lunar missions are targeting the Moon’s water-ice-rich South Pole to test 3D-printing structures out of lunar dust. They are on a locked-in trajectory to land Chinese astronauts on the lunar surface by 2030, running a parallel track to NASA’s Artemis program.
China doesn’t need to steal basic rocket science anymore; they have plenty of brilliant minds. What they need is velocity. They are locked in a high-stakes sprint against the West, and in a race that tight, you can't waste years blowing up prototypes on a test stand.
The hybrid clones: Zhuque-3 and Hyperbola-3
This need for velocity is exactly why the cloning phenomenon goes far deeper than a simple copy-paste of a 2010s-era Falcon 9. Look at LandSpace’s Zhuque-3 or i-Space’s upcoming Hyperbola-3.
Visually, they check every Falcon 9 box: the 4.5-meter diameter, the grid fins, and the structural silhouette. But under the hood, the internal plumbing tells a fascinating story of technological leapfrogging.
Instead of copying the Falcon 9’s kerosene-burning engines, both the Zhuque-3 and Hyperbola-3 utilize liquid methane and liquid oxygen (Methalox). Furthermore, the Zhuque-3 features a stainless steel hull.
If those specs sound familiar, it's because they are the exact material science breakthroughs and chemical choices Elon Musk implemented for SpaceX's Starship.
In essence, Chinese engineers appear to be "Frankenstein-ing" Western aerospace IP. They have taken the highly optimized, operationally proven aerodynamic form factor of the Falcon 9 and stuffed it with the bleeding-edge propulsion chemistry and metallurgy of Starship. It is an optimization shortcut designed to slash their launch costs overnight and fuel their own massive broadband megaconstellations.
The frantic demand for this rapid optimization materialized in spectacular, concrete fashion on July 10, 2026. During the maiden flight of CASC’s Long March 10B, China bypassed a decade of SpaceX-style landing leg evolution by executing a completely novel maneuver: catching a 63-meter-tall descending orbital booster in a giant, hydraulically damped net strung across a recovery ship in the South China Sea. By utilizing four deployable hooks near the grid fins to snag tensioned steel cables, Chinese engineers managed to shift the immense structural weight and complexity of landing legs entirely off the vehicle and onto the sea-based infrastructure—maximizing payload capacity and aiming for a re-flight of the exact same booster before the year ends.
The catch was a massive, unprecedented milestone achieved on a rocket’s very first flight; a feat that mathematically signals China has successfully bypassed the agonizingly slow R&D failure phase to achieve immediate, operational reusability parity.
The stakes: Why launch velocity is a national security crisis
For China, this isn't just about seeking prestige and international legitimacy. Winning this modern space race delivers terrifyingly concrete, strategic military advantages.
When a nation masters high-cadence, reusable medium-to-heavy lift rocketry, they unlock capabilities that completely reshape global defense:
- The megaconstellation hegemony: To control the future of the global internet, you need an endless conveyor belt of rockets. By dominating these orbital planes and locking down finite radio frequencies, Beijing can challenge Starlink’s global monopoly and control information flows across the Global South.
- Tactical rapid-launch capabilities: Reusable rockets give a military the power to replace assets on the fly. If a hot conflict breaks out on Earth, China can use these rapid-turnaround boosters to instantly deploy purpose-built satellites into low Earth orbit. This means an on-demand flood of high-resolution reconnaissance satellites, GPS-spoofing constellations, and signal-jamming payloads capable of blinding Western forces over a theater like the Taiwan Strait.
- Lunar "soft annexation": While the Outer Space Treaty strictly prohibits nations from claiming sovereignty over the Moon, it does not forbid establishing "safety zones" around operational equipment. If China establishes its International Lunar Research Station (ILRS) at the water-ice-rich lunar South Pole first, it can effectively declare exclusion zones under the guise of scientific safety, achieving de facto territorial dominance over the most valuable real estate on the Moon.
From intellectual theft to kinetic sabotage: Securing the vehicle
Up to this point, the primary threat to the space industrial base has been data exfiltration—stealing ideas to save time. But as rockets become increasingly software-defined, we have to look beyond the theft of blueprints and confront a much more chilling reality: the threat of direct, kinetic cyber attacks against the vehicles themselves.
