• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, Tactical Comms, AI, Cyber, EW, Cloud Computing & Homeland Security

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

July 4, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

————————————————————————————————————————————————————————————————————————————————————————————————————————————————-

01 Jul 25. German Premiere With Live Flight Demo: German Industry Team Showcases Electromagnetic Combat from the Air. Airbus, bKEC, HENSOLDT, IBM, MBDA, PLATH, Rohde & Schwarz, and Schönhofer have demonstrated live in Germany for the first time how military aircraft can fly unhindered missions in a crisis area with active air defense systems using electromagnetic jamming measures. In the live flight demonstration in Manching, the team of German defense companies simulated a scenario close to real operations in front of numerous representatives of the German Armed Forces: the evacuation of German citizens from a crisis area equipped with comprehensive air defense systems. A Pilatus PC-12 turboprop aircraft, a simulated Airbus A400M military airlifter, a SHARCS technology demonstrator serving as an unmanned remote carrier, and an SA-8 air defense missile system representing the enemy’s air defense were used. The PC-12 was equipped with an electromagnetic surveillance and jamming system. It acted as a stand-off jammer, or jamming aircraft, which detected and classified the SA-8 system from a safe distance, jammed it with electromagnetic countermeasures, and rendered it incapable of combat. Without functioning enemy air defenses, the simulated A400M was able to fly into the crisis area undetected, land, and evacuate citizens. The SHARCS remote carrier, equipped with a stand-in jammer, provided support by simultaneously suppressing communications, thereby delaying a response from enemy forces. The seamless communication between friendly forces, the exchange of reconnaissance and effect data, and the processing and AI-supported analysis of the data took place in a secure cloud. The demonstration showed how effectively forces of electromagnetic combat (EC) can operate and protect friendly forces during missions. Since EC operates without ammunition and is non-kinetic, there is also no damage. The capability demonstrated in the demonstration is an essential component of the German defense project “luftgestützte Wirkung im elektromagnetischen Spektrum” (Airborne Effects in the Electromagnetic Spectrum), or luWES for short, in which the German Armed Forces are building up EC capabilities. Developing the technologies for this is the declared goal of Airbus, bKEC, HENSOLDT, IBM, MBDA, PLATH, Rohde & Schwarz, and Schönhofer. Under the motto “EC made in Germany for Germany,” they want to enable the German Air Force to deploy these capabilities independently and sovereignly. Following the flight demonstration, the next step will be to further develop the individual luWES components. luWES will form a “system of systems” consisting of complementary and modular subsystems that provide electromagnetic protection from the air for armed forces. The stand-off jammer operates from a great distance and enables enemy radar and communications systems to be jammed outside their direct range. This not only protects friendly forces, but also increases their effectiveness, as enemy sensors are suppressed before their area of operation is entered. The escort jammer operates alongside manned mission platforms. It actively protects them in enemy territory by continuously jamming enemy radar and missile systems. The stand-in jammer penetrates directly into the enemy’s effective range. It suppresses enemy air defense systems at close range, protecting friendly weapons and thus increasing their effectiveness and assertiveness. (Source: ASD Network)

 

01 Jul 25. Thales Alenia Space to Develop SOLiS Very-high-throughput Laser Communications Demonstrator. Thales Alenia Space, the joint venture between Thales (67%) and Leonardo (33%), has been selected by the French space agency CNES, as part of the space component of the France 2030 program launched by the French government, to develop a very-high-throughput laser communications demonstrator. Called SOLiS — for Service Optique de Liaisons Spatiales Sécurisées (secure optical space link service) — this project aims to demonstrate the technical and economic viability of an optical communications service relying on geostationary satellites. Such a service is designed to make intercontinental networks more resilient at a time when there is a growing number of acts of sabotage targeting land and undersea optical fiber links. Geostationary satellites offer an effective and cost-effective solution for ultra-secure transfers of large amounts of data between two users on Earth, delivering very high data rates of up to one terabit per second despite distances and atmospheric disturbances. SOLiS harnesses technologies developed through the government-backed Optical Communications (CO-OP) project led by CNES and a group of 17 SMEs and large primes, and draws on the outcomes of demonstrations delivered for the VERTIGO project funded by the European Commission. Thales Alenia Space will lead the SOLiS project consortium, composed of large industry primes and mid-tier firms (Safran Data Systems, Bertin Technologies, Exail, Keopsys), SMEs (Cedrat Technologies), startups (OGS Technologies, Reuniwatt), and a research center (ONERA), most of which have already worked on the CO-OP project. SOLiS plans to develop an optical communications payload and a pilot ground station designed to demonstrate very-high-throughput laser communications. In accordance with a memorandum of understanding between Thales Alenia Space and operator Hellas Sat signed in 2024, this payload will be flown on the Hellas Sat 5 geostationary communications satellite, while the pilot ground station will be set up at the operator’s teleport in Cyprus. This station will communicate with CNES’s FROGS station already operating at the Côte d’Azur Observatory on the Mediterranean coast. Building on the accomplishments of the CO-OP project, SOLiS will put French manufacturers — large primes, mid-tier firms, SMEs, and startups — at the forefront in space communications for the 2030s as they strive to address the challenges of security, resilience, fast data rates, and multi-orbit interoperability (between the ground, constellations, and geostationary satellites).

“We are delighted to be starting development of the payload for the optical communications system, marking a crucial step toward establishing a secure, very-high-throughput optical network,” said Alcino De Sousa, Executive VP, Telecommunications at Thales Alenia Space. “Satellite laser communications projects like SOLiS are set to usher in a new era in telecommunications services, driving development of multi-orbit communications networks.” (Source: ASD Network)

 

02 Jul 25. Global: Increased cyber criminal, state-sponsored convergence points to heightened security risks. On 30 June, the cyber security company Proofpoint reported that cyber criminal and state-sponsored cyber threat actor activity is increasingly overlapping. In February, the company detected several cyber espionage operations that it attributed to the financially motivated threat group ‘TA829’. While it is unclear whether TA829 has any connections to the Russian state, the group notably conducted cyber espionage operations against Ukraine following the onset of the war in that country in February 2022. It typically employs tactics associated with cyber criminal activity, likely in a bid to enhance detection evasion and to complicate attribution efforts. In the same month, Proofpoint also uncovered another activity cluster (‘UNK_GreenSec’) that used similar tactics to TA829 to target organisations in North America. However, UNK_GreenSec used different infrastructure and deployment methods compared to TA829. We assess this further showcases the complications stemming from the increasing convergence between cyber criminal operations and state-sponsored activity, which is in turn heightening security risks for global businesses. (Source: Sibylline)

 

18 Jun 25. Textbook SEAD. For at least the past two decades, the Islamic Republic of Iran has expended considerable propaganda capital waxing lyrical on the potency of its air defences. Videos depicted imported, as well as home-grown, surface-to-air missile batteries on bombastic parades, and deployed in the field. Targets were never missed, air defenders were professional and everything was perfectly choreographed. The message was clear; launch an air war against Iran and your airpower will be decimated. It did not really work out like that. Just before midnight local time on Friday 13th June, an ironic date to be sure, the Israeli military commenced Operation Rising Lion. Airstrikes were unleashed by the Israeli Air Force (IAF) against Weapons of Mass Destruction (WMD) and politico-military targets in north and western Iran. Domestic sabotage operations, presumably executed by Israel’s feared and respected Mossad intelligence service, were activated simultaneously. Individual scientists working on Iran’s WMD programme, and senior Iranian military officials, were killed. Within 48 hours, Israel was claiming air superiority over Tehran. Just over a week later, strike packages of United States Air Force (USAF) and US Navy combat aircraft hit three Iranian nuclear weapons facilities. By 23rd June, Iran and Israel had agreed a ceasefire. US President Donald Trump declared that Iran’s nuclear weapons programme had been “obliterated”. The extent to which the combined Israel-US strikes have set Iran’s WMD programme back is being hotly debated, but one thing is certain: The IAF performed a textbook air defence suppression effort as part of its wider offensive counter air mission. Armada understands that cyber and electronic attacks initially wrought havoc with the command, control and communications Iran’s Integrated Air Defence System (IADS) relied on. Ground-based air surveillance and fire control/ground-controlled interception radars were jammed. With radars blinded, IAF strike packages could then hit IADS targets kinetically, permanently taking them out of the fight. Jammed, smashed and hacked Iran’s IADS was in no position to challenge Israeli or American mastery of the skies. Further, similar attacks ensured that the USAF B-2A Spirit stealth bombers hitting Iran’s deeply buried nuclear facilities could do so unmolested. Alongside a plethora of locally produced systems, Iran relied on Russian-furnished ground-based air defence systems to protect her skies. Judging from the lack of crewed aircraft losses suffered by Israel and the US, Russian-supplied SAM systems performed abysmally. From Iraq to the Balkans and Libya, Soviet/Russian air defences have a habit of disappointing. They are simply no match for a disciplined, well-planned SEAD effort. Iran is one of five nations, including Russia, that acquired the latter’s flagship S-400 Triumf (NATO reporting name SA-21 Growler) long-range, high-altitude SAM system. Russian air defence systems are increasingly looking like a waste of cash. (Source: Armada)

 

18 Jun 25.  SEAD Force Tour de Force. Sobashi radar station was struck by the Israeli Air Force early in Operation Rising Lion. The destruction of the two structures most likely housing the radars, and their radomes, is clear in this before and after picture. It is likely that this facility was home to Iranian ground-based air surveillance and/or fire control/ground-controlled interception radars. The Israeli Air Force appears to have rapidly secured air superiority over Tehran, and possibly northwestern Iran, in the two countries’ latest round of hostilities, through tried and tested air defence suppression tactics. Israel commenced Operation Rising Lion in the early hours of 13th June against Weapons of Mass Destruction (WMD), politico-military leadership and military bases in the Islamic Republic of Iran. The military action by Israel was the culmination of years of tension between the two countries. The Israeli government led by Prime Minister Benjamin Netanyahu has made no secret of its desire to prevent Iran from acquiring WMDs. Iran’s sponsorship of militant Islamic insurgent organisations has been a similar irritant. Hamas in the Gaza Strip, western Israel and Hezbollah, active in southern Lebanon and Syria, have both attacked targets in Israel. The Israeli Air Force (IAF) has led the offensive hitting numerous targets in Iran. The force appears to have executed a textbook Offensive Counter-Air (OCA) campaign. The United States Air Force (USAF) defines OCA as actions “to dominate enemy airspace and prevent the launch of threats, resulting in greater freedom from attack and increased freedom of action.” The definition continues that OCA employs four means to “achieve specific counterair effects: attack operations, SEAD (Suppression of Enemy Air Defences), fighter escort, and fighter sweep.” OCA is integral to winning and sustaining air superiority as a prelude to winning and sustaining air supremacy. The USAF defines air superiority as “that degree of control of the air by one force that permits the conduct of its operations at a given time and place without prohibitive interference from air and missile threats.” Air supremacy is “that degree of control of the air wherein the opposing force is incapable of effective interference within the operational area using air and missile threats.” Both conditions can be temporally and spatially limited in terms of duration and geographical footprint. As of the time of writing (17th June), the IAF’s OCA approach appears to have paid dividends. No Israeli warplanes are thought to have been lost so far. On 16th June, the IAF declared air superiority over Tehran. Furthermore, it is likely that the IAF may have secured air superiority across much of western and northwestern Iran.

Initial strikes

Much remains unknown regarding the specifics of the IAF’s airstrikes on targets in Iran. Nonetheless, some interesting information regarding the IAF’s OCA battle has come to light. Israel has hit numerous Iranian air defence sites in the west and northwest of that country. This article will concentrate on the electronic warfare aspects of this battle, notably against fixed site Iranian ground-based air surveillance radars. It seems likely that the IAF has employed several vectors to attack Iranian radars: Individual aircraft may have jammed systems using their own integrated self-defence systems. Radars may have been engaged by powerful escort jammers equipping combat aircraft. One example of such kit is the Rafael Advanced Defence Systems’ Sky Shield jamming pod. Sky Shield is believed to be in IAF service onboard its McDonnell Douglas/Boeing F-15 series combat aircraft. Although details remain classified, it is likely that Sky Shield can engage radar threats across a waveband of at least two gigahertz/GHz to 18GHz. Kinetic effects such as Israel Military Industries’ Delilah series of anti-radiation missiles may have engaged some of the radars. Delilah is likely to prosecute radar threats in similar wavebands to Sky Shield. The missile is known to be deployed by IAF General Dynamics/Lockheed Martin F-16I Soufa fighters. Conventional air-to-surface stand-in and stand-off weaponry is also likely to have been used against these targets. Open source media reports have noted that some Islamic Republic of Iran Air Defence Force (IRIADF) radar operators experienced their systems being jammed shortly before the IAF strikes commenced. The IRIADF is responsible for the country’s Integrated Air Defence System (IADS). Radars covering the IAF’s planned ingress and egress routes may have been heavily jammed to shield incoming strike packages of IAF aircraft. These aircraft then used kinetic effects against the radars to take them permanently out of the fight. Meanwhile, cyberattacks could have been launched against the IADS’ computerised command and control systems. The IAF is no stranger to using cyberattacks against IADS, having adopted similar tactics during a raid on a nuclear reactor in eastern Syria on 6th September 2007. The IAF’s OCA battle rhythm appears to have initially focused on targeting IRIADF long-range Over-The-Horizon (OTH) radars such as the Ghadir system. The Ghadir is a high frequency (HF: three megahertz/MHz to 30MHz) radar transmitting on frequencies of 28MHz to 29.7MHz with a maximum range of circa 594 nautical miles/nm (1,100 kilometres/km), according to open sources. Other sources state that Ghadir may transmit in very high frequencies of 30MHz to 300MHz. OTH radars may be tasked with covering a large swathe of Iranian airspace and providing early warning of incoming aircraft hundreds of nautical miles from Iran’s border. Given the comparatively low frequencies these radars use, they can detect air targets with low radar cross sections. The radars cannot do this with sufficient accuracy to guide a surface-to-air or air-to-air missile towards a target. Nonetheless, they can give useful indications of the general location of air targets. It would have been imperative for Israel that such radars were destroyed early in the conflict.

Reading the SEAD battle

According to analysis performed by the Institute for the Study of War, the IAF is thought to have destroyed the Ghadir radar near Tabriz, northwestern Iraq, during the first wave of Israeli air strikes on 13th June. This radar’s destruction would have helped cleanse Iranian airspace for IAF aircraft striking other WMD and military targets in these areas. It appears that a similar Ghadir radar, this one located in Qods in the southwestern suburbs of Tehran, may have been struck shortly afterwards. Hitting the radar in Tabriz would have deprived the Iranian IADS of early warning of IAF aircraft approaching the northwest of the country. The loss of the Ghadir outside Tehran may have had a similar effect for the airspace over the Iranian capital. An additional four IRIADF radars have been identified as destroyed by the IAF between 13th June and 16th June. These include systems located at Sobashi radar station, northwestern Iran; Khatam ol Anbia radar station and Hamadan airbase, both in Hamadan province, and at the Piranshahr military base also in northwestern Iran. Ascertaining the type and model of these radars is difficult at best. Given that they appeared to have been mounted in relatively large radomes it is reasonable to assume they maybe L-band (1.215 gigahertz/GHz to 1.4GHz) or S-band (2.3GHz to 2.5GHz/2.7GHz to 3.7GHz) ground-based air surveillance or fire control/ground-controlled interception radars. Based on general figures for such systems, L/S-band radars usually provide instrumented ranges of circa 216nm (400km). It is possible that these radars send their Recognised Air Picture (RAP) upwards to higher IRIADF echelons. There, the regional and national ‘Super RAPs’ are composed by converging disparate local recognised air pictures. The radars may also be used to aid tactical air battle management. This article has only discussed the loss of radars reported in the Institute for the Study of War’s analysis, and by reliable media outlets like the British Broadcasting Corporation. It is all but certain that other IRIADF radars have been destroyed. Shahryar Pasandideh, an open-source researcher and analyst, and an expert on the Iranian military, told Armada that “seemingly every stationary early warning radar site in western Iran and other sectors, appear to have been targeted through one means or another.” Mr. Pasandideh’s extensive analysis of the Iranian military can be found here. Radars will continue to be a high priority for the IAF as it continues its air strikes in Iran. The force has secured air superiority in a comparatively short time at least over Tehran, and possibly over northwestern Iran. This is testament to the Israeli Air Force’s adherence to tried and tested SEAD methods to win air superiority as part of the wider OCA fight. Whether Iran’s air defences can recover is another question entirely. (Source: Armada)

 

04 Jun 25. The Spectrum’s Coalition of the Willing. The new Electronic Warfare Capability Coalition will not only intensify EW support for Ukraine, but will also inform the electronic warfare postures and capabilities of the initiative’s member nations.

“The electronic warfare capability coalition is in place to fill critical gaps, train forces and establish effective policy and doctrine.”

This was how a senior member of the newly formed European Electronic Warfare Capability Coalition (EW CAPCO) describes three of the key missions for this new grouping. The new Capability Coalition (CAPCO) was under discussion at this year’s Association of Old Crows EW Europe conference and exhibition. The event was held in Rome on 7th and 8th May. News emerged in mid-May that several European nations would band together to improve their collective EW capabilities. A key goal of the coalition is to intensify electronic warfare support for Ukraine as she continues her efforts to expel Russia’s occupation of her lands. Nonetheless, as conference discussions underscored, the coalition’s work will have significant relevance beyond the Ukrainian theatre. Ukraine is one member of the coalition alongside Czechia, Denmark, France, Germany, Lithuania, Latvia, Norway, Poland and the United Kingdom. It was stressed during conference discussions that Ukraine is not involved in the coalition solely as a passive partner. The nation is taking an active role in feeding lessons learned into the coalition, and detailing the EW capabilities she needs. All the nations involved in the initiative have the same status within the coalition. Spinning up the initiative required an initial letter of intent and a subsequent multinational contract. The next steps developed the coalition’s Terms-of-Reference (TORs) and established ‘battle rhythm’. The latter has been vital in ensuring the coalition is as responsive as possible to the electromagnetic battle in Ukraine. The TORs provide the framework for the coalition’s deliverables. These include the supply of appropriate EW capabilities to the Ukrainians, training Ukrainian personnel and developing unified EW strategies, policies and doctrines. EW CAPCO sources say the group has a ‘shopping list’ from Ukraine regarding specific systems. Efforts are ongoing to shape these requirements into capabilities as opposed to solely addressing specific EW demands with kit.

Organisation

A German two-star officer is the EW CAPCO’s director with two subordinate secretaries also from Germany. The CAPCO then divides into three distinct working groups covering procurement, training and education, and policy and doctrine. The EW Capability Coalition is not the only such grouping in this ‘coalition of the willing’ of European nations pledging their support to Ukraine’s ongoing fight. Other CAPCOs cover air defence, airpower, armour, artillery, demining, information technology, sea power and uninhabited aerial vehicles. Sources continued that all these groupings have “EW issues” and depend on the electromagnetic spectrum in some shape or form. As a result, the EW CAPCO can perform cross cutting work across the other groupings providing assistance and advice as and when required.

Post Conflict

How the Ukraine War will conclude remains to be seen. Nonetheless, the EW CAPCO’s thoughts are turning to how EW capabilities will fit into Ukraine’s wider post-conflict force structure. Beyond Ukraine, “exchanging lessons learned is crucial for the future,” the sources noted. These lessons are not only relevant for Ukraine, but germane to the wider EW CAPCO membership. Additional nations may join the initiative in the future. The group’s officials are keen to stress that EW CAPCO is neither a North Atlantic Treaty Organisation nor European Union initiative. Nonetheless, the EW CAPCO’s activation marks an important sharpening of the continent’s current and future electronic warfare posture and capabilities. (Source: Armada)

 

05 Jun 25. Hold that door. The RAF’s Tekever AR3 UAV equipped with the StormShroud electronic attack payload can mimic crewed aircraft to sow confusion in the minds of air defenders. The RAF’s new StormShroud stand-in jammer represents another arrow in the force’s electronic attack quiver to help it defeat today’s and tomorrow’s air defences. The Royal Air Force’s (RAF’s) Electronic Warfare (EW) capabilities have evolved once more with the revelation that the service has taken delivery of its new StormShroud stand-in jammer. The news was announced by the United Kingdom Ministry of Defence on 2nd May. The announcement was made by the UK’s Prime Minister Keir Starmer during a visit to Leonardo’s facilities in Luton, southeast England. StormShroud’s electronic attack payload has been developed by Leonardo. The payload is carried by a rail-launched Tekever AR3 Uninhabited Aerial Vehicle (UAV). StormShroud will be the responsibility of the RAF Regiment’s 216 Squadron.

Concept of Operations

Speaking at the 2025 Association of Old Crows Electronic Warfare Europe conference and exhibition held in Rome on 7th and 8th May, Leonardo officials provided Armada with more details on StormShroud. Primarily, the system will help crewed aircraft operate in heavily contested airspace. For example, StormShroud UAVs could fly into the engagement footprint of a Surface-to-Air Missile (SAM) battery. The aircraft’s integral BriteStorm payload could be programmed to emit Radio Frequency (RF) signals. These signals could simulate an incoming strike package of aircraft. This could help distract the SAM battery’s air defenders while an actual strike package is doing its work elsewhere. The UAV would, in effect, ‘hold open the door’ for the crewed aircraft to fly unchallenged through the battery’s engagement footprint. In fact, the UAVs could represent so many false targets that real potential targets could be mixed within the cacophony of confusion. Conversely, BriteStorm payloads could be used to unleash heavy jamming. Electronic attacks such as these could prevent the battery’s ground-based air surveillance and fire control radars from seeing the actual threats. BriteStorm uses a Digital Radio Frequency Memory is programmed to compose and deploy the desired electronic effects in support of the mission. It is understood that the payload can engage threats transmitting on frequencies of zero megahertz to 20 gigahertz. Joining StormShroud is the electronic attack functionality of Leonardo’s ECRS Mk.2 X-band (8.5 gigahertz/GHz to 10.68GHz) fire control radar. The company’s BriteCloud expendable decoy provides individual aircraft protection against radars and radar-guided threats like SAMs and air-to-air missiles. The ECRS Mk.2 can attack radar threats with jamming within its field-of-view. The ECRS Mk.2 will equip all new Typhoon FGR Mk.4 combat aircraft and can also furnish legacy Typhoon marques in service with the RAF. Although not yet funded, MBDA’s SPEAR-EW (Select Precision Effects at Range – EW) loitering EW system could be added to this mix. It is possible that SPEAR-EW could be deployed as a stand-off or escort jammer, with StormShroud providing stand-in jamming, and BriteCloud and ECRS Mk.2 affording individual aircraft protection. (Source: Armada)

 

05 Jun 25. June Spectrum SitRep. The Simulate, Emulate, Stimulate, Calibrate and Operate approach to electronic warfare training pioneered by MASS was launched at this year’s Association of Old Crows EW Europe exhibition and conference.

GNSS Jamming Detection for ATAK

An electronic intelligence system developed by Zephr is garnering interest in the United States. It was reported in October 2024 that the company had developed a networked signals intelligence system. The system exploits local cellphone networks to detect Global Navigation Satellite System (GNSS) jamming. By networking cellphones and cellphone towers together, this architecture can act as a giant distributed antenna. The phones and towers will detect GNSS interference and its source. Zephr has developed the system for deployment in Ukraine. In February, the company was awarded a contract worth $1.7 m from the US Air Force Research Laboratory (AFRL). The work will develop real time GNSS jamming and spoofing detection and geolocation techniques. Reports have stated that, over the long term, the US Department of Defence (DOD) is interested in this functionality for the AFRL’s Android-based Tactical Assault Kit (ATAK). ATAK will integrate “Zephr’s jamming/spoofing detection and localisation capabilities,” the company said in a written statement. “(T)he capability will not require any additional hardware beyond the existing Android phones it will run on.” The contract’s duration is for two years. Zephr’s work with the AFRL in this regard is currently at Technology Readiness Level Seven (TRL-7). According to US DOD definitions, this denotes that a working model or prototype has been demonstrated in an operational environment. The company continued that the contract should help advance the technology to TRL-8 vis-à-vis ATAK. TRL-8 denotes that the system has been qualified through test and evaluation: “One of our motivations for doing real world testing in active conflict zones (such as Ukraine) is to build a battle-ready technology that we are confident can help both the warfighter and civilian users,” the company added.

MASS Unveils SESCO

MASS launched its new SESCO (Simulate, Emulate, Stimulate, Calibrate and Operate) Electronic Warfare (EW) training methodology at this year’s EW Europe conference and exhibition. The show was hosted by the Association of Old Crows global EW advocacy organisation, and held in Rome on 7th and 8th May. Company representatives told Armada at the event that the SESCO methodology takes a holistic approach to EW training. Personnel with no, or limited, electronic warfare experience will, stage-by-stage, acquire the knowledge and acumen they need to ensure they are ready for operational spectrum challenges when deployed. A key aspect of SESCO is that it involves the company’s NEWTS training system. NEWTS allows students to experience an accurate electromagnetic environment without the trainers emitting any RF (Radio Frequency) signals. Students experience the electromagnetic challenges they may face operationally. However, trainers do not need a range, or permissions to emit, that the use of actual RF signals would otherwise entail. In fact, the students will experience a simulated RF environment until they reach the ‘Calibrate’ stage of their training. Simulated RF signals work directly with the equipment and capabilities students will use operationally. MASS representatives added that the SESCO methodology is under trials to enable the most modern RF threats to be detected and decoded/demodulated in real time.

We Practice to Deceive

Roke’s new EM-Vis Deceive electronic warfare system has been designed to incorporate open standards easing the integration and upgrade path for the system during its service life. Roke also took advantage of the EW Europe conference and exhibition to launch the company’s new EM-Vis Deceive portable Electronic Warfare (EW) system. EM-Vis Deceive is designed to help land forces detect, track and engage hostile communications, uninhabited aerial vehicle Radio Frequency (RF) links and other RF signals. The company says the new product has been realised using the Standards for Integrated Command, Control, Communications, Computer, Cyber, Intelligence, Surveillance, Reconnaissance and Electronic Warfare (STICS). The STICS suite of open standards is designed to assist command and control; intelligence, surveillance and reconnaissance, and EW system interoperability. EM-Vis Deceive can be carried by a single soldier and used by an unskilled operator. John Bottomley, Roke’s senior cyber and electromagnetic activities engineer, told Armada that the system can detect, track and jam threats emitting on frequencies of 20 megahertz up to six gigahertz/GHz. He added that the company is working on antenna arrays that could extend this waveband to 18GHz. Work commenced on the EM-Vis Deceive two years ago. The company “has completed initial deliveries, with further shipments scheduled for early 2026.” Those initial deliveries “enable our current user communities to trial, deploy and feedback into Roke prioritisation of applications as we spirally enhance EM-Vis Deceive to continually address the challenges our users face,” Mr. Bottomley continued.

 

03 Jul 25. Silvus Technologies Launches Spectrum Dominance 2.0 Next Generation EW Defenses. Silvus Technologies, Inc., a global provider of advanced wireless networking solutions, has announced the launch of Spectrum Dominance 2.0 – the next evolution of its EW-resilient communications capabilities. Available as a software licensable extension to Silvus’ battle-proven MN-MIMO waveform, Spectrum Dominance 2.0 is adds new features including Wake on Wireless and Dual Frequency Link to an ever-expanding suite of Low Probability of Intercept/Low Probability of Detection (LPI/LPD), Anti-Jam (AJ) and Advanced Threat Protection (ATP) capabilities that provide secure and protected mesh network communications in the most contested RF environments. Together, they enable StreamCaster MANET radios (AN/PRC-169) to perform in congested and contested environments – empowering their operators with robust, mission-critical communications solutions to achieve their mission objectives even under electronic attack. Building on years of real-world operational deployment and mission success, Spectrum Dominance 2.0 takes a layered approach to EW defense, forcing an adversary to penetrate all layers before disrupting communications. Spectrum Dominance 2.0 offers modular flexibility – enabling users to deploy features independently or combine them into a tailored EW defense profile to enhance mission performance and achieve RF spectrum overmatch. Silvus is the only tactical MANET provider that delivers Spectrum Dominance without sacrificing range, throughput, robustness, or scalability.

“Spectrum Dominance 2.0 is the direct result of field-driven innovation from the front lines of today’s EW battlespace,” said Jimi Henderson, Vice President of Sales at Silvus Technologies. “Our unique multi-layered approach for LPD and AJ resilience provides the warfighter with tools to outmaneuver even the most sophisticated EW threats.”

“Our mission is to equip the warfighter with next-generation communications that deliver decision dominance and RF spectrum overmatch across today’s dynamically changing battlespace,” added Babak Daneshrad, Silvus Founder and CEO. “With Spectrum Dominance 2.0, we’ve elevated EW resilience to a new standard – delivering the reliable performance users expect from StreamCaster MANET radios – even when operating in EW contested environments.”

Spectrum Dominance 2.0 – Key Capabilities:

LPI/LPD: Delay or Deny Adversarial Detection

  • MANET Power Control (MAN-PC): Automatically minimizes the RF footprint of StreamCaster MANET radios – dynamically throttling power to the minimum amount necessary to maintain network connectivity
  • Wake On Wireless: Enables StreamCaster MANET radios to receive data without emitting control traffic to gather intelligence without revealing position. A radio in Stealth Mode can be activated via Wake on Wireless, either remotely or locally.

Anti-Jam: Mitigate Electronic Warfare Attack

  • MANET Interference Cancellation (MAN-IC): StreamCaster MANET radios automatically perform real-time interference monitoring. At the onset of jamming, MAN-IC employs sophisticated spatial signal processing techniques to nullify the offending interfering signal.
  • MANET Interference Avoidance (MAN-IA): StreamCaster MANET radios dynamically scan and monitor the RF spectrum for interference across multiple user-defined channels. At the onset of jamming, MAN-IA moves the entire mesh network to the cleanest frequency without user intervention.
  • Dual Frequency Link: Enables StreamCaster MANET radios to transmit on one frequency channel and receive on a different frequency channel – enhancing jamming resilience in distributed operations.

Advanced Threat Protection: Waveform Resilience

  • MANET Protected Waveform (MAN-PW): When MAN-PW is enabled, the MN-MIMO waveform is hardened for increased resilience.

The Spectrum Dominance 2.0 expansive suite of capabilities can be downloaded onto existing Silvus StreamCaster MANET radios via simple firmware updates, extending their operational value. Certain capabilities are available exclusively to U.S. Government customers or subject to ITAR-control. Some features are non-ITAR controlled and commercially available to all Silvus customers.

Mission Critical Solutions

Spectrum Dominance 2.0 is fully interoperable across Silvus’ family of StreamCaster (both the 4000 and upcoming 5000 Series) MANET radios. Available in handheld, mounted, and OEM module formats, StreamCaster MANET radios deliver optimized output power (1–80 Watts effective, thanks to TX Eigen Beamforming), up to 100 Mbps data rate, industry leading frequency agility with over 30 single/dual frequency band options (300-6000 MHz) and advanced encryption including AES-256, and FIPS 140-3 Level 2 validation – the U.S. Government’s latest security requirements of cryptographic modules to protect sensitive data. At the heart of every StreamCaster MANET radio is Silvus’ battle-proven MN-MIMO waveform that creates a self-forming and adaptive mesh network – capable of connecting hundreds of nodes with unmatched range and data throughput in complex, multi-path, and non-line-of-sight environments. (Source: UAS VISION)

 

30 Jun 25. Russia’s Weaponisation of AI for Disinformation.

“Generative AI is no longer a concern of the future but an active component of ongoing Russian-aligned influence operations.”

This is the view expressed in a Royal United Services Institute (RUSI) Emerging Insight report by Claudia Wallner, with Simon Copeland and Antonio Giustozzi, titled Russia, AI and the Future of Disinformation Warfare.

Drawing on primary-source material from Russian-linked online communications, the research shows how a wide range of actors – including those linked to the Wagner Group, hacktivist collectives, and pro-Russian influencers – are actively using artificial intelligence to transform both the form and function of Russian disinformation strategies and contributing to emerging security threats in the European digital domain. Far from being a distant risk, the research shows how AI is already central in Russian disinformation operations for its ability to scale, and personalise disinformation, generate content automatically, and reduce attribution risks. The report offers a unique lens on how generative AI is being used to automate propaganda production and shape strategic thinking, recruit tech-literate operatives, and refine narratives about Russia’s geopolitical role. The research highlights the urgent need for policymakers and civil society to understand and respond to these evolving dynamics.

Key Findings

  • AI is a Force Multiplier for Influence Operations. The report says: “Generative AI is already being integrated into Russian disinformation operations… automating content production, overwhelming adversaries, and further blurring the boundary between truth and fabrication.”
  • Strategic Use by Wagner. “Channels affiliated with Wagner on Telegram and other semi-public platforms reveal significant engagement with generative AI technologies. They position these technologies as tools to undermine trust in Western institutions, sow discord among populations in the West, and frame any Russian cyber activities as defensive responses to perceived Western aggression.
  • Use in Cyber Attacks by Hacktivists. “The hacktivist group NoName057(16) exemplifies the convergence of AI and cyber operations. Since emerging in early 2022, NoName057(16) has openly discussed AI as a force multiplier for DDoS attacks, misinformation campaigns, and reputational sabotage.”
  • Disillusionment with Russia’s own AI Infrastructure. “The monitored online communities also expressed substantial criticism and frustration regarding the limitations of Russia’s domestic AI platforms, primarily Sberbank’s GigaChat and YandexGPT. These criticisms reflect broader anxieties about technological autonomy, ideological biases, and operational constraints, as well as suspicions regarding the political loyalties of major Russian tech firms. Pro-Russian actors’ dissatisfaction with domestic AI has led to a continued preference for Western tools, which undermines the Kremlin’s narrative of building a successful autonomous and ideologically aligned AI infrastructure.”

Key Recommendations

  • Monitor Actor-Level AI Discourse. The report says: “The decentralised and multilingual nature of Russian-aligned influence networks highlights the importance of monitoring actor discourse, rather than just focusing on outputs. Without this, the ability to anticipate emerging tactics and narratives is significantly reduced.”
  • Support Civil Society Resilience Against AI-Enabled Threats. “There is also a need to support civil society and media ecosystems that are directly targeted by these operations. Aside from protecting them from AI-enabled attacks, this includes investment in digital literacy and resilience programming against synthetic content and manipulated narratives.
  • Advance Cross-Sector Countermeasures. “AI is reshaping, but not replacing, the mechanics and logic of Russian disinformation. It acts as an amplifier, enabling greater reach, faster response, and more dynamic narrative adaptation. But it also introduces new vulnerabilities, contradictions, and frictions within Russian influence networks themselves. Understanding and engaging with these internal dynamics will be important to inform future policy design and the development of effective countermeasures.”
  • Develop AI Governance Frameworks to Prevent Abuse. “The fusion of AI and influence operations reinforces the need for AI governance frameworks that explicitly address malign use cases … Coordination between governments, platforms, researchers, and journalists must also happen at a larger scale … sharing insights on observed tactics and uses of AI tools.”

Conclusion

The research shows how generative AI is no longer merely a tool – but is an ideological and operational centrepiece reshaping the mechanics, narratives, and strategic cultures of Russian disinformation. While Russian influence actors prize AI for its ability to scale, anonymise, and personalise propaganda, they also voice deep concern over the Western monopoly on high-performance AI tools and the ideological unreliability of domestic alternatives. By highlighting actor-level conversations, recruitment efforts, and operational applications, the report offers a rare window into how Russia’s digital influence ecosystem is evolving in real time and how competing narratives – of empowerment and vulnerability – are fuelling an information arms race, where the ability to manipulate perception and shape narratives through technology is becoming just as critical as traditional warfare capabilities. The findings underscore the necessity for renewed vigilance in AI governance and disinformation strategy, not only to understand how AI tools are used, but how they are discussed, imagined, and embedded in adversarial worldviews. Responding effectively will require a whole-of-society effort — combining regulation, threat monitoring, and public education — to defend against a new, algorithmically enhanced era of information warfare.

 

27 Jun 25. Cyber Update Key points.

  • The increased distribution of artificial intelligence (AI)-generated content on social media underscores elevated mis- and disinformation risks amid regional conflict in the Middle East (see Sibylline Cyber Daily Analytical Update – 23 June 2025).
  • A social engineering campaign against US-based academics and critics of Russia underscores heightened security risks from the suspected Russian state-sponsored group ‘UNC6293’ (see Sibylline Cyber Daily Analytical Update – 24 June 2025 and our Technical analysis below).
  • The continued expansion of the ‘Androxgh0st’ botnet underscores the increased security and financial risks facing global businesses (see Sibylline Cyber Daily Analytical Update – 25 June 2025).
  • A long-term cyber intrusion campaign against organisations across the US and East Asia points to sustained security risks from Chinese actors (see Sibylline Cyber Daily Analytical Update – 26 June 2025).
  • Activity from a new ransomware group (‘Dire Wolf’) highlights sustained operational and financial risks to global firms (see Sibylline Cyber Daily Analytical Update – 27 June 2025).

Technical analysis of weekly stories

The suspected Russian state-sponsored group UNC6293 has been targeting prominent academics and critics of the Russian authorities in the US via a social engineering campaign since at least April. The group distributes spear phishing emails impersonating the US State Department as an initial attack vector. The emails contain additional fake email addresses in the carbon copy (CC) recipient line, impersonating other State Department employees; they are also sent during typical working hours in the capital Washington DC to enhance credibility. This step of the attack likely required extensive research and preparation, underscoring the premeditated nature, sophistication and resources of this campaign. The language used throughout the emails also does not display any grammatical errors and is general in tone, suggesting that UNC6293 may have possibly used AI to draft the content. The content invites victims to join a private online consultation centred around the victim’s area of expertise to trick them into following instructions to create an application-specific password (ASP). Notably, the group exchanges several emails with victims before coercing them into creating the password, marking a departure from traditional Russian social engineering techniques that typically rely on urgency. Victims then share the password with UNC6293 under the pretence that it will be used to log them into a government-controlled guest tenant account and subsequently a private online meeting platform. However, UNC6293 then uses the ASP to hijack victims’ email accounts and subsequently exfiltrate sensitive information. The group will likely manipulate and release the stolen information at a later stage as part of an influence operation based on previous operations’ modus operandi (MO).

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

Our cyber word(s) of the week: Application-specific password (ASP) (Source: Sibylline)

——————————————————————————————————————————————————————————————————————————————————————————————————————————————

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————-

 

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

June 27, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

———————————————————————————————————————————————————————————————————————————————————————————————————————————————

27 Jun 25.  Thales and KONGSBERG to establish new major Defence communications joint venture in Norway.

  • Thales, a global high-tech leader, and Kongsberg Defence & Aerospace, part of the Kongsberg group and a premier supplier of defence products and systems, have signed an agreement to set up a joint venture company in secure communications.
  • The new company will consolidate Thales’ crypto and secure communications business in Norway and KONGSBERG’s communications business, which includes software-defined military radios. This collaboration aims to better address the current and future needs of armed forces in Norway, NATO and internationally, employing approximatively 350 people.
  • The merger will create a new key player with a strong and comprehensive secure communications portfolio, particularly relevant in the context of accelerating defence spending across Europe.

Thales and Kongsberg Defence & Aerospace have agreed to combine two of their businesses – KONGSBERG’s secure communications unit and Thales’ crypto and secure communications business in Norway – in a joint venture designed to meet the growing connectivity needs of defence forces in Norway, NATO countries and other nations. This new company is a response to European armed forces’ call for greater interoperability, sovereignty, and the urgent need for large-scale equipment delivery. The new company will be jointly owned 50/50 by Thales and Kongsberg Defence & Aerospace with approximatively 350 strong workforce based across Oslo, Trondheim and Asker, Norway.   These two businesses had combined revenues of about NOK 1.5bn (130m euros) in 2024. The venture anticipates continued growth, projecting that the combined businesses will achieve NOK 3bn (254m euros) in revenue by end of the decade driven by substantial market opportunities and product synergies. It will have a broader product mix with powerful and advanced systems. Thales in Norway provides high-grade crypto networks and voice communication systems to NATO and other nations. KONGSBERG delivers tactical radio systems for the land domain (combat vehicles and soldiers) and tactical networks for many systems, including NASAMS air defence. Both companies have a strong history in their respective domestic defence and secure communications markets, with significant export potential. ​

“By consolidating KONGSBERG’s secure communications and Thales’ crypto expertise, we will create a comprehensive, robust communications offering and be better positioned to deliver and develop current and future technologies and services to the armed forces,” said Eirik Lie, President of Kongsberg Defence & Aerospace. “Together, we can develop and sustain a broader and stronger product portfolio and domain expertise to create a solid partner for the Norwegian customer, while also gaining access to better market channels internationally, particularly with the support of Thales’ global distribution network,” said Lie.  “Through this jointly owned company, we will be able to strengthen collaboration and leverage synergies between KONGSBERG and Thales, creating a new key player ​ in secure communications that supports bilateral cooperation between Norway and France. The new company will be also particularly well-positioned to address markets where there are complementarities between Thales and KONGSBERG’s portfolio and geographical footprint,” said Christophe Salomon, Executive Vice President of Thales, Secure Communications & Information Systems.

The completion of the transaction is subject to customary regulatory approvals.

 

26 Jun 25. Bittium launches a comprehensive portfolio of life cycle services to maximize the operational life and performance of tactical communications solutions and to enable local servicing and repair capabilities for the customers in the defense sector. The services are offered for all life cycle stages of the products and systems to support their deployment, use, and eventually transition into a new generation of solutions. The life cycle services support the operational activities of the customers and are adapted to their needs flexibly. Core of the life cycle services is a comprehensive entity of support and maintenance services that entails technical support by Bittium and local partners as well as maintenance of both hardware and software over their entire life cycle. Bittium’s products and systems for tactical communications are designed for extremely demanding use over decades, requiring active management of hardware component life cycles. In systems based on software-defined radio technology, also software maintenance and updates play a particularly significant role. The support and maintenance services entity covers software maintenance and updates and ensuring software compatibility with other elements of the system as well as third-party elements integrated with the system. In addition to the support and maintenance services, Bittium provides several additional services such as training and on-site support according to customer needs. Especially in military crises, customers have a need for localized servicing and repair measures. Bittium enables it by offering different levels of services that can be trained and transferred as part of the customer’s organization. The localized servicing and repair capabilities empower customer sovereignty and maximize operational availability, reducing dependence on Bittium’s support.

“We have formed our life cycle services as a comprehensive entity that meet the requirements of our customers and support their operational activities flexibly. Due to the shift in the state of the world, the need for localized services has grown, and it is important to consider when offering the services. The implementation of life cycle services as complete solutions also helps our customers budget annual expenses and ensure service availability,” said Tommi Kangas, Senior Vice President of Bittium’s Defense & Security business segment.

Life cycle services are an important part of the overall offering of Bittium’s Defense & Security business segment. By developing the offering of life cycle services, Bittium responds to growing customer needs, which also supports Bittium’s growth objectives.

More information on Bittium’s life cycle services: https://www.bittium.com/defense-security/life-cycle-services/

 

27 Jun 25. Global: New ransomware group points to sustained operational, financial risks facing global firms. On 24 June, the cyber security company Trustwave reported that a new ransomware group (‘Dire Wolf’) has targeted at least 16 global entities since its emergence in May. The group has primarily targeted organisations in the technology and manufacturing sectors, highlighting the elevated operational and financial risks facing these sectors. The group’s victims are global in nature; targets in the US and Thailand have reported the highest number of attacks by Dire Wolf since May. Dire Wolf uses UPX (an executable file compressor tool), which is a common method employed by cyber threat actors to obfuscate malware code so as to inhibit static analysis, pointing to the group’s moderate sophistication. While Dire Wolf’s current arsenal is relatively standard for ransomware groups, we assess that the continuous emergence of new ransomware groups along with the uptick in ransomware operations in 2025 will sustain operational and financial risks facing global firms. (Source: Sibylline)

 

26 Jun 25. US-East Asia: Long-term intrusion campaign highlights security risks from Chinese threat actors. On 23 June, the cyber security company SecurityScorecard reported that unnamed China-linked threat actors have conducted multiple intrusion campaigns to infect devices across the US and East Asia since at least September 2023. The assailants typically integrate targeted devices – including small and home office (SOHO) routers, Internet-of-Things (IoT) devices, virtual servers and IP cameras – into an operational relay box (ORB) network (‘LapDogs’) to conduct stealthy cyber activity. LapDogs typically infects no more than 60 devices at a time and comprises at least 162 intrusion sets, highlighting the scale and targeted nature of these operations. China-linked threat actors use ORBs to conceal the origins of malicious traffic, likely in a bid to enhance stealth. The report follows an uptick in the number of instances concerning Chinese intrusions into organisations operating across the aforementioned regions. Consequently, we assess this highlights the elevated security risks stemming from China-linked actors amid ongoing geopolitical tensions. (Source: Sibylline)

 

25 Jun 25. Senior Official Promotes Bolstering DOD Cyber Workforce. During a cybersecurity workforce showcase in Washington yesterday, a senior-level Defense Department official spoke to members of Congress and representatives from the academic and cyber communities about the need to increase the department’s cybersecurity workforce.

Mark Gorak, director of DOD’s Cyber Academic Engagement Office, said there is currently a shortage of over 20,000 cyber professionals departmentwide, including 7,000 essential positions. “We’re at a critical point; cyber talent is a national security imperative,” he told the group, adding that the need for skilled cyber professionals has never been greater amid a constantly changing digital landscape filled with relentless adversaries.

To meet that challenge, Gorak highlighted the work being done through “CyberSkills2Work.”

That program, he said, focuses on drawing in veterans, transitioning service members, first responders and current federal employees, and then providing them with the skills needed to work in the cybersecurity field.

“These individuals understand service, often hold security clearances, possess mission-focused experience and are eager to continue contributing to our national defense,” Gorak said.  “Through tailored coursework, industry-aligned certifications and support networks, the program equips participants to transition into cybersecurity roles quickly and effectively to serve the nation,” he added.

In highlighting the progress made thus far, Gorak said the program has already prepared approximately 3,500 cybersecurity professionals, providing more than $10,000 in education and training.  Noting the program is “just one piece of a larger puzzle,” Gorak said a “comprehensive, multipronged approach” is needed to strengthen the cyber workforce. To that end, he said DOD’s chief information officer is pursuing five key initiatives to develop a “world-class” cyber workforce:

  • Qualifying personnel;
  • Mature, skills-based hiring;
  • Increasing certification and training opportunities;
  • Enhancing cyber workforce initiatives and pay flexibilities; and
  • Recognizing and addressing resource limitations.

Gorak said the CIO is increasingly relying on data to make better decisions about the cyber workforce and that a newly developed workforce health report is providing leaders with a clearer understanding of their cyber team by showing individual skill sets and the jobs the team is working on.

“This report pulls together information from across the department, helping leaders see where we have gaps in our workforce and how we can better recruit and keep talented people,” he said, adding that the report helps the department gauge the overall health of its cyber team.

Gorak concluded by emphasizing the role government plays in supporting the department, stating that — by supporting the Cyber Academic Engagement Office — Congress can expect improved cyber workforce development, enhanced national security readiness, streamlined points of contact for congressional inquiries, reduced redundancy and improved return on investment, and a one-stop shop for academia, partners and students.

“To the congressional members who support this program, to the educators who deliver this training and education, and to the learners, thank you,” Gorak said. “Let’s keep building the cyber workforce our nation needs into the 21st century and beyond.” (Source: U.S. DoD)

 

24 Jun 25. Turkish Air Force inducts F-16 EDPOD into operation. The EDPOD system is fully designed and developed using local resources. The Turkish Air Force has integrated a domestically produced electronic warfare system, the F-16 Electronic Support Pod (EDPOD), into its inventory. The system, created by the TUBITAK Informatics and Information Security Research Center (BILGEM), completed tests flight against actual radar systems, Türkiye Industry and Technology Minister Mehmet Fatih Kacir said in a post on X. Fully designed and developed from local resources, the EDPOD system can identify, categorise, document, and pinpoint radar signals from various enemy radars involved in target detection, tracking, missile guidance, and illumination, according to local newspaper Türkiye Today. This indigenous development aims to decrease Türkiye’s reliance on international defence technology.

“Developed to reduce our country’s dependence on foreign defence technologies, EDPOD has provided a strategic contribution to our electronic warfare capabilities,” Kacir said.

The EDPOD is equipped with both narrowband and wideband receivers, enabling it to detect multiple threats concurrently. The system’s analytical capabilities allow for comprehensive signal parameter assessment, facilitating the creation of an electronic order of battle for electronic warfare operation planning, the newspaper added. Additionally, EDPOD can archive extensive raw signal data for detailed post-mission analysis and facilitate real-time threat data sharing through Link-16 with ground forces and other airborne systems. This significantly improves situational awareness for F-16 pilots and aids in synchronized electronic warfare strategies.

“I congratulate all our colleagues who contributed to this effort and thank the Ministry of National Defense and the Presidency of Defense Industries for paving the way for the development of national systems,” Kacir added. (Source: airforce-technology.com)

 

25 Jun 25. Global: Botnet expansion underscores increased security, financial risks facing businesses. On 22 June, the security company CloudSEK reported that threat actors have been exploiting legitimate servers to expand the ‘Androxgh0st’ infrastructure. The perpetrators have employed a wider range of initial attack vectors since a previous report was issued in 2024, which has resulted in an approximately 50% expansion of the botnet’s arsenal. This includes the exploitation of software vulnerabilities in internet-facing servers used by prominent academic institutions. The threat actors then establish communication with command-and-control (C2) infrastructure before installing web shells to maintain persistence. Androxgh0st operators also typically exploit additional software vulnerabilities to execute commands remotely; they subsequently steal sensitive information and ‘mine’ for cryptocurrency. The botnets allow the threat actors to propagate cyber attacks via a network of infected devices, underscoring the potential scale and impact of Androxgh0st’s activity. We assess this will increase security, disruption and financial risks facing global entities amid a spike in botnet-related operations since the beginning of 2025. (Source: Sibylline)

 

24 Jun 25. US: Cyber campaign underscores heightened security risks facing academics, Russia critics. On 21 June, international news outlets reported that the suspected Russian state-sponsored group ‘UNC6293’ has been targeting prominent academics and critics of Russia in the US via a social engineering campaign since at least April. The group distributes spear phishing emails impersonating the US State Department as an initial attack vector. The emails trick victims into creating and sharing an app-specific password to log in to a threat actor-made online meeting platform. UNC6293 then steals the password to hijack victims’ Gmail accounts, likely to monitor user activity and exfiltrate sensitive data. The group often exchanges several emails with victims before coercing them into creating the password, showcasing the premeditated and prolonged nature of this campaign. The attack also requires pre-obtained knowledge of the victims’ systems, highlighting the group’s sophistication and resources. As such, we assess this campaign underscores the heightened security, social engineering and data theft risks facing the aforementioned entities amid current geopolitical instability. (Source: Sibylline)

 

20 Jun 25. Cyber Update Key points

  • A cyber surveillance operation underscores heightened security risks posed to European journalists by the spyware ‘Graphite’.
  • The new wiper feature for the Ransomware-as-a-Service (RaaS) operation ‘Anubis’ will increase security, disruption and destruction risks to global businesses.
  • Increased cyber activity highlights elevated financial, operational and security risks to operators in Israel and Iran amid the escalating war.
  • A deepfake-enhanced cyber campaign raises security risks from the North Korean state-sponsored group ‘BlueNoroff’ (see Sibylline Cyber Daily Analytical Update – 19 June 2025 and our Technical analysis below).
  • A cyber espionage operation against a US-based telecommunications provider highlights long-term national security risks posed by the Chinese state-sponsored group ‘Salt Typhoon’ (see Sibylline Cyber Daily Analytical Update – 20 June 2025).

Technical analysis of weekly stories

The Anubis RaaS operation has been responsible for destructive cyber attacks against global businesses (including the construction engineering and healthcare sectors) since at least December 2024. Anubis can be purchased on several cyber criminal forums and enables affiliates to choose from different monetisation avenues, underscoring the continuous evolution of RaaS operations and cyber criminal revenue streams. Threat actors reportedly distribute Anubis via spear phishing emails that trick victims into opening a malicious attachment. The attachment then executes the main ransomware payload before escalating privileges and deleting all backup system files to hinder recovery efforts. Threat actors subsequently identify and encrypt all system files via the Elliptic Curve Integrated Encryption Scheme (ECIES), exfiltrate sensitive data for double extortion and issue a ransom demand for file decryption. The ransomware also contains a wiper component (/WIPEMODE) that can permanently delete all encrypted files regardless of whether the ransom is paid. This feature marks a departure from typical ransomware variants that focus on temporary disruption for financial gain. The North Korean state-sponsored group BlueNoroff is using artificial intelligence (AI)-generated deepfakes to conduct a cryptocurrency-theft campaign against macOS systems. In one incident, the group contacted an employee at an unnamed cryptocurrency company via the messaging platform Telegram to trick them into joining an online meeting. The online session used a fake domain for the virtual meeting platform Zoom and displayed several deepfakes that impersonated members of the company’s leadership as well as external participants. This highlights the continued incorporation of deepfakes into cyber operations to enhance credibility. During the meeting, the actors also faked a microphone issue to coerce the employee into downloading a fake Zoom extension that contained a malicious payload and script. The malicious code then executes an implant (‘Telegram 2’) to establish command-and-control (C2) communication and download additional payloads. This included a backdoor and a remote access trojan (RAT) to maintain persistence within compromised systems and enable remote code execution, as well as a keylogger and a cryptocurrency-focused information stealer to steal user credentials for financial profit. BlueNoroff also exploited several macOS edge cases to inject code into existing processes, highlighting the group’s sophistication.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

Our cyber word(s) of the week: Deepfake (Source: Sibylline)

 

20 Jun 25. Silvus Technologies StreamCaster LITE 5200 Added to DIU Blue UAS Framework. Silvus Technologies, Inc., a global leader in advanced wireless networking communication systems, announced that the U.S. Department of Defense (DoD), Defense Innovation Unit (DIU), has officially added Silvus’ StreamCaster LITE 5200 (SL5200) OEM Module to the Blue UAS Framework. Delivering powerful MANET radio performance for today’s leading-edge unmanned systems, the SL5200 unifies C2, sensor and telemetry data with communications relay capabilities in an easy to integrate, ultra-low SWaP OEM module form factor. After undergoing the Blue UAS program’s rigorous evaluation, this certification validates the SL5200 compliance with DoD standards for cybersecurity, supply chain integrity and operational reliability. Interoperable and NDAA compliant, the SL5200 has been approved for use in conjunction with Blue UAS platforms. The SL5200 joins the StreamCaster SC4200EP and StreamCaster LITE SL4200 MANET radios on the Blue UAS Framework – exemplifying Silvus’ commitment to delivering robust, secure, and reliable C2 and mesh networked communications solutions for unmanned operations across any domain.

“Silvus continues to push the boundaries of mesh networking for mission-critical unmanned systems applications,” said Jimi Henderson, VP of Sales, Silvus Technologies. “With all three of our latest StreamCaster MANET radios now on the Blue UAS Framework – we’re proud to lead the way in secure, resilient communications technology for unmanned systems developers.”

SL5200: Blue UAS Framework Certified. The Power To Perform

Compact and powerfully versatile, the SL5200 delivers class-leading power, range, and tactical mobility with up to 2 Watts output power (4W effective power, thanks to TX Eigen-Beamforming), and 100 Mbps data rate for bi-directional C2, video, sensor and telemetry data communications in one self-contained OEM Module.

Featuring an ultra-low SWaP profile (52g), with multiple I/O interface options (Ethernet, USB, RS232), the SL5200 is designed for seamless integration into leading-edge unmanned systems, loitering munitions, and other SWaP constrained embedded applications. Systems operators can now experience Group 2 UAV level radio performance in a compact form factor engineered for Group 1 sized platforms.

At the heart of every StreamCaster MANET radio is Silvus’ battle-proven MN-MIMO waveform, that creates a self-forming and adaptive mesh network – capable of linking hundreds of nodes with unmatched range, throughput, EW resiliency and scalability. With the SL5200, operators can connect multiple UAVs, UGVs, USVs, sensors, personnel, and manned/unmanned platforms, to actualize a common operating picture through one massively scalable mesh network. The SL5200 is seamlessly compatible with 4000-series StreamCaster MANET radios, ensuring interoperability across a diverse range of applications. In addition to AES256 and FIPS 140-3 encryption for secure operations, the SL5200 provides available access to Silvus’ Spectrum Dominance – an expansive suite of LPI/LPD and Anti-Jamming resiliency capabilities. Silvus is the only tactical MANET radio provider that delivers Spectrum Dominance secure and protected communications in complex, congested and contested environments, without sacrificing performance. (Source: UAS VISION)

——————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

June 20, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

——————————————————————————————————————————————————————————————————————————————————————————————————————————————

19 Jun 25. Global: Deepfake-enhanced cyber campaign will increase security risks from North Korean actors. On 18 June, the security company Huntress reported that the North Korean state-sponsored group ‘BlueNoroff’ is using artificial intelligence (AI)-generated deepfakes to conduct a cryptocurrency-theft campaign against macOS systems. In one incident, the group contacted an employee at an unnamed company to trick them into joining an online meeting. During the meeting, the actors used deepfakes to impersonate members of the company’s leadership as well as external participants, highlighting the continued incorporation of deepfakes into cyber operations to enhance credibility. The group subsequently tricked the employee into downloading a malicious file containing a backdoor and a cryptocurrency-focused information-stealer to extract user credentials for financial profit. This incident marks the first adoption of deepfakes to impersonate company executives by North Korean state-sponsored groups. This underscores increased security and financial risks to global businesses as Pyongyang continues to leverage social engineering and AI tools to bolster its weapons and missile programme. (Source: Sibylline)

 

18 Jun 25. Accelerating Cyber Resilience: Air Force, DARPA Join Forces to Strengthen Cyber Defenses. The United States Air Force will incorporate formal methods-based tools on the MQ-9 Reaper via DARPA’s Resilient Software Systems Capstone program A strong, lethal military demands cutting-edge and resilient software to power every weapon and support system our U.S. warfighters depend on. However, the Department of Defense’s (DOD) reliance on aging IT infrastructure, using security policies developed over the last 30 years, creates inherent vulnerabilities in its systems, from legacy architectures to advanced weapons. Meanwhile, threat actors are actively exploiting these vulnerabilities, targeting critical infrastructure, stealing sensitive military code, and reengineering sensitive systems to compromise national security. In response, DARPA has been developing powerful tools leveraging formal methods—a mathematically rigorous approach to software development that helps eliminate exploitable vulnerabilities before software is deployed. Working closely with DARPA, the U.S. Air Force will incorporate this rigorous approach into its MQ-9 Reaper program. Rather than testing software for vulnerabilities after it’s built, formal methods use mathematical proofs to verify software behavior as it’s developed. This approach ensures software performs exactly as intended, making it inherently more secure. Many of DARPA’s formal methods tools have already transitioned to military services for further development and operational deployment. Strong overall cyber resilience requires urgent, broader adoption.

Resilient Software Systems Capstone program

The agency is partnering with each of the services via its Resilient Software Systems Capstone program to address this pressing need. The Capstone program comprises jointly funded projects on operational platforms aimed at assessing critical findings, including level of resiliency, cost, time, and level of expertise required to adopt various formal methods capabilities.

Each project will run for approximately 24 months. Objectives include:

  • Achieving inherently more secure software;
  • Accelerating the Authority to Operate (ATO) process;
  • Streamlining software developmental testing; and
  • Developing a “Best Practices Guide” to support broad adoption.

“The current patch-and-pray approach to software development for DOD systems is simply unacceptable when lives depend on those systems,” said Stephen Kuhn, DARPA Capstone program manager. “DARPA’s transition approach through the Capstone brings resilient software tools to both the services and industry partners and will allow us to capture the lessons learned to drive broad adoption of correct by construction. This effort will serve as a template that can be used by others to help jumpstart their efforts to incorporate DARPA’s resilient software tools into their platforms and development pipelines.”

The U.S. Air Force is the first organization to identify their pilot weapon system – the MQ-9 Reaper program, developed by General Atomics-Aeronautical Systems Incorporated (GA-ASI).

Traditionally, when developing resilient cyber-physical systems, original equipment manufacturers (OEMs), such as GA-ASI, and Program Offices design to standardized industry controls. They use static code analysis tools to identify manual coding errors that may lead to issues in software stability and/or potential cyber vulnerabilities.

The challenge is that the span and complexity of software changes on legacy weapon systems often result in vast amounts of developmental and cyber testing, which can last 12-18 months in a typical software upgrade program.

Formal methods have shown promise in combating these lengthy test and evaluation cycles. DARPA’s suite of software assurance/cyber resiliency tools have demonstrated the ability to conduct more verification activities upstream into the development environment, as opposed to the typical test stages when the software is already finalized.  Designed for use on existing legacy source code, these tools can generate validated models of software behaviors directly from that code, dynamically assess those behaviors for resiliency/stability/safety, and can even generate specific artifacts used for certification purposes such as ATOs and airworthiness.

Simply put, Program Offices and OEMs now have software acceleration tools to use on existing code, that complement policy improvements such as the Software Acquisition Pathway.

Air Force selects MQ-9 as capstone

The Air Force team working with DARPA on the Capstone chose the MQ-9 due to the lower technical barriers-to-entry of the weapon system itself, as well as the lower cultural barriers-to-entry within the organizational enterprise.

“The MQ-9 Capstone program will improve DARPA program support by providing a step-increase in our ability to accelerate robust and resilient weapon system software to the field,” said Oren Edwards, Chief Engineer of the Air Force Life Cycle Management Center’s Medium Altitude UAS Division.

“One of the cultural barriers-to-entry of digital transformation is the misperception that massive investments in time and money are required to show any transition wins on a program, a misperception we commonly associate with the ‘valley of death’” he said. “Investments are, in fact, required, but there’s an entire cottage industry of government and commercial tools that continuously show that misperception to be false, and that’s what we’re doing here. Using DARPA’s assurance acceleration tools to move certain verification activities upstream in the software development cycle will improve agility not only for the MQ-9 but will also present significant leverage opportunities for follow-on programs across the USAF and DOD.”

DARPA is also working with the Departments of the Navy and Army, and the National Aeronautics and Space Administration (NASA) on additional Capstone program platform experiments. (Source: ASD Network)

 

18 Jun 25. Thales unveils mini electronic warfare payload for drones.

  • Thales has launched a lightweight, remotely controlled electronic warfare payload for deployment by small drones to detect and locate radio signals.
  • Easy to use by military operators with no specialised training, the mini payload heralds a new generation of interoperable, quick-to-deploy sensors that will complement dedicated electronic warfare assets in the theatre of operations.
  • The new system represents a breakthrough in terms of access to electromagnetic intelligence, offering front-line units an unprecedented operational intelligence capability for that is readily accessible, agile and discreet and can be adapted for use by land or naval forces. At the Paris Air Show (16-22 June 2025), Thales is presenting a new electronic warfare solution to meet the need for more closely integrated electromagnetic dominance operations across all military units.

Traditionally only conducted by highly specialised units, electromagnetic dominance operations are now needed by all tactical formations as a pre-requisite for battlefield superiority.

With the growing intensity of electronic warfare operations, this new Thales solution is designed to provide all deployed forces, including non-specialised units, with an initial, autonomous detection, location and analysis capability.The development of this innovative solution follows a proof-of-concept (PoC) awarded to Thales by France’s Defence Innovation Agency (AID) after a European competitive procurement process. During the PoC phase, multiple users successfully tested the solution in a range of different use cases.

“The current geopolitical context and the emergence of new threats have underscored the expanding role of electronic warfare in the theatre of operations and demonstrated a growing need for all combat units to have direct access to these crucial capabilities. Today we are able to offer a unique new solution that is discreet and easy to use by non-specialised units to enable deployed forces to gain and maintain information superiority in the field. The new solution demonstrates Thales’s capacity for innovation and the ability of our development teams to respond extremely quickly to new operational requirements,” said Christophe Groshenry, Vice President, Radio Communications Products, Thales.

Weighing less than 5 kg and with a power requirement of under 40 W, the new payload is optimised for deployment by light drones. It can be installed on free-flying or autonomous drones, or on tethered drones powered and connected to the ground by a cable, to detect radio sources tens of kilometres away with no active emissions, which is a major advantage in contested environments.

 

17 Jun 25. Singapore’s Defence Science and Technology Agency (DSTA) and Italy’s ELT Group have signed a Memorandum of Understanding (MOU) to advance collaboration in the co-development of defence technologies for the Singapore Armed Forces (SAF). The agreement was signed on the sidelines of Paris Airshow 2025 and reinforces the successful cooperation between DSTA and ELT Group. The partnership will focus on innovation in sensors and digital technologies, and application of artificial intelligence and machine learning to advance Electro-Magnetic Spectrum Operation (EMSO) capabilities. This will support Singapore’s defence capability development in EMSO.

DSTA’s Chief Executive, Mr Ng Chad-Son said, “In today’s multi-domain operational landscape, the ability to sense, sense-make and act is decisive. We look forward to working with ELT Group to develop innovative solutions in the EMSO domain to give the SAF the edge to operate faster, smarter and more securely in challenging environments.”

ELT Group’s CEO & COO, Ms Domitilla Benigni said “We are very proud of the signing of this agreement, which confirms, once again, that our expertise in electromagnetic spectrum management is recognised and appreciated. Our relationship with Singapore is getting stronger and stronger, and we now look forward to work with DSTA and strengthening our collaboration in new domains such as EMSO on unmanned platforms”.

 

17 Jun 25. The R&S FSWP phase noise analyzer and VCO tester from Rohde & Schwarz, the industry standard for phase noise testing, has just received a major performance update. It is the optimal test solution for radar applications and when developing and manufacturing synthesizers, OCXOs, DROs and VCOs. With the new option R&S FSWP-B56G, Rohde & Schwarz has extended the frequency range for absolute phase noise measurements from 50 GHz up to 56 GHz. Done simply by pushing a button, no external converter is needed. These frequencies are needed for satellite communication and for jitter measurements in high-speed digital applications such as ultra-fast LAN IEEE 802.3dj or CEI-224G (Common Electrical I/O).

Speeding up measurements with external high-end signal sources

In addition, the updated R&S FSWP now supports external signal sources as local oscillators for absolute phase noise measurements up to 56 GHz. Using a high-end signal source enables users to get their results much faster, because only a few cross correlations are needed to measure the phase noise of the DUT, such as another high-end oscillator. Depending on the quality of the source, users can measure up to 1000 times faster compared to the internal source. The R&S FSWP provides tuning outputs to lock the signal source frequencies used as local oscillators to the DUT frequency. In this mode, users can measure with one or two external oscillators to get the full advantage using cross-correlation techniques. Alternatively, they can use this mode to measure two identical sources against each other (2 DUT method) and correct the results by 3 dB.

Additive and residual phase noise measurements up to 56 GHz

Equipped with R&S FSWP-B56G option, the instrument is also useful for additive and residual phase noise measurements up to 56 GHz with a frequency offset of 40 MHz on amplifiers or other components. The frequency range of the internal source for this application is now extended to 50 GHz, or up to 54 GHz with the R&S FSWP-B56G option. With external sources users can measure up to 56 GHz.

In addition, the R&S FSWP features a new marker function “NOISE FIGURE MARKER”. Users can measure the noise figure of an amplifier easily, just connecting it between the output of the signal source and input of the R&S FSWP. This easy new method for measuring the small signal noise figure of amplifiers is based just on the phase demodulation same as the phase noise measurement. As the R&S FSWP is equipped with a signal and spectrum analyzer, it delivers both the Y-factor measurement based on noise sources with a calibrated ENR in the spectrum analyzer as well as the new noise figure measurement based on demodulation in the phase noise tester.

The updated R&S FSWP phase noise analyzer and VCO tester is available from Rohde & Schwarz as off July 2025. It will be showcased for the first time to the public at IMS2025 Exhibition from June 17 to 19, 2025, at the Moscone Center in San Francisco, CA, at the Rohde & Schwarz booth 1443. For further product information, go to: https://www.rohde-schwarz.com/product/fswp

 

16 Jun 25. Telespazio UK Announces Successful Completion of Critical Phase in ALIGN Programme. ALIGN is the UK’s first Autonomous Laser Inter-Satellite Communications Programme. Telespazio UK, a subsidiary of Telespazio (a 67/33% joint venture between Leonardo and Thales), is proud to announce the successful completion of Phase 3 of the Autonomous Laser Intersatellite Gigabit Network (ALIGN) programme – an important milestone in developing the UK’s first commercially available autonomous, laser-based, inter-satellite communications system for CubeSats. The ALIGN project, funded through the UK Space Agency’s National Space Innovation Programme (NSIP), aims to revolutionise satellite communications by enabling secure, high-capacity data transfer using laser-based inter-satellite links (ISL). Laser communication can transmit up to 1,000 times more data per second than conventional radio systems, with enhanced security and reliability.

Led by Northumbria University, the ALIGN consortium includes Telespazio, Durham University and SMS Electronics, and receives support from Lockheed Martin. Since the start of Phase 3 in January 2023, the project has successfully navigated significant technical and programmatic challenges to achieve key objectives by the 31 March 2025 project close deadline:

  • Development of the LDB CODEC board: Telespazio UK successfully designed and delivered the Laser Data Buffer (LDB), a bespoke board with integrated software and firmware that serves as the central control system for the optical inter-satellite link (ISL) payload. It manages all core payload functions and codes, and decodes high-speed laser data.
  • Design and Demonstration of Optical ISL Payload: Two engineering models of the optical payload, named “FOCUS” (Freespace Optical Communication Unit for Space), were built, integrated and tested. These included the LDB board and successfully demonstrated high-speed laser communication between units.
  • CubeSat Platform Integration: The ALIGN team completed integration and interface testing of the CubeSat platform, validating power and data communication links between the platform and the FOCUS payload.

Looking ahead, the ALIGN team is exploring opportunities for a potential Phase 4. Telespazio UK’s LDB product is poised to play a vital role not only in the ALIGN programme, but also in future missions involving optical communications and satellite networking. A first in-orbit demonstration of the technology is on the horizon.

Trevor Beard, Telespazio UK’s VP – Research and Development, said: “We were delighted to integrate and demonstrate our LDBs into the FOCUS engineering models and see high-speed data going end-to-end on the free-space laser links. It is exciting to work with the novel laser, sensor and optical assemblies from our ALIGN partners, and to see just what impressive performance can be achieved in these miniaturised Inter Satellite Link terminals. We are looking forward to preparing the space-ready assemblies.” (Source: ASD Network)

 

16 Jun 25. Europeans rush drone-based radar jammers in effort to supplant US tech. European NATO countries are eyeing drones for airborne electromagnetic-warfare operations including radar jamming, a skill many of the continent’s air forces are currently lacking. Italy’s Leonardo says between ten and twenty NATO countries have expressed interest in a capability similar to the StormShroud radar-jammer drone it provided to the U.K. Leonardo has taken a lead in radar-jamming drones with StormShroud, built around the company’s BriteStorm jammer on an unmanned aerial system from Portugal’s Tekever. U.S., European and Israeli rivals will be presenting some of their airborne electronic warfare offerings at the Paris Air Show starting here on Monday. Europe largely depends on the U.S. for airborne electromagnetic warfare, a gap some countries are looking to address amid uncertainty about American commitment to the continent. Meanwhile, an aggressive Russia has been expanding capabilities based on its experience in Ukraine, where drones are omni-present, including in the electronic-warfare role. Ukraine “has become a drone war with drone and counter-drones, and electronic jamming is part of that,” said Dick Zandee, senior research fellow at Dutch think tank Clingendael Institute and former head of planning at the European Defence Agency. “You see a ‘dronization’ taking place in a lot of areas now, including in electronic warfare.”

European NATO countries face a “critical” capability gap in airborne electromagnetic warfare, a potential risk in case of Russian aggression, analyst Justin Bronk at the U.K.’s Royal United Services Institute said in a report in March. Bronk called for European countries to lift funding to develop stand-in airborne electromagnetic attack capabilities, based on “relatively cheap” uncrewed autonomous systems that can loiter over hostile territory and would be a quick way to expand their capabilities. Leonardo has received “significant interest” in BriteStorm from NATO countries as well as defense primes, according to Michael Lea, the company’s vice president of sales for electronic warfare. Lea added he doesn’t expect any public announcement before the fourth quarter of 2025. There is “clearly the desire from some European nations to not be as dependent on the U.S. as they have been previously,” Lea said. The executive declined to name possible drone partners, but noted Leonardo has ties with drone makers including General Atomics, the maker of the MQ-9 Reaper, and Turkish Aerospace Industries. While Leonardo won’t showcase StormShroud in Paris, it will be holding a signing ceremony for a joint venture with Turkish drone maker Baykar Technologies on Monday. Stand-in radar jamming is typically in close proximity to hostile air-defense systems, as opposed to long-range stand-off jamming outside of weapons-engagement zone. Escort jamming is typically used to protect the own forces from enemy air defenses. Countries in Eastern Europe including Poland face threats with a “very extended range, so you are into stand-in jamming the moment you get airborne,” Lea said. “They can’t do stand-off jamming because they’re inside the threat envelope of adversary systems.” Drone-based stand-in jammers are cheaper, attritable, and potentially more effective by operating closer to the threat, which means that in the European theater of operations they may be a better solution than stand-off jamming, according to Lea. Still, the two approaches are complimentary and will continue to exist together, the executive said. One thing Ukraine has shown is that uncrewed capabilities planned to accompany sixth-generation fighter aircraft need to become available “far earlier,” with systems such as StormShroud allowing fourth and fifth-generation fighters to be more effective and operate more freely.

“If you can have a larger number of electronic-warfare, decoy and deception platforms, that has a value in itself, and that has absolutely been demonstrated in Ukraine,” Lea said. “I can absolutely see how you can solve a mass challenge with uncrewed platforms that allows the four-generation platform to operate as it was intended at the start of its design case.”

The trend is to move the anti-radar mission to drones because the size and recognizability of aircraft makes them easier to detect and therefore take down, as well as “terribly expensive,” Zandee said. “So, you do that kind of thing with drones.” Leonardo has an advantage in being able to declare an operational capability in radar-jamming drones with the Royal Air Force, though Lea expects announcements from competitors within the next 12 months.

“As a result of the very urgent requirement to operate in a contested electronic warfare environment, a lot of companies are trying to tackle this challenge,” Lea said. “We would be complacent to think that other competitors aren’t developing their products in the market.”

Raytheon makes the MALD-J, a jamming variant of its expendable decoy missile which the company says is the first-ever stand-in jammer to enter production. Leonardo meanwhile is working with pan-European missile maker MBDA to develop the Spear-EW stand-in jammer missile for the U.K.

At the Paris Air Show, Raytheon will present its Next Generation Jammer, a long-range jammer for the U.S. Navy’s E/A-18 Growler electronic-warfare aircraft. The Navy declared initial operational capability for the mid-range band version of the system in December. Modern Western radar-jamming systems including BriteStorm and MALD use Digital Radio Frequency Memory, which allows a jammer to record incoming radar signal and retransmit them with modifications, creating false targets and signals or just overwhelming the enemy system with noise. The work on StormShroud is based on the BriteCloud digital decoy ordered by the U.S. for the F-35, also used by the U.K. on the Eurofighter and available as an option on the Saab Gripen. Due to the situation in Ukraine, the Middle East and farther East, “our potential adversaries are learning very quickly,” Lea said. “StormShroud’s development is the U.K.’s clear aspiration to demonstrate it has a capability that can seek to challenge those threats.” Germany’s Hensoldt has been developing the Kalaetron Attack radar jammer for airborne electronic attack, focused on stand-off jamming or as an escort jammer onboard the Eurofighter, and also available in a stand-in jamming configuration. The company, which will be present in Paris, flight tested the DRFM-based system in 2023. A consortium led by Indra Sistemas that also includes Hensoldt, Elettronica and Saab has been working on a project called Responsive Electronic Attack for Cooperative Tasks, or REACT, aimed at developing a multi-jamming capability that can be integrated inside unmanned aerial combat vehicles for stand-in jamming or in pods for escort jamming. The project’s second phase will last through 2028 and received €40 m in European Union funding in 2023, on a total budget of €69.7 m, following a first three-year phase of feasibility studies and design. REACT is part of the Airborne Electronic Attack project established in 2019 within the EU’s Permanent Structured Cooperation framework. The Danish armed forces in May tested drone-based electronic warfare with a UAS from Ukraine’s Skyeton equipped with a radio-frequency payload from Denmark’s Quadsat, which the Danes said can locate and attack an adversary from hundreds of kilometers away. Skyeton and Quadsat followed up with an agreement later that month to jointly offer drone-based electromagnetic-spectrum surveillance. Electronic warfare until recent years has mostly been platform centric, so focused around the aircraft performing that mission, from specialists such as the U.S. Navy’s Growler to electronic-warfare suites such as Thales’s Spectra on the French Rafale. Thales will unveil a miniaturized electronic-warfare payload for small drones on Monday, designed to detect and locate radio communications and which the company says will be a breakthrough in electromagnetic intelligence and provide forces in combat with “unprecedented operational intelligence capabilities.” Elbit Systems will have a dedicated electromagnetic warfare section at its Paris Air Show, but said it won’t be displaying any drone-based EW systems.