Modern reusable rockets are not the analog, hard-wired machines of the Apollo era. They are flying data centers. From the thrust-vectoring algorithms controlling the landing burn to the encrypted telemetry links communicating with ground control, every phase of a flight relies on millions of lines of code.
If a nation-state actor can compromise a boutique component manufacturer to steal a CAD drawing, they can just as easily use that access to plant a malicious firmware update into a critical guidance sensor or an engine valve actuator. This turns a routine espionage operation into a latent cyber weapon. During a geopolitical crisis, an adversary wouldn't need to fire a missile to disable a Western launch facility; they could simply trigger a pre-positioned vulnerability in a rocket's guidance software, causing the vehicle to fail mid-air or fail to deploy its national security payload.
Securing the space race can no longer just be about data protection. We must transition to zero-trust architectures for rocket avionics, end-to-end hardware encryption, and rigorous software bill of materials (SBOM) verification for every microchip that leaves Earth. If we don't secure the vehicles themselves, the very systems designed to take us to the stars could be turned against us with a single keystroke.
The timeline clash: Starlink vs. Qianfan
The urgency driving this behavior is transparent when you look at the launch schedules. SpaceX's Starlink has a massive head start, but Beijing has mandated an aggressive, compressed timeline for its flagship competitor, Qianfan (Spacesail / G60), alongside its state-backed sister network, Guowang.
| Capability | SpaceX Starlink | China's Qianfan (Spacesail) |
| First batch launched | May 2019 | August 2024 |
| Satellites in orbit | Over 6,000+ | ~200+ (Rapidly scaling) |
| Target constellation size | 12,000 to 42,000 | 15,000+ |
| The 2025/2026 milestone | Global commercial dominance | Phase 1 initial deployment (648 Satellites) |
| The 2030 ultimate goal | Full next-gen Starship integration | Full global network coverage (15,000 Satellites) |
Source Data Compiled From:
|
||
To get 15,000 satellites into orbit by 2030, China has had to radically scale its launch cadence, targeting over 140 orbital launches. They physically do not have the time to engineer these heavy-lift, reusable platforms from scratch. Cyber-enabled shortcuts are the only way to make the 2030 timeline mathematically possible.
SpaceX's "patents"
This begs the question: How are these design principles migrating across the Pacific so fluidly?
The first assumption most people make is that if a design is public, it’s because it was patented. But SpaceX deliberately avoids filing patents. Registering a patent creates a public, step-by-step instructional manual that foreign competitors can utilize without legal repercussions.
Instead, Western aerospace companies rely entirely on heavily guarded trade secrets, air-gapped networks, and strict compliance with the International Traffic in Arms Regulations (ITAR). To steal a piece of a rocket, you can't just look up a patent filing. You have to breach the network.
The vulnerable underbelly: The third-party supply chain
While a direct cyber attack on primary players like NASA or SpaceX is incredibly difficult due to elite-tier security architectures, cyber espionage rarely takes the front door. Threat actors prefer the path of least resistance. For example, targeting the upstream manufacturing supply chain, and it is this domain in which we have seen the "blueprints" for modern reusable rocketry leaked multiple times:
- The LockBit/Maximum Industries incident: The LockBit ransomware group successfully breached Maximum Industries, a Texas-based laser-cutting and CNC machining contractor for SpaceX. The criminals openly boasted about exfiltrating roughly 3,000 engineering drawings certified by SpaceX engineers, threatening to auction them off.
- The DoppelPaymer/Visser Precision breach: Years earlier, the DoppelPaymer gang hit Visser Precision, a specialized aerospace component manufacturer, exposing proprietary non-disclosure agreements and manufacturing schematics tied to Tesla and SpaceX.
While these were criminal, financially motivated ransomware attacks, the threat intel community knows that state-sponsored APTs regularly monitor cybercriminal dumping grounds. To a state actor looking to fast-follow Western aerospace achievements, a leaked CAD file of a rocket engine valve or a grid fin actuator is worth its weight in gold.
Furthermore, these were attacks that were publicly exposed by the actor who committed them. If a sophisticated state-sponsored actor were to gain a similar level of access, they would certainly not brag about it on a leak site. They would quietly siphon the data over months or years, leaving both security researchers and the victims completely unaware of the compromise. Any useful stolen information would be quickly passed on to Chinese rocket manufacturers.