For now, BriteStorm doesn’t incorporate artificial-intelligence enabled “genuine cognitive EW capability,” also due to the power requirements of AI, according to Lea.

“It’s clearly on our roadmap for the future, but we will have to understand how we incorporate some of the exceptionally rapid developments in machine learning and artificial intelligence onto a quite small payload that may have to operate autonomously,” Lea said, adding he doesn’t expect much in the way of public announcements there. “People will tend to be quite coy about that.”(Source: Defense News)

 

13 Jun 25. Global: Evolution of ransomware tactics underscores increased security risks facing businesses. On 12 June, the cyber security company Symantec reported that the ‘Fog’ ransomware operation is using legitimate open-source tools to conduct cyber operations. The group typically uses stolen credentials and/or exploits software vulnerabilities to infiltrate targeted systems. It then conducts ‘pass-the-hash’ attacks to escalate privileges; it subsequently deploys open-source tools to mimic legitimate activity and enhance detection evasion. In May, Fog used a legitimate employee monitoring software (‘Syteca’) against an unnamed financial institution in the Asia-Pacific region to collect sensitive employee information. The group also employs backdoors, system monitoring utilities and other remote execution tools to establish communication with command-and-control (C2) infrastructure, as well as to maintain its persistence, exfiltrate data and conduct additional malicious activity. Fog then disables security tools before encrypting all system files. We assess the adoption of open-source software marks a departure from traditional ransomware tactics, underscoring the increased security risks stemming from the continuous evolution of ransomware operations. (Source: Sibylline)

 

16 Jun 25.  Chess Dynamics, part of the Cohort plc Group, has successfully demonstrated the exceptional capabilities of its Vision4ce Deep Embedded Feature Tracking (DEFT) technology during the comprehensive WINTERMUTE 3 trial with the Defence Science and Technology Laboratory (Dstl). The rigorous testing event provided one of the most challenging scenarios possible, featuring multiple targets including sea vessels, helicopters, drones and land vehicles operating simultaneously in cluttered backgrounds with varied visibility conditions. Chess Dynamics’ Vision4ce tracking software, deployed on the Hawkeye Multi Sensor (Hawkeye MS), delivered robust performance that met high expectations across both daylight and infrared sensors, even when contrast was low.

The DEFT AI algorithm demonstrated exceptional tracking capability, maintaining robust target lock in complex and cluttered environments while adapting dynamically to changes in contrast, target size, orientation and movement patterns. The system’s fine-grain classification capability distinguished between different vessel types – a critical requirement for autonomous navigation and maritime law applications.

Key performance highlights included:

  • Outstanding closed-loop performance with highly dynamic targets, showcasing the advanced capabilities of both the Hawkeye MS platform and Vision4ce technology
  • Market-leading infrared capability with clean, low-noise imagery that clearly identified thermal signatures and points of interest
  • Robust all-weather performance maintaining detection and tracking capabilities across varied environmental conditions
  • Reduced operator burden through intuitive joypad controller interface and reliable tracking once targets are selected

The Hawkeye MS proved extremely reliable, robust and accurate throughout the week-long trials, which included daily dismantling and setup procedures, with no technical issues encountered. The platform’s precision movement capabilities and strong motors effectively counteracted wind conditions while maintaining exact positioning.

Steve Hogg, Director of Image Processing at Chess Dynamics, said: “These trials validated our Vision4ce technology’s exceptional performance in real-world conditions and confirmed we are very close to achieving ‘point and shoot’ capability with high-quality data on auto mode, requiring minimal operator training. The DEFT tracking system’s ability to maintain accurate target identification and tracking in such challenging multi-target scenarios demonstrates our market-leading position in AI-driven surveillance solutions. This performance validation builds crucial credibility beyond our internal testing and proves our technology is ready to meet the evolving demands of modern defence applications.”

The successful trials enabled Chess Dynamics to identify specific failure cases, driving a streamlined and automated process for rapid iteration, development and deployment of enhanced AI models. The comprehensive testing provided rare opportunities to validate system ease-of-use and gather critical user feedback from military end-users. A DSTL Spokesperson commented, “We were delighted to be able to try out Chess’s object detection and tracking system at WINTERMUTE 3 trial which provided a challenging set of multiple fast crossing and weaving boats. The joypad controller interface is very natural and intuitive to use, and we were impressed with the rock-solid tracking once a boat was selected.” DEFT represents Chess Dynamics’ latest advancement in real-time video and image processing solutions for electro-optic systems, designed to provide advanced autonomous capabilities while reducing training requirements and operational complexity. For more information, please visit www.chess-dynamics.com

 

13 Jun 25. Cyber Update Key points.

  • A new variant of the ‘Mirai’ botnet will sustain elevated security and disruption risks for vulnerable video recording devices (see Sibylline Cyber Daily Analytical Update – 9 June 2025).
  • A destructive cyber operation has underscored the security risks facing global businesses via malicious npm packages (see Sibylline Cyber Daily Analytical Update – 10 June 2025 and our Technical analysis below).
  • A spike in distributed denial-of-service (DDoS) attacks has underscored the elevated security and disruption risks facing the financial sector see our Technical analysis below).
  • A new cyber attack methodology (‘SmartAttack’) is showcasing the security risks facing air-gapped environments via smartwatch devices.
  • Evolving cyber tactics have underscored the increasing security risks stemming from the ransomware operation ‘Fog.’

Technical analysis of weekly stories

Unnamed threat actors are targeting global developers in a destructive cyber operation that starts with attackers injecting npm packages (‘express-api-sync’ and ‘system-health-sync-api’) with malicious code. The packages are typically used by developers to download application programming interfaces (APIs) that enable data syncing between two applications. However, the modified packages covertly install backdoor malware onto compromised systems. Express-api-sync uses flexible parameters to facilitate remote command execution; it then deletes all system files (including source codes, configuration files and local databases), effectively rendering the system unusable. System-health-sync-api contains several data syncing and configuration capabilities to feign legitimacy. The package also collects significant amounts of system information before deleting a system’s files; it can operate across several different systems, highlighting its sophistication compared to express-api-sync. Both packages use the Simple Mail Transfer Protocol (SMTP) to conceal command-and-control (C2) communication and to enhance detection evasion. The packages also create three endpoints upon execution to ensure platform-specific file deletion in case one of the endpoints fails. The attacks reportedly leave no trace of their execution, further showcasing the threat actors’ advanced capabilities. The Fog ransomware operation uses legitimate open-source tools to conduct cyber operations. The group typically employs stolen user credentials and/or exploits patched software vulnerabilities (including CVE-2024-40711); it often targets Microsoft Exchange servers to infiltrate systems. It then typically conducts pass-the-hash attacks to escalate privileges and to deploy open-source tools so as to mimic legitimate activity and enhance detection evasion. In May, Fog used legitimate open-source employee-monitoring software (‘Syteca’) against an unnamed financial institution in the Asia-Pacific region to collect sensitive employee information. Fog also executed several commands to remove traces of Syteca and other evidence of its deployment, highlighting the group’s obfuscation efforts. The group also employs backdoors, system-monitoring utilities and other remote execution tools to establish communication with command-and-control (C2) infrastructure, as well as to maintain persistence, exfiltrate data and conduct additional malicious activity. This includes the open-source tool ‘GC2’ (which Fog employs to exfiltrate sensitive files that use Google Drive and/or Microsoft SharePoint) and the C2 beacon ‘Adaptix’.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

Our cyber word(s) of the week: Pass-the-hash attack  (Source: Sibylline)

 

13 Jun 25. Rohde & Schwarz introduces the brand-new FSWX signal and spectrum analyzer, the first multichannel signal and spectrum analyzer with multiple input ports, unlocking new possibilities in signal analysis. It is also the first instrument of its kind with a cutting-edge internal multi-path architecture enabling a novel cross-correlation feature. Combined with its low phase noise for high signal purity, its spurious-free dynamic range and its outstanding residual EVM, the FSWX delivers an RF performance like no other signal and spectrum analyzer in the market. The instrument’s wide internal bandwidth of 8 GHz allows for comprehensive analysis even of complex waveforms and modulation schemes. Combined with a high measurement speed and analysis tools tailored to the user’s needs, the FSWX brings new levels of performance and precision to signal analysis for modern RF applications – from active RF components testing to state-of-the-art automotive radar testing to complex airborne radar scenarios and satellite test in A&D applications to the latest test challenges in WLAN and cellular technologies like 5G and beyond.

Michael Fischlein, Vice President Spectrum & Network Analyzers, EMC & Antenna Test at Rohde & Schwarz, is thrilled to introduce the new FSWX: “Our team has truly re-imagined signal and spectrum analysis technology with our new FSWX. They have come up with an innovative architecture and design to empower our customers to tackle complex measurement scenarios in the evolving landscape of wireless communications and radar technology that were previously unattainable. In other words, the FSWX makes measuring the impossible, possible.” The instrument’s innovative design features include multiple input ports, cross-correlation capabilities, advanced filter banks and broadband ADCs.

Multiple input ports

The multichannel FSWX offers the ability to measure multiple signal sources simultaneously, regardless of whether they operate at the same or different frequencies. With synchronous input ports, each featuring 4 GHz analysis bandwidth, users can seamlessly analyze the interactions between diverse signals. This opens up a multitude of new measurement scenarios, for instance, phase-coherent measurements of antenna arrays used in beamforming for wireless communications as well as in airborne and automotive radar sensors.

Multi-path architecture and cross-correlation

Its advanced internal multi-path architecture allows for the cross-correlation mode, a novel feature of the FSWX. A single signal input is internally split into two independent signal paths, each equipped with its own local oscillator and ADC. With this innovative design, advanced cross-correlation algorithms can be applied in the digital backend, effectively removing the inherent noise of the measurement instrument. This feature reveals spurs not easily seen without cross-correlation. It is especially helpful when, for instance, measuring Error Vector Magnitude (EVM), a critical factor in mobile communications. The added wideband noise of traditional signal and spectrum analyzers limits the accuracy and dynamic of EVM measurements. With the cross-correlation feature, however, the FSWX provides an unobstructed view of the DUT for precise EVM analysis. The internal multi-path architecture also offers advanced triggering options. For example, users can apply an IF or RF power trigger at distinct frequencies, as the multi-path design allows for independent frequency settings for each receive path behind the splitter. This way, the FSWX can easily reveal effects between two RF signals.

Advanced filter banks and broadband ADCs

Traditionally, for preselection in the microwave range, spectrum analyzers rely on YIG filters. Since they are known for their challenging frequency response, YIG filters need to be bypassed for wideband signal analysis. The FSWX, however, employs broadband ADCs in conjunction with filter banks that span the entire operating frequency range, allowing for pre-selected signal analysis while eliminating the need for YIG filters. The filter banks provide high precision, optimizing instrument settings for specific applications and significantly reducing the risk of unwanted signal images contaminating results. For users requiring narrowband applications, a YIG filter can still be added optionally.

Innovative firmware applications

The FSWX also provides innovative firmware applications such as the CrossACT (Cross Application Control and Triggering) firmware feature. It synchronizes various measurements across different input channels, allowing for simultaneous analysis with multiple tools. This capability simplifies comparisons, such as determining whether the higher harmonics of a radar signal directly impact the EVM performance of a 5G signal. The Linux-based operating system of the FSWX provides a high level of security and long-term support, essential features for users in security-sensitive environments. This robust operating system ensures reliability and stability, making the FSWX an ideal choice for demanding applications.

Rohde & Schwarz will present its new FSWX signal and spectrum analyzer for the first time to the public at the IEEE MTT-S International Microwave Symposium (IMS) from June 17 to 19, 2025, at the Moscone Center in San Francisco, CA, at the company’s booth 1443.

——————————————————————————————————————————————————————————————————————————————————————————————————————————————–

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

June 12, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

———————————————————————————————————————————————————————————————————————————————————————————————————————————————–

11 Jun 25. Spectra Group, a specialist provider of secure voice, data and satellite communications systems, is unveiling its new Troposcatter on the Move (TOTM) capability at Indo Defence and will be showcasing this and their other strategic communication capabilities in Booth D167f at Jakarta International Expo, June 11-14th 2025. Asia Pacific nations face unique challenges in achieving seamless connectivity across vast island chains and coastal territories. TOTM, engineered with Spectra’s signature expertise in advanced troposcatter technology, delivers robust, secure, high-bandwidth data communications between ship-to-shore and ship-to-ship — even while on the move.  Unlike satellite-based systems, TOTM operates independently of GPS and offers a critical advantage in contested or denied environments marking a significant leap forward in mobile, high-bandwidth data communications for the Asia Pacific region’s maritime and archipelagic requirements. Spectra Group has been working in partnership with Comtech and BATS Wireless antennas throughout 2024 to develop the TOTM concept, for which, as the systems integrator Spectra Group has full distribution rights.  Comtech and Spectra Group recognised the need for increased manoeuvre and large network data on the move, and so, working together with BATS wireless proved the concept of TOTM.  Subsequently, Spectra Group working in partnership with BATS Wireless has produced a fully integrated TOTM solution that combines Comtech’s COMET troposcatter with BATS Electronically Steered Antennas (ESAs) into a single fully integrated terminal to deliver an industry first capability. Extensive sea trials successfully tested and validated TOTM scenarios by simulating island hopping in the Florida Keys, Florida Panhandle and off the coast of California.  The tests involved ship to shore and ship to ship scenarios proving the concept of TOTM by demonstrating systems tracking and communicating with other nodes while on the move using GPS, but also showcasing the potential for advanced mobile connectivity in challenging environments without reliance on GPS. TOTM enhances the utility and operational effectiveness of COMET in a littoral manoeuvre context, especially in contested, GPS or satellite denied environments.  Its mobility and capacity delivers band-widths of up to 210 Mbps and ranges in excess of 100 Km to support a wide range of mobile applications such as Ship to Ship or Ship to Shore communications, Beyond Line of Sight strategic communications or Wide Area Networks, secure data links for autonomous sensors, control of remote vessels, Intelligence Surveillance and Reconnaissance (ISR) and any other application that requires big data delivered to the front line.  The TOTM solution can also be utilized with land vehicles for efficient “at the pause” applications, enabling users to quickly establish Troposcatter communications without having to set up and align antennas, allowing rapid data transmission from positions of opportunity.

Simon Davies, CEO of Spectra Group said: “TOTM’s launch in Asia Pacific couldn’t be more timely, with increasing demands for rapid, resilient connectivity across archipelagic states, TOTM provides a decisive edge in high-mobility scenarios.  TOTM is about ensuring command and control even in the most challenging maritime environments.”

 

12 Jun 25. Viasat developing wearable MOJO Mini variant. Satellite communications (satcom) provider Viasat is developing a wearable variant of its Move Out/Jump Off (MOJO) Mini tactical satcom gateway, with programme officials working to mature the yet-to-be released prototype system, Janes has learnt. Programme engineers at Viasat have designed the wearable MOJO Mini prototype, along with a vest-based mounting system with integrated computing and power management capability, and this is ready for demonstration, said David Schmolke, vice-president of Mission Connections and Cybersecurity at Viasat.

“We even integrated high assurance encryption capability” he said of the wearable prototype satcom gateway system, dubbed the Secure Wireless Hub (SWH), during a June interview with Janes.

On the compute side, the new SWH prototype “can host a lot of the functionality of that common operational picture (COP) integration” and intermesh that functionality with the data from the tactical satcom radios the user is already equipped with, Schmolke said.

“They are already carrying a Link 16-enabled radio, or something along those lines … they can high-end their existing [tactical] radio ecosystem” and have COP data integrated into that ecosystem, via the MOJO Mini prototype, he added.

If applicable, the prototype can also incorporate the user’s Android Team Awareness Kit (ATAK) application for an additional layer of mobile, cellular data into the ecosystem, he said. The wearable variant “is not formally on the market yet, but its sort of like at [technology readiness level] 6 or 7 capability”, according to Schmolke. (Source: Janes)

 

12 Jun 25. Network to Deter. Perhaps not receiving the coverage it should, but there’s good news from Taiwan’s Ministry of National Defence. In early May, it announced that the country’s Field Information Communications System (FICS) had completed testing in the United States. Few details exist in the public domain, but it is understood that FICS is an operational and tactical level communications, and Command and Control (C2), system. Reports have stated that deliveries of the system will commence by the end of 2025. FICS was procured in 2020 as a replacement for the Taiwanese Army’s existing Tactical Area Communications System. Taiwan’s Chungshan Institute of Science and Technology is responsible for implementing the system and has worked closely with the United States Army in this endeavour. As an internet protocol-dependent system, robust cybersecurity has been a sine qua non for FICS from the outset. The introduction of the new system comes at a time of deepening tensions between Taiwan and the People’s Republic of China (PRC). The latter regards Taiwan as a renegade province which must be unified with China, by force if necessary. The introduction of the Field Information Communications System represents an important enhancement of the Taiwanese Army’s C2 and communications systems. Sophisticated and survivable C2 and networks are likely to prove themselves vital war-winning weapons during any war between Beijing and Taipei. Enhancing interoperability within and between Taiwan’s armed forces will be key, as will connectivity with Taiwan’s allies. The global disruption that would be caused by an attempted invasion of Taiwan by China would require a global response. Hopefully, Taiwan’s allies like the United States will come to her aid to defend the country against Chinese aggression. Ensuring that similarly robust and survivable connectivity and networking exists outwards to connect Taiwan’s friends and allies will be vitally important. (Source: Armada)

 

09 Jun 25. Trunk Flunked. This graphic demonstrates the coverage footprint above Russia and eastern Ukraine provided by the Express AMU-1 communications satellite. Recent analysis has revealed that this satellite provides trunk communications for Russian forces occupying parts of Ukraine. Further details have come to light, courtesy of the counteroffensive.pro news service and website, concerning Russian military trunk communications in Ukraine. In an analysis published in April two of counteroffensive.pro’s authors, Oleksandr Matviienko and Zoriana Semenovych, provided some new perspectives on this intriguing subject. A key observation of their analysis was that Russian forces in Ukraine seem to lack dedicated, theatre-wide, operational level communications. Instead, a variety of different systems and networks appear to be employed. A recent Armada article noted that Russian forces are illicitly using the United States’ Ultra High Frequency Follow-On (UFO) military Satellite Communications (SATCOM) constellation. It appears that Russian units can access this network and use it for beyond line-of-sight trunk communications in Ukraine.

Express AMU-1

Counteroffensive.pro’s analysis stated that other capabilities like Russia’s Express AMU-1 satellite support tactical and operational communications. Express AMU-1 was designed and built by EADS Astrium, now part of Airbus’ defence and space subsidiary. The satellite was launched in October 2015 and provides uplink channels using Ka-band frequencies of 29.4 gigahertz/GHz to 30GHz. Downlink is provided on frequencies of 19.2GHz to 20.2GHz. Open sources say the Express AMU-1 SATCOM network ensures data rates of between ten megabits-per-second and 40mbps. Counteroffensive.pro continued that Express AMU-1 provides coverage over eastern Ukraine. Users access Express AMU-1 via an appropriate terminal housing the correct waveform software. This satellite supplements the unauthorised Russian military access to SpaceX’s Starlink SATCOM network which has been documented in the past.

Cellular provision

Beyond SATCOM, the analysis continues that Wi-Fi provides internet access on the battlefield at distances of up to 50 kilometres (31 miles) from the Wi-Fi transmitter. Internet protocol traffic is sent and received via the transmitter which then routes traffic through cables to its intended destination. Likewise, Orlan-10 Uninhabited Aerial Vehicles (UAVs) have been used by Russian land forces as airborne relays. It is known that the Russian Army’s RB-314V Leer-3 electronic warfare system uses Orlan-10 UAVs. These UAVs gather communications intelligence from cellphones and jam these devices. Leer-3 can also disseminate false, demoralising and misleading traffic to cellphones. Suitably equipped Orlan-10s perform this mission by acting as airborne cellphone nodes. It is possible that these nodes can be used to provide an airborne cellphone network as and when required. The UAVs could then connect to terrestrial cellphone networks to move cellular traffic within and without the theatre of operations. Counteroffensive.pro’s analysis adds that Russian forces use the cellular infrastructure present in the parts of Ukraine they currently occupy.

Azarts and Aqueducts

This recent analysis helps fill some important gaps in the existing knowledge of Russian tactical and operational level communications in the Ukraine theatre. It is already known that Russia’s military communications satellite constellations provide operational and strategic connectivity. Russia is though to possess around 40 dedicated military communications satellites. The Cosmos and Meridian constellations are the most numerous. Russian forces use High Frequency (HF: three megahertz to 30MHz) transceivers such as the legacy R-123 Magnolia vehicular radio for trunk communications. The R-123 is in the process of being replaced by the R-187P Azart handheld transceiver which uses frequencies of 27MHz to 520MHz. Russia’s airborne forces employ the R-168 Aqueduct multiband radio. Aqueduct provides HF and very/ultra high frequency links on a 30 megahertz to three gigahertz waveband. The disappointing performance of the R-168 is seeing the radio replaced by the R-187P.

Networking weaknesses

The plethora of links used for trunk communications by Russian forces in Ukraine indicate that the Russian military writ large has struggled to deploy robust, secure theatre-wide operational level communications networks with built-in redundancy. Mixing military systems like the R-187 with civilian systems like Express AMU-1 and cellphone networks bring Communications/Transmission Security (COMSEC/TRANSEC) challenges. It is unlikely these civilian networks have military-grade standard COMSEC/TRANSEC bringing attendant security shortfalls. Insufficiently robust COMSEC/TRANSEC within Russian military communications and networks has been a persistent problem for Moscow throughout the conflict. It is unlikely common messaging standards and protocols exist to move traffic seamlessly between these differing civilian and military networks. This may mean that traffic which should be classified is often moved en clair. The lackadaisical approach Russian personnel take to discussing classified and secret information on publicly accessible networks is well known, as scores of radio amateurs can attest.

It seems unlikely that Russia’s land forces operational communications challenges will be solved any time soon. The country remains locked in a war that she looks unable to win, with a huge proportion of her forces supporting this effort. These are hardly conditions conducive to the roll-out of new military-grade trunk communications networks. The Russian military was conducting a major upgrade of its land forces communications systems and networks when the second invasion of Ukraine occurred in 2022. Notionally, this programme is continuing. Nonetheless, all it appears to have yielded so far is a hodgepodge of new and legacy military and civilian communications systems and networks that struggle to interoperate. Good news for Ukraine, but bad news for Russia. (Source: Armada)

 

10 Jun 25. Talking to UFOs. Up to eight of the original UFO military communications satellites manufactured by Boeing are presumed to remain in service. Some of the satellites are believed to be used by the Russian military for trunk communications in Ukraine. The Russian military is thought to be using communications channels provided by the US Department of Defence’s UFO satellite constellation. The Hackaday website has revealed that the Russian military maybe using the United States’ Department of Defence’s Ultra High Frequency Follow-On (UFO) satellites for communications. The report articulated revelations shared by the saveitforparts Youtube channel. The Hackaday report says that it has been possible to listen to unencrypted Russian military communications moving across these satellites. This is done using a web-based Software Defined Radio, known as a WebSDR. Open sources note that the UFO satellites use a 243 megahertz/MHz to 270MHz downlink channel, and an uplink employing a waveband of 292MHz to 317MHz. Each satellite provides 17 25 kilohertz and 21 five kilohertz channels. The sources continue that, as of 2025, eight of the satellites remain active in a geostationary orbit, although they are approaching the end of their operational lives.

Altai and FLTSATCOM

The Youtube video explains that it is not impossible to access these satellites using radios and Satellite Communications (SATCOM) terminals adapted to the UFO constellation’s frequencies. The video says that Russia’s Altai mobile phone system introduced in the mid-1960s used frequencies of 250MHz to 300MHz. Altai employed a switching system that allowed radio telephony to connect with landlines and vice versa. Early US military SATCOM constellations like the Fleet Satellite Communications System (FLTSATCOM), the forerunner of UFO, could receive radio traffic moving across Altai. Russian communications experts realised they could use FLTSATCOM to provide beyond line-of-sight communications. This was presumably a significant benefit given the Soviet Union, and now Russia’s, significant landmass. It is possible that Russian forces in Ukraine are using the UFO F/0 7 and UFO F/O 10 satellites. Both spacecraft are positioned over the middle of the Atlantic Ocean in an equatorial geostationary orbit.

The use of the UFO satellites for Russian military trunk communications in Ukraine may have arisen because of technical problems experienced with the country’s existing SATCOM constellations. Armada’s records indicate that Russia’s Ministry of Defence may have circa 40 communications satellites in its possession. However, the capabilities and condition of these spacecraft remain unknown. Existing Russian military SATCOM wavebands could be saturated which may explain a spillover onto the UFO SATCOM channels. In February 2024, Ukraine’s defence intelligence service said the Russian military was making unauthorised use of the SpaceX Starlink SATCOM network. Russian forces were thought to be using Starlink to satisfy trunk communication requirement that could not be met with existing domestic capabilities.

Ease of Access

Why is the Russian military able to employ these UFO channels? Firstly, it is not thought that any specific barriers exist to Russian users accessing the constellation’s frequencies and using them accordingly. It is arguably in the interest of the US signals intelligence community to ensure the Russian military keep using the UFO channels. Much of what is discussed across the constellation tends to be unencrypted chat. Russian troops complain about their superiors and local civilians under Russian occupation. Such information provides important indications of Russian morale in Ukraine. One UFO satellite, UFO F/O 11, has even been used by a Russian pirate radio station for broadcasts. UFO F/O 11 is in a geostationary equatorial orbit above the middle of the Indian Ocean. Armada contacted the US Space Force to obtain more information about Russia’s use of the UFO constellation, how the Russian military was able to do this, and steps that could be taken to prevent this access. Unfortunately, we did not receive any responses to our questions before this article was published. (Source: Armada)

 

12 Jun 25. June Radio Roundup. Bittium is supplying its TAC WIN tactical internet protocol communications system to the Croatian military. TAC WIN was used during a recent demonstration of fourth-generation and fifth-generation tactical cellular connectivity involving Nokia. Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.

New Comms for Croatia

Bittium made two announcements in late April. The first concerned communications the company is supplying to Croatia, and the second covered a new initiative involving Nokia. Bittium is supplying $2 m worth of tactical communications systems to Croatia. These capabilities include the company’s Tactical Wireless Internet Protocol Network, also known as TACWIN. Joining TACWIN in the Croatian order is Bittium’s Tough SDR vehicular radios. Reports continued that these new radios include the European Secure Software Defined Radio (ESSOR) High Data Rate Waveform (HDRWF). This marks the second occasion on which a country beyond the original ESSOR national membership has procured the HDRWF. The first non-ESSOR partner nation to do so was the Republic of Ireland. Bittium told Armada that the supply of these radios to the Croatian armed forces will commence and conclude this year. The transceivers will be used by Hrvatska Kopnena Vojska (Croatian Army) and Hrvatska Ratna Mornarica (Croatian Navy). On 30th April, news emerged that Bittium and Nokia had demonstrated a hybrid tactical communications network to the Finnish military. The demonstration involved Bittium’s TAC WIN and Tough SDR handheld and vehicular radios. These communications systems were used alongside Nokia’s Banshee Mobile Radio and Banshee Tactical Radio. Combining these capabilities enabled a zone of fourth and fifth generation (4G/5G) cellular communications to be created over a specific area. Bittium told Armada that “(i)n this demonstration the hybrid network was a combination of a tactical network and military-grade 4G/5G bubbles.” These bubbles provide 4G/5G connectivity as part of the wider, deployed tactical network. This also allowed devices using 4G and 5G connectivity to access the tactical network: “Hybrid networking can be seen as something that benefits multi-domain operations and total defence,” Bittium added.

Viasat recently launched its new MOJO Mini Next tactical gateway which facilitates Link-16 tactical datalink network access and use. The product has a reduced Size, Weight and Power (SWAP) consumption footprint to ease deployment on board SWAP-constrained platforms.

Find your MOJO

On 5th May, Viasat revealed its new MOJO Mini Next expeditionary tactical gateway. The new product provides Link-16 tactical datalink (960 megahertz/MHz to 1.215 gigahertz/GHz) connectivity. A company press release said that the MOJO Mini Next has been designed to have low Size, Weight and Power (SWAP) consumption characteristics. Applications mooted for the new product include installation on SWAP-constrained platforms like small boats and ground vehicles. The MOJO Mini Next works alongside L3Harris’ KOR-24A Link-16 multichannel radio which provides the requisite communications security. David Schmolke, Viasat’s vice president of mission connections and cybersecurity, told Armada that the product “has successfully completed development and prototyping phases, with baseline hardware and system integration validated.” The company has already secured customers and “interest in the solution has been strong across both US and international defence communities.” Moreover, “full rate production is moving forward, and customers are now able to purchase the new solution.” The product forms part of Viasat’s wider MOJO family of tactical gateways and “builds on this operational legacy with a more compact, ruggedised form factor tailored for expeditionary missions.” (Source: Armada)

 

11 Jun 25. Today, Securonix, a five-time Leader in the Gartner® Magic Quadrant™ for Security Information and Event Management (SIEM), announced the acquisition of ThreatQuotient, a four-time leader in threat intelligence based on QKS Group Spark Matrix report and the force behind ThreatQ, the most innovative external threat intelligence platform. This combination will create a comprehensive, modular, and fully integrated AI-driven platform for threat detection, investigation, and response (TDIR), leveraging advanced analytics and insights across both internal and external threats. This acquisition accelerates the modernisation of security operations by uniting internal and external threat intelligence with real-time analytics and agentic AI. Unlike external threat intelligence bolt-on solutions with disconnected management interfaces, the integrated platform from Securonix and ThreatQuotient will deliver unified visibility, faster response, and greater operational clarity.

“Bringing threat intelligence management and SIEM together in a unified platform is a game changer. We’ve already seen the value of deeply enriched advanced analytics and detection in our Securonix SIEM environment – but coupling that with integrated threat curation, prioritisation, and response should help customers move even faster. It means fewer swivel-chair investigations, more accurate triage, and greater confidence that security analysts are working with the most relevant threats. This kind of integration has the potential to accelerate the ability to detect, respond, and stay ahead,” said Marcel Jonker, Director of Cybersecurity Operations at Cambia Health Systems.

The integration of Securonix and ThreatQuotient promises to deliver up to a 70% reduction in Mean Time to Respond (MTTR), enabling security teams to detect, investigate, and remediate threats significantly faster. By combining curated threat intelligence with AI-driven automation, the solution will deliver exponential improvements in filtering out false positives, enriching alerts with actionable context, and automating historical threat sweeps and incident response. This reduces alert overload, speeds up root cause analysis, and minimises manual handoffs – cutting investigation time from hours to minutes and enabling automated containment before threats escalate.

“Security teams are drowning in noise and struggling to keep up with evolving threats,” said Kash Shaikh, CEO and President of Securonix. “This acquisition brings together Securonix’s Agentic AI-driven Platform with ThreatQuotient’s deep threat intelligence to deliver clarity, speed, and automated workflows to our customers, reducing false positives by up to 90%. Together, we’re building the modern SOC Platform – proactive, intelligent, and built for what’s next.”

Kash added, “Securonix and ThreatQuotient bring together complementary strengths – deep innovation across internal and external threat domains, and a shared commitment to innovation and customer service. Both companies serve enterprise and government customers as well as Managed Security Service Providers (MSSPs), and we’re excited to welcome the talented ThreatQuotient team and their customers to Securonix.”

Purpose-Built for Analysts. Proven Against Real-World Threats.

ThreatQuotient’s Threat Intelligence Platform (TIP) strength lies in delivering curated, contextualised threat intelligence that drives smart, timely decisions. When combined with Securonix’s EON Agentic AI-based SIEM, SOAR, UEBA and Data Pipeline Manager, customers can accelerate their migration from reactive threat hunting-based defence to proactive, real-time, behaviour-driven, open-agentic security operations.

With this integration, Securonix customers and partners will enjoy the following benefits:

  • Gain clear visibility: Integrate deep enriched real-time analytics from Securonix with curated external intelligence from ThreatQuotient to create a single, high-context stream of alerts. Eliminate blind spots and accelerate threat identification with confidence.
  • Stay ahead of risk: Auto-enrich Indicator of compromise (IoCs) and pre-emptively respond to repeat attacks, blocking 90 percent before they start.
  • Act smarter: Automate repetitive tasks, reduce false positives, and streamline investigations. Teams can stay focused on high-priority threats and reduce time spent on manual triage.
  • Deploy your way: Continue to use ThreatQ as a standalone threat intelligence platform or as part of the fully integrated Securonix solution. Deploy on-premise or SaaS in a way that fits the current architecture and scales with needs.
  • Accelerated Roadmap: Combined R&D synergies will accelerate upcoming roadmap innovations, including Agentic AI and ThreatQuotient’s innovation priorities.

With this acquisition, ThreatQuotient customers and partners will enjoy the following benefits:

  • Increased Scale: ThreatQ customers can take advantage of Securonix’s global R&D scale and GTM reach, including access to Securonix’s Threat Labs Intelligence.
  • Deeper Integrations: Gain access to an enriched roadmap and integration between Securonix’s best-in-class SIEM, SOAR and UEBA portfolio and ThreatQ, including extension of Agentic AI advancements.
  • Continued Focus: Zero interruption of their existing service, as ThreatQuotient will continue to operate as a standalone offering, with no disruption to existing roadmap and workflows.

“Enterprises, government institutions and Managed Security Service Providers rely on ThreatQuotient to protect their mission critical businesses. Joining Securonix marks a powerful new chapter for ThreatQuotient. By uniting our strengths, we can accelerate innovation, expand our reach, and deliver greater value to our customers. I’m proud of what we’ve built and excited for what’s ahead.” said John Czupak, CEO of ThreatQuotient.

BTIG, LLC served as exclusive financial advisor, and King & Spalding LLP served as legal advisor to ThreatQuotient. Vinson & Elkins LLP served as legal advisor to Securonix.

 

09 Jun 25. Nuvotronics, a leader in advanced Radio Frequency (RF) technology, announces the launch of the StrataWorks ® platform, a web-based design solution that enables customers to rapidly create and customize PolyStrata®-based passive RF components. The first capability in the StrataWorks suite, StrataWorks® Filters, allows engineers to design high-performance, surface-mount RF filters with exceptional speed, precision, and flexibility.

“Our customers told us they needed a faster, more flexible, and cost-efficient way to create custom filters without sacrificing performance or reliability,” said Scott Meller, General Manager, Nuvotronics. “With the StrataWorks design tool, users can go from concept to simulation in minutes, receiving quotes within 24 hours. These designs are ready for volume production with the quality and repeatability Nuvotronics is known for.”

The StrataWorks platform streamlines the design and specification process for production of RF devices using the company’s proprietary PolyStrata® microfabrication technology. The tool incorporates intelligent design rules that empower engineers with complete freedom to tailor components to their exact specifications, enabling true design innovation without compromise. Production is equally efficient. Designs can be fabricated on Nuvotronics’ regularly scheduled bi-monthly multi-user runs, delivering high-performance, surface-mountable components in as little as 12–16 weeks. While the initial release focuses on filter design, the StrataWorks platform will expand to support a broad range of passive RF devices, allowing engineers to leverage PolyStrata technology across an even wider array of applications.

“We invite forward-thinking companies to explore StrataWorks and experience a faster, smarter path to RF innovation,” Meller added. “With our platform, expert support, and scalable production, your custom designs are closer to reality than ever before.”

 

10 Jun 25. As part of the Letter of Intent (LOI) signed in February 2025 between ELT Group and EDGE Group, a Strategic Cooperation Letter was signed today to advance discussions on the supply of electronic warfare (EW) systems for the Kuwait Navy’s missile boats, with ELT Group outlined as the preferred supplier. The letter was signed by Domitilla Benigni, CEO & COO of ELT Group, and Omar Al Zaabi, President – Trading and Mission Support, EDGE Group, and was witnessed by Rodrigo Torres, Group CFO, EDGE, and Paolo Zani, Managing Director for ELT Group UAE. The letter reflects both Parties’ shared intent to accelerate the process and collaborate towards formalising the contract. It marks the first significant milestone in their partnership, which also includes plans for the potential establishment of a joint venture in the UAE.

 

10 Jun 25. Global: Cyber operation highlights security risks to businesses. On 9 June, international news outlets reported that unnamed threat actors are targeting global developers in a destructive cyber operation. Threat actors inject legitimate npm packages (typically used by developers to download two application programming interfaces that enable data syncing between two applications) with malicious code that covertly installs backdoor malware onto compromised systems. The backdoors prepare targeted systems for attack by establishing communication with command-and-control (C2) infrastructure and by conducting initial system reconnaissance. Threat actors then use the backdoors to inject a hidden command that subsequently erases all data from infected applications (including source code and directory), effectively rendering the system unusable. The attack reportedly leaves no traces of its execution and uses legitimate processes for communication, showcasing its sophistication. This operation highlights the increased development of destructive cyber capabilities designed to permanently disrupt adversarial systems. This indicates elevated security risks to global businesses amid the continuous evolution of cyber tactics. (Source: Sibylline)

 

10 Jun 25. pureLiFi has announced the release of its latest LiFi system, Kitefin XE, designed to protect networks in an era marked by growing security threats. This cutting-edge wireless technology, first released exclusively within the National Security community, is now available to a wider spectrum of sectors, from government and defence to enterprise customers and beyond. Guaranteeing data security has become an increasingly complex task for both governmental bodies and private businesses. The Kitefin XE system is founded on technology crafted for the National Security community and has demonstrated its reliability in the most secure settings where communication privacy is paramount. Customers have reported that Kitefin XE allows them to introduce wireless capabilities where previously not possible, improving mission viability and success. This revolutionary system allows for high-speed wireless internet connectivity through Invisible Light rather than Radio Frequencies (RF) used in traditional wireless technologies such as WiFi and Cellular. LiFi provides a revolutionary level of security unmatched by RF technologies as it is not susceptible to detection, interception and jamming. LiFi also offers massive capacity that outperforms WiFi in real-world environments, and its low latency capabilities offer a better user experience.

Alistair Banham, CEO of pureLiFi, stated, “Securing sensitive data, whether it’s critical to national security, protecting intellectual property, and company data is becoming increasingly challenging for both governments and enterprises. Kitefin XE will enable wireless communication in previously impossible scenarios and revolutionise the way companies deploy connectivity, providing confidence and protection in this evolving security landscape.”

pureLiFi is part of In-Q-Tel’s (IQT) portfolio, the not-for-profit strategic investor for the U.S. national security community and its allies.

Clayton Williams, Managing Director of IQT, remarked, “IQT is excited to support the broader launch of Kitefin XE. This innovation has the potential to transform how our partners approach wireless connectivity—and help enterprises stay secure in today’s complex cybersecurity landscape.”

Kitefin XE is the latest in a series of Kitefin systems developed for government and defence that aims to save missions and lives. Kitefin Tactical and Kitefin Office were deployed with the US Army in the first-ever large-scale deployment of LiFi. Building on their predecessors’ success, Kitefin XE offers room-filling LiFi coverage of over 80 Sq. Metres and provides Gbps capacity, making it the highest-performing LiFi system available on the market for government and defence which complies with IEEE 802.11bb standard. All pureLiFi systems are based on IEEE 802.11 protocols, making them the simplest LiFi systems to integrate into existing networks. Kitefin XE is also available for both ethernet and fibre deployments.

With Kitefin XE, pureLiFi sets a new standard in secure, high-capacity wireless communication technology, paving the way for a future where data security is uncompromised.

 

10 Jun 25. Thales and Proximus consortium will enhanceme the resilience and efficiency of NATO’s Communications and Information Agency business network

  • NATO Communications and Information Agency (NCIA) has awarded a contract to a consortium formed by Thales, a global leader in high technology, and Proximus, Belgium’s leading telecommunications provider.
  • This strategic partnership will operate and manage some key infrastructure elements for NCIA’s business network, ensuring enhanced resilience, security, and operational efficiency across five NCIA locations The infrastructure will be supported using cloud based technology, providing NCIA’s personnel with highly secure and efficient access to essential IT services, facilitating real-time communication, collaboration and data management across multiple sites.

This modernisation is an opportunity to enhance capacity, improve compatibility, and upgrade systems to ensure optimal performance.

Under the terms of the contract, Thales and Proximus will deliver a fully managed service, providing:

  • infrastructure as a service (IaaS) on a certified and accredited cloud;
  • end-user devices as a service (DaaS) for personnel;
  • robust cybersecurity solutions, ensuring a highly secure digital environment;
  • advanced networking capabilities at NCIA sites for seamless connectivity;
  • comprehensive platform administration services;
  • scalable cloud services for secure storage and high-performance computing.

Thales is providing a secure cloud infrastructure and a fully managed service, while Proximus is delivering a secure multi-domain laptop and is upgrading the Wi-Fi networks at The Hague and Braine L’Alleud, as well as enabling a high speed connection to their Cloud for 5,000 users at NCIA sites.

“Together with Proximus, Thales reaffirms its commitment to strengthening NATO’s digital resilience, ensuring secure, high-performance and future-proof IT infrastructure to support the Alliance’s evolving needs. By outsourcing commodity services to trusted industry leaders, NCIA is taking a forward-looking approach that ensures a fully managed, secure, and scalable solution.” said Alex Bottero, VP Network and Infrastructure Systems, Thales.

“This strategic project reflects our commitment to providing cutting-edge connectivity, mobility, and security solutions. We are proud that Proximus has been chosen for this large-scale project, which will enable NATO to strengthen its digital capabilities with a secure and scalable infrastructure. Thanks to our collaboration with Thales, we are confident that we will be able to meet NCIA’s needs and support its essential missions.” adds Anne-Sophie Lotgering, Enterprise Market Lead at Proximus.

With stringent performance metrics and service level agreements (SLAs) in place, this solution will guarantee high availability, security and operational stability for NCIA’s ecosystem.

 

09 Jun 25. Global: New botnet variant sustains elevated security, disruption risks to vulnerable devices. On 6 June, the cyber security company Kaspersky reported that unnamed threat actors are exploiting a software vulnerability (CVE-2024-3721) to distribute a new variant of the ‘Mirai’ botnet. The vulnerability reportedly affects digital video recording devices (versions TBK DVR-4104 and DVR-4216) and enables remote command execution. Threat actors exploit CVE-2024-3721 after infiltrating targeted systems to deploy a malicious payload, establish communication with command-and-control (C2) servers and enlist infected devices into the botnet infrastructure. It is likely that threat actors subsequently use the botnet to proxy malicious traffic for additional cyber activity and/or to conduct distributed denial-of-service (DDoS) attacks. It is unclear whether the provider has released a fix for CVE-2024-3721; approximately 50,000 internet-facing devices are vulnerable to exploitation. This underscores the potential large-scale impact of the operation. We assess that this report showcases sustained security and disruption risks to vulnerable devices stemming from botnet-related activity. (Source: Sibylline)

 

06 Jun 25. Cyber Update Key points.

  • A series of cyber attacks against US-based healthcare facilities indicates elevated security and disruption risks to the sector (see Sibylline Cyber Daily Analytical Update – 2 June 2025).
  • A cryptocurrency-theft operation underscores the security and financial risks to global Windows and Linux systems (see Sibylline Cyber Daily Analytical Update – 3 June 2025 and our Technical analysis below).
  • A new version of the ‘Crocodilus’ malware points to increased security and financial risks to global Android mobile users (see Sibylline Cyber Daily Analytical Update – 4 June 2025 and our Technical analysis below).
  • The rise in cyber attack attempts against operational technology (OT) environments indicates raised long-term security risks (see Sibylline Cyber Daily Analytical Update – 5 June 2025).
  • A cyber attack against a critical national infrastructure (CNI) entity in Ukraine showcases sustained security and operational risks from Russian actors (see Sibylline Cyber Daily Analytical Update – 6 June 2025).

Technical analysis of weekly stories

Threat actors exploited an internet-facing artificial intelligence (AI) interface (Open WebUI) to conduct a crypto-jacking campaign against an unnamed company. The interface was mistakenly configured to allow for unauthenticated administrator access; it enabled threat actors to inject malicious Python code into Open WebUI and execute remote commands. Threat actors also reportedly used large language models (LLMs) to partially assist with the script’s creation, showcasing the increased incorporation of AI in malicious cyber operations. The code subsequently downloads crypto-mining payloads (‘T-Rex’ and ‘XMRig’), compiles headers for stealth and establishes persistence and communication within command-and-control (C2) infrastructure. Threat actors then use T-Rex and XMRig to mine cryptocurrency before transferring it to actor-controlled cryptocurrency wallets. The script can dynamically adjust the malware’s execution process based on the type of compromised system (Linux or Windows systems) and boasts several other highly advanced obfuscation techniques, further highlighting its sophistication.

An unnamed Russia-nexus advanced persistent threat (APT) group used a new wiper malware (‘PathWiper’) to conduct a destructive cyber attack against a CNI entity in Ukraine. The group reportedly compromised a legitimate administrative console to manage the attack and enable remote command execution, though the initial attack vector is unknown. The console communicated with all endpoints within the compromised system, enabling threat actors to run a VBScript file and ultimately download the main PathWiper payload. Throughout the attack, threat actors also mimicked legitimate system activity, highlighting the premeditated nature of this operation. PathWiper then listed all connected storage media (including physical drives, containers and network drives) before overriding all files directly on a system’s disk with random data, effectively destroying a system’s functionality. While the impact of the attack is unknown, there is a realistic possibility that the malware will permanently disrupt the target organisation’s ability to provide key services. PathWiper’s capabilities resemble those of another wiper malware (‘HermeticWiper’) that was used by the Russian state-sponsored group ‘Sandworm’ to target Ukrainian entities in 2022; we assess that this highlights a possible overlap between the two groups.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

Our cyber word(s) of the week: Vishing

(Source: Sibylline)

————————————————————————————————————————————————————————————————————————————————————————————————————————————–

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

June 6, 2025 by

Sponsored By Curtiss Wright

 

https://www.curtisswright.com/

———————————————————————————————————————————————————————————————————————————————————————————————————————————-

06 Jun 25. UK urged to set up Counter-Intelligence Unit for defence. Authors of the Strategic Defence Review instruct the government to set up a Counter-Intelligence Unit by November 2025. One obligation that may have gone unnoticed in the UK’s Strategic Defence Review (SDR), published on 2 June 2025, was the creation of a Counter-Intelligence Unit (CIU) that will reside within Defence Intelligence (DI). Authors of the report instruct the government to set up the CIU by November 2025. The body will have a mandate to protect UK defence from hostile intelligence services, working closely with the wider UK intelligence community in the process. CIU would ensure resources are focused on protecting the most critical defence capabilities, at home and overseas, against serious threats. The unit would also provide a single point of contact within the Ministry of Defence (MoD) for industry – to protect critical supply chains from disruption and to procure innovative technology – besides collaboration with Nato, Five Eyes, and other partners.

Integration: Military Intelligence Services

In the spirit of integration, the SDR also advises the MoD to maximise all its intelligence capabilities. This will leverage information from all three armed services, the Permanent Joint Headquarters, Special Forces, Space Command, and others to form a single, integrated defence enterprise known as the ‘Military Intelligence Services’ (MIS). DI will lead this vague intra-departmental enterprise. Notably, DI is one of few intelligence organisations around the world that carries out collection, reporting, assessment, targeting and operations, including counter-intelligence. While MIS does encourage agencies to work closely, which helps coordinate collective responses to the growing stream of defence-related information, one can be forgiven for the confusion that comes when trying to define the overlapping responsibilities of each agency. Army Technology contacted the MoD for comment on the potential ambiguity of the new structure but they were unable to offer anything beyond details released in the SDR at this stage.

More demand, less manpower

GCHQ, the UK’s cyber and signals intelligence agency, has repeatedly exposed Russia’s military intelligence service in a campaign of malicious cyber activity against western logistics entities and technology companies over the last three years. This has included targetting organisations involved in the co-ordination, transport and delivery of support to Ukraine, and across the defence, IT services, maritime, airports, ports and air traffic management systems sectors in multiple Nato members. This is not limited to Russia, but also China, whose sophisticated Military-Civilian Fusion initiative bleeds information from innovative commercial and defence companies in the West to benefit People’s Liberation Army. In January, the US Department of Defense identified familiar technology brands CATL, Huawei, and Tencent as such entities. Although the demand for DI services are increasing, there are approximately 500 fewer people working in DI today than in 2019 and its digital programmes have been subject to significant cuts and deferments. There are also barriers to interoperability between the MoD and the UK intelligence community, risking their collective capabilities by delivering less than the sum of their parts, according to the SDR. Demand for high-fidelity intelligence will only increase as the global environment deteriorates. And the document is right to point to the sheer volume of data that must be harnessed to enable effective decision-making, including through using artificial intelligence (AI).

“Conflict with a ‘peer’ military adversary today would create a demand for intelligence that significantly surpasses that of the Afghanistan and Iraq wars,” the SDR reads. (Source: army-technology.com)

 

05 Jun 25. Safe Pro Group Inc. (Nasdaq: SPAI) (“Safe Pro” or the “Company”), a leader in AI-powered security solutions, today announced a major artificial intelligence (AI) data processing milestone, solidifying its position in the forefront of battlefield intelligence and threat detection. The Company’s patented AI ecosystem has successfully analyzed over 1.6 million real-world images from Ukraine conflict zones, establishing one of the world’s most detailed datasets of landmines, cluster munitions, anti-personnel mines and evidence points captured by commercially available, off-the-shelf drones. This strategic achievement marks a critical inflection point in Safe Pro’s scale, product validation and commercialization efforts. This real-world data enhancement is used to more accurately detect small explosive threats, delivering greater value and battlefield awareness to end users.

“This milestone represents a significant advance in our AI-driven capabilities for real-time defense, commercial and humanitarian operations, enhancing its value as a strategic asset for large-scale Government and Commercial customers,” said Dan Erdberg, Chairman and CEO of Safe Pro Group. “Driven by one of the world’s most detailed real-world drone imagery datasets processed by AI, we are building a company positioned to capitalize on a large unmet need for on-the-ground threat intelligence that can enable safer missions for military personnel, first responders, humanitarian workers, and commercial operators.”

The Company’s proprietary Safe Pro Object Threat Detection (SPOTD) technology, which enables the real-time detection of small explosive threats such as unexploded ordnance (UXO) and landmines, now benefits from enhanced accuracy and predictive capabilities derived from this unparalleled dataset.

“Furthering the capabilities of our state-of-the-art AI algorithms will support our continued commercialization efforts and create opportunities to grow our network of partnerships and secure valuable contacts this year,” concluded Mr. Erdberg.

As of June 2025, Safe Pro’s SPOTD dataset includes GPS-tagged imagery identifying approximately 27,450 threats across more than 6,614 hectares in Ukraine, an area larger than Manhattan.

Global Opportunity and Strategic Integration with U.S. Military Tech Infrastructure

Today, nearly 60 countries are impacted by land mines or Unexploded Remnants of War (ERW) (source: Landmine Monitor, 2024), creating a large global opportunity for Safe Pro Group. Supported by US Patent No. 12,146,729 including 21 claims, the Company’s patent application entitled, “Systems and Methods for Detecting and Identifying Explosives,” covers autonomous detection, identification, and labeling of explosives in orthomosaic images using AI processing of drone imagery. Valid until 2043, the patent captures the groundbreaking nature of the Company’s technology and applicability for national defense and security applications as well as supporting global commercial and industrial markets ranging from humanitarian demining, agriculture, to post-conflict reconstruction. Building upon the continued enhancement of its threat detection capabilities, Safe Pro confirmed its ongoing integration of SPOTD with the U.S. military’s TAK (Team Awareness Kit) software ecosystem which powers tactical communications and situational awareness for defense, law enforcement, and first responders. This integration is designed to allow instant detection and dissemination of explosive threats across hundreds of thousands of soldier-carried and vehicle-mounted devices using the Android Tactical Assault Kit (ATAK) software application.

“Successful integration with ATAK could represent a large opportunity to support multiple Army programs that operate on the TAK ecosystem,” added Mr. Erdberg. “We believe this positions Safe Pro to capture a share of the $15B+ global defense tech market, particularly in AI, drone reconnaissance, and threat detection.”

AI Growth, Defense Contracts, and Market Expansion

  • Real-World AI Leadership: Safe Pro has now amassed one of the most extensive UXO drone imagery datasets, strengthening its competitive advantage and long-term revenue potential.
  • Defense Sector Tailwinds: With growing global demand for real-time threat intelligence and battlefield automation, Safe Pro is strategically aligned with priority defense initiatives.
  • Commercial-Ready Tech: Integration with U.S. military platforms signals readiness for scale, contract eligibility, and near-term monetization. (Source: BUSINESS WIRE)

 

05 Jun 25. Qlik®, a global leader in data integration, analytics, and AI, has secured Provisional Authorization at Impact Level 4 (IL4) for Qlik Cloud Government – DoD from the United States Defense Information Systems Agency (DISA), under the Department of Defense’s Cloud Computing Security Requirements Guide. Qlik Cloud Government – DoD is available immediately, including DISA Boundary Cloud Access Point (BCAP) connectivity to the DISA NIPRNet. This provisional authorization, which meets DISA’s security requirements for storing and handling controlled unclassified information (CUI), including For Official Use Only (FOUO) information, allows government agencies and their contractors to confidently utilize Qlik’s advanced capabilities, transforming data challenges into strategic opportunities and creating a decision advantage for U.S. DoD, Combat Support Agencies, Combatant Commands, and the Defense Industrial Base.

“Data is the backbone of decision-making in defense and government, but it’s only valuable when it’s secure, accessible, and actionable,” said Mike Capone, CEO of Qlik. “With DISA IL4 authorization, Qlik Cloud Government – DoD gives agencies the confidence to move critical data and analytics operations to the cloud, accelerating operational efficiency, readiness, and mission success.”

Qlik has numerous DoD customers who have implemented Qlik’s products and many are initiating strategic moves to Qlik Cloud Government – DoD products to ignite innovation with a secure and scalable cloud environment. These transitions aim to unlock the value of their data by improving operational efficiencies and reducing costs across their agencies. Qlik can now offer the cost, speed, and scalability benefits of cloud computing to its Department of Defense, Armed Services, and Defense Industrial Base customers while meeting the rigorous security standards set forth by DISA.

“Qlik Cloud Government – DoD products enable clients to drive outcomes through advanced analytics and AI-ready infrastructure, while ensuring strict compliance and security standards,” said Andrew Churchill, Vice President of Federal at Qlik. “We are committed to supporting these agencies with the tools they need to scale insight generation and accelerate mission impact.”

Qlik Cloud Government delivers several critical benefits to government agencies, including:

  • Built-in Security and Compliance: Ensuring rigorous adherence to DISA IL4 security controls and continuous monitoring requirements.
  • Cost Efficiency and Quicker Time to Value: No-touch maintenance, continuous feature deployment and significant compliance and infrastructure cost savings with Qlik Cloud Government – DoD.
  • End-to-End Capabilities: A unified set of solutions encompassing data integration, data quality, and analytics, enabling organizations to rely on a single provider to manage, govern, and extract value from their data.
  • Data Trust and Discoverability: Access to trusted, governed data through Qlik’s integrated marketplace, data quality tools, and Qlik Talend Trust Score™, accelerating confident data use across teams.
  • Flexibility: Platform-agnostic solutions that integrate seamlessly with leading environments including AWS, Snowflake, and Databricks, avoiding vendor lock-in and fostering adaptability.
  • Real-Time Data Integration: Advanced capabilities for replication and transformation that support real-time decision-making across complex enterprise systems.

Qlik Cloud Government – DoD is built on AWS GovCloud (US) and is available in AWS Marketplace. (Source: BUSINESS WIRE)

 

05 Jun 25. Hertz over the Himalayas. Much remains unknown about the recent spat between India and Pakistan. Hostilities erupted once more between the two countries on 7th May. On 25th April, 25 Indian tourists were killed during an insurgent attack in the region of Kashmir, in northern South Asia. Skirmishes involving Indian and Pakistani troops across the Line of Control (LOC) commenced on 24th May. The LOC represents the de facto border between the two countries in this part of the world. Skirmishes escalated into air and missile strikes by India against targets in Pakistan on 7th May. Pakistan responded in kind. The conflict largely ended on 12th May, although both sides accused the other of subsequently breaking the ceasefire. India and Pakistan are thought to have lost combat aircraft during the confrontation, although how many is difficult to ascertain independently. News reports said that Pakistan’s military claimed it had downed at least one Indian Air Force (IAF) Rafale combat aircraft. Some reports have stated that the IAF may have lost as many as three Rafales. Moreover, the Pakistan Air Force (PAF) is believed to have given its J-10 fighter aircraft the type’s combat debut. Claims have been made that the latter may have shot down the IAF Rafales. The PAF may have also performed the maiden deployment of its PL-15E (NATO reporting name CH-AA-10 Abaddon) long-range, high-altitude surface-to-air missile. Should the Rafale losses prove to be true, this raises some troubling questions about both IAF doctrine and China’s military hardware; both the J-10 and PL-15E being Chinese in origin. Reports have stated that the IAF may have lost up to five combat aircraft in as many days. This should never have happened. The IAF should have had a detailed knowledge of the ground-based air surveillance and fire control/ground-controlled interception radars protecting Pakistan’s airspace. Likewise, the IAF should have been cognisant of the communications networking Pakistan’s Integrated Air Defence System (IADS) and deployed Ground-Based Air Defences (GBAD). IAF Offensive Counter Air (OCA) and Suppression of Enemy Air Defence (SEAD) plans should have been up to date thanks to continuous Signals Intelligence (SIGINT) gathering vis-à-vis Pakistan’s IADS and GBAD. A thorough and comprehensive OCA and SEAD effort should have been undertaken until the IAF had won and sustained air superiority. At that point non-air defence targets could be prosecuted. Assuming five aircraft have been lost, this would indicate that IAF SIGINT efforts and OCA/SEAD doctrines are lacking. IAF loss rates such as those reported would be unsustainable over a longer conflict. Secondly, it is possible that the IAF performed all the OCA/SEAD it should have done and had the most comprehensive and up-to-date SIGINT possible regarding the PAF’s IADS and GBAD. If this was the case, then it indicates the force may have underestimated Chinese military technology. That is a lesson that India, and allied nations around the world, will also have to digest. (Source: Armada)

 

03 Jun 25. Clouds and Carriers for LUWES. The Eurofighter Typhoon-EK variant of the eponymous fighter is one of the constituent parts of the Luftwaffe’s LUWES programme that is under contract. Other components are expected to follow in the future. It has been almost two years since Armada examined the Luftwaffe’s (German Air Force’s) LUWES (Luftgestützte Wirkung im Elektromagnetischen Spektrum/Airborne Effects in the Electromagnetic Spectrum) Suppression of Enemy Air Defence (SEAD) Concept of Operations (CONOPS). Since then, news regarding the initiative has been sporadic. As Armada reported previously the Luftwaffe began thinking about LUWES in circa 2018. LUWES is a system-of-systems with stand-off jamming and escort electronic attack aircraft. Uninhabited Aerial Vehicles (UAVs) and stand-in jammers will also play crucial roles. All these assets will be supported by new mission planning, battle management, mission data, and command and control systems. The goal is to provide an overarching SEAD capability to serve the Luftwaffe and the North Atlantic Treaty Organisation (NATO). The Luftwaffe joins the Aeronautica Militare (Italian Air Force) and US Air Force in providing European SEAD capabilities. Eight companies; Airbus, bKEC, Hensoldt, IBM, MBDA, PLATH, Rohde & Schwarz and Schönhofer are developing the LUWES concept.

Platforms and effectors

The Luftwaffe has been the lynchpin of NATO’s European SEAD posture since the early 1980s when the Panavia Tornado-ECR air defence suppression jet entered service. The Tornado-ECR will retire by the end of this decade to be replaced by the Eurofighter Typhoon-EK. The Typhoon-EK will be a dedicated EW and SEAD platform. Nonetheless, LUWES goes further than a single platform reflecting the inherent complexity of today’s Integrated Air Defence Systems (IADS) which NATO SEAD assets may need to fight. The LUWES architecture will be scalable to the operation at hand. Tactical emitter targets of opportunity could be engaged by platforms and effectors during the enforcement of a no-fly zone for example. Likewise, the architecture could support a prolonged operational/strategic air campaign against a near-peer adversary. Stand-off radar and communications jamming will be performed by a suitably equipped large aircraft with a converted Airbus A400M Atlas turboprop airlifter suggested as one possible airframe. A large platform such as this could also attack emitters with radio-delivered cyber effects. A second echelon would be deployed closer to the threat and focus on an escort jamming capability provided by the Typhoon-EK, and their soft and hard kill capabilities. The latter includes Northrop Grumman AGM-88E Advanced Anti-Radiation Guided Missiles supplemented by electronic jamming pods. Finally, stand-in jammers will be deployed in the so-called ‘no escape zone’. This is where the lethal engagement envelopes of the enemy’s ground-based air defences are their most dangerous. LUWES elements will receive mission data from the Luftwaffe’s forthcoming Bombardier G-6500 Pegasus Signals Intelligence (SIGINT) aircraft. This data will be uploaded to an Electronic Warfare (EW) cloud. The cloud will provide a data clearing house to support the LUWES SEAD mission. The LUWES architecture will be knitted together using standard NATO Link-11 and Link-16 Tactical Datalinks (TDLs). Also vital will be NATO’s Cooperative Electronic Support Measures (CESMO) TDL designed specifically to handle relevant EW information.

LUWES Networking

More details came to light regarding the elements that will underpin LUWES at the 2025 Association of Old Crows Electronic Warfare Europe conference and exhibition held in Rome between 7th and 8th May. Industrial sources disclosed that progress has been made on the LUWES’ stand-in jammer and EW combat cloud. The cloud will work closely with the CESMO TDL which will be a key conduit for the movement of this data. A demonstration of the combat cloud capability is scheduled to be made to the Luftwaffe in June. This demonstration forms part of a larger demonstration of LUWES software and some undisclosed hardware. The work performed on the EW combat cloud could have wider relevance to NATO writ large. In mid-2024, the alliance commenced a study known as SG-299. SG-299 explores electronic warfare combat cloud capabilities. The study was commissioned by NATO’s Industrial Advisory Group (NIAG). Sources said that the findings of the study, which has now concluded, have been handed to the Alliance. NATO will decide if the findings should inform any future Standardisation Agreement (STANAG) covering EW cloud specifications. The alliance may then decide to adopt such a STANAG so that can be adhered to by NATO’s membership. MBDA has proposed a remote carrier that could be equipped with an array of modular payloads according to the mission at hand. From a SEAD perspective, these payloads could include SIGINT collection or jamming modules. The four-metre (13-feet) long remote carrier airframe has a similar design to the company’s KEPD-350 Taurus air-to-surface missile that MBDA has developed with Saab. The airframe has a low radar cross section and can be launched from the ground, from surface vessels or from the air. The remote carriers could be used to swarm hostile air defences for jamming, spoofing and/or provocation. Regardless of the mission, the remote carriers will be networked using conventional radio and satellite communications. These links will let the remote carriers receive and share mission data from and to the EW cloud. Development work for the remote carrier is ongoing. There is no word on when a prototype may be developed, or the technology readiness level of current efforts. Beyond the Typhoon-EK programme other capabilities such as the EW combat cloud and remote carrier are awaiting formal acquisition. Sources continued that LUWES is still in the conceptual phase, although it is possible that contract awards could begin in the next twelve months. While news regarding LUWES has been sporadic, it does appear the programme is moving forward. It is possible that more developments may grace the public domain in the coming 18 months. (Source: Armada)

 

04 Jun 25. The Spectrum’s Coalition of the Willing. The new Electronic Warfare Capability Coalition will not only intensify EW support for Ukraine, but will also inform the electronic warfare postures and capabilities of the initiative’s member nations.

“The electronic warfare capability coalition is in place to fill critical gaps, train forces and establish effective policy and doctrine.”

This was how a senior member of the newly formed European Electronic Warfare Capability Coalition (EW CAPCO) describes three of the key missions for this new grouping. The new Capability Coalition (CAPCO) was under discussion at this year’s Association of Old Crows EW Europe conference and exhibition. The event was held in Rome on 7th and 8th May. News emerged in mid-May that several European nations would band together to improve their collective EW capabilities. A key goal of the coalition is to intensify electronic warfare support for Ukraine as she continues her efforts to expel Russia’s occupation of her lands. Nonetheless, as conference discussions underscored, the coalition’s work will have significant relevance beyond the Ukrainian theatre. Ukraine is one member of the coalition alongside Czechia, Denmark, France, Germany, Lithuania, Latvia, Norway, Poland and the United Kingdom. It was stressed during conference discussions that Ukraine is not involved in the coalition solely as a passive partner. The nation is taking an active role in feeding lessons learned into the coalition, and detailing the EW capabilities she needs. All the nations involved in the initiative have the same status within the coalition. Spinning up the initiative required an initial letter of intent and a subsequent multinational contract. The next steps developed the coalition’s Terms-of-Reference (TORs) and established ‘battle rhythm’. The latter has been vital in ensuring the coalition is as responsive as possible to the electromagnetic battle in Ukraine. The TORs provide the framework for the coalition’s deliverables. These include the supply of appropriate EW capabilities to the Ukrainians, training Ukrainian personnel and developing unified EW strategies, policies and doctrines. EW CAPCO sources say the group has a ‘shopping list’ from Ukraine regarding specific systems. Efforts are ongoing to shape these requirements into capabilities as opposed to solely addressing specific EW demands with kit.

Organisation

A German two-star officer is the EW CAPCO’s director with two subordinate secretaries also from Germany. The CAPCO then divides into three distinct working groups covering procurement, training and education, and policy and doctrine. The EW Capability Coalition is not the only such grouping in this ‘coalition of the willing’ of European nations pledging their support to Ukraine’s ongoing fight. Other CAPCOs cover air defence, airpower, armour, artillery, demining, information technology, sea power and uninhabited aerial vehicles. Sources continued that all these groupings have “EW issues” and depend on the electromagnetic spectrum in some shape or form. As a result, the EW CAPCO can perform cross cutting work across the other groupings providing assistance and advice as and when required.

Post Conflict

How the Ukraine War will conclude remains to be seen. Nonetheless, the EW CAPCO’s thoughts are turning to how EW capabilities will fit into Ukraine’s wider post-conflict force structure. Beyond Ukraine, “exchanging lessons learned is crucial for the future,” the sources noted. These lessons are not only relevant for Ukraine, but germane to the wider EW CAPCO membership. Additional nations may join the initiative in the future. The group’s officials are keen to stress that EW CAPCO is neither a North Atlantic Treaty Organisation nor European Union initiative. Nonetheless, the EW CAPCO’s activation marks an important sharpening of the continent’s current and future electronic warfare posture and capabilities. (Source: Armada)

 

05 Jun 25. Hold that door. The RAF’s Tekever AR3 UAV equipped with the StormShroud electronic attack payload can mimic crewed aircraft to sow confusion in the minds of air defenders. The RAF’s new StormShroud stand-in jammer represents another arrow in the force’s electronic attack quiver to help it defeat today’s and tomorrow’s air defences. The Royal Air Force’s (RAF’s) Electronic Warfare (EW) capabilities have evolved once more with the revelation that the service has taken delivery of its new StormShroud stand-in jammer. The news was announced by the United Kingdom Ministry of Defence on 2nd May. The announcement was made by the UK’s Prime Minister Keir Starmer during a visit to Leonardo’s facilities in Luton, southeast England. StormShroud’s electronic attack payload has been developed by Leonardo. The payload is carried by a rail-launched Tekever AR3 Uninhabited Aerial Vehicle (UAV). StormShroud will be the responsibility of the RAF Regiment’s 216 Squadron.

Concept of Operations

Speaking at the 2025 Association of Old Crows Electronic Warfare Europe conference and exhibition held in Rome on 7th and 8th May, Leonardo officials provided Armada with more details on StormShroud. Primarily, the system will help crewed aircraft operate in heavily contested airspace. For example, StormShroud UAVs could fly into the engagement footprint of a Surface-to-Air Missile (SAM) battery. The StormShroud payload could be programmed to emit Radio Frequency (RF) signals. These signals could simulate an incoming strike package of aircraft. This could help distract the SAM battery’s air defenders while an actual strike package is doing its work elsewhere. The UAV would, in effect, ‘hold open the door’ for the crewed aircraft to fly unchallenged through the battery’s engagement footprint. In fact, the UAVs could represent so many false targets that real potential targets could be mixed within the cacophony of confusion. Conversely, StormShroud payloads could be used to unleash heavy jamming. Electronic attacks such as these could prevent the battery’s ground-based air surveillance and fire control radars from seeing the actual threats. Armada discussed StormShroud’s development last year when the system was initially known as BriteStorm. Leonardo’s BriteCloud air-launched self-protection decoy, BriteStorm and subsequently StormShroud are all thought to use the same Digital Radio Frequency Memory (DRFM). The DRFM is programmed to compose and deploy the desired electronic effects in support of the mission. It is understood that StormShroud can engage threats transmitting on frequencies of zero megahertz to 20 gigahertz.

Joining BriteCloud and StormShroud is the electronic attack functionality of Leonardo’s ECRS Mk.2 X-band (8.5 gigahertz/GHz to 10.68GHz) fire control radar. BriteCloud provides individual aircraft protection against radars and radar-guided threats like SAMs and air-to-air missiles. The ECRS Mk.2 can attack radar threats with jamming within its field-of-view. The ECRS Mk.2 will equip all new Typhoon FGR Mk.4 combat aircraft and can also furnish legacy Typhoon marques in service with the RAF. Although not yet funded, MBDA’s SPEAR-EW (Select Precision Effects at Range – EW) loitering EW system could be added to this mix. It is possible that SPEAR-EW could be deployed as a stand-off or escort jammer, with StormShroud providing stand-in jamming, and BriteCloud and ECRS Mk.2 affording individual aircraft protection.

Programme

The RAF is said to have procured an initial 24 StormShroud systems for $25.2m, working out at just over $1 m per system. Sources have shared with Armada that additional systems may be procured in the future. Leonardo sources said that the realisation of StormShroud took just twelve months. They added that, while StormShroud is equipping the AR3 UAVs, the payload could outfit other platforms. These platforms would need to a minimum of 3.5-litres (0.12-cubic feet) of internal volume. StormShroud imposes a 2.5 kilograms (5.5 pounds) weight penalty. The realisation of StormShroud represents the continuing commitment of the RAF to enhancing the force’s air defence suppression posture. Alongside ECRS Mk.2, BriteCloud and perhaps SPEAR-EW in the future, with StormShroud the service is sharpening its EW capabilities writ large. This will not only benefit the RAF, but the North Atlantic Treaty Organisation, and allied nations as a whole, during future coalition operations. (Source: Armada)

 

05 Jun 25. June Spectrum SitRep. The Simulate, Emulate, Stimulate, Calibrate and Operate approach to electronic warfare training pioneered by MASS was launched at this year’s Association of Old Crows EW Europe exhibition and conference. Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.

GNSS Jamming Detection for ATAK

An electronic intelligence system developed by Zephr is garnering interest in the United States. It was reported in October 2024 that the company had developed a networked signals intelligence system. The system exploits local cellphone networks to detect Global Navigation Satellite System (GNSS) jamming. By networking cellphones and cellphone towers together, this architecture can act as a giant distributed antenna. The phones and towers will detect GNSS interference and its source. Zephr has developed the system for deployment in Ukraine. In February, the company was awarded a contract worth $1.7 m from the US Air Force Research Laboratory (AFRL). The work will develop real time GNSS jamming and spoofing detection and geolocation techniques. Reports have stated that, over the long term, the US Department of Defence (DOD) is interested in this functionality for the AFRL’s Android-based Tactical Assault Kit (ATAK). ATAK will integrate “Zephr’s jamming/spoofing detection and localisation capabilities,” the company said in a written statement. “(T)he capability will not require any additional hardware beyond the existing Android phones it will run on.” The contract’s duration is for two years. Zephr’s work with the AFRL in this regard is currently at Technology Readiness Level Seven (TRL-7). According to US DOD definitions, this denotes that a working model or prototype has been demonstrated in an operational environment. The company continued that the contract should help advance the technology to TRL-8 vis-à-vis ATAK. TRL-8 denotes that the system has been qualified through test and evaluation: “One of our motivations for doing real world testing in active conflict zones (such as Ukraine) is to build a battle-ready technology that we are confident can help both the warfighter and civilian users,” the company added.

MASS Unveils SESCO

MASS launched its new SESCO (Simulate, Emulate, Stimulate, Calibrate and Operate) Electronic Warfare (EW) training methodology at this year’s EW Europe conference and exhibition. The show was hosted by the Association of Old Crows global EW advocacy organisation, and held in Rome on 7th and 8th May. Company representatives told Armada at the event that the SESCO methodology takes a holistic approach to EW training. Personnel with no, or limited, electronic warfare experience will, stage-by-stage, acquire the knowledge and acumen they need to ensure they are ready for operational spectrum challenges when deployed. A key aspect of SESCO is that it involves the company’s NEWTS training system. NEWTS allows students to experience an accurate electromagnetic environment without the trainers emitting any RF (Radio Frequency) signals. Students experience the electromagnetic challenges they may face operationally. However, trainers do not need a range, or permissions to emit, that the use of actual RF signals would otherwise entail. In fact, the students will experience a simulated RF environment until they reach the ‘Calibrate’ stage of their training. Simulated RF signals work directly with the equipment and capabilities students will use operationally. MASS representatives added that the SESCO methodology is under trials to enable the most modern RF threats to be detected and decoded/demodulated in real time.

We Practice to Deceive

Roke’s new EM-Vis Deceive electronic warfare system has been designed to incorporate open standards easing the integration and upgrade path for the system during its service life. Roke also took advantage of the EW Europe conference and exhibition to launch the company’s new EM-Vis Deceive portable Electronic Warfare (EW) system. EM-Vis Deceive is designed to help land forces detect, track and engage hostile communications, uninhabited aerial vehicle Radio Frequency (RF) links and other RF signals. The company says the new product has been realised using the Standards for Integrated Command, Control, Communications, Computer, Cyber, Intelligence, Surveillance, Reconnaissance and Electronic Warfare (STICS). The STICS suite of open standards is designed to assist command and control; intelligence, surveillance and reconnaissance, and EW system interoperability. EM-Vis Deceive can be carried by a single soldier and used by an unskilled operator. John Bottomley, Roke’s senior cyber and electromagnetic activities engineer, told Armada that the system can detect, track and jam threats emitting on frequencies of 20 megahertz up to six gigahertz/GHz. He added that the company is working on antenna arrays that could extend this waveband to 18GHz. Work commenced on the EM-Vis Deceive two years ago. The company “has completed initial deliveries, with further shipments scheduled for early 2026.” Those initial deliveries “enable our current user communities to trial, deploy and feedback into Roke prioritisation of applications as we spirally enhance EM-Vis Deceive to continually address the challenges our users face,” Mr. Bottomley continued. (Source: Armada)

 

04 Jun 25. New flagship Arbitrary Waveform Generators with 3.9 GHz bandwidth and 10 GS/s output rate. marking a significant milestone in the company’s product portfolio. Designed for demanding applications in radio frequency (RF) and microwave signal generation, the new AWGs deliver output rates up to 10 GS/s with exceptional 16-bit vertical resolution and bandwidths reaching up to 3.9 GHz. The new products are aimed at engineers and scientists working in cutting-edge fields such as wireless communications, radar system development, quantum research, and aerospace testing.