Sifting through campaign telemetry
Trellix campaign intelligence data confirms a sustained and escalating pattern of Chinese state-sponsored cyber operations targeting Western space, aerospace, satellite, and defense organizations. This activity spans multiple well-documented Chinese APT groups operating simultaneously, reflecting a broad, coordinated effort rather than isolated incidents.
Several documented campaigns directly and explicitly target the Western space and aerospace industrial base. APT31's "Dragon Breath" campaign, active as recently as April 2026, used advanced BYOVD (Bring Your Own Vulnerable Driver) zero-day techniques to compromise aerospace and defense companies in the United States, the United Kingdom, Norway, and Finland. The Earth Ammit campaign targeted satellite navigation systems and drone supply chains. Operation CuckooBees, attributed to APT41, focused on stealing intellectual property from aerospace and defense firms. The Space Pirates threat group — named explicitly for its aerospace focus — conducted continuous operations from 2022 through 2025. APT40 has been formally documented by Western intelligence agencies, including a joint advisory from the US, UK, EU, and Australian governments, for systematic targeting of aerospace, defense, and satellite organizations.
Of particular strategic concern is Volt Typhoon, which has been specifically linked to targeting satellite infrastructure and assessed — including by the US Cybersecurity and Infrastructure Security Agency (CISA) — to be pre-positioning for potential disruption of critical infrastructure rather than conducting pure espionage. This distinction elevates the threat beyond intellectual property theft into the realm of potential sabotage.
The actors involved — APT40, APT41, APT27, APT31, Mustang Panda, and Volt Typhoon — are all well-attested Chinese state-sponsored groups with extensive public documentation from government agencies, academic researchers, and the broader security community. Their simultaneous, sustained focus on the space and aerospace sector points to a deliberate, state-directed prioritization of this industry as a strategic intelligence target.
Taken together, the documented campaign evidence paints a clear picture: Chinese state-sponsored threat actors are systematically targeting the Western space industrial base — from prime defense contractors to satellite operators to supply chain vendors — and the pace of that activity is accelerating into 2026.
(Caveat: This summary is based on documented, attributed campaign data from Trellix threat intelligence. It does not include unverified detection counts or claims that could not be independently corroborated against specific named organizations.
The cislunar battleground
We are firmly locked into Space Race 2.0. On one side, the US and the Artemis Accords; on the other, China and the International Lunar Research Station (ILRS). As both factions race to secure strategic positions like the Moon’s South Pole, the space industry is no longer just about exploration — it is critical national infrastructure.
The rockets we see on the pads today are the physical manifestations of a shadow war that was fought in our networks years ago. Moving forward, securing the stars will require us to secure the small, specialized machine shops right here on Earth.
But this is only the opening salvo. As humanity pushes further into space — transitioning from low-Earth-orbit megaconstellations to permanent lunar bases and deep-space logistics networks — the intersection of space and cybersecurity will become the premier front of global conflict. The intelligence requirements of our adversaries will evolve in lockstep with our technological milestones. If the West intends to lead the next century of extraterrestrial exploration, we must accept a harsh reality: We cannot secure our future among the stars until we can successfully protect the digital blueprints on our screens.
Defending the next frontier requires visibility into the threats of today. Learn how Trellix Threat Intelligence and the Trellix Advanced Research Center provide the proactive insights security leaders need to anticipate, track, and mitigate global adversary campaigns before they breach the supply chain.
1https://www.justice.gov/archives/opa/pr/chinese-national-pleads-guilty-conspiring-hack-us-defense-contractors-systems-steal-sensitive2https://www.justice.gov/archives/opa/pr/chinese-company-sinovel-wind-group-convicted-theft-trade-secrets
RECENT NEWS
-
Aug 24, 2026
Trellix Expands Leadership Team to Accelerate Growth and Cyber Resilience
-
May 19, 2026
Trellix Appoints Joe Chen as Chief Technology Officer
-
Apr 08, 2026
Trellix prevents enterprise data exposure in sanctioned and shadow AI
-
Mar 02, 2026
Trellix strengthens executive leadership team to accelerate cyber resilience vision
-
Feb 10, 2026
Trellix SecondSight actionable threat hunting strengthens cyber resilience
RECENT STORIES
Latest from our newsroom
Get the latest
Stay up to date with the latest cybersecurity trends, best practices, security vulnerabilities, and so much more.
Zero spam. Unsubscribe at any time.