“This launch represents a major leap forward for us,” said Oliver Rovini, CTO of Spectrum Instrumentation.

“It’s the first time we’ve entered the high-bandwidth space, and we’re doing it with a product line that sets new standards in quality and capability. With these new AWGs, we’re giving our customers a tool that enables next-generation innovation.”

The new flagship AWGs are available as PCIe cards with up to 10 GB/s streaming, as well as stand-alone NETBOX units with easy control via Ethernet, connecting directly to laptops, PCs or company networks. The new instruments are ideal for integration into automated test systems. Key features include:

  • Output rates up to 10 GS/s for ultra-fast signal generation
  • 16-bit vertical resolution to ensure exceptional signal fidelity
  • Analog bandwidths up to 3.9 GHz, enabling true-to-life reproduction of wideband RF & microwave signals
  • Single-Ended or Differential outputs with up to 4V output swings
  • Multi-channel synchronization for complex signal simulations across multiple outputs
  • Up to 8 GSample memory per channel for flexibility in waveform generation

These features make the new AWGs particularly well-suited for applications that demand high signal quality over wide bandwidths, such as testing of communication standards like 5G and 6G, simulating radar echoes, or generating waveforms for experimental physics and quantum systems. In addition to their powerful hardware, the new AWGs are supported by Spectrum’s comprehensive software suite, including drivers for Windows and Linux, as well as programming examples for languages like C/C++, Python, MATLAB, and LabVIEW, plus Spectrum’s SBench 6 software for interactive operation. These new flagships include a 5-year warranty, free lifetime software/firmware updates, and support directly from Spectrum’s design engineers.

 

02 Jun 25. Hanwha Ocean signs MOUs with BlackBerry, L3 Harris MAPPS. The collaboration with L3 Harris MAPPS is on integrated simulation and platform automation technologies. South Korean shipbuilding company Hanwha Ocean has signed memorandum of understandings (MOUs) with BlackBerry and L3 Harris MAPPS, at the Canada’s Global Defence & Security Trade Show (CANSEC 2025) defence exhibition held in Ottawa. Through these agreements with BlackBerry and L3 Harris MAPPS, Hanwha Ocean is boosting its Canadian submarine business. BlackBerry is a Canadian firm with a focus on cybersecurity and secure communication technologies. The company has delivered security solutions to an international clientele, including government entities and vital industry sectors. L3 Harris MAPPS, part of L3 Harris Technologies, concentrates on providing integrated automation platforms and advanced simulation systems tailored for the marine defence and energy sectors. The company has a history of equipping naval forces globally with various marine electronic systems and solutions, with the Korean Navy being among its customers.

Hanwha Global Defense CEO Michael Coulter said: “There is the potential for infinite synergy to be created through the cooperative relationship between Hanwha Ocean and its Canadian partners BlackBerry and L3 Harris MAPPS.

“Through this MoU signing, Hanwha Ocean will establish a full-fledged cooperative relationship with these partners, and will greatly contribute to further solidifying and strengthening the bilateral relationship between Korea and Canada.”

Canada’s current submarine procurement initiative stipulates offset trade conditions that benefit the local economy and industry, said Hanwha Ocean. Previously, Hanwha Ocean established agreements with Canadian entities CAE, Curtiss-Wright Indal Technologies, and GASTOPS during 2024’s CANSEC exhibition. Hanwha Ocean said it developed a 3,000-tonne submarine “with its own technology”. The company’s Jangbogo-III Batch-II-class submarine (KSS-III), proposed for Canada, features innovative lithium-ion batteries and an air-independent propulsion system (AIP), making it suitable for Arctic operations with its extensive range and submerged endurance. In addition to its Canadian ventures, Hanwha Ocean CEO Kim Hee-chul signed an MoU with PGZ SW and Nautic Shipyard for strategic cooperation in shipbuilding and maintenance at Korea’s MADEX 2025 exhibition. This collaboration seeks to advance joint development and export of various naval vessels and systems. The partnership is set to enhance Poland’s naval ship industry through joint projects such as the Orka submarine project and will involve technology transfer and localisation efforts.

Sung-Chul Eo said: “The cooperation with a major Polish company goes beyond a simple technological alliance and will serve as a bridge for shipbuilding industry cooperation between Korea and Poland.”

In September 2024, Hanwha Ocean approached a major Polish military technology company, WB Group, to work together in pursuit of supporting Poland’s Orka submarine programme. (Source: naval-technology.com)

 

30 May 25. A like-minded partnership on Cyber and Capability Collaboration. As we face complex technological challenges, sharing knowledge and expertise with our allies is essential to safeguard our mutual interests and strengthen our national security.

The UK and Japan continue to deepen their strategic collaboration in cyber, working together to uphold a free, open, and secure digital world. From joint cyber exercises to the responsible use of cyber power, this like-minded partnership strengthens resilience and sets the global example of trusted cooperation in the cyber domain.

DSEI Japan

Strategic Command was proud to lead the Ministry of Defence (MOD) presence at DSEI Japan in support of UK Defence and Security Exports (UKDSE) and Minister for Defence Procurement and Industry (Min(DPI)), the Rt Hon Maria Eagle MP.

DSEI Japan is Asia’s only integrated Defence and Security Expo and, to some extent emulates the long-running UK model. As a forum, and in terms of its wider international importance, it is growing exponentially. This year DSEI Japan involved over 100 countries and delegations and over 300 exhibitors. For the first time DSEI Japan featured a keynote address from the Japanese Prime Minister, Shigeru Ishiba.

The MOD delegation was in Japan to support UKDSE and the UK’s wider prosperity agenda, as well as supporting outreach on behalf of UK industry and Small and Medium-sized enterprises. Presentations at the MOD stand focussed on driving innovation, the Cyber & Electromagnetic (Cyber & EM) Domain and Global Strategic Trends 7.

Working Together in Cyberspace

Our involvement in DSEI was preceded by a joint UK-Japan cyber seminar at the British Embassy in Tokyo. The event signalled the next stage in the maturing of our bilateral co-operation across the Cyber Domain.

HMA Julia Longbottom and Lt Gen Sir Tom Copinger-Symes led the seminar with approximately 100 invited guests from across the Japanese MOD, and related think-tanks and media.

Japan is embracing the concept of Active Cyber Defence. Considerable resources and effort are being put into understanding the Cyber Threat and the whole of society response that is needed to maintain cyber security. New legislation has pushed the boundaries of Japan’s approach to Cyber providing new means for the Japanese MOD to protect citizens and continue to defend Japanese networks.

The Active Cyber Defence legislation provides Japan with the legal permissions to – having been blocked by the constitution for over 70 years – intercept communications data for the purposes of cyber security and, in severe situations, to deliver offensive cyber operations. It also enables reforms to Japan’s cyber structures and public-private partnership mechanisms. The adoption of the Active Cyber Defence legislation is a significant milestone, as it meant flexing the boundaries of Japan’s constitution and long-standing political conventions.

There is much both the UK and Japan can do to learn from each other, both in terms of training and supporting our people, but also operating differently to address cross-cutting threats to our ways of living, which demand and need whole of society responses. The UK’s Cyber Primer provides one model for how this can be done.

Lt Gen Sir Tom Copinger-Symes followed his presentation by giving a pooled interview to the Japanese media, during which he complimented the Japanese Government and MOD on the novel and far-sighted nature of their reforms. Calling it a foundation for “genuinely strong cooperation”, he reaffirmed the UK’s commitment to working with Japan and other partners to address threats.

With reference to the recent, and ground-breaking legislation on Active Cyber Defence, HMA Tokyo, Julia Longbottom, said

… we often say cyber is a team sport, but I’d go one step further and call it an international team sport relying on us all to play our part. So, it is only right that we commend that team. From the Japanese politicians, officials and experts who have been involved in the development of the legislation. To like-minded partners, industry and my own team for their tireless work to share lessons and learn from Japan’s transformational reforms.

Deepening our Strategic Collaboration

The MOD presence also served to highlight the continued importance attached to Global Combat Air Programme (GCAP) and the close working partnership we enjoy with Japan and Italy, as partners in the development of this sixth-generation capability. Detailed conversations with our Japanese partners also emphasised the importance of the digital enablement of GCAP, including the overarching digital backbone and related architecture.

In her keynote address, Min(DPI) emphasised the importance of the UK and Japan working together as trusted partners. Similarly, in her interview with Nikkei, she reinforced the importance of international collaboration by necessity, and the benefits of like-minded partners working increasingly together. The need to work differently with industry, particularly in the newer domains of Cyber & EM was also brought to the fore by Lt Gen Sir Tom Copinger-Symes. (Source: https://www.gov.uk/)

 

30 May 25.  Cyber Update Key points.

  • A cyber extortion campaign carried out by the cyber criminal group ‘Luna Moth’ underscores the heightened security risks facing the legal sector (see Sibylline Cyber Daily Analytical Update – 27 May 2025).
  • A new Russian state-sponsored group (‘Void Blizzard’) will elevate the security and cyber espionage risks facing the government and defence sectors across Europe and North America (see Sibylline Cyber Daily Analytical Update – 28 May 2025 and our Technical analysis below).
  • A new remote access trojan (RAT, ‘NodeSnake’) will elevate the security risks posed by the ransomware group ‘Interlock’ to UK- and US-based educational institutions (see Sibylline Cyber Daily Analytical Update – 29 May 2025 and our Technical analysis below).
  • A covert cyber operation carried out by the Chinese state-sponsored group ‘APT41’ highlights the long-term security risks facing key sectors (see Sibylline Cyber Daily Analytical Update – 30 May 2025).

Technical analysis of weekly stories

The ransomware group Interlock has been using a new RAT (NodeSnake) to target educational institutions in the UK and the US since at least January. Interlock typically distributes phishing emails containing malicious links and/or attachments to infiltrate systems. Upon installation, the malware establishes communication with command-and-control (C2) infrastructure and exfiltrates sensitive system metadata (including user privileges, running processes and network information). NodeSnake often proxies C2 traffic via pre-defined domains and/or hardcoded IP addresses, encrypting and cycling all communication with randomised delays to enhance obfuscation. The malware also heavily obfuscates its code and disrupts native de-bugging processes, showcasing the sophistication of its detection-evasion capabilities. It uses two command execution programmes (PowerShell and CMD) to write a registry entry and ensure execution during a system’s startup, allowing threat actors to maintain persistence. In March, Interlock used a new version of NodeSnake that enables dynamic C2 communication and command execution, as well as enhanced obfuscation, encryption and anti-analysis techniques; we assess this underscores the malware’s rapid evolution.

A new Russian state-sponsored group (Void Blizzard) has targeted government and defence sectors across Europe and North America in a cyber espionage operation since at least 2024. Void Blizzard typically purchases stolen user credentials on the dark web to hijack user accounts using password spraying attacks, highlighting the low-resource and low-cost nature of these attacks. The group primarily hijacks Microsoft Exchange and SharePoint online services to steal sensitive information. In April, Void Blizzard also started a spear phishing campaign, showcasing the rapid development of the group’s tactics. The group impersonated an organiser from the European Defence and Security Summit to trick victims into opening a malicious attachment purporting to contain an invitation to the summit. The invitation displayed a QR code that redirected victims to a spoofed domain for Microsoft Entra’s authentication portal. Void Blizzard then likely used the open-source ‘Evilginx’ attack framework to conduct an Adversary-in-the-Middle (AitM) attack, enabling the threat actors to authenticate and hijack legitimate user accounts. The group reportedly exploited hijacked accounts to extract emails, files and chats, likely in a bid to collect strategic information pertaining to the Russo-Ukrainian war and the security posture of Ukraine’s allies.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

Our cyber word(s) of the week: Telephone-oriented attack delivery (TOAD) (Source: Sibylline)

 

30 May 25. Global: Covert cyber operation highlights long-term security risks from Chinese threat actors. On 28 May, the technology company Google reported that the Chinese state-sponsored group ‘APT41’ has been targeting global organisations (including government, shipping, technology and transport entities) in a cyber operation since at least 2024. APT41 distributes phishing emails to trick potential victims into clicking on a malicious link. The link redirects victims to a compromised government website that downloads two malicious payloads via a multi-stage process. Both payloads are disguised as images for stealth purposes. They subsequently deploy the main malware (‘Toughprogress’), establishing communication with command-and-control (C2) infrastructure via Google Calendar services. More specifically, Toughprogress conceals command execution and system responses within calendar events, thus enhancing detection evasion. Chinese state-sponsored groups routinely target global organisations to obtain strategic information and establish prolonged persistence in their victims’ systems. As such, we assess that long-term security risks will continue to impact the aforementioned sectors amid the ongoing development of China’s cyber capabilities. (Source: Sibylline)

 

30 May 25. Persistent Systems Awarded Basic Ordering Agreement by NATO Communications and Information Agency. Company now positioned to directly support NATO and Partnership for Peace nations Persistent Systems, LLC (“Persistent”), a leader in mobile ad hoc network (MANET) technology, announced that it has been added to a Basic Ordering Agreement (BOA) from the NATO Communications and Information Agency (NCIA). This milestone allows Persistent to directly accept orders from NATO and Partnership for Peace (PfP) nations—removing barriers to access and expediting the procurement of the company’s Wave Relay® MANET products and services.

“In partnership with our International Resellers, Persistent is expanding our contract mechanisms available to support our Allies,” said Brian Spurlock, Vice President of Growth and Strategy at Persistent Systems. “With our addition to the BOA, NATO customers have a new path to procure our American-made technology—and tap into our training and engineering expertise to unlock the full capabilities of the Wave Relay® network.”

A BOA is a pre-negotiated framework agreement that defines terms and conditions for future orders, streamlining acquisition and delivery. Persistent is the only MANET company currently holding such an agreement with NCIA. Persistent’s international sales have more than doubled in the past two years, driven by growing global demand for secure, resilient, and scalable communications. With geopolitical threats on the rise, this agreement enables NATO and PfP partners to more rapidly procure a proven solution.

Persistent’s Wave Relay® MANET technology is already fielded across Europe:

  • In March, the company announced contracts totaling $29 m to supply MPU5 handheld MANET radios and tower-mounted antennas to several Baltic Sea nations.
  • During the 2024 Summer Olympics, French authorities employed the network for maritime domain awareness in Marseilles—supporting sailing events and securing the Olympic Torch arrival.
  • In 2023, the UK Royal Marines deployed over 1,000 MPU5 radios as part of the Future Commando Force modernization initiative.

“This Basic Ordering Agreement opens new doors for Persistent Systems across Europe,” said Eve Shapiro, Vice President of International Sales at Persistent Systems. “It streamlines the path for NATO and PfP nations to access our Wave Relay® MANET technology—enabling faster deployments, closer collaboration, and enhanced mission success for our international partners.”

Acquiring a NATO BOA reinforces Persistent’s long-standing commitment to supporting its customers with an unmatched end-user experience—beginning with the first inquiry and continuing through delivery, training, and ongoing support. Eligible NATO and Partnership for Peace nations can procure Persistent Systems technology through this BOA by contacting their national procurement authorities and referencing BOA number 42511081. (Source: ASD Network)

—————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

————————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

May 30, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

———————————————————————————————————————————————————————————————————————————————————————————————————————————–

28 May 25. Europe-North America: Russian state-sponsored group will elevate security risks for defence sector. On 27 May, the technology company Microsoft reported that a new Russian state-sponsored group (‘Void Blizzard’) has targeted government and defence sectors across Europe and North America in a cyber espionage operation since at least 2024. Void Blizzard typically purchases stolen user credentials on the dark web to hijack user accounts via password spraying attacks, highlighting the low-resource and low-cost nature of these attacks. More recently, the group has also started using spoofed login pages resembling those for the identity management service ‘Microsoft Entra’ to steal authentication data, showcasing the rapid evolution of Void Blizzard’s skillset. The group has reportedly extracted emails, files and chats throughout its campaign, likely in a bid to collect strategic information pertaining to the war in Ukraine and the security posture of Ukraine’s allies. We assess this underscores the elevated security risks facing the aforementioned sectors amid the continued expansion of Russia’s cyber strategy. (Source: Sibylline)

 

28 May 25. Nokia and blackned to create next-generation deployable tactical networks for the defense sector. Companies sign agreement to provide advanced, deployable mobile communication systems for military battlefield operation

Tailored for Germany’s defense requirements, with adaptability for international use

Leverages Nokia’s cutting-edge 5G technology and blackned’s expertise in defense digitalization to enable high performance, scalability and strategic advantage

Nokia and blackned GmbH, in which the Düsseldorf-based technology group Rheinmetall holds a 51% stake, have entered into a memorandum of understanding to create advanced deployable tactical networks for the defense sector, the companies announced today. The partnership brings together Nokia’s 5G technology and blackned’s expertise in defense digitalization to develop high-performance, next-generation tactical communications solutions that provide secure and reliable connectivity for military operations in the field. Under the agreement, the companies will integrate their respective product and solution portfolios to design a unique, deployable communication system tailored to Germany’s defense needs and adaptable for use in other countries. This collaboration will leverage Nokia’s 5G tactical communications technology and blackned’s software-based defense solutions, creating an ideally integrated platform for the Rheinmetall Battlesuite. Deployable tactical networks are cutting-edge, mobile solutions designed for quick deployment and extended reach. Built for various battlefield environments, these systems provide reliable, uninterrupted connectivity and high data rates for military teams supporting the Software Defined Defense paradigm. These deployable tactical networks enhance situational awareness, speed up decision making and improve asset co-ordination

“blackned is dedicated to advancing innovation in defense digitalization, and our agreement with Nokia represents an important milestone in that mission. Together, we will provide powerful, flexible and future-ready tactical network solutions built for the realities of modern defense, said” Timo Zaiser, CTO at blackned GmbH.

“In a rapidly evolving tactical environment, speed, mobility and adaptability are paramount. Through the partnership with blackned, our 5G technology will empower defense forces to deploy robust communication capabilities swiftly and share intelligence more effectively, providing our customers with a decisive advantage on the battlefield,” added Giuseppe Targia, Head of Space and Defense at Nokia.

 

27 May 25. US: Evolving social engineering tactics underscore heightened security risks facing legal sector. Earlier on 27 May, international news outlets reported that the cyber criminal group ‘Luna Moth’ has targeted US law firms in a cyber extortion campaign since at least 2023. Luna Moth uses phishing or telephone-oriented attack delivery (TOAD) techniques to trick victims into calling a customer support phone number embedded in a phishing email. During the phone call, victims receive a link that covertly installs a remote access programme, providing threat actors with prolonged access to compromised systems. Luna Moth started shifting its tactics in March. Threat actors are known to impersonate IT personnel so as to trick victims into enabling remote access sessions to facilitate covert data exfiltration. The group then exfiltrates sensitive data and sends an extortion note to victims, threatening to leak the stolen data unless a payment is made. The report underscores the heightened security, social engineering and financial risks facing the legal sector amid the continuous evolution of cyber criminal tactics. (Source: Sibylline)

 

23 May 25. Cyber Update Key points.

  • A new backdoor (‘Skitnet’) will elevate the security risks facing global entities from ransomware groups (see Sibylline Cyber Daily Analytical Update – 19 May 2025 and our Technical analysis below).
  • State-sponsored cyber attacks showcase the ongoing security risks facing perceived adversarial entities as geopolitical tensions continue to strain (see Sibylline Cyber Daily Analytical Update – 20 May 2025).
  • A series of ransomware attacks by the threat group ‘Scattered Spider’ point to the elevated security risks facing global businesses in the medium term (see Sibylline Cyber Daily Analytical Update – 21 May 2025).
  • A long-term cyber espionage operation by the Russian state-sponsored group ‘APT28’ underscores the heightened security risks facing European and US entities.
  • The exploitation of a zero-day software vulnerability underscores the heightened security, supply chain and pre-positioning risks from the Chinese-speaking group ‘UAT-6382.’

Technical analysis of weekly stories

Ransomware groups are increasingly deploying a new backdoor (Skitnet) to conduct stealthy post-exploitation activities. Threat actors typically use a first-stage malware-loader to decrypt and execute Skitnet within a compromised system’s memory upon infiltrating said system. Skitnet then establishes communication with threat actor-controlled infrastructure and initiates three separate channels of communication (for command execution, data exfiltration and monitoring activities), showcasing its sophistication. The backdoor relies on a domain name system (DNS) and the hypertext transfer protocol (HTTP) for command-and-control (C2) communication to assimilate with legitimate traffic and enhance Skitnet’s stealth. Skitnet can download remote access tools for remote command execution, take screenshots, enumerate active security software and perform persistence tasks. It can also execute PowerShell scripts for enhanced attack customisation, allowing threat actors to retain prolonged control over compromised systems. Skitnet is available for purchase on dark web forums; this likely enables ransomware groups to upscale and streamline cyber operations quickly.

The Chinese language-speaking group UAT-6382 has been exploiting a zero-day vulnerability (CVE-2025-0994) to penetrate targeted systems since at least January. The vulnerability affects an asset management platform (Trimble Cityworks) that is widely used by local governing bodies across the US; it enables authenticated users to execute code remotely on compromised systems. UAT-6382 infiltrated the platform before exploiting CVE-2025-0994 to conduct initial system reconnaissance and to deploy malware. This included the deployment of several web shells (‘AntSword’, ‘chinatso’ and ‘Behinder’), backdoors, ‘Cobalt Strike’ beacons and a ‘VShell’ stager to maintain prolonged access to compromised systems and execute additional malicious code. The group also used the web shells to facilitate data exfiltration after enumerating multiple directories and files of interest. Furthermore, UAT-6382 used a malware loader (‘TetraLoader’) to deploy the beacons and stager into legitimate system processes so as to enhance detection evasion. The group then pivoted into customer environments (particularly those involved in utility and public asset management), likely in an effort to monitor systems and conduct pre-positioning activities.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

Our cyber word(s) of the week: Beacons. (Source: Sibylline)

 

23 May 25. US: Vulnerability exploitation points to security risks from Chinese-speaking threat actors. On 22 May, the cyber security company Cisco Talos reported that the Chinese language-speaking group ‘UAT-6382’ has been exploiting a zero-day vulnerability (CVE-2025-0994) to penetrate targeted systems since at least January. CVE-2025-0994 affects an asset management platform (Trimble Cityworks) that is widely used by local governing bodies across the US. UAT-6382 infiltrated the platform before exploiting the vulnerability to execute malicious code on compromised servers. This enabled the group to conduct initial system reconnaissance, and subsequently to deploy malware to prolong access. UAT-6382 then pivoted into customer environments (particularly those involved in utility and public asset management) in a likely bid to monitor systems and conduct pre-positioning activities. Trimble released a patch for this vulnerability in February, showcasing the importance of timely patch-management policies. China-linked threat actors routinely target and establish persistence within US national infrastructure; we assess this underscores the heightened security, supply chain and pre-positioning risks facing the aforementioned sectors. (Source: Sibylline)

 

20 May 25. Network Innovations today announced the launch of Argus, a software-defined platform that transforms how organizations deploy, secure, and scale communications across terrestrial, wireless, and satellite environments. This includes Network Innovations’ own VSAT network, third-party satellite networks (Starlink, OneWeb), 5G/LTE, private LTE, and terrestrial transport. Argus is a mission-ready overlay framework that bridges multi-path connectivity, security, and operational complexity by unifying disparate technologies under a single cohesive platform. The result is simplified deployment with strengthened network security and operational efficiency for customers in the government, enterprise and maritime sectors, among others.

“Argus was developed with the understanding that lives, missions, and outcomes depend on unfailing, agile, and secure connectivity in an increasingly complex environment,” said Derek Dawson, CEO of Network Innovations. “This solution serves as an invisible backbone to bring these technologies into one cohesive framework, so organizations have visibility, control, security, and resilience to focus on what matters, when and where it matters, without worrying about their network.”

 

26 May 25. Switzerland to expand EU defense ties with new cyber-defense role. Switzerland has received the European Union’s approval to join a multinational military cybersecurity project, the EU’s Council announced this week. The decision allows Switzerland to become part of the Estonian-led Cyber Ranges Federations project under the EU’s Permanent Structured Cooperation (PESCO) framework, marking a notable advance in Swiss–EU military cooperation. This comes despite Bern’s famously longstanding policy of strict military neutrality. Switzerland had applied to join the project in October of last year, shortly after submitting an application for another joint project focused on military mobility. Two formalities remain before becoming a full project member: Estonia must invite Switzerland to the cooperation, and Bern needs a so-called administrative arrangement with the EU governing formalities such a data exchange and other parameters. The Swiss government welcomed this week’s EU decision, saying that the country “will take part in the European PESCO project.” Switzerland has beefed up its own cyber defense capabilities in recent years with its Swiss Cyber Training Range and a Cyber-Defence Campus. The EU’s Cyber Ranges Federations initiative seeks to centralize capacity, pool unique services and automate processes across member states, reducing manual workload during exercises and accelerating the development of advanced cybersecurity technologies. Austria, Belgium, Bulgaria, Finland, France, Italy and Luxembourg are already members of the project, in addition to Estonia. Under PESCO’s third-state participation rules established in 2020, non-EU countries may join individual projects if they share EU values and pose no threat to member states’ security interests. The Council confirmed that Switzerland meets the required political, legal and substantive criteria and will bring “substantial added value and mutual benefit” to the federation, it said in a press release. The Council retains oversight of third-state involvement and may adjust conditions should security considerations evolve, ensuring alignment with the EU’s collective defense objectives. Swiss defense planners have balanced these new engagements with Bern’s policy of armed neutrality, with federal officials calling cooperation in PESCO initiatives “ad hoc collaboration on specific projects which are thematically in the interest of both parties and which do not create critical dependencies for neutrality.” Participation in the cyber project enables Switzerland to contribute – and benefit from – expertise and infrastructure without entangling the country too deeply in broader EU defense commitments, from Bern’s point of view. The Swiss government said that “participation will take place selectively and on a needs-oriented basis.” The latest project represents part of Switzerland’s broader strategic approach to selective participation in PESCO projects that align with its defense interests while maintaining neutrality. It’s not Switzerland’s first brush with EU defense initiatives. In January, the government received the green light to join an EU-led military mobility project, which it applied for in September 2024. The Military Mobility project aims to simplify and standardize national cross-border military transport procedures, enabling swift movement of military personnel and assets throughout the EU via road, rail, sea, or air. Other non-EU countries, such as the UK, Northway, the USA and Canada are also part of this project. In addition to deepening engagement with the EU, Switzerland has also been a member of NATO’s partnership for peace since the 1990s, as has its neutral eastern neighbor, Austria. Hardline neutrality defenders have long taken issue with Swiss engagement on military projects beyond its own borders. Their criticism received new urgency in the aftermath of Russia’s attack on Ukraine in 2022. Last year, a civil movement garnered more 130,000 certified signatures to organize a national referendum on strengthening Switzerland’s international neutrality. The referendum organizers specifically want to prevent what they see as a gradual erosion of Switzerland’s traditional neutrality through strengthened international defense cooperation. (Source: Defense News)

——————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

May 22, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

———————————————————————————————————————————————————————————————————————————————————————————————————————————————

22 May 25. Terma announced the launch of Terma SPECTRA, a Software-Defined Radio (SDR) TT&C modem. Developed in collaboration with the European Space Agency (ESA) and built by experts in Electrical Ground Support Equipment (EGSE) and Radio Frequency Special Check-Out Equipment (RF-SCOE), Terma SPECTRA reflects years of hands-on experience, protocol mastery and innovation in real-world space missions.  Terma announces the launch of Terma SPECTRA (Software-defined Platform for Enhanced Communication, Telemetry, and Ranging Applications) — a new SDR TT&C modem, a flexible, scalable solution for satellite communication and testing. Powered by SDR technology, the modem combines flexible and cloud-ready architecture, multi-channel support for TX & RX, built-in security by design and native L- and S-Band support to deliver a compact and cost-effective solution for reducing CAPEX and OPEX. Designed to serve ground stations and testing facilities, the modem supports operations from satellite modem verification to satellite communications, EGSE/SCOE integration, system-level and end-to-end testing. Its versatility makes it a strong backbone for both operational and testing environments. Built by experts with deep domain knowledge in satellite EGSE and RF-SCOE – and developed in collaboration with ESA – Terma SPECTRA reflects years of hands-on experience, protocol expertise, and innovation in real-world space missions. Its modular design ensures users benefit from easy upgrade paths, keeping the software ready for future mission needs while being cost effective. Among its standout capabilities are CCSDS-compliant TM/TC processing, multi-channel support for transmission and reception, and a compact, cost-effective footprint. An intuitive and multi-functional user interface ensures it is easy to use, while a secure and fail-safe design gives you the security and reliability that you need.

“Terma SPECTRA is a game-changer in communication, offering unparalleled flexibility with its distributed architecture, parallel processing capabilities, and cloud-readiness. By supporting industry standards and enabling scalable, multi-mission operations, it provides customers with the reliability, flexibility, and efficiency needed to tackle the most demanding environments,” says Günther F. Lackner, Senior Vice President at Terma Space.

With its future-proof architecture, Terma SPECTRA overcomes the limitations of traditional hardware-based RF systems, empowering ground stations to operate more efficiently and respond more rapidly to evolving mission requirements.

 

21 May 25.  Global: Ransomware attacks will sustain elevated security risks for businesses in medium term. Earlier on 21 May, international news outlets reported that the threat group ‘Scattered Spider’ targeted the financial sector via ransomware attacks before April. This preceded three consecutive cyber attacks against high-profile UK retailers (Marks & Spencer, The Co-operative Group and Harrods) between April and early May, highlighting the group’s wide target pool. These attacks resulted in the exfiltration of customer data and significant operational disruption, as well as long-term reputational and financial damage for the targeted retailers. On 14 May, the technology company Google also warned that Scattered Spider had started to target retailers in the US, underscoring the rapid propagation of its operations. The group reportedly often switches targeted sectors depending on the skillset of its current members; we assess this will sustain elevated security risks for global businesses in the medium term given the momentum and rapidity of Scattered Spider’s recent attacks. (Source: Sibylline)

 

21 May 25. Nokia 5G tech supports defence ops at Joint Viking 2025. During the trials, capabilities of the 5G technology helped improve situational awareness and collaboration. Finnish telecommunications company Nokia has conducted trials of its 5G technology within the context of Joint Viking 2025 military exercise in northern Norway. The test was carried out in collaboration with various industry entities and aimed at demonstrating the role of 5G in a defence setting. During the trial, Nokia deployed its 5G AirScale radio products and 5G Standalone Core technology, which had been tailored for defence applications. These tools were used to support tactical communication and improve information systems across the multinational force. Nokia’s 5G communications platform enabled military units to access real-time battlefield data. This capability supported quicker decision-making and bolstered situational awareness. The command-and-control leadership of Joint Viking used the technology to coordinate operations more effectively, enhancing both safety and operational efficiency. Norway’s Ministry of Defense liaison for 5G COMPAD programme and radio architect Kennet Nomeland said: “We collaborate with the industry to develop innovative defence solutions based on commercial technologies. (Source: army-technology.com)

 

21 May 25. Rubrik (NYSE: RBRK), a leading cyber resilience company, and Rackspace Technology (NASDAQ: RXT), a leading end-to-end hybrid cloud and AI solutions company, have announced Rackspace Cyber Recovery Service – a new managed service for customers operating in public cloud. By combining Rubrik’s orchestrated data protection and cyber recovery solutions with Rackspace’s DevOps principles and managed services, enterprises can simplify and accelerate recovery from ransomware attacks. Automated workflows deliver clean data and workloads through immutable backups, zero-trust architecture and Infrastructure as Code. With Rackspace Cyber Recovery Service, critical business workloads running in public clouds can be restored in hours, helping enterprises significantly strengthen their cyber resilience.

Why does this matter?

Organizations running key workloads in public clouds face growing challenges when responding to cyber attacks – from limited visibility and inconsistent backup policies to slow recovery times and lack of automation to rebuild at scale. At the same time, IT leaders are grappling with increasingly complex and distributed cloud environments, making it difficult to maintain consistency, ensure visibility and execute reliable recovery. Recently, Rubrik Zero Labs revealed that 90% of global IT and security executives reported cyber attacks in the last year. In the event of major disruptions – such as ransomware attacks – many enterprises struggle to restore critical workloads quickly due to fragmented tooling, manual processes, untrusted data and inadequate automation.

“Enterprises can no longer rely on traditional recovery methods in a cloud-first, threat-intensified world,” said DK Sinha, President for Public Cloud at Rackspace Technology. “To ensure recoverability in the public cloud, they must adopt a new approach that leverages cloud native tools, modern DevOps methodologies and trusted expertise. Through our partnership with Rubrik, Rackspace Cyber Recovery Service sets a new standard for cyber resilience of public cloud workloads.”

Rackspace Cyber Recovery Service Extends Fast and Confident Cyber Resilience to Public Cloud

Rackspace Cyber Recovery Service applies Infrastructure as Code and platform engineering principles to cyber recovery, enabling restoration of critical workloads across multi-cloud environments. The journey begins with a professional services-led transformation, where Rackspace experts modernize recovery architectures and codify resilient workflows tailored to each environment. These capabilities are then transitioned into a ‘Day 2’ fully managed service, ensuring continuous validation, optimization and operational readiness. By orchestrating Recovery as Code, the solution delivers rapid, repeatable and auditable workflows aligned with modern DevOps practices. Paired with Rubrik’s immutable architecture and AI-driven threat detection and containment, it ensures clean data recovery into secure landing zones with minimal operational disruption.

“Amidst the evolving complexities of multiple cloud environments, proactive cyber resilience is not a luxury but a necessity. Together, Rackspace and Rubrik offer a differentiated, engineering-led approach to cyber resilience,” said Ghazal Asif, Vice President of Global Channels and Alliances at Rubrik. “Specifically designed for complex, distributed cloud environments, our companies are at the forefront of safeguarding organizations against the rising tide of ransomware attacks in the realm of cloud and SaaS platforms.”

Rackspace Cyber Recovery Service provides enterprises running public cloud workloads with:

  • Proactive Protection: Continuous anomaly detection and threat monitoring to identify and resolve potential issues before they impact backups or recovery capabilities
  • Expert Management: Optimal backup configuration, policy and lifecycle management
  • Cloud Management: Infrastructure management services to ensure your applications are managed efficiently in the cloud while infrastructure and data restoration procedures are tested for recovery during incidents or disasters
  • Improved Compliance: The ability to support data retention policies and regulatory requirements with consistent management and detailed reporting
  • Advisory & Professional Services: Strategic guidance and implementation of Rubrik-powered cyber recovery solutions – including RTO/RPO planning, regulatory alignment and deployment of automated Infrastructure as Code workflows into secure landing zones

About Rackspace Technology

Rackspace Technology is a leading end-to-end, hybrid, and AI solutions company. We can design, build, and operate our customers’ cloud environments across all major technology platforms, irrespective of technology stack or deployment model. We partner with our customers at every stage of their cloud journey, enabling them to modernize applications, build new products, and adopt innovative technologies.

About Rubrik

Rubrik (NYSE: RBRK) is on a mission to secure the world’s data. With Zero Trust Data Security™, we help organizations achieve business resilience against cyberattacks, malicious insiders, and operational disruptions. Rubrik Security Cloud, powered by machine learning, secures data across enterprise, cloud, and SaaS applications. We help organizations uphold data integrity, deliver data availability that withstands adverse conditions, continuously monitor data risks and threats, and restore businesses with their data when infrastructure is attacked.

 

21 May 25. Roke, a UK company that stands at the forefront of defence and security, and Kaigai Corporation have announced an expansion of their strategic partnership, significantly increasing the availability of Roke’s cutting-edge products and services to the Japanese market.  Building on a successful foundation of cooperation, the expanded agreement will see a broader portfolio of Roke’s advanced solutions—including Electromagnetic Warfare (EW) systems, Resilient Position Navigation and Timing (RPNT), Cyber, AI-enabled surveillance technologies, and secure communications platforms—offered through the Japanese defence contractor’s extensive defence and security network in the country. The new enhanced partnership reinforces both companies’ commitment to advancing national security and technological innovation in the region.

Paul MacGregor, MD of Roke, said: “Japan represents a key strategic market for Roke, and this partnership allows us to deliver greater value to Japanese defence and security stakeholders through localised support and expanded access to our technologies. This announcement comes at a time of increasing demand for advanced defence technologies in the Asia-Pacific region, and underscores both companies’ dedication to supporting the evolving needs of allied nations. This partnership marks a pivotal step in our mission to bring world-class defence technologies to Japan,” said Masayoshi Yamazaki, President of Kaigai Corporation. “Roke’s proven expertise and innovative capabilities align perfectly with our vision for a safer, more secure future.”

The expanded partnership will also include knowledge exchange programs and enhanced technical support to ensure seamless integration of Roke’s solutions into Japan’s defence infrastructure.

 

20 May 25. Global: State-sponsored cyber attacks showcase long-term security risks amid global tensions. On 19 May, the software company ESET reported that threat groups aligned with China, Iran, North Korea and Russia continued to consistently use cyber operations to achieve their strategic objectives between October 2024 and March. China-nexus groups focused on cyber espionage operations primarily against the governmental and transportation sectors in Europe. These groups often exploited third-party virtual private network (VPN) services to infiltrate targeted systems, underscoring the security risks associated with the software supply chain. Groups aligned with North Korea honed in on financially motivated cyber operations against the financial services and cryptocurrency sectors. These groups aimed to combat ongoing economic sanctions and bolster Pyongyang’s weapons programme. Iran- and Russia-nexus groups continued to target Israeli and Ukrainian organisations amid ongoing regional wars; Russia is notably shifting towards a more methodical and less destructive cyber strategy against Ukraine. As such, we assess that this report indicates sustained security risks to perceived adversarial entities amid ongoing geopolitical tensions.   (Source: Sibylline)

 

20 May 25. Quadsat, expert in UAV-based RF testing and measurement, has entered a strategic collaboration with Skyeton, a Ukrainian manufacturer of unmanned aerial systems (UAS) to deliver solutions for monitoring the electromagnetic spectrum. Together the companies are supporting electromagnetic warfare operations, enhancing situational awareness, and strengthening threat response in contested electromagnetic environments. The partnership combines Skyeton’s fixed-wing UAS platform, Raybird, known for its battlefield-proven performance in Ukraine, with Quadsat’s industry-validated radio frequency (RF) payload and spectrum monitoring technology. Raybird has proven an unmatched endurance and exceptional resilience, making it a natural choice for gathering battlefield intelligence. Quadsat’s test and measurement solutions are relied upon by many of the world’s leading satellite companies to ensure a high level of equipment performance. The joint solution offers a highly effective, scalable, and tactically agile solution for acquiring real-time electromagnetic spectrum intelligence. It expands Skyeton’s portfolio of mission-ready systems with advanced capabilities for spectrum monitoring and RF emitter detection in complex operational environments.

Klaus Aude, Chief Commercial Officer, Quadsat, commented: “By combining our robust RF payload with Skyeton’s battle-proven UAS, we are able to bring a powerful new solution to the electromagnetic warfare space. The fact that Raybird has exceptional endurance, with up to 28 hours of flight time, while being easy and rapid to deploy, makes it especially practical for defense applications. Quadsat’s technology is platform-agnostic, and our integration with fixed-wing systems is a clear demonstration of that.”

Pavlo Shevchuk, International CEO of Skyeton: “This partnership marks a significant step forward in expanding the capabilities of our Raybird UAS. By integrating Quadsat’s cutting-edge RF technology, we are equipping our platform with an advanced spectrum monitoring tool that is essential for modern operational environments. It’s a natural evolution of our mission to deliver high-endurance, mission-ready systems that provide actionable intelligence when and where it matters most”.

Quadsat and Skyeton will co-exhibit and perform a joint demonstration flight at the International Drone Show 2025 in Denmark from 18th–19th June. The demo will feature Skyeton’s Raybird UAS carrying Quadsat’s RF payload, showcasing real-time spectrum monitoring and RF target detection capabilities.

 

19 May 25. Global: New malware underscores elevated security risks posed by ransomware groups. On 16 May, international news outlets reported that ransomware groups are deploying a new backdoor (‘Skitnet’) during attacks on an increased basis to conduct post-exploitation activities. Threat actors typically use a first-stage malware loader to execute Skitnet within a compromised system’s memory, leveraging several highly obfuscated techniques to evade traditional security measures. The malware then connects to command-and-control (C2) infrastructure, initiating three separate channels of communication to facilitate command execution, data exfiltration and monitoring activities. Skitnet can execute PowerShell scripts for enhanced attack customisation, allowing it to download remote access tools and perform persistence tasks. This likely enables threat actors to retain prolonged control over compromised systems, pointing to the longevity of infections. The malware can be purchased online, allowing threat actors to quickly upscale and streamline cyber operations. Skitnet has already been used in ransomware attacks by well-known groups (such as ‘BlackBasta’ and ‘Cactus’), highlighting the elevated security risks associated with the continuous evolution of ransomware enterprises. (Source: Sibylline)

 

18 May 25. Royal Air Force introduces StormShroud with Leonardo’s BriteStorm electronic warfare payload. The Royal Air Force (RAF) has unveiled its new ‘StormShroud’ autonomous collaborative platforms (ACPs), equipped with BriteStorm, Leonardo’s latest electronic warfare payload. This cutting-edge system aims to confuse and suppress enemy radars during air combat missions, offering a strategic advantage against advanced air defence systems. BriteStorm, described as a ‘stand-in jammer’, is designed to operate ahead of high-value crewed combat aircraft, using small uncrewed aircraft or missiles. It disrupts enemy Integrated Air Defence Systems (IADS) by employing high-powered digital jamming and deception techniques, maximising operational freedom for friendly forces.

“BriteStorm counters the threats of today and tomorrow,” said a Leonardo spokesperson. The payload’s adaptability is enhanced by its open software approach, allowing operators to configure it against a wide range of evolving threats, using intelligence gathered during missions.

The system consists of a Miniature Techniques Generator (MTG) and Transmit Receive Modules (TRMs), which are lightweight and energy-efficient. This makes BriteStorm adaptable to various uncrewed aircraft, including the Tekever AR3 small Uncrewed Air Systems (UAS), which will enter RAF service under the StormShroud name. BriteStorm’s design reflects lessons learned from recent operations, emphasising its attritable nature. While it can be rapidly reprogrammed and redeployed after a mission, the system’s loss in defence of higher-value platforms would be considered acceptable. Research and development of BriteStorm began in 2017 at Leonardo’s Luton site, Europe’s leading hub for electronic warfare technology. The facility, employing over 1,200 people, invested nearly £175 m with British suppliers in 2024, contributing significantly to the UK’s defence industrial combat air enterprise. StormShroud itself has been developed by the Royal Air Force Rapid Capabilities Office (RCO) and the Catalyst team in Defence Equipment & Support (DE&S). It will be operated by both regular and reserve personnel from 216 Squadron, with ongoing support from Leonardo and other industry partners. (Source: DIE)

 

16 May 25. Cyber Update Key points.

  • A new information-stealing malware (‘Noodlophile’) abuses generative artificial intelligence (AI) tools, elevating information-theft and financial risks to global users (see Sibylline Cyber Daily Analytical Update – 12 May 2025).
  • A multi-stage cyber operation highlights long-term security risks posed by the China-nexus group ‘Earth Ammit’ towards high-value targets in Taiwan and South Korea (see Sibylline Cyber Daily Analytical Update – 13 May 2025).
  • Multiple cyber operations against Ukrainian government entities underscore elevated cyber espionage risks from the North Korean state-sponsored group ‘Konni’.
  • A new, highly advanced information-stealing malware (‘Chihuahua’) highlights heightened data-theft and financial risks to global users.
  • A suspected Russian state-sponsored cyber operation (‘RoundPress’) highlights long-term cyber espionage risks exacerbated by the exploitation of software vulnerabilities

A new, highly advanced information-stealing malware (Chihuahua) is being used to target global users in an ongoing data-theft operation. Threat actors likely use social engineering techniques to trick victims into opening a Google Drive document. The document reportedly contains a PowerShell script that initiates a highly obfuscated, multi-stage infection process. Namely, the script installs a malware loader that deploys the Chihuahua payload into a system’s memory, after establishing communication with command-and-control (C2) infrastructure. The payload is hidden within a PowerShell string (a sequence of characters) and is dynamically decoded and re-constructed to evade signature-based detection, highlighting the sophistication of Chihuahua’s obfuscation capabilities. Chihuahua then gathers system information, assigning encrypted victim identifiers to each system to facilitate data exfiltration and storage. The malware extracts sensitive data from web browsers (including autofill data, browsing history, cookies, credentials and payment information) as well as cryptocurrency wallets, likely to hijack user accounts for financial profit. Chihuahua then uses file and directory deletion commands to erase logs and evade detection.

Threat actors exploited several zero-day and pre-existing cross-site scripting (XSS) vulnerabilities (affecting several high-profile email providers) to conduct a cyber espionage operation (RoundPress) between 2023 and 2024. RoundPress targeted government entities, defence companies and national infrastructure across Africa, Eastern Europe and Latin America and was likely carried out by the Russian state-sponsored group ‘APT28’. Threat actors used spear-phishing emails concerning current political events as initial attack vectors to trick victims into opening the email in a web browser. The emails then exploited the vulnerabilities to execute malicious code hidden within the email body without requiring any additional user interaction. This then established communication with C2 infrastructure and installed a JavaScript payload (‘SpyPress’) to exfiltrate sensitive information, including authentication data, credentials and login history. The operation did not display any sophisticated persistence mechanism, though the malicious code is re-loaded every time victims open the phishing email. Threat actors exploited both newly identified and old vulnerabilities, highlighting the importance of timely patch management policies to prevent exploitation.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

Our cyber word(s) of the week: Cross-site scripting (XSS) (Source: Sibylline)

 

16 May 25. Global: Exploitation of vulnerabilities highlights long-term espionage risks facing critical sectors. On 15 May, the cyber security company ESET reported that threat actors exploited cross-site scripting (XSS) vulnerabilities (affecting high-profile email providers) to conduct a cyber espionage operation (‘RoundPress’) between 2023 and 2024. The operation targeted government entities, defence companies and national infrastructure across Africa, Eastern Europe and Latin America; it was likely carried out by the Russian state-sponsored group ‘APT28’. Threat actors distributed spear phishing emails to victims so that they could infiltrate targeted systems. When the victims opened the emails, software vulnerabilities were exploited so as to execute malicious code (hidden within the email body); this did not require any additional user interaction. Communication was consequently established with command-and-control (C2) infrastructure, automating the exfiltration of sensitive information. Software vulnerabilities continue to provide state-sponsored groups with an effective access and remote execution vector into high-value sectors; as such, we assess this highlights the long-term cyber espionage risks stemming from Russian state-sponsored actors facing the aforementioned sectors. (Source: Sibylline)

 

16 May 25.  DOD Leaders Urge Congress to Bolster Cyberdefenses. Defense Department leaders delivered a stark warning about adversaries exploiting cyberspace and threatening national security during a House Armed Services Committee cyber, information technologies and innovation subcommittee hearing in Washington today. Laurie Buckhout, performing the duties of assistant secretary of defense for cyber policy, and Army Lt. Gen. William Hartman, acting commander of U.S. Cyber Command, called for heightened strategic focus, cutting-edge innovation and a world-class workforce to counter sophisticated cyberthreats.

“Adversaries transform cyberspace — a domain powering global connectivity, communications and innovation — into a contested battlespace,” Buckhout said.

With over 40 years of experience in communications, intelligence and cyberoperations, Buckhout spotlighted the alarming rise of Chinese state-sponsored actors like Volt Typhoon. She said the group infiltrates critical infrastructure, including power grids, water systems and telecommunications networks, using stealthy “living off the land” tactics that exploit legitimate tools to evade detection.

“Volt Typhoon’s actions expose the urgent need for relentless vigilance and advanced countermeasures,” she said, citing its potential to disrupt essential services or enable espionage.

Her warning aligns with a 2024 Cybersecurity and Infrastructure Security Agency advisory, which revealed Volt Typhoon’s deep penetration of infrastructure sectors, posing a “significant risk” to national security.

Buckhout also flagged Russia’s integration of cyberoperations with geopolitical aims, Iran’s persistent malicious activities and North Korea’s ransomware campaigns. She noted that transnational criminal organizations further increase the threat, targeting infrastructure with profit-driven cyberattacks.

Defense Secretary Pete Hegseth’s vision for cyberdominance underpins Buckhout’s call to action.

“We’re pushing real-time inclusion of cyber — offense and defense — into planning cycles to leverage it fully,” he said during an address at the U.S. Naval Academy in April. “In a world where cyber and space dominance will determine future battlefields, if we do it right … it should be our comparative advantage.”

His directive drives the department’s push to align resources with the most lethal and effective capabilities, prioritizing homeland defense against near-peer competitors like China.

Cybercom’s Daily Battle

Hartman painted a vivid picture of Cybercom’s relentless engagement.

“We fight cyberwarfare every day, defending the nation, securing DOD networks and empowering the joint force,” he said.

In 2024, Cybercom executed over 6,000 operations — a 25% surge from 2023 — targeting malicious actors worldwide. “Our operations grow in scale, speed and complexity,” he told lawmakers, projecting even greater activity this year.

Hartman highlighted the command’s collaboration with the National Security Agency to optimize resources and technical expertise. He cited a congressionally mandated artificial intelligence roadmap, which fuels pilot programs to enhance operational efficiency.

“AI transforms how we analyze threats and deploy capabilities,” Hartman said, aligning with President Donald J. Trump’s emphasis on AI as a cornerstone of cybersecurity superiority.

Refining Cybercom 2.0

Buckhout addressed the ongoing evolution of Cybercom 2.0, an initiative inherited from the prior administration to streamline workforce management, training and innovation.

“We value Cybercom 2.0’s foundation but recognize its shortcomings,” she said. The current administration is conducting a comprehensive review to align the program with evolving threats.

“We view cyberspace as mission-critical and we’re committed to delivering a refined strategy,” Buckhout told the committee.

After lawmakers pressed for clarity on Cybercom 2.0’s future structure, Hartman revealed that Cybercom favors a model similar to U.S. Special Operations Command, where a unified command oversees training and force development while geographic combatant commanders retain operational control.

“This model balances efficiency with flexibility,” Hartman explained.

Workforce Challenges in a Competitive Landscape

Hartman said building a world-class cyber workforce remains a top priority, but intense competition with the private sector complicates recruitment and retention. He added that strong retention in specialized roles — interactive on-net operators, exploitation analysts and coders — is driven by the unique allure of national security missions.

“We offer opportunities no tech company can match,” he said. However, Cybercom is struggling to attract broader talent, such as linguists, intelligence analysts and planners essential for comprehensive cyberoperations.

Hartman said the current hiring freeze and workforce reductions threaten to increase these challenges, noting that 5 to 8% of the command’s workforce accepted voluntary separation offers.

“Our junior leaders will step up, but the loss is significant,” he said.

Mental health support for cyberoperators facing chronic stressors emerged as a concern during the hearing. Lawmakers cited a congressional report targeting inadequate mental health resources for cyberpersonnel.

Hartman explained that Cybercom hired its first psychologist in 2025 and is actively seeking additional specialists to combat the issue. (Source: U.S. DoD)

 

15 May 25. US Army may halve planned HADES buy from 12 to 6 new spy planes.

“This is very early in the process. My guidance, to my staff, is nobody really overreact to this global transformation. We must transform,” said ISR Task Force Director Andrew Evans.

AAAA 2025 — The US Army will potentially pare its fleet of High Accuracy Detection and Exploitation System (HADES) aircraft in half as part of a larger acquisition shakeup, according to an EXORD obtained by Breaking Defense and confirmed by service officials.

Earlier this month, the service began releasing details about force structure changes and weapons cuts as part of its Army’s Transformation Initiative (ATI), and an executive order from Army leadership dated May 7 details additional cuts, including cutting the HADES fleet from 12 aircraft down to six.

“This is very early in the process,” ISR Task Force Director Andrew Evans told reporters today. “My guidance, to my staff, is nobody really overreact to this global transformation. We must transform … and we’re all in on supporting the Army’s effort to do this.”

Col. Joe Minor, the project manager for fixed-wing aircraft, said that since the plan was always to produce a small number of HADES that are essentially “hand-built,” he does not expect the overall cost of the program to soar if the buy is halved.

Last year, the Sierra Nevada Corporation (SNC) won an Army contract to integrate a suite of capabilities onto the Bombardier Global 6500 jet under the HADES program. The service wants to have an initial aircraft ready for the force by the end of 2026 or early 2027 and had planned to acquire more than a dozen aircraft under a one-per-year buy, depending on budgets and the threat analysis.

Then on Wednesday, at the Army Aviation Association of America’s annual conference in Nashville, Tenn., Laurence Mixon — with the Program Executive Office for Intelligence, Electronic Warfare and Sensors — told reporters that there would likely be several changes to his team’s portfolio while Evans hinted at today’s HADES announcement.

“There’s nothing … that we can say specifically on a specific program that’s going away or changing,” Mixon told reporters. “But I will tell you, there is no longer an appetite to reinforce failure.”

The key question for HADES, Evans added, will be how many systems the service ultimately acquires.

“It will not be whether we require it at all … until warfighters cease their demand for ISR,” Evans said.  (Source: Breaking Defense.com)

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

——————————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

May 9, 2025 by

Sponsored By Curtiss Wright

 

https://www.curtisswright.com/

 

———————————————————————————————————————————————————————————————————————————————————————————————————————————————-

06 May 25. EPW Project advances to Phase II. The EPW project aims to deliver secure and interoperable systems aligned with broader European strategic goals. Belgium-based ST Engineering iDirect Europe confirmed that the European Protected Waveform (EPW) project has progressed into its second phase, a step forward in improving secure and independent satellite communications capabilities within Europe. The advancement is crucial for military operations and government needs, given the increasing complexity of operational environments. This development, overseen by the Ministry of Defence of Belgium, is spearheaded by ST Engineering iDirect Europe as the head of the consortium. The project brings together a consortium of 22 organisations from 12 EU Member States comprising experts from industry, government and academia. The consortium’s objective is to create a robust, end-to-end waveform solution that will bolster resilient and secure communications. Following the groundwork laid in Phase I, which established the development framework, the EU-funded Phase II will focus on the prototyping and integration of the EPW system. The objective is to deliver secure and interoperable systems aligned with broader European strategic goals, including the future Interface Region Imaging Spectrograph (IRIS) satellite constellation and the EU GovSatCom programme.

ST Engineering iDirect Europe EU Programmes vice-president Koen Willems said: “The advancement to EPW Phase II underscores the strategic importance of this initiative to bolster European autonomy in secure satellite communications. This recognition by the European Defence Fund demonstrates the urgent necessity to address emerging threats and foster resilience for critical operations across Europe.”

The overall investment in the EPW project has reached €65m, with €35m ($39.7m) allocated to Phase II, building on the €30m invested in Phase I.

Belgian Minister of Defence Theo Francken said: “Together with ST Engineering iDirect Europe, we are investing in the backbone of modern military operations: secure and reliable communication. With support from the European Defence Fund, we are advancing technological innovation, strengthening strategic autonomy, and enhancing the safety of our troops. In today’s uncertain world, European cooperation in research and development is not a luxury — it’s an absolute necessity. This project aligns perfectly with our broader mission to modernise Defence and deepen European collaboration in R&D.”

The project consortium includes Airbus D&S, Amphinicy, Antwerp Space, Belgian Royal Military Academy, CTG Celestia, Elital, Eutelsat, GISS, Indra, Lasting, Leonardo, LuxGovSat, NeoSat, NLR, OHB, Quadsat, ST Engineering iDirect Europe, Telespazio, Thales Alenia Space and Thales Six. (Source: army-technology.com)

 

08 May 25. Out With a Bang. Yevgeny Rytikov is no more. He was blown to bits by a car bomb on the night of 18th April in the city of Bryansk, southwest of Moscow. Mr. Rytikov and a colleague were getting into their vehicle when it exploded, according to media reports. You may not have heard of Mr. Rytikov, but Ukraine certainly had. He was the head of the Bryansk Electromechanical Plant, and an engineer by training. Mr. Rytikov’s factory builds the 1L269 Krasukha-2 and IRL257 Krasukha-4 vehicle-mounted Electronic Warfare (EW) platforms. Both these systems are used at the operational level by dedicated Russian electronic warfare brigades. Their targets include airborne early warning, fire control and weapons guidance radars. Several Krasukha systems have been deployed to Ukraine since the first Russian invasion of 2014. As one can imagine, Mr. Rytikov would have been a prominent target for Ukrainian operatives plying their trade behind enemy lines, although at this point, no-one seems to have admitted responsibility for his slaying. The ongoing war in Ukraine has underscored that industrialists on both sides are increasingly becoming targets. In July 2024 it was reported that the boss of Rheinmetall, Armin Papperger, had been targeted for assassination by Russian spooks as part of a plot foiled by German and US intelligence. Mr. Papperger was one of several defence industrialists across Europe Moscow had planned to kill. What is interesting about the successful attack on Mr. Rytikov was that it underscored the centrality of the electromagnetic spectrum to the ongoing war in Ukraine. Those building sophisticated electronic warfare systems are considered fair game given the havoc they can wreak on the battlefield. The knowledge equipping individuals like Mr. Papperger means their acumen would be integral to future EW system design. Such losses are not easy to replace, and more such targeting can be expected. (Source: Armada)

 

08 May 25. Safe Space?

US Space Force personnel conduct a test of the Remote Modular Terminal which is believed to be a deployable system which can be used for satellite communications jamming. Russia and the United States, among other nations, are continuing to plough investment into offensive counterspace electronic warfare capabilities, according to a new report. Armada always looks forward to the release of the Secure World Foundation’s (SWF) Global Counterspace Capabilities report. The publication shines much needed light onto counterspace capabilities, particularly in the Electronic Warfare (EW) domain, around the world.  The SWF “envisions the secure, sustainable and peaceful uses of outer space contributing to global stability and benefits on Earth” says the organisation. The Global Counterspace Capabilities report is written by Victoria Samson, the SWF’s chief director for space security and stability; and Dr. Laetitia Cesari, a legal practitioner and researcher working on the law and policy of outer space. As per 2024’s publication, the 2025 report examines the counterspace EW postures of several nations in the Asia-Pacific, Europe, the Middle East and North America. Writ large, the report says that Israel, the People’s Republic of China, Russia and the United States all maintain significant counterspace EW capabilities. Australia, the Democratic People’s Republic of Korea (DPRK), India, France and the Islamic Republic of Iran are all identified as investing in such capabilities. Israel, Russia and the US are performing counterspace EW research, development and testing. They have all deployed such systems operationally and used them in combat. The PRC has a similar status, although has not deployed counterspace EW systems en masse in anger. India has not yet deployed any counterspace EW system or used any in conflict, although capabilities are believed to be in development. Likewise, Australia and the ROK are thought to be performing counterspace EW research and development. The situation in France regarding counterspace EW remains opaque, much as it does in Iran. The Islamic Republic may have performed some operational deployment and used counterspace EW systems in conflict. Finally, the DPRK is thought to be continuing counterspace EW research, development and testing efforts.

United States

US space EW capabilities are underpinned by the L3Harris Counterspace Communications System (CCS). The CCS can attack Satellite Communications (SATCOM) receivers. As of 2024, the CCS has been joined by the Remote Modular Terminal which is also intended to jam SATCOM terminals. Both the RMT and CCS are deployed by the United States Space Force. More details regarding the RMT’s capabilities can be found in this article. One key discriminator vis-à-vis the CCS and RMT is that the former may be deployed statically to jam SATCOM, while the latter can deploy dynamically in support of the land manoeuvre force, for example.

Russia

One interesting revelation in the report concerning Russian counterspace electronic warfare capabilities is that the country maybe working on a system called Kalinka. Kalinka is said to detect and geolocate SATCOM terminals using SpaceX’s Starlink SATCOM system. Starlink provides Ku-band (14 gigahertz/GHz uplink/10.9GHz to 12.75GHz downlink) and Ka-band (26.5 gigahertz/GHz to 40GHz uplink/18GHz to 20GHz downlink) channels. Starlink terminals have been deployed extensively to Ukraine. Armada understands that Russian ground-based EW systems have struggled to attack Starlink Ka-band signals. This shortcoming has been due to a lack of systems capable of engaging these frequencies. Russian cyberwarfare was successful in hacking Starlink terminals in the aftermath of Russia’s second invasion of Ukraine in February 2022. It seems that Kalinka is used to detect and locate Ka-band/Ku-band signals transmitted by a Starlink terminal. Once the location of these terminals is determined, these coordinates could be exploited for kinetic attack.

Asia-Pacific and Europe

No new details regarding Chinese counterspace EW capabilities appear to have come to light in the 2025 SWF report. Nonetheless, the publication disclosed that India is developing the Himshakti electronic attack system, two of which will be deployed with the Indian Army, to engage SATCOM signals. Development of Himshakti is believed to have commenced in November 2023. Australia, meanwhile, is continuing with her acquisition of CCS systems from the United States. As per the SWF’s 2024 report, the DPRK is believed to be continuing to attack Global Navigation Satellite Signal (GNSS) Position, Navigation and Timing (PNT) signals. The ROK noted incidents of PNT jamming originating from the southwest DRPK, north of the Demilitarised Zone. The zone is the de facto border separating the two countries. The jamming reportedly affected civilian GNSS receivers on aircraft and ships in the vicinity of the offending signals. Tantalisingly, the report noted that the ROK Air Force is working on offensive counterspace EW capabilities. Few details have emerged in the public domain as to the exact nature of this work. Details on French counterspace EW efforts likewise are all but non-existent in the public domain. Nonetheless, the report noted that the chief of the Armée de l’Air (French Air Force), General Jérôme Bellanger, said in October 2024 that the force is examining offensive space EW.

Middle East

The SWF’s 2025 report stated that the Islamic Republic of Iran had opened a new electronic warfare centre, operated by the Iranian Army, known as Jangaal in the east of the country. The extent to which this facility concentrates on space EW remains unknown. Elsewhere in the Middle East, the report detailed examples of GNSS PNT jamming believed to originate from Israel. Reports have noted an uptick in incidences of GNSS PNT engagement since the Hamas attacks against targets in southern Israel on 7th October 2023. GNSS jamming is believed to be performed to prevent hostile uninhabited aerial vehicles using PNT signals to guide towards their targets in Israel.

Outlook

The SWF’s annual Global Counterspace Capabilities reports have emerged as the publication of record detailing national efforts around the world to contest the cosmos. Electronic warfare, for several nations, is a key capability in this regard. The successive reports are a welcome resource illustrating how these capabilities are building up over time around the world. Expect to see similar trends in next year’s publication. (Source: Armada)

 

07 May 25. CESMO Mooted for Border Security Role. Poland is strengthening her border with Belarus. The move follows deteriorating relations between the European Union and NATO on one side, and Russia and Belarus on the other. NATO’s CESMO electronic intelligence processing capability could form part of this overall border security enhancement. NATO’s Cooperative Electronic Support Measure Operations electronic intelligence processing protocol could be used to enhance border security. Poland is enhancing her border security as tensions between the North Atlantic Treaty Organisation (NATO), European Union (EU) and Russia continue to increase. Poland shares a border with Russia’s Kaliningrad exclave in the north and with Russian client state Belarus towards the east. Warsaw is performing a major enhancement of Poland’s 418-kilometre/km (260-mile) border with Belarus. In 2021, the government of Belarus forced thousands of refugees across that border, resulting in 20 fatalities. Minsk attempted to exploit the refugees to prompt a political crisis in Poland, Lithuania and Latvia. The move followed a sharp decline in relations between Belarus and the EU in 2020. That year, Belarus’ President Alexander Lukashenko was re-elected via a poll condemned by international organisations, including the EU, as unfair and undemocratic. Poland’s enhancement of her border security will help defend the border against such actions in the future. It will also help protect the country in the event of a future joint Russian-Belarussian land invasion.

CESMO

Sources close to the modernisation initiative have revealed that the CESMO (Cooperative Electronic Support Measure) Electronic Intelligence (ELINT) protocol is being considered as part of this enhancement. CESMO helps aircraft share hostile emitter location information so the latter can be avoided or engaged. The SEWWG (NATO Signals Intelligence and Electronic Warfare Working Group) is CESMO’s custodian. Military aircraft are routinely equipped with Radar Warning Receivers (RWRs) and Electronic Support Measures (ESMs). ESMs and RWRs protect aircraft by detecting, identifying and locating hostile ground-based air surveillance and fire control/ground-controlled interception radars. An RWR tends to give aircrew a relatively simple warning with details of a radar’s bearing relative to the aircraft. An ESM supplies more detailed information on the radar’s identity and location. The electronic support measure will also furnish specifics on the waveforms the radar is using although RWR and ESM functions can overlap.

RWRs and ESMs can use two mechanisms to detect and locate red force radars, chiefly Angle-Of-Arrival (AOA) and Time Difference of Arrival (TDOA). AOA determines the Line-of-Bearing (LOB) from one point to another, in this case between an aircraft and a hostile radar. Consider three aircraft flying in the vicinity of a ground-based air surveillance radar. One aircraft is flying towards the radar on a north-south bearing, the second is flying on an east-west radial away from it and the third is flying on a south-north bearing towards it. Each plane is equipped with an RWR which determines the radar’s line-of-bearing relative to the aircraft. All three planes detect the same radar transmission. The RWR on the first aircraft determines a southern LOB to the radar. The RWR on the second determines a westerly LOB while the third aircraft’s RWR determines a northerly line-of-bearing. By using this information, the radar’s position is determined as the point where all three bearings cross.

TDOA works slightly differently. We will stick with our three aircraft, all of which are continuing to fly the same courses in the vicinity of the hostile radar. One aircraft is 100 nautical miles/nm (185.2km) from the radar flying on north-south bearing. The second is 150nm (277.8km) from the radar flying away on an east-west radial. The third is 50nm (92.6km) away flying on a south-north bearing. Triangulation relies on the fact that radar transmissions move at light speed (161,595 nautical miles-per-second/299,274 kilometres-per-second). Radar transmissions will take different times to reach each aircraft’s RWR. For the first plane it will take the transmissions 0.6 milliseconds to get there. For the second it will take 0.9 milliseconds and for the third 0.1 milliseconds. Calculating the time difference taken by the radar transmissions to reach each aircraft relative to their position computes the radar’s location. This data is fused with the aircraft’s position as derived from its navigation equipment and sent from each aircraft via their standard communications links. The data reaches a central computer housing the CESMO software. Once the data arrives, the software computes the point where the lines-of-bearing from each RWR meet. The CESMO software ascertains the radar’s location it retransmits this to other friendly aircraft at risk of detection. The radar can then be avoided or engaged with kinetic, electronic and/or cyberattack. CESMO information is sent back out across the same communications links. Data is carried on standard very/ultra-high frequency (30 megahertz to three gigahertz) links and tactical datalinks like NATO’s Link-16. Traffic is carried in IP (Internet Protocol) format messages absorbing under 16 kilobits-per-second of bandwidth. Furthermore, CESMO is a node-less network as there is no single, central point of network control. Should one platform sharing its information be lost this will not cause the collapse of the CESMO network.

CESMO and border security

In the context of border security, CESMO could help to enrich the overall intelligence picture of what is happening beyond the Polish border. The sources said that the CESMO capability can be adapted to process signals-of-interest from an aircraft’s radar, be that a fire control radar, a weather radar or radar altimeter. Alternatively, signals of interest from an aircraft’s radios could be exploited. Several antennas could be located on the ground close to the border on vantage points such as elevated terrain. Such sites provide a good field-of-view of the airspace over and beyond the border. Signals of interest could be captured by these antennas and then geolocated using the AOA and TDOA processes discussed above. CESMO’s capabilities would be ideal for detecting and tracking Uninhabited Aerial Vehicles (UAVs) flying close to the border via the radio links connecting the aircraft to its pilot. UAV flights close to the border could indicate that these aircraft are performing a reconnaissance of the frontier. The asset of CESMO is that it could provide the initial detection of a potential air target using the target’s radio and radar emissions. It may also be possible to identify this target via those emissions. CESMO target information could then be shared with the Siły Powietrzne (Polish Air Force) national Integrated Air Defence System (IADS). Decisions can be taken whether further investigations of this target, or even the target’s interception, should be performed. Using CESMO in this role helps plug gaps in border air surveillance perhaps not covered by existing ground-based air surveillance radars. As CESMO is passive, it can monitor airspace without having to perform any electromagnetic emissions. Should CESMO be adopted for this role in Poland, it could mark an important step towards enhancing the country’s border security, particularly in the air domain. If this adoption proves successful, it may mark a new concept of operations for CESMO. A future Polish deployment may trigger similar deployments elsewhere in the EU and NATO’s European membership helping strengthen the continent’s borders. (Source: Armada)

 

06 May 25. More information has come to light regarding the mission fit equipping the Deutsche Marine’s (German Navy’s) forthcoming ‘Type 424’ class Signals Intelligence (SIGINT) ships. Three vessels are equipping the class with the first example entering production in December 2024. German shipbuilder NVL is constructing the vessels. The ‘Type 424’ ships replace the German Navy’s existing ‘Oste’ class SIGINT vessels which commissioned from 1988. Reports note that the first of the new SIGINT ships will commission from 2027. Construction and commissioning of the entire class expected to be complete by 2029. Alongside NVL, Rohde & Schwarz is integrating the ship’s mission system. Sources close to the programme have shared that these ships will collect, process and distribute Electronic Intelligence (ELINT) and Communications Intelligence (COMINT). The mission system will process signals from circa three megahertz/MHz up to circa 40 gigahertz. Thus, the ships will collect COMINT on High Frequency (HF: three megahertz to 30MHz) and Very/Ultra High Frequency (V/UHF: 30MHz to three gigahertz) signals. Beyond communications, the ships will process ELINT on radar signals from VHF bands (133MHz to 144MHz/216MHz to 225MHz) to Ka-band (33.4GHz to 36GHz). Assuming the ship’s SIGINT receivers are positioned circa 30 metres (98 feet) above the waterline, they could detect emitters on the surface at ranges of around eleven nautical miles (22 kilometres). The sources disclosed that the ships will also have Imagery Intelligence (IMINT) collection equipment. IMINT systems will allow signals of interest to be matched with the emitter’s source, such as a surface combatant.

CESMO

Armada has learned that the ships will be able to process Common Electronic Support Measure (CESMO) ELINT. CESMO is a North Atlantic Treaty Organisation (NATO) data sharing protocol. The protocol receives data gathered by aircraft or ship Radar Warning Receivers (RWRs). The RWRs share data across standard communications links regarding emitters in range with a computer running the CESMO software. These conduits can include standard tactical data links like NATO’s Link-11/22 and Link-16 protocols. Link-11/22 is chiefly used to support naval operations, with Link-16 primarily assisting air operations. The CESMO software receives the ELINT and uses this to locate the position of radars through triangulation. For example, if three ships detect the same radar, but on different Lines-of-Bearing (LOBs) relative to each ship, the radar will be located at the point where the LOBs cross. The German Navy uses the CESMO protocol for the detection of emitters of interest, having embarked on experiments to this end from 2018.

Other platforms

Alongside Rhode & Schwarz, PLATH is believed to be providing COMINT equipment as part of the overall mission system. Rohde & Schwarz subsidiary Schӧhhofer is furnishing its Tawan intelligence analysis software. The vessel’s SIGINT mission fit includes Rohde & Schwarz’s Kora Electronic Support Measure (ESM) which collects and process ELINT in wavebands of circa two gigahertz up to 40GHz. Kora, alongside the PLATH COMINT capabilities, the exact model of which is unknown, can also collect and process COMINT. Additional company equipment furnishing the ‘Type-424’ class includes the company’s ADD-557 direction-finding antenna. ADD-557 covers wavebands of 20MHz to six gigahertz or eight gigahertz if desired by the customer. It is possible that the ADD-557 is used to geolocate communications and radar emitters in these wavebands. Higher-band signals may be geolocated with the Kora system. One possible concept of operations for the ‘Type-424’ class mission fit is for the Kora ESM to perform the initial detection and geolocation of Signals of Interest (SOIs). The PLATH equipment may then perform a more detailed collection and analysis of communications SOIs.

Sources continued that the mission system design is expected to be frozen by the end of May. Mission system construction and installation is expected to commence by the end of the year. Preparations are already being made at Rohde & Schwarz facilities to this end. Alongside the Type-424 class, the Tawan software is expected to equip the Luftwaffe’s (German Air Force) new Hensoldt Pegasus airborne SIGINT platform. Pegasus is housed onboard a Bombardier Global Express business jet airframe. Tawan is also being employed as the intelligence analysis software for the Luftwaffe’s (Luftgestützte Wirkung im Elektromagnetischen Spektrum/Airborne Effects in the Electromagnetic Spectrum) air defence suppression architecture. (Source: Armada)

 

05 May 25. The Royal Australian Air Force’s new Lockheed Martin C-130J-30 turboprop airlifters will be outfitted with new Northrop Grumman AN/ALQ-251 radar warning receivers. Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.

Herculean Protection

Northrop Grumman announced in early April that the company will outfit the Royal Australian Air Force’s (RAAF’s) new Lockheed Martin C-130J-30 turboprop airlifters with self-protection systems. Northrop Grumman will supply its AN/ALQ-251 radar warning receiver to equip these aircraft. The AN/ALQ-251 is thought capable of detecting radio frequency threats in wavebands of at least two gigahertz/GHz to 18GHz. The system provides signal angle-of-arrival information and gives warnings of simultaneous Radio Frequency (RF) threats. The AN/ALQ-251 architecture includes a digital receiver enabling high fidelity RF signal measurement which can be reprogrammed on the flight line. James Conroy, Northrop Grumman’s vice president for navigation, targeting and survivability, told Armada that the “AN/ALQ-251 provides superior situational awareness and protection against electronic warfare systems and radar-guided weapons, often in contested and congested electromagnetic spectrum environments.” He continued that “(a)s more advanced radio frequency threats proliferate this level of protection will be essential for safe operations.” Mr. Conroy continued that the AN/ALQ-251s will be installed on the RAAF’s new C-130J-30s as they are manufactured. Installation is expected to be completed by 2029.

Pixus Technologies has partnered with COMINT Consulting to provide the latter company’s signals intelligence software within its ruggedised software defined radios.

New Partnerships and Decoders

Pixus Technologies and COMINT Consulting have established a partnership to offer the latter’s Krypto1000 Very/Super High Frequency (30 megahertzMHz to 30 gigahertz) Signals Intelligence (SIGINT) software. The software can furnish the ruggedised Emerson URSP software defined radios Pixus Technologies provides. COMINT Consulting told Armada that the Krypto1000 software lets the radio perform communications/signals intelligence work “from any platform in harsh conditions.” It is possible that the company’s other offerings, like its Krypto500 SIGINT software, could be added to additional Pixus Technologies products in the future. Regarding the latter, in early May COMINT Consulting unveiled a new software release, v1.278, for the Krypto500. The company disclosed that the release includes three new decoders covering an array of communications protocols. The Krypto500 software covers wavebands of 300 kilohertz up to 30MHz. (Source: Armada)

 

08 May 25. US: Zero-day vulnerability underscores security risks posed by ransomware groups. On 7 May, the cyber security company Symantec reported that the ransomware group ‘Play’ exploited a zero-day vulnerability (CVE-2025-29824) to deploy malware onto a compromised system. CVE-2025-29824 affects the Common Log File System (CLFS) Driver on Windows systems and mistakenly de-allocates a section of a system’s memory. The group reportedly used an internet-facing Cisco security appliance to infiltrate a US-based organisation. The vulnerability then enabled Play to use the de-allocated memory to deploy multiple malicious payloads, effectively granting the group elevated system privileges. Play subsequently installed information-stealing malware (‘Grixba’), likely in a bid to steal user credentials. A patch was released for CVE-2025-29824 on 8 April, highlighting the importance of timely patch management policies. This vulnerability was also reportedly exploited by threat actor ‘Storm-2460’ in a separate campaign, further underscoring the financial, operational and security risks posed by the exploitation of zero-day vulnerabilities by ransomware groups. (Source: Sibylline)

 

06 May 25. Viasat launches MOJO Mini Next. The MOJO Mini Next is designed to cater to the needs of rapidly deployable and on-the-move applications.Viasat has introduced MOJO Mini Next, a new addition to its tactical gateway portfolio, aimed at enhancing situational awareness and communications for military operations. This product is engineered to offer Link 16 Tactical Data Link situational awareness in a small and durable form factor suitable for both stationary and mobile operations in various settings. Intended to cater to the needs of rapidly deployable and on-the-move applications across various environments, the new product integrates disparate air, sea and land communications into a single view. The MOJO Mini Next, developed under Viasat’s Defense and Advanced Technologies segment, also serves as a cost-effective solution to traditional, larger gateway systems, the company said. It provides line-of-sight and beyond line of sight capabilities, centralising expeditionary data and intelligence into a common operating picture. This supports command and control (C2), targeting, and real-time decision-making, ultimately aiming to reduce the risk of fratricide in mission operations.

US Tariffs are shifting – will you react or anticipate?

Don’t let policy changes catch you off guard. Stay proactive with real-time data and expert analysis.

Viasat Government mission connections and cybersecurity vice-president David Schmolke said: “As military operations integrate new technologies and applications to support global missions, Viasat is helping connect those technologies to enable seamless, reliable and resilient information sharing to improve situational awareness.”

Designed based on user feedback, the MOJO Mini Next addresses the increasing demand for mobile and tactical capabilities. (Source: airforce-technology.com)

 

06 May 25. Creomagic Ltd. and RT LTA Systems Ltd. have joined forces to deliver SkyCnet, a new, integrated solution combining RT’s advanced aerostat systems for persistent aerial surveillance with Creomagic’s secure, real-time tactical communications. This cutting-edge integration promises to deliver enhanced situational awareness for frontline forces, providing a significant operational advantage for mission-critical operations, with faster, more informed decision-making in complex environments. The companies will unveil the new integrated system at the upcoming DEFEA Expo in Athens. Real-time visual intelligence is critical for mission success, providing frontline forces with a decisive edge in scenarios ranging from securing national borders to executing high-stakes special operations. Purpose-built for defense, homeland security, law enforcement and border protection, SkyCnet delivers comprehensive situational awareness and secure communications in the most challenging environments. By integrating RT’s combat-proven SkyStar™ aerostats with Creomagic’s advanced and resilient radio technology, SkyCnet establishes a tactical communication bubble for frontline forces that extends operational reach, maintains connectivity for ground forces, and ensures reliable, real-time data flow for mission-critical operations across both military and civilian domains/applications. SkyCnet offers a comprehensive suite of critical operational advantages through its rapidly deployable and highly resilient network. Leveraging the advanced Skystar™ aerostat and Creomagic’s innovative MANET-based (Mobile Ad-Hoc Network) communication technologies, SkyCnet provides continuous 360° visual coverage and seamless connectivity across diverse terrains—day and night, over land, sea, or within urban zones. The system features high mobility and cost efficiency, with rapid deployment within a mere 20 minutes by a small, two-man crew. SkyCnet’s high-performance data links facilitate the seamless transfer of large volumes of critical data such as real-time video and mapping information, ensuring mission-ready connectivity and intelligence sharing even in remote, beyond-line-of-sight operations and contested electronic warfare (EW) environments. Ultimately, this capability enables uninterrupted, long-endurance, 24/7 surveillance and communications.

“SkyCnet was developed to precisely meet the critical communication demands of tactical forces. By combining Creomagic’s communications expertise with RT’s best-in-class, persistent ISR, SkyCnet acts as a significant force multiplier for contemporary tactical operations,” explained Alex Shapochnic, CEO of Creomagic. RT’s CEO, Rami Shmueli, elaborated on the versatility of their new system: “Our partnership with Creomagic allows us to deliver resilient, high-performance communication solutions tailored to the needs of maritime, border security and HLS missions—a vital necessity today with the growing challenges along Europe’s borders.

 

07 May 25. Silvus Unveils New DualStream PTT Controller. Silvus Technologies, Inc., a global supplier of  advanced wireless networking communications, has announced the launch of its latest innovation – the DualStream PTT Controller – at Special Operations Forces (SOF) Week 2025 in Tampa, Florida. Designed for the connected operator, the DualStream PTT Controller streamlines tactical communications, enhancing situational awareness in the most demanding environments. Engineered for mission-critical performance, the DualStream PTT Controller features a glove-friendly 16-position talk group selector and real-time audio prompts that allow for fast, intuitive talk group assignment, even under pressure. Its dedicated volume control, left/right audio channel output, and dual PTT buttons enable operators to rapidly switch between two talk groups—or key both simultaneously. Natively compatible with 4000 (and the upcoming 5000) Series StreamCaster® MANET radios, the DualStream PTT Controller is compatible with headsets from leading manufacturers including Atlantic Signal, and Ops-Core, with planned support for INVISIO, OTTO, and FalCom.

“The DualStream PTT Controller is purpose-built to give operators a tactical edge in complex, multi-mission environments,” said Neema Daneshvar, Vice President of Product at Silvus Technologies. “With seamless talk group management, dual-channel audio control and a rugged, user-centric form factor, it empowers the warfighter with reliable, real-time communication capabilities when it matters most.”

Built to withstand extreme conditions, the DualStream PTT Controller is IP67 rated, and features waterproof volume buttons housed in a ruggedized form factor for maximum durability in the field. A rotatable MOLLE clip offers flexible mounting options, ensuring quick, easy access for both left- and right-handed operators. Silvus showcased the DualStream PTT Controller and the full StreamCaster family of MANET radios at SOF Week (Booth #641), alongside live demonstrations of innovative mesh networking technology that, together are empowering the warfighter to achieve Spectrum Dominance across today’s dynamic battlespace.

  • Spectrum Dominance – a software licensable extension to Silvus’ battle-proven MN-MIMO waveform, this expansive suite of Low Probability of Intercept/Low Probability of Detection (LPI/LPD) and Anti-Jamming resiliency capabilities enables secure and protected communications in EW contested environments without sacrificing performance.
  • StreamCaster LITE 5200 – designed for today’s leading-edge unmanned systems, the SL5200 unifies C2, sensor and telemetry data with communications relay capabilities in an ultra-low SWaP, easy-to-integrate MANET radio module.
  • StreamCaster PRISM – a family of modular Precision Integrated Sectorized MIMO antenna radio systems that provide long-range sectorized coverage across wide areas of operation. Designed for tactical operations, at-the-halt, and fixed infrastructure applications, StreamCaster PRISM’s ruggedized construction and toolless set-up enables it to be rapidly deployed for operational flexibility.
  • StreamConnect: Global Ad Hoc Network – an adaptable data transport technology that seamlessly integrates StreamCaster MANET radios with internet connectivity to connect teams operating anywhere around the globe with 5G, Satcom or other internet source, enabling BLOS communications from virtually anywhere on the globe. (Source: UAS VISION)

 

06 May 25. Pentagon wireless spectrum sale could put Trump Golden Dome plan at risk, senator says. The top Democrat on the Senate Commerce Committee said the sale of wireless spectrum held by the Pentagon could put President Donald Trump’s “Golden Dome” missile defense shield and other military projects at risk. Senator Maria Cantwell said mandating the sale of military wireless spectrum also could endanger a substantial number of military radar systems. Lawmakers are considering legislation that would approve new auctions to free up spectrum for growing wireless use in a long-running debate over whether to repurpose some spectrum held by the U.S. military. The Federal Communications Commission lost the broad authority from Congress for wireless spectrum sales in 2023. (Source: Reuters)

 

06 May 25. Skydio Delivers the 1st Systems for Tranche 2 of the US Army’s SRR Program, Equipping a Deploying Unit in Days. Skydio, the leading U.S. drone manufacturer and world leader in autonomous flight technology, today announced it has fulfilled the first order under the U.S. Army’s Short Range Reconnaissance (SRR) Tranche 2 program with the delivery of X10D small unmanned aircraft systems (sUAS). With this order, Skydio X10D is the only system delivered to date as part of Tranche 2 of the U.S. Army’s SRR Program of Record. Skydio equipped a U.S. Army Transforming in Contact (TiC) unit preparing for imminent deployment with hundreds of X10D aircraft systems, demonstrating the company’s ability to rapidly respond to the demands of the U.S. Department of Defense (DoD). Skydio X10D, part of the DoD’s Blue UAS Cleared List, will provide essential intelligence, surveillance, and reconnaissance (ISR) capabilities to the TiC unit, enhancing operational effectiveness and situational awareness in contested environments.

“When the Army contracted Skydio to fill this urgent need, we shipped systems within 5 days, ensuring soldiers had this critical equipment before their deployment,” commented Adam Bry, cofounder and CEO of Skydio. “We produce 1,000+ drones a month at our facility in California with the ability to rapidly scale beyond that rate, enabling us to ship at the speed of need. Ultimately, production readiness is deterrence. By investing in our production capacity, we can accelerate delivery of war-winning capabilities, making America’s enemies think twice before challenging the world’s most capable fighting force.”

All Skydio drones are designed, assembled, and supported in the United States, and Skydio’s manufacturing facility in Hayward, CA is one of the world’s largest drone manufacturing facilities outside of China. With the recent shipment of its 55,000th drone, the company’s investments in manufacturing scale are paying off – an X10 and X10D drone can now be built in nine minutes.

Skydio X10D is designed to meet the mission on the modern battlefield:

  • A sensor package that is unrivaled in any sUAS this size, including a 48MP telephoto camera
  • A best-in-class Teledyne FLIR Boson+ thermal sensor that can pinpoint temperature differences at each pixel
  • Resiliency in the face of electronic warfare with onboard AI and autonomy
  • Advanced obstacle avoidance in every direction
  • Enhanced operational resilience in challenging navigation environments through advanced proprietary technology that maintains positional awareness without relying on conventional navigation methods
  • Modular, open platform that supports custom third-party attachments and controllers
  • Powerful, full-stack security, starting with the chipset and its firmware
  • IP55 rating for nearly all-weather operation

Skydio has now delivered drones to every branch of the DoD and armed forces in 25 allied nations. (Source: ASD Network)

 

06 May 25. Anduril Introduces Menace-T: A Compact, Field-Deployable C4 System Designed for the Tactical Edge. A reconnaissance team touches down near a fishing village suspected of harboring hostile assets. The terrain is rocky. There’s no infrastructure. All these operators have is a satellite uplink that drops every few minutes, and a jumble of legacy computing and communication gear that takes four people half a day to rig. Nothing works out of the box. While the operators are studying and troubleshooting the network, the window to relay intelligence closes. A high-value target slips through. The team packs up without ever making contact. Mission failed.

This used to be normal.

Now: same mission, same location. One operator arrives with Menace-T. Within minutes, the operator is running the team’s full software stack: Lattice Mesh, intelligence collection, encrypted communications. Real-time targeting data is pushed directly to a joint operations center hundreds of miles away. No waiting for setup. No dependence on external infrastructure. No missed opportunity.

The mission completes in under one hour. Target identified, tracked, and relayed. No one knows Menace-T was there—except the people who needed it. This is what command, control, communications, and computing (C4) should look like in the field. Lightweight. Reliable. Fast. And no-fail.

Menace-T is the latest addition to the Menace family C4 solutions designed for the most challenging and rugged environments. It’s a compact, two-case C4 system that can be deployed by a single operator and operational in minutes. No extra cables. No integration headaches. Just compute power in the most austere locations. Menace-T is resilient and provides secure connectivity in a form factor small enough to carry and rugged enough to survive the field. Built on Voyager compute and communications and powered by Anduril’s Lattice Mesh, Menace-T runs the same mission-critical software that drives Anduril’s larger Menace systems. Menace-T can also run any third-party software stack with the power to run edge AI inferencing and learning. Operators can lift their entire tech stack and run it from anywhere, with no trade-offs in performance or interoperability. It’s already in use around the world. Menace-T has enabled real-time targeting data relay, been deployed in ground vehicles, maritime vessels and more. It’s proven effective in joint environments, coalition operations, and austere conditions where traditional systems can’t operate. Our warfighters need the best software solutions, especially in the most austere locations. With Menace-T, Anduril continues transforming warfighting capabilities at the tactical edge. (Source: ASD Network)

 

06 May 25. MASS, part of the Cohort plc Group, has launched its SESCO training methodology for electronic warfare (EW) and cyber and electromagnetic activities (CEMA) operators, analysts and command staff at AOC Europe. Comprising of five key stages – simulate, emulate, stimulate, calibrate and operate – the training methodology takes personnel with limited-to-no experience of EW and CEMA, and provides the knowledge, skills and experience to ensure they are ready for deployed operations.

The SESCO methodology incorporates MASS’ proven EW training solutions NEWTS, replicating the four-stage intelligence cycle for immersive training, which simulates the intensity of operations in the field.

The integration of NEWTS enables passive training without emitting an RF footprint – except for in the final ‘calibrate’ stage – that could be intercepted and utilised by adversaries. This is crucial for ensuring security when training is being conducted, as training is typically based on operational combat.

Keith Norton, Managing Director at MASS said, “Recent conflicts have clearly highlighted the importance of EW for obtaining operational advantage. Preparation and training are crucial to ensuring EW operators have the skills and experience needed to navigate a congested and contested electromagnetic environment before deployment. This is where the SESCO approach is unique – it enables personnel to train in a realistic environment, facing the challenges of congestion to apply their classroom-based learning.”

The first two stages of the methodology are classroom based:

Simulate – Operator, analyst and command staff scenario-based training in a simulated simple electromagnetic environment (EME) using MASS’ NEWTS capability and “representative” data. This provides the ability to simulate end-to-end EW/CEMA process in a simulated EME with no RF footprint.

Emulate – Advanced operator, analyst and command staff scenario-based training in a realistic contested EME utilising IQ data. This leverages NEWTS and combines it with BATTLEYE to superimpose in-phase and quadrature (IQ) signals on the real-world spectrum without producing a RF footprint.

Building on the classroom learning, the second half of the training is field based to put the theory into practice:

Stimulate – Original Equipment Manufacturer (OEM) equipment specific training. This stage stimulates OEM in service equipment with signals of interest (SOI) via wire.  This signal generation uses IQ data for real world target sets. No RF footprint is produced.

Calibrate – PacEX / FTX and PDT detachment drills and processes. With the ability to calibrate OEM in service equipment and expose exercising troops to specific SOI via RF from predesignated locations, this stage provides a realistic train as you operate environment.

Operate – The SESCO methodology ensures that EW / CEMA personnel are fully trained, and have awareness of roles and responsibilities at all levels. The training incorporates mission planning and mission rehearsals, testing and calibration of equipment as well as testing and trialling of robust standard operating procedures (SOPs), tactics techniques and procedures (TTPs) and concept of operations (CONOPS).

Stuart Willumsen, Head of Training and Principal CEMA Consultant at MASS added, “For EW operators, analysts and commanders to feel confident and prepared for operations, we must go beyond classroom learning. By combining theoretical understanding with the experience of operating in a safe, yet realistically congested simulated contemporary multi-threat environment, EW staff gain the knowledge, skills, and practical insights needed to secure operational advantage and develop professionally.”

 

06 May 25. DTC, the company that helps its customers get and stay connected wherever they are, and when it matters most, and the Idaho National Laboratory (INL), a national laboratory focused on energy and national security research, announced a Cooperative Research and Development Agreement (CRADA). This CRADA underscores the shared commitment of DTC and INL to advance cutting-edge technologies in secure communications, resilient systems and innovative defense and government applications. Through this partnership, both organizations aim to leverage their unique expertise to address critical challenges in national security and energy resilience.

“Our partnership with INL opens the door to transformative solutions that merge DTC’s tactical innovation with INL’s renowned research capabilities,” said Paul Sangster, President of DTC. “Together, we are committed to pioneering delivery of solutions that advance and sustain the information advantage for our customers in a rapidly evolving digital battlespace.”

“At INL we are committed to solving complex problems and bridging the gap between research and real-world applications,” said Tom Holschuh, INL Wireless Communications Research Division Director. “Securing global telecommunications technologies is more important than ever. By partnering with DTC, we are confident we can improve secure and reliable communications for critical operations, and we’re proud to contribute to advancements that benefit society at large.”

The CRADA details collaborative research projects aimed at combining DTC’s solutions with INL’s Dynamic Spectrum Access technology and will ensure uninterrupted data transmissions even when multiple users are operating on the same frequency. In addition, the CRADA will advance INL’s patented WSComm waveforms to enhance each solution’s security and prevent communication disruptions during critical operations. These efforts leverage DTC’s strong background in delivering critical tactical solutions and INL’s deep expertise in communications research, testing and training.

 

04 May 25. MyDefence introduces industry-first Wideband Antenna. MyDefence, the company behind Wingman, one of the smallest wearable drone detectors on the market, has launched a new technology designed to expose the unseen threats shaping modern warfare. The next-generation compact Wideband Antenna, purpose-built for integration with Wingman and ATAK, delivers a major advancement in spectrum awareness by expanding detection into critical low-frequency ranges used by today’s most evasive drones.

The threat has shifted – detection must catch up

Modern drone warfare is evolving fast. In high-threat environments like Ukraine, enemies increasingly use low-band frequencies, especially 350–1300 MHz, to evade conventional counter-drone systems. The UN Human Rights Monitoring Mission in Ukraine reports that short-range drones now cause more battlefield casualties than any other weapon system, emphasizing the urgent need for tools that can detect threats hiding in the lower spectrum.

Precision coverage in vital frequency bands

The Wideband Antenna is optimized for superior detection across the 350–1300 MHz range, directly addressing gaps exploited by FPV drones and other low-band emitters. It also continues to support the 2.4 GHz band (2400–2500 MHz) and now adds complete coverage in the 5 GHz range (5000–6000 MHz), offering spectrum awareness where it is vital today.

– The most fatal threats are often the hardest to see and they now operate in parts of the spectrum most systems fail to detect. Our new compact Wideband Antenna fills that gap, with a clear focus on adding the full 350–1300 MHz range where real-world attacks are now happening as well, Dan Hermansen, CEO, MyDefence

Visualization powered by ATAK

While the antenna delivers next-level detection capability, spectrum visualization is handled through ATAK (Android Tactical Assault Kit). Spectrum activity captured by the antenna is streamed directly into ATAK, allowing users to map, monitor, and react to hostile signals in real time.

This integration enhances situational awareness for soldiers and security teams by combining wearable detection, low and high frequency sensing, and advanced visual analytics, all within the military’s preferred tactical platform.

Built for the battlefield and beyond

More than 2000 Wingman units are currently deployed in Ukraine, where they support frontline troops in environments saturated with drone activity. The new Wideband Antenna offers these users a critical upgrade—allowing them to detect signal activity that was previously invisible, especially in the low-band range.

Thanks to its compact form factor, broad spectral reach, and plug-and-play compatibility, the antenna is also suited for conflict zones and border operations, law enforcement and public safety and VIP protection and homeland security

Scaling for a global mission

This launch marks the first in a new wave of antenna innovations planned by MyDefence for 2025. In response to growing international demand, the company has expanded its production capacity tenfold with a new facility launched in 2024.

– Our mission is to save lives by staying ahead of the evolving drone threat landscape. This new antenna strengthens integration between MyDefence solutions and tactical platforms, Dan Hermansen, CEO, MyDefence.

About MyDefence

Founded in 2013 by military veterans, MyDefence specializes in RF-based counter-drone technology for the protection of personnel, vehicles, and critical infrastructure. The company continues to lead with solutions built for the realities of modern conflict and validated in combat environments.

Built by veterans. Trusted by defense forces. Field-proven in combat. We save lives.

 

05 May 25. INVISIO further expands capability of market-leading wireless intercom system. Tactical communications expert INVISIO is expanding the capability of its market-leading intercom system made for tailored user and radio communication. The expansion will deliver enhanced mobility, flexibility, interoperability and functionality for mission-critical users.

INVISIO Link™, due to ship in the next few months, provides wireless access to the INVISIO Intercom system by adding a body worn dongle and a base station to the equipment setup.

Two additional new products – the INVISIO Intercom Switch and the INVISIO Intercom Loudspeaker – further expands the intercom ecosystem and allow communication to larger user groups. The intercom switch provides power and enables interconnectivity between multiple Link Stations to give wireless access to up to 16 users. In a wired setting, the switch can expand the number of wired users up to 27 via multiple intercoms. The loudspeaker can play audio to groups in settings such as a command center or vehicle.

Announced in 2024, INVISIO Link™ offers a range of benefits, including:

  • Tailored connectivity: Keeps users always connected, with wireless access for tailored user and radio communication and seamless integration of platform communication.
  • Unlimited mobility: No tangled cords enable complete mobility, eliminating current platform and proximity issues.
  • Seamless communication: Smooth transitions between mounted and dismounted, and wired and wireless, with auto-connect functionality for easy use.
  • Uncompromised quality: Uncompromised speech intelligibility along with strong connectivity, even in challenging environments.
  • Secure and lightweight: Unparalleled in size and weight, with a body-worn dongle weighing just 70g (2.5oz). System security through AES 256 encryption and low detectability thanks to user-adjustable transmitting power.
  • Mounted anywhere: Can be fixed to MOLLE webbing, stored in a bag or permanently installed. Leight weight of 270g (9.5oz) and small footprint of 186 x 100 x 30mm (7.3 x 3.9 x 1.2 in) ensures easy positioning for optimal transmission, with optional external antenna support for challenging RF installations.

Jacob Tranegaard, Director Intercom Product Management at INVISIO, said: “These advances ensure the INVISIO Intercom eco-system continues to excel in flexible, tailored wireless communication that offers a whole range of use cases, from military vehicles to maritime uses and command post communications, and non-military scenarios.

INVISIO Link™ gives users more freedom and mobility than ever, along with uncompromised speech intelligibility, secure encryption and a small footprint. The switch and the loudspeaker further expand INVISIO’s capability to ensure our systems remain market-leading in the world of tactical communications.”

INVISIO Link™ is available for demo at SOF Week – visit Booth #1541 at Level 3 (Danish Pavilion) or INVISIO’s yacht, “Reel Blonde” next to the Tampa Convention Center. Alternatively, visit invisio.com or contact your local INVISIO representative.

 

02 May 25. Cyber Update

Key points

  • A new Ransomware-as-a-Service (RaaS) model by the threat group ‘DragonForce’ highlights the long-term security and financial risks facing businesses (see Sibylline Cyber Daily Analytical Update – 28 April 2025).
  • US cyber security assistance cuts to foreign aid programs will likely elevate security risks to Ukrainian entities amid the war in Ukraine (see Sibylline Cyber Daily Analytical Update – 29 April 2025).
  • The government sector in France will face long-term security risks from the Russian state-sponsored group ‘APT28’ (see Sibylline Cyber Daily Analytical Update – 30 April 2025).
  • A new information-stealing malware variant (‘Gremlin’) highlights security and information-theft risks facing global users (see Sibylline Cyber Daily Analytical Update – 1 May 2025 and our Technical analysis below).
  • A new variant of the ‘Spellbinder’ tool will heighten security risks from the China-nexus group ‘TheWizards’ (see Sibylline Cyber Daily Analytical Update – 2 May 2025 and our Technical analysis below).

Technical analysis of weekly stories

Unnamed threat actors have been advertising a new version of the ‘Gremlin’ information-stealing malware on the communications platform Telegram since at least mid-March. Gremlin can collect data from a wide variety of Chromium and Gecko-based web browsers, as well as from the Discord and Telegram social media platforms. It can also obtain File Transfer Protocol (FTP) and virtual private network (VPN) credentials. This is in addition to its capacity to bypass Google Chrome’s ‘v20’ cookie prefix to decrypt and steal session cookies, alongside stealing cryptocurrency wallets and other system information. Gremlin stores stolen data in multiple local plain-text files before merging them into a single .ZIP archive; the archive file is then exfiltrated to the actors’ website via a Telegram bot. The website reportedly displays 14 .ZIP archives as of the date of writing, showcasing the scale of this operation. Gremlin customers are also provided with access to the actors’ website to exfiltrate stolen data as part of Gremlin’s service offering. The malware is undergoing active development, highlighting the security and information-theft risks stemming from the continuous development of malware variants.

The China-nexus advanced persistent threat (APT) group (TheWizards) has used a new variant of the Spellbinder tool in cyber operations since at least 2023. TheWizards uses the dynamic-link library (DLL) side-loading technique to execute shellcode and deploy the SpellBinder tool after infiltrating targeted systems. The tool then abuses the stateless address autoconfiguration (SLAAC) feature to configure the actor-controlled server as the system’s main router, enabling TheWizards to hijack the network’s traffic. Subsequently, the server receives and analyses all data packets in a bid to covertly deploy additional malicious payloads. This includes a custom backdoor (‘WizardNET’) that is remotely installed onto compromised systems via an Adversary-in-the-Middle (AitM) attack. Here, the group intercepts a data packet to inject WizardNET into compromised systems under the guise of a legitimate software update. The backdoor then establishes communication with command-and-control (C2) infrastructure, allowing the group to maintain persistence within compromised systems and conduct further malicious activity. Spellbinder is also executed within the system’s memory to prolong detection evasion.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

Our cyber word(s) of the week: Stateless address autoconfiguration (SLAAC) (Source: Sibylline)

 

02 May 25.  Global: New custom tool variant heightens security risks posed by China-nexus groups. On 30 April, the software company ESET reported that the China-nexus advanced persistent threat (APT) group ‘TheWizards’ has used a new variant of the ‘Spellbinder’ tool in cyber operations since at least 2023. The group uses shellcode to install Spellbinder after infiltrating targeted systems. It then abuses the stateless address autoconfiguration (SLAAC) feature to hijack and redirect a system’s traffic to an actor-controlled server. This enables TheWizards to conduct an Adversary-in-the-Middle (AitM) attack to intercept network communication and deploy additional malicious payloads. This includes the use of a custom backdoor (‘WizardNet’) to establish communication with command-and-control (C2) infrastructure, maintain persistence within compromised systems, and conduct other malicious activities. TheWizards typically targets entities in Cambodia, China, Hong Kong, the Philippines and the UAE. As such, we assess that this development heightens security risks to entities in these countries, especially given the continuous evolution of Spellbinder. (Source: Sibylline)

 

06 May 25. Octasic Inc. and Octasic US Inc. today announced its collaborative launch of Wraith, a portfolio of ‘Mod Payload’ ultra-compact, multi-mission solutions that bring specialized radio frequency and other wireless functions to the modern signals intelligence warfighter. Purpose-built to meet the USSOCOM Modular Payload Standard, Wraith solves many tactical edge issues all at once, including reliability, interchangeability and maintainability, faster in-field replacements, and a reduction in life cycle costs for all relevant EW/EA, SIGINT, PSYOPS/CMAS, C5ISR, and Cyber systems.

“Wraith embodies our vision for the next generation of modular, mission-adaptable payloads,” said Sébastien Leblanc, CEO of Octasic. “It delivers the advanced wireless capabilities forces need to protect, deter, and respond with precision across today’s complex operational environments.” Spectrum dominance starts with the right payloads on the right platforms,” said Greg Gerou, President and General Manager of Octasic US. “Wraith is engineered to help our partners close capability gaps and maintain operational advantage in a fast-moving threat environment.”

Recognized globally by public and national security organizations, Octasic is seeking to expand its wireless signal processing and advanced 5G SA detection, localization, and geolocation capabilities to the defense market.  Wraith solutions address this by leveraging the deep Octasic expertise in highly integrated Software Defined Radio (SDR) technologies that offer best-in-class low size, weight, and power payload designs for Uncrewed Aerial Systems (UAS), Uncrewed Surface Vehicles (USVs), Uncrewed Underwater Vehicles (UUVs), and even larger crewed airborne craft. The Wraith payload system roadmap includes a range of RF Front End options to meet mission altitude and performance requirements. To reduce the time and complexity for crews to swap capabilities down range ‘modularity’ is the winning strategy. It enables incremental improvements of components, subsystems, software, and mixing-and-matching capabilities according to objectives. The arsenal of the future is a drone fleet that benefits from updatable software libraries and plug-and-play payloads.

 

02 May 25. Advancing Multi-domain EW Operations: Rohde & Schwarz Unveils Latest Innovations at AOC Europe. Rohde & Schwarz demonstrates the next generation of SIGINT/EW systems,sensor fusion and signal analysis solutions, designed to meet the evolving needs of tactical and strategic missions. As a reliable partner and system integrator for enhanced situational awareness and network monitoring, Rohde & Schwarz presents its latest and innovative portfolio of cutting-edge signal intelligence (SIGINT) and electromagnetic warfare (EW) solutions at AOC Europe 2025 from May 6 to 8, in Rome, Italy. The company offers a unique one-stop shop, providing turnkey solutions that encompass the entire signal chain, from signal testing and generation to detection and localization, as well as securing and analyzing signals, all conveniently available under one roof. This is accomplished through a range of capabilities, including test & measurement solutions for radar signal simulation, as well as communications intelligence (COMINT) systems for tactical and strategic missions. Sensor fusion and signal analysis are enhanced through the use of AI-enriched data, providing a comprehensive understanding of the signal environment and supporting informed decision-making.

“We are excited to showcase our state-of-the-art SIGINT/EW systems and situational awareness solutions at AOC Europe,” says Thomas Geißler, Senior Director Sales Defense / Security / Critical Infrastructure Europe, Rohde & Schwarz. “Our solutions support multi-domain EW operations and are backed by uncompromising service, ensuring worldwide support throughout the whole lifecycle.”

Rohde & Schwarz will also show its test and measurement equipment to present sophisticated radar signal simulation solutions. The R&S Pulse Sequencer, a potent radar simulation software, when paired with a Rohde & Schwarz vector signal generator, provides a robust solution to engineers and technicians assigned with testing radar receivers. This state-of-the-art approach aligns with the prevalent industry trend of conducting intensive lab testing, thereby offering a cost-effective alternative to pricey field testing. The R&S Pulse Sequencer software is capable of supporting all pertinent modern test scenarios of radar and electronic warfare technology and can account for real-world environmental conditions. As a privately owned and independent partner, Rohde & Schwarz prioritizes its customers’ needs, thereby minimizing risk through its high vertical integration of mission-critical components, ensuring a tailored approach to each partnership. (Source: ASD Network)

——————————————————————————————————————————————————————————————————————————————————————————————————————–

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

———————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

May 2, 2025 by

Sponsored By Curtiss Wright

https://www.curtisswright.com/

————————————————————————————————————————————————————————————————————————————————————————————————————————————————-

01 May 25. Spectra Group launches new Troposcatter on the Move (TOTM) capability at SOF Week. Spectra Group, a specialist provider of secure voice, data and satellite communications systems, has developed in partnership with BATS Wireless antennas a new capability enhancement for Comtech Telecommunications Corp. (Comtech) Troposcatter 10-Watt Compact Over-the-Horizon Mobile Expeditionary Terminals (COMET) called Troposcatter on the Move (TOTM). Since 2024, Spectra Group has global distribution rights for Comtech’s Troposcatter Family of Systems (less the USA, Canada and Mexico which Comtech retains). They have been working in partnership with Comtech and BATS Wireless antennas throughout 2024 to develop the TOTM concept, for which, as the systems integrator Spectra Group has full distribution rights. Spectra Group are launching this new TOTM capability at SOF Week and will be showcasing this and their other strategic communication capabilities in Booth #1805.
The use of the troposphere for communications is not new, but in the past, it was constrained by large dishes and significant power that was not suitable for modern manoeuvre warfare. Comtech’s COMET system revolutionised this capability making it small, lightweight and portable. The COMET system is ideal for providing a secure big data network for deployed headquarters from divisional down to company level or below because it is small, lightweight and due to its low power and directional nature it is also extremely difficult to detect and deny. Critically, it is also satellite independent, can work in a GPS/GNSS denied environment and is proven in the polar regions making it ideal for use during global peer-on-peer conflict and when multi-domain integration is required. However, in the past it did need to be static.
Comtech and Spectra Group recognised the need for increased manoeuvre and large network data on the move, and so, working together with BATS wireless proved the concept of TOTM. Subsequently, Spectra Group working in partnership with BATS Wireless has produced a fully integrated TOTM solution that combines Comtech’s COMET troposcatter with BATS Electronically Steered Antennas (ESAs) into a single fully integrated terminal to deliver an industry first capability. Extensive sea trials successfully tested and validated TOTM scenarios by simulating island hopping in the Florida Keys, Florida Panhandle and off the coast of California. The tests involved ship to shore and ship to ship scenarios proving the concept of TOTM by demonstrating systems tracking and communicating with other nodes while on the move using GPS, but also showcasing the potential for advanced mobile connectivity in challenging environments without reliance on GPS.
TOTM enhances the utility and operational effectiveness of COMET in a littoral manoeuvre context, especially in contested, GPS or satellite denied environments. Its mobility and capacity delivers band-widths of up to 210 Mbps and ranges in excess of 100 Km to support a wide range of mobile applications such as Ship to Ship or Ship to Shore communications, Beyond Line of Sight strategic communications or Wide Area Networks, secure data links for autonomous sensors, control of remote vessels, Intelligence Surveillance and Reconnaissance (ISR) and any other application that requires big data delivered to the front line. The TOTM solution can also be utilized with land vehicles for efficient “at the pause” applications, enabling users to quickly establish Troposcatter communications without having to set up and align antennas, allowing rapid data transmission from positions of opportunity.
Simon Davies, CEO of Spectra Group said: “We pride ourselves at Spectra Group on being able to work in partnership with industry leaders to push the boundaries of what can be achieved using the latest technology to meet the demands of regular and specialist forces in the ever-evolving battlespace. Our trials have successfully proved the Troposcatter on the Move capability which is a significant enhancement to the existing Troposcatter COMETs utility, especially in the littoral manoeuvre space, and superbly complements the Troposcatter Family of Systems and our award-winning SlingShotTM radio and new GENSS platform which also enables BLOS and COTM for troops deployed in austere locations globally.”

 

01 May 25. NASA Tests Ultralight Antennas. NASA engineers are using one of the world’s lightest solid materials to construct an antenna that could be embedded into the skin of an aircraft, creating a more aerodynamic and reliable communication solution for drones and other future air transportation options. Developed by NASA, this ultra-lightweight aerogel antenna is designed to enable satellite communications where power and space are limited. The aerogel is made up of flexible, high-performance plastics known as polymers. The design features high air content (95%) and offers a combination of light weight and strength. Researchers can adjust its properties to achieve either the flexibility of plastic wrap or the rigidity of plexiglass.
“By removing the liquid portion of a gel, you’re left with this incredibly porous structure,” said Stephanie Vivod, a chemical engineer at NASA’s Glenn Research Center in Cleveland. “If you’ve ever made Jell-O, you’ve performed chemistry that’s similar to the first step of making an aerogel.”
NASA sandwiched a layer of aerogel between a small circuit board and an array of thin, circular copper cells, then topped the design off with a type of film known for its electrical insulation properties. This innovation is known at NASA and in the aviation community as an active phased array aerogel antenna.
Research Center in Cleveland. Credit: NASA/Sara Lowthian-Hanna
In addition to decreasing drag by conforming to the shape of aircraft, aerogel antennas save weight and space and come with the ability to adjust their individual array elements to reduce signal interference. They are also less visually intrusive compared to other types of antennas, such as spikes and blades. The finished product looks like a honeycomb but lays flat on an aircraft’s surface.
In the summer of 2024, researchers tested a rigid version of the antenna on a Britten-Norman Defender aircraft during an in-flight demonstration with the U.S. Navy at Naval Air Station Patuxent River in Maryland.
Then, last October, researchers at NASA Glenn and the satellite communications firm Eutelsat America Corp., of Houston, began ground testing a version of the antenna mounted to a platform. The team successfully connected with a Eutelsat satellite in geostationary orbit, which bounced a signal back down to a satellite dish on a building at Glenn. Other demonstrations of the system at Glenn connected with a constellation of communications satellites operated in low Earth orbit by the data relay company Kepler. NASA researchers will design, build, and test a flexible version of the antenna later this year.
“This is significant because we are able to use the same antenna to connect with two very different satellite systems,”
said Glenn researcher Bryan Schoenholz. Low Earth orbit satellites are relatively close – at 1,200 miles from the surface – and move quickly around the planet. Geostationary satellites are much farther – more than 22,000 miles from the surface – but orbit at speeds matching the Earth’s rotation, so they appear to remain in a fixed position above the equator.
The satellite testing was crucial for analyzing the aerogel antenna concept’s potential real-world applications. When modern aircraft communicate with stations on the ground, those signals are often transmitted through satellite relays, which can come with delays and loss of communication. This NASA-developed technology will make sure these satellite links are not disrupted during flight as the aerogel antenna’s beam is a concentrated flow of radio waves that can be electronically steered with precision to maintain the connection.
As new types of air transportation options are brought to the market and U.S airspace – from the small, piloted aircraft of today to the autonomous air taxis and delivery drones of tomorrow – these kinds of steady connections will become increasingly important. That’s why NASA’s Advanced Air Mobility mission and Transformative Aeronautics Concepts program are supporting research like the aerogel antennas that can boost industry efforts to safely expand the emerging marketplace for these transportation systems.
“If an autonomous air taxi or drone flight loses its communications link, we have a very unsafe situation,” Schoenholz said. “We can’t afford a ‘dropped call’ up there because that connection is critical to the safety of the flight.”
Schoenholz, Vivod, and others work on NASA’s Antenna Deployment and Optimization Technologies activity within the Transformational Tools and Technologies project. The activity aims to develop technologies that reduce the risk of radio frequency interference from air taxis, drones, commercial passenger jets, and other aircraft in increasingly crowded airspace. (Source: UAS VISION)

 

01 May 25. Cyber Update Key points
• On 30 April, international news outlets reported that The Co-operative Group (Co-op) partially shut down several of its systems as a precautionary measure after detecting an attempted cyber attack.
• Marks & Spencer (M&S) is currently carrying out its own remediation efforts after the retailer was targeted in a cyber attack on 21 April; these efforts will likely take several weeks (and result in protracted operational disruption) due to the severity and scale of the attack.
• Additional attempted cyber attacks against other high-profile retailers are likely in the short term given the timeline of these reported attacks.
• M&S will likely incur significant reputational damage, showcasing the operational and financial risks stemming from ransomware attacks against high-profile businesses.
Context
At the time of writing, the cyber criminal group ‘Scattered Spider’ is suspected to have conducted the attack against M&S; the retailer is currently working with several external cyber security and incident-response experts to investigate and manage the incident.
Forecast
Remediation efforts will likely take several weeks, resulting in prolonged operational disruption
Scattered Spider has yet to claim the attack and/or to issue a public ransom demand; we assess this will likely extend the duration of the current disruption. If Scattered Spider is the perpetrator, there is a realistic possibility that it obtained M&S’ system data in February. The stolen data included hashed credentials for Windows user accounts, which possibly enabled the group to hijack accounts and subsequently move laterally through the network. The perpetrator then deployed its custom encryptor to block access to all files hosted within the company’s virtual server infrastructure.
The attack temporarily disrupted in-store contactless payments until late on 24 April. On 25 April, the retailer announced that all online orders via its websites and applications would be halted indefinitely, highlighting the prolonged impact of this attack. The suspension of online services includes M&S products purchased via the online retailer ‘Ocado’, while in-store cash and contactless payments resumed with no further disruption.
On 30 April, M&S disclosed that various in-store products are also running low as a result of the continued disruption. The retailer announced that it is currently co-operating with cyber security and incident-response experts to investigate and resolve the issue; it also reported the attack to the UK National Cyber Security Centre (NCSC), whose founding chief executive, Ciaran Martin, called the incident a ‘highly disruptive event’. We assess this suggests that remediation efforts will likely take several weeks given the ostensible severity of the incident. This will likely result in protracted operational disruption as the retailer continues to regain access to its systems.
Additional cyber attack attempts against other retailers are likely in the short term, highlighting the elevated security and operational risks facing high-profile retailers and their customers
On 30 April, international news outlets reported that Co-op was forced to shut down its IT systems (partially) following the detection of the attempted cyber attack. This shutdown is a preventative measure to protect the company’s systems from further malicious attempts; the retailer has since stressed that no customer data has been compromised. Although some back office and call centre services have been impacted as a result of these measures, all other services (including those related to stores, funeral homes and online deliveries) remain unaffected. There is also no indication that the attacks against M&S and Co-op are related at the time of writing. However, we assess that additional cyber attack attempts against other high-profile retailers are possible in the short term given the timeline of the recent incidents.
M&S is yet to confirm whether any of its customer data was exposed during the attack. We assess there is a realistic possibility that the threat actors behind the attack did manage to exfiltrate sensitive data (before encrypting the company’s files) to coerce the firm into paying a ransom. As such, it is possible that any stolen data will be advertised for sale on the dark web, heightening the risk of follow-on social engineering attacks against M&S online customers in the short term.
M&S will likely incur significant reputational damage following the attack, highlighting the operational risks stemming from cyber attacks against high-profile retailers
The attack against M&S reportedly impacted several of the retailer’s clothing and household goods sales over the Easter bank holiday weekend (18-21 April). Around a third of these sales are typically made through the retailer’s online platforms, highlighting the financial impact of such incidents. We also assess that the attack will possibly negatively impact customer confidence in the short term (given the possibility that customer data was stolen); this will possibly lead to a decrease in revenue. Additionally, M&S shares fell by 2.3% on 25 April, marking one of the biggest losses in the Financial Times Stock Exchange 100 Index. This was followed by an additional 2.4% decrease on 28 April as investors reacted to the absence of positive news regarding the incident. We assess the developments highlight the reputational damage and financial losses associated with such incidents, at least in the short-to-medium term. (Source: Sibylline)

 

30 Apr 25. Somewear Labs, a leader in software-defined networking at the tactical edge, is proud to announce its fielding initiative with the United States Marine Corps (USMC), sponsored by the Defense Innovation Unit. The fielding initiative will accelerate the development of a modular open system and resilient tactical network necessary for meeting the unique requirements of the United States Indo-Pacific Command (INDOPACOM) and drive towards the future transition of the Advanced Tactical Communications program into the hands of the United States Marine Corps (USMC). Years of rigorous development and prototyping across military services produced a resilient, secure, and scalable communications solution. Through this effort, Somewear’s software-defined network supported joint and partner force operations, providing critical data management and transmission capabilities that bridge the gap between strategic command and the tactical edge. Under this initiative, Somewear Labs will build upon existing capabilities to automate data flow across multiple line-of-sight (LOS) and beyond-line-of-sight (BLOS) networks. The scalable, decentralized data fabric will dynamically adapt to disruptions while connecting operators and augmenting unmanned assets across all domains. The Somewear Grid platform will be utilized for advanced network management and configuration, enabling strategic oversight and real-time adjustments across these diversified networks. This capability ensures that critical information is prioritized and securely delivered across all echelons, maintaining operational continuity and tactical superiority in contested environments.
Somewear Labs will expand its communications solutions with an immediate focus on deployments with the United States Marine Corps (USMC). The Advanced Tactical Communications contract will support the USMC in adopting commercial capabilities for government use. This effort underscores DIU’s and the USMC’s shared alignment to utilize commercial technology for secure, operational deployments.
As Somewear Labs transitions its capabilities to deploying at scale with the USMC, this partnership will demonstrate Somewear’s flexibility and reliability for critical data exchange across INDOPACOM’s diverse tactical environments.
“Our partnership with the Defense Innovation Unit highlights our shared commitment to enhancing the capabilities of our armed forces,” said James Kubik, CEO of Somewear Labs. “This contract not only reinforces our role in supporting the DoD’s network modernization efforts but also marks a significant transition for Somewear and DIU. Together, we are transitioning from supporting tactical units to enterprise level field deployments, bringing robust, secure, and efficient communication tools to the hands of USMC operators.”
Somewear Labs remains dedicated to delivering capabilities at speed that meet the operational needs of today’s missions. We will continue to work closely with our partners at DIU and the United States Marine Corps, driving forward our shared goal to deploy a resilient, adaptable, and scalable tactical communications network. For more information, please visit somewearlabs.com.

 

30 Apr 25. Bittium and Nokia Demonstrated a Hybrid Tactical Communications Network for the Finnish Defence Forces. Bittium, a leading supplier of resilient tactical communications networks based on software-defined radio technology, and Nokia, a technology innovation leader delivering secure, reliable and resilient networks for defense communications, recently combined their solutions into a hybrid tactical communications network. The companies showcased the joint solution in a demonstration for the Finnish Defence Forces. The hybrid network enables the integration of Nokia’s military-grade 4G/5G bubbles as part of the tactical communications network and collaboration with other authorities that are using 4G/5G networks.
The demonstration showed the interoperability of Bittium’s and Nokia’s solutions as a hybrid tactical network where Bittium’s distributed tactical communications network independent from servers is in a key role. During the demonstration, the hybrid network was applied to different use cases, including delivery of voice across the network regardless of the terminal device, use of situational awareness applications, and transmission of video feed over the network.
“Our high-performance and interference-resistant communications system offers an excellent interface also for other communication solutions. The collaborative demonstration with Nokia proved the integrability of Nokia’s 4G/5G network technology with Bittium’s tactical communications system. The 4G/5G solutions complement tactical communications networks and the formed hybrid network expands the network used for operative command,” said Tommi Kangas, Senior Vice President of Bittium’s Defense & Security business segment.
Giuseppe Targia, Head of Space and Defense at Nokia, said: “This milestone in interoperability is a game-changer for mission-critical operations, seamlessly integrating Bittium’s tactical communications solutions with our military-grade 4G/5G technology. By delivering secure and resilient connectivity with high data speeds, we empower real-time data and enhanced operational agility in even the most challenging environments.”
The demonstrated solution consisted of Bittium Tactical Wireless IP Network™ (TAC WIN) and Bittium Tough SDR™ vehicle and soldier radios, which were networked with Bittium TAC WIN Waveform™ and connected the mobile 4G/5G users to the hybrid network. The 4G/5G bubbles were formed using Nokia’s vehicular Banshee Mobile Radio (BMR) and Banshee Tactical Radio (BTR) which was carried in a backpack worn by a soldier. The BMR and BTR provided the network connectivity for smartphones, including Bittium Tough Mobile™2, that used a situational awareness application. Bittium Tough VoIP Service™ enabled voice across the hybrid network.

30 Apr 25. Northrop Grumman Corporation’s (NYSE: NOC) IVEWS (Integrated Viper Electronic Warfare Suite) has successfully completed Operational Assessment flight testing on U.S. Air Force F-16 aircraft, demonstrating its effectiveness against advanced radar-guided threats. This accomplishment represents an important milestone in the maturation of the system and provides an option for the Air Force to go to production and fielding.
• During testing, IVEWS was subjected to highly accurate representations of complex, modern radio frequency (RF) threats in operationally relevant environments, verifying the results seen during rigorous laboratory, chamber and early flight testing.
• The system detected, identified and countered the full range of radar threats, providing complete RF protection for operationally representative missions and enhanced situational awareness of the battlespace.
• IVEWS and Northrop Grumman’s SABR radar demonstrated digital interoperability. By communicating on a pulse-by-pulse basis, the two systems ensure that neither one will reduce the performance of the other, allowing for simultaneous electronic warfare and targeting capabilities.
Experts:
Lt. Col. Christopher B. James, USAF, Deputy Division Chief, F-16 USAF Programs: “Our USAF F-16 System Program Office, in collaboration with our Northrop Grumman, Lockheed Martin, Eglin’s OFP/CTF and Terma partners, has successfully completed the IVEWS Operational Assessment with excellent results. The team conducted more than 70 flights and 100-plus flying hours in a seven-month timeframe. Not only did the system perform well, but it also worked during its first flight on two aircraft, which is unprecedented for a complex and fully integrated electronic warfare system. It has earned the slogan, ‘IVEWS, works first time, every time.’”
James Conroy, vice president, navigation, targeting and survivability, Northrop Grumman: “These successful flight tests showed the maturity and readiness of IVEWS to protect the F-16 fleet against the most advanced radio frequency threats – modernizing the Viper with the electronic warfare capabilities it needs to remain lethal and survivable for years to come.”
Details on IVEWS Flight Testing:
Flight testing took place at Eglin AFB, Florida, and Nellis AFB, Nevada, as part of the Operational Assessment of the system. IVEWS is installed on two F-16 Block 50 aircraft and has demonstrated stable performance across more than 70 sorties, covering a range of environmental conditions and typical mission scenarios including air-to-air, air-to-ground and mixed threat engagements. While laboratory and chamber threat simulations provide opportunities to test technical capabilities, flight testing on customer aircraft remains the gold standard for verifying system performance under combat-representative conditions.
Northrop Grumman’s IVEWS improves aircraft survivability in highly contested and congested electromagnetic spectrum environments, maintaining relevance for fourth generation platforms in the future fight. Fully digital and founded on open systems design principles, the ultra-wideband architecture in IVEWS provides extended frequency coverage including millimeter wave, 360-degree spatial coverage and operationally relevant geolocation. IVEWS is one example of how Northrop Grumman is helping its customers worldwide modernize to meet the challenge of evolving threats.
Northrop Grumman is a leading global aerospace and defense technology company. Our pioneering solutions equip our customers with the capabilities they need to connect and protect the world, and push the boundaries of human exploration across the universe. Driven by a shared purpose to solve our customers’ toughest problems, our employees define possible every day.

 

30 Apr 25.  France: Government sector will face long-term security risks from Russian state-sponsored groups. On 29 April, the National Agency for the Security of Information Systems (ANSSI) in France reported that the Russian state-sponsored group ‘APT28’ targeted multiple French entities in various cyber operations since at least 2020. In 2021, APT28 repeatedly targeted email and web server providers to disseminate phishing attacks, using commercial services as its attack infrastructure to remain obfuscated. The group has primarily targeted organisations from the aerospace, financial, governmental, research, technology and think tank sectors. APT28’s attacks have also reportedly focused on stealing strategic intelligence from governmental, diplomatic, research, and think tank organisations since the beginning of 2024, highlighting a potential shift in the group’s cyber strategy. This report follows French Foreign Minister Jean-Noël Barrot’s allegation that APT28 interfered with Emmanuel Macron’s candidacy during the 2017 presidential campaign. We assess that France will likely remain a primary target in the medium term, as it appears to be leading efforts to support Ukraine, sustaining security risks. (Source: Sibylline)

 

29 Apr 25. US Army seeks real-time modelling for battlefield C2. The US Army is looking to develop a new suite of modelling tools designed to allow combat commanders the ability to collect, consolidate, and process real-time battlefield data and distil that information into viable courses of action (COAs) quickly. Officials from Program Executive Office Command, Control, Communications-Network (PEO C3N), in conjunction with Army Futures Command (AFC), are soliciting industry input for prototype development for the new suite of Operational Modeling Tools (OMTs), according to a 25 April broad agency announcement (BAA).
“These [OMT] tools must employ advanced, data-centric methods capable of efficiently consuming and producing actionable information. Solutions should integrate top-down strategic and bottom-up tactical data streams to deliver intuitive visual and auditory alerts, ensuring real-time and near-realtime situational awareness,” service officials said in the BAA.
Regarding the COAs produced out of the OMT suite of tools, service programme officials have defined three key criteria the tools should provide combat commanders.
First, the OMT algorithms used to assist in COA development should have an integrated “transparent analytic capability” to confirm the algorithm validity, according to the BAA. Second, the OMT suite should have a “comprehensive logging” requirement for all validation metrics used to develop COAs. Finally, these validation metrics must be paired with a slate of “clearly communicated confidence intervals” for all COAs developed via the OMTs, the solicitation stated.
With regard to the OMTs, they are expected to provide combat commanders with “a reliable and quantifiable operational forecast, enhancing their ability to anticipate threats, dynamically adapt, and effectively manage current and future missions”, army officials said in the BAA. (Source: Janes)

 

29 Apr 25. Anduril announces lighter, smaller Pulsar jammer. Defense technology firm Anduril Industries on Tuesday rolled out a lighter, more mobile version of its Pulsar electronic warfighter system, designed to track and take out enemy targets, including drone swarms.
The software-driven signal jammer, Pulsar-L, comes in two configurations — airborne and expeditionary. The company unveiled its first three Pulsar variants last year: Pulsar-V, which is a vehicle version; Pulsar Alpha, which is airborne; and a fixed-site configuration.
The primary differentiator between those variants and Pulsar-L is size, weight and power, Anduril’s Chief Revenue and Strategy Officer Chris Brose told reporters Monday. The smaller system is about the size of a shoebox and weighs less than 25 pounds.
“Think of Pulsar-L as a smaller form factor that’s going to extend that capability even farther out to the tactical edge onboard platforms and weapon systems,” Brose said.
Pulsar-L is already being used in operations and was first fielded last year. Brose declined to tell reporters where it’s stationed, but noted the system is “participating in real-world operations in the most stressing EW environments.”
Brose touted the speed at which the Anduril developed Pulsar-L, saying it took just eight months to move from the concept phase to fielding, largely because of the company’s common hardware and software platforms.
Pulsar-L can operate independently or with Anduril’s Lattice software, is user-friendly and can be set up in a matter of minutes, officials said. The company is pitching the system as an alternative to clunkier EW capabilities that it described in a press release as “rigid, manual, cumbersome and threat-specific.”
The system’s usability is closely tied to its autonomous technology, according to Sam El-Akkad, general manager of radio frequency and EW systems.
“All the operator needs to do, they can put it in an autonomous mode where it ingests the spectrum, figures out what’s out there, decides what’s a threat and what’s not and then engages those things,” he said in the briefing with Brose. “It all happens magically under the hood.”
With the first units fielded, Anduril is focused on ramping up production. El-Akkad said the firm plans to produce more than 100 low-rate initial production units by the end of this year, with a goal of scaling to thousands of Pulsar-L jammers annually in the next few years.
Brose declined to name Anduril’s early Pulsar-L buyers, but the company has been awarded several contracts in recent years for similar technologies.
Last October, an undisclosed Defense Department bought an unspecified number of Pulsar jammers as part of a $250 m counter-drone package that included 500 all-up rounds of Anduril’s Roadrunner interceptor.
The firm is also on a 10-year, indefinite-delivery, indefinite-quantity contract worth up to $1 bn with U.S. Special Operations Command to supply counter-drone hardware and software, including Pulsar, Lattice, Sentry Tower and its Anvil interceptor. (Source: News Now/Defense News)

 

28 Apr 25. Commtact, a global provider of advanced wireless communication solutions for defense, security forces, and robotic platforms, will showcase its latest innovation, the Micro Phoenix, at the DEFEA 2025 exhibition in Athens, Greece. As part of the company’s portfolio of mission-critical communication systems, the Micro Phoenix delivers secure, resilient, and high-performance connectivity for land, air, and maritime platforms, in a compact, lighter-than-ever design. Commtact is also proud to announce its first contract for the Micro Phoenix, securing a deal with a defense customer to integrate the system into missiles and unmanned platforms.
The Micro Phoenix is a compact, lightweight data link solution designed for drones, missiles, and unmanned systems. Engineered with SWaP (Size, Weight, and Power) constraints in mind, it weighs only 110 grams and offers advanced full-duplex wideband digital links with robust anti-jamming and GPS-deprived operational capabilities. The system supports multiple topologies, including Point-to-Point (P2P), Point-to-Multipoint (P2MP), Relay, and Multi-Platform Smart MESH, ensuring long-range connectivity of up to 150 km in complex operational environments.
“The introduction of the Micro Phoenix marks a significant step in Commtact’s continuous innovation in secure and resilient communication solutions,” said Guy Avrahami, VP Sales & Marketing at Commtact. “This system is tailored to meet the growing demand for lightweight, high-performance communication solutions for unmanned and missile platforms. It demonstrates our commitment to delivering value for customers in the field of munitions—where information must be transferred in real-time. We are proud to announce our first contract for the Micro Phoenix, demonstrating the immediate value it brings to our customers.”
Building on the success of its predecessor, the Phoenix system, the Micro Phoenix seamlessly integrates with existing Phoenix command and control infrastructure. This enables current users of the Phoenix system to expand their capabilities without requiring additional control systems, enhancing operational flexibility and cost-effectiveness.
The Micro Phoenix is also equipped with AES-256 encryption and optional CAT & TSV security layers, providing high-level data protection. Its Software Defined Radio (SDR) architecture allows for configuration and adaptation based on customer-specific requirements, making it an ideal solution for defense and security forces worldwide.
At DEFEA 2025, visitors to Commtact’s booth will have the opportunity to explore the Micro Phoenix and the company’s full range of advanced wireless communication solutions which are ideal for aerial, ground, and naval operations.
About Commtact
Commtact is a global leader in mission-critical, battle-proven digital wireless communication solutions for defense applications. Specializing in aerial, ground, and naval operations, Commtact delivers innovative and resilient field-proven systems featuring advanced MESH networking and robust anti-jamming capabilities, ensuring reliable performance in the most challenging environments. For more information, visit https://commtact-systems.com/

 

28 Apr 25. Global: New RaaS model highlights long-term security, financial risks facing businesses. On 26 April, international news outlets reported that the ransomware group ‘DragonForce’ has advertised a new Ransomware-as-a-Service (RaaS) model on the dark web since at least March. The group reportedly provides its affiliates with pre-established infrastructure (including negotiation tools, storage for stolen data and malware administration) with which to conduct ransomware attacks; we assess this likely appeals to a large number of low-skilled and low-resource threat actors. Affiliates can also use the DragonForce encryptor to encrypt a system’s data and to demand a ransom payment, likely in a bid to remain obfuscated or to begin building their own brand reputation. DragonForce retains 20% of its affiliates’ profits, underscoring the lucrative nature of this operation. The group also claims that several affiliate entities capable of targeting a wide variety of systems are now operating the new model, highlighting its potentially widespread impact. As such, we assess this showcases the long-term security, financial and operational risks stemming from the continuous expansion of ransomware enterprises. (Source: Sibylline)

 

25 Apr 25. Soldiers to access Northrop Grumman IBCS mobile app in 3-5 years. While the concept is in an early stage, and with a delivery timeframe in mind, an IBCS application comes with potential issues. Northrop Grumman is planning to make its Intregrated Battle Command System (IBCS) accessible to soldiers at the tactical level through a mobile app, with an intention to deliver the capability within the next five years. This next step in the IBCS programme comes in response to discussions with the US Army regarding its requirements.
The IBCS capability, which first reached initial operating capability (IOC) in April 2023, connects sensors and effectors across land, sea, and air that were never designed to work together into one command and control (C2) system, providing a holistic picture of the battlespace.
This agnostic network allows systems to cohere and share data to execute an optimal response to enemy threats, which is why IBCS is often considered in an integrated air and missile defence (IAMD) context.
At present, IBCS is directed through numerous Engagement Operation Centres (EOCs), effectively mobile shelters hosting a C2 centre comprising between eight to ten personnel. As many as six EOCs are deployed to support one Patriot battery.
Soon, however, this grand picture of the battlespace will be more readily accessible to soldiers on the ground.
While the concept remains an area of focus at an early stage, and with a delivery timeframe in mind, questions remain about how an IBCS application would be delivered. This includes digital security as a mobile app, as well as questions around the role of a tactical force with a view of the operational level.
Army Technology contacted Northrop Grumman but the corporation did not provide comment before publication.
IBCS: how it works
In an immersive demonstration during IDEX 2025 in February, a Northrop Grumman spokesperson explained to Army Technology that sensors in the IBCS system will make recommendations of where to place assets to optimise coverage of an area of operations.
The orchestration is done automatically through a computer programme called the Integrated Defense Designer, which has a number of algorithms.
“We have the ability to put it in almost a semi autonomous mode,” the Northrop Grumman spokesperson explained. “The operator is on top of the loop. The system is making the recommendations and is going to launch on its own, unless you deny it.”
The data collected is grouped into priorities. The more important data gets higher priority over the network, so that it gets passed around, and lower priority data would have more time. If it becomes congested, the IBCS system ensures that the higher priority data take the lead.
“We were given requirements for our software to be very modular, so it’s very modular,” the spokesperson said, adding that the code was broken down into segments, rather than in a single monolithic block.
“If we need to go in and modify some code or add a new module, we can do that quickly and easily,” the spokesperson detailed.
Demand signal
Besides the United States, Poland is currently the only other operator which uses IBCS to optimise its IAMD architecture, which includes an assortment of US and European missiles and systems that constitute its short-range PILICA+ and NAREW air defense structures. Poland’s IBCS reached IOC in December 2024.
“I know for a fact that our project office that manages this programme have investigated using IBCS in a variety of scenarios across the globe,” the Northrop Grumman spokesperson said.
“It’s the same storyline. Maybe different threats, different distances, of course, but the same concepts, same interest, and same demand signal.”
Northrop Grumman IBCS spokesperson
Other nations have expressed interest in Northrop Grumman’s integrator product. The spokesperson revealed official visits to countries in the Asia-Pacific region.
Likewise, many Gulf countries consulted the US supplier during IDEX 2025 to discuss their unique requirements and existing architectures, without naming any specific nations.
“It’s the same storyline,” the spokesperson said. “Maybe different threats, different distances, of course, but the same concepts, same interest, and same demand signal.” (Source: airforce-technology.com)

 

24 Apr 25. Cyber Update
Key points
• Reports of a new, stealthy variant of the Phishing-as-a-Service (PhaaS) kit ‘Tycoon2FA’ underscore long-term security and financial risks to firms (see Sibylline Cyber Daily Analytical Update – 14 April 2025).
• A new remote access trojan (RAT; ‘ResolverRAT’) will sustain long-term security and data-theft risks to the healthcare and pharmaceutical sectors (see Sibylline Cyber Daily Analytical Update – 15 April 2025).
• European diplomatic entities face long-term security and cyber espionage risks from the Russian state-sponsored group ‘Midnight Blizzard’ (see Sibylline Cyber Daily Analytical Update – 16 April 2025 and our Technical analysis below).
• The China-nexus group ‘UNC5221’ has used a new backdoor (‘BRICKSTORM’) in a cyber espionage operation, highlighting long-term security risks to European organisations (see Sibylline Cyber Daily Analytical Update – 17 April 2025).
• A cyber operation will sustain security and information-theft risks to global national infrastructure from North Korean state-sponsored group ‘Larva-24005’ (see Sibylline Cyber Daily Analytical Update – 22 April 2025).
• A data breach of South Korea’s largest telecommunications provider underscores the long-term security risks facing the sector (see Sibylline Cyber Daily Analytical Update – 23 April 2025).
• The North Korean state-sponsored group ‘Void Dokkaebi’ is using Russian infrastructure to conduct cyber operations, sustaining long-term security risks to global entities (see Sibylline Cyber Daily Analytical Update – 24 April 2025).
• A new ‘Mimic’ ransomware variant (‘ELENOR-corp’) is targeting the healthcare sector, underscoring long-term security, disruption and financial risks (see Sibylline Cyber Daily Analytical Update – 25 April 2025 and our Technical analysis below).
Technical analysis of weekly stories
The Russian state-sponsored group Midnight Blizzard has been targeting diplomatic entities in Europe in a cyber espionage campaign since at least January. Midnight Blizzard sends spear phishing emails from a spoofed email domain to trick victims into clicking on an embedded link and to infiltrate targeted systems. The emails purport to invite victims to a wine tasting event and are sent from a domain emulating an unnamed ministry of foreign affairs. If the right system parameters are met, the link installs two legitimate files to feign legitimacy alongside covertly installing a custom malware loader (‘GrapeLoader’). Additionally, the link redirects the user to the legitimate Ministry of Foreign Affairs website to evade detection. GrapeLoader establishes communication with command-and-control (C2) infrastructure before initiating system reconnaissance and data exfiltration. The malware primarily collects system information to deploy a new version of the ‘WineLoader’ backdoor. WineLoader enables Midnight Blizzard to establish persistence within compromised systems and conduct additional malicious activity. Both malware variants boast several new, advanced detection evasion mechanisms, thus showcasing the development of Midnight Blizzard’s cyber capabilities.
Threat actors have used a new variant of the Mimic ransomware (ELENOR-corp) to target the healthcare sector since at least March. In one instance, threat actors likely exploited pre-obtained access to a compromised system to deploy the ransomware. Threat actors conceal ELENOR-corp within an inaccessible hidden directory to evade detection before abusing the sticky keys exploit to enable remote code execution. ELENOR-corp uses remote desktop protocol (RDP) to facilitate lateral movement and to maintain persistence within compromised systems. It subsequently disables all file sharing and deletes backup files, highlighting the sophistication of the ransomware’s capabilities to hinder recovery and maximise its impact. ELENOR-corp modifies the system’s power settings to accelerate the encryption process and performs other operations to further optimise file access and encryption. The ransomware can also dynamically fine-tune the encryption parameters if Microsoft’s .NET Framework 4 is detected, further showcasing ELENOR-corp’s advanced capabilities. This enables threat actors to effectively block access to all of a system’s files and demand a ransom payment for decryption. Additionally, ELENOR-corp exfiltrates sensitive data from compromised systems prior to encryption to coerce victims into paying the ransom. The ransomware simultaneously deletes all system logs, histories and registry entries to evade detection and hinder analysis, pointing to its stealth.
Non-exhaustive recommendations to mitigate against these threats include:
• Monitor devices and networks for suspicious activity
• Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
• Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
• Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering
Our cyber word(s) of the week: Sticky keys exploit. (Source: Sibylline)

 

28 Apr 25. NASA’s Airborne Laser Communication Testbed. The Airborne Laser Communication Testbed (ALCT) is a research platform in high-data-rate communication systems designed to complement existing aeronautical radio frequency (RF) communications. This innovative technology offers several distinct advantages: exceptional data transmission rates, resistance to jamming, enhanced physical security, and low probability of interception/detection (LPI/LPD). Notably, it operates independently of RF spectrum allocations, requiring clear line of sight (LOS) to establish a link within its operational range. The system’s reliability has been extensively validated through three comprehensive flight campaigns, accumulating over 50 hours of operational link-time across aircraft platforms – including the DHC-6 Twin Otter and PC-12 – with ground station operations centered at NASA Glenn Research Center’s hangar facility. Recent developments of the ALCT have provided practical approaches to critical aerospace communication challenges. Through rigorous flight testing conducted between 2019 and early 2025, research teams have successfully demonstrated the system’s capability to maintain high-speed data transmission across significant distances in both air-to-ground and preliminary air-to-air configurations.
This advanced laser communication technology has proven its viability as a powerful complement to conventional RF systems, showing promise for both manned and unmanned aircraft operations.
The ALCT’s ability to sustain gigabit-class data rates at distances up to 60km slant path, while maintaining operational links at even greater ranges, marks a significant advancement in aeronautical communication capabilities. A particularly noteworthy achievement has been the successful implementation of air-to-air tracking, validated through retroreflector testing. These innovations hold special significance for urban air mobility applications and address the growing demand for reliable, high-bandwidth communication solutions in increasingly congested airspace environments. (Source: UAS VISION)
——————————————————————————————————————————————————————————————————————————————————————————————————————————–
Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.
We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete. Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

PIVOT TO GROWTH STRATEGY

Our new Pivot to Growth strategy presented during our May 2021 Investor Day focuses on maximizing revenue and operating income growth for our shareholders. Since early 2021, we have implemented numerous steps under this new strategy, including the simplification of our story and business model where we transitioned to a new and more cohesive segment and end market structure. This, in turn, positions us to further unlock shareholder value.
Curtiss-Wright is an integrated business that provides highly engineered products, solutions and services with two-thirds of our sales to Aerospace & Defense (A&D) markets, as well as critical technologies in demanding Commercial Power, Process and Industrial markets.
Importantly, Curtiss-Wright is differentiated because we have strength in the combined portfolio benefitting from long-term stability in our defense businesses and agility in our commercial businesses.

——————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

April 18, 2025 by

17 Apr 25. Europe: New backdoor underscores long-term security, espionage risks from China-nexus groups. On 15 April, the security company NVISO reported that the China-nexus threat group ‘UNC5221’ has been targeting European organisations in a suspected cyber espionage operation since at least 2022. The group has reportedly been employing a new version of the custom backdoor ‘BRICKSTORM’ to target Windows environments. BRICKSTORM was originally developed to target Linux servers; this suggests that UNC5221 has modified its tools in order to expand its victim pool. The new variant facilitates lateral movement and obfuscation within compromised systems via file-management and network-tunnelling capabilities. UNC5221 then exploits legitimate network protocols to execute commands and conduct additional malicious activity. Several different cloud providers host BRICKSTORM’s command-and-control (C2) infrastructure; the group also uses common protocols for communication. We assess this showcases the sophistication of the group’s detection-evasion capabilities. As such, the operation underscores the security and cyber espionage risks facing European entities from China-nexus groups amid currently elevated geopolitical tensions. (Source: Sibylline)

 

15 Apr 25. Portugal and Brazil to jointly develop a new C-390 Millennium variant for strategic intelligence gathering. On April 1, 2025, during the LAAD Defense & Security exhibition in Rio de Janeiro, the Portuguese Air Force officially announced its decision to join Embraer and the Brazilian Air Force (FAB) in joint studies aimed at adapting the C-390 Millennium multi-mission transport aircraft to perform Intelligence, Surveillance, and Reconnaissance (ISR) missions. The announcement was made at a formal ceremony attended by General João Cartaxo Alves, Commander of the Portuguese Air Force; Lieutenant-Brigadier Marcelo Kanitz Damasceno, Commander of the Brazilian Air Force; Francisco Gomes Neto, President and CEO of Embraer; and Bosco da Costa Junior, President and CEO of Embraer Defense & Security. A concept image was presented showing the roll-on/roll-off modular ISR mission system currently under development. This system is designed to enable ISR capabilities while retaining the aircraft’s existing multi-mission functions. The ISR-capable version of the aircraft is officially designated as the C-390 IVR. This variant is part of an effort led by the Brazilian Air Force and Embraer to integrate ISR capabilities such as synthetic aperture radar, electro-optical and infrared sensors, advanced communication systems, and two hardpoints for external payloads. The development is intended to maintain compatibility with current operational and logistical systems. Structured studies are ongoing to evaluate potential adaptations of the C-390 platform, particularly for maritime patrol and ISR tasks. According to Lieutenant-Brigadier Damasceno, these studies are being conducted efficiently and systematically. Bosco da Costa Junior stated that the initiative is aligned with an ongoing partnership to extend the aircraft’s operational scope.

The announcement by Portugal builds on developments from December 3, 2024, when Embraer and the FAB signed agreements at the Mostra BID National Defense and Security Fair in Brasília to develop ISR and maritime patrol capabilities for the aircraft. These efforts are focused on increasing surveillance coverage across multiple operational environments, including coastal zones and national airspace. The concept of a roll-on/roll-off ISR mission system supports rapid reconfiguration for different missions, including those involving monitoring of territorial waters, Exclusive Economic Zones, and national infrastructure. The Portuguese Air Force’s participation adds operational experience and contributes to technical evaluation processes for the ISR configuration. The C-390 IVR development aligns with increased global demand for ISR platforms. The ISR aircraft and drones market was valued at $13.37 bn in 2023 and is projected to reach $22.1 bn by 2033. ISR systems are used to monitor large areas for security, environmental, or resource-related purposes. Brazil’s maritime geography and offshore interests are cited as drivers behind the decision to adapt the C-390 to ISR and maritime patrol missions. Similar needs exist in other regions such as Southeast Asia, the Middle East, and Eastern Europe. Countries already operating the C-390 Millennium, including South Korea and Sweden, may assess the ISR variant’s relevance for their maritime or border surveillance requirements. The C-390 Millennium was developed by Embraer beginning in the mid-2000s with financial support from the Brazilian government and Air Force. It was designed as a twin-engine, jet-powered alternative to turboprop tactical transports such as the C-130. The project received a $1.5bn development contract in April 2009, and the aircraft’s first flight occurred on February 3, 2015. The aircraft entered service with the Brazilian Air Force in 2019. By June 2022, the C-390 fleet had flown over 8,200 hours across 6,000 flights. According to Embraer and the FAB, the platform achieved a technical availability rate of approximately 80% and a mission completion rate of 99.5%. The aircraft has been used in various missions, including pandemic response in Manaus, humanitarian aid to Lebanon and Haiti, joint exercises in the United States, Antarctic supply flights, and repatriation efforts during the Russia–Ukraine conflict. Portugal has been part of the C-390 program since 2010. It ordered five aircraft in 2019 to replace its C-130 fleet. The first C-390 was delivered in October 2022, reached full operational status in October 2023, and has since completed transatlantic missions and international exercises. Portugal’s OGMA company is involved in the industrial production of the aircraft, including structural components and systems. On April 25, 2023, Brazilian President Luiz Inácio Lula da Silva and Portuguese Prime Minister António Costa announced that the KC-390 could be assembled at OGMA for European customers. The Portuguese Air Force’s involvement in ISR studies reflects its existing operational use of the aircraft and participation in the industrial base. (Source: Google/armyrecognition.com)

 

16 Apr 25. The USAF is demonstrating its commitment to joint warfighting capabilities, integrating airpower into a vast network of sensors and shooters during Project Convergence Capstone 5, a large-scale military modernization experiment held amidst the desolate California desert, the Shadow Operations Center-Nellis Air Force Base, Nevada, and other locations February through April. Project Convergence Capstone 5, hosted by Army Futures Command, serves as a vital experimentation ground for the future of warfare. It focuses on the continued integration of joint and multi-national layered air and missile defense systems. The Air Force Futures Directorate is the primary organization responsible for the Air Force contributions to the Army’s large force experiment. The event brings together forces from the Air Force, Space Force, Air National Guard, Army, Navy, Marine Corps and coalition partners from the United Kingdom, Australia, Canada, New Zealand, France and Japan.

“We are in the middle of a generational evolution when it comes to developing operational concepts, fielding technologies, and pursuing new levels of force integration,” said Lt. Gen. Dave Harris, deputy chief of staff for Air Force Futures. “These events are critical as we develop and deliver capabilities for the joint force that provide decision advantages that keep the U.S. well ahead of the threat.”

A key program for the experiment is the continued development of the Tactical Operations Center-Light Major Release 1, a program managed by the Department of the Air Force Program Executive Office for Command, Control, Communications and Battle Management. Airmen used the system to refine integration with joint force systems, including Palantir’s AI-driven Maven Smart System and the System-of Systems Technology Integration Tool Chain.

“PC-C5 brings multiple agencies together, allowing us to integrate diverse software and applications into a unified operating picture and troubleshoot systems like the TOC-L,” said Tech. Sgt. Timothy Keefer, a weapons and tactics flight chief for the 752nd Operations Support Squadron, and acting as the advanced Joint Interface Control Center operator for the experiment. “Legacy systems offer some mobility, but not agility. The TOC-L moves us toward both, which is essential for future battlefields.”

PC-C5 serves as a crucial operational venue for data-gathering, providing valuable insights into the effectiveness of these programs within the DAF BATTLE NETWORK, the Air Force’s contribution to Combined Joint All Domain Command and Control. Air Force Futures creates the Air Force’s strategy across multiple time epochs, develops the corresponding force design, and advocates for the necessary requirements to ensure the Air Force possesses the capabilities to deter, and if required, defeat strategic competitors. Their Advanced Battle Management System Cross Functional Team is leading the planning, management and execution of Air Force support to PC-C5.

The Air Force Operational Test and Evaluation Center is leading the Air Force’s campaign of learning during the experiment.

“We’re focused on delivering valuable data to senior leaders – data about both the systems and their human operators,” said Kristopher Looney, AFOTEC’s Experimentation Directorate director. “System data reveals precisely how operators and technology interact, highlighting successes and failures. Directly interviewing operators provides crucial context, helping us understand why things worked or didn’t.”

The shift from traditional, siloed testing to collaborative development in a real-world environment is central to the Air Force’s modernization strategy. Project Convergence embodies this approach, allowing for rapid iteration and feedback loops that accelerate the development and refinement of tactics, techniques and procedures for multi-domain operations.

“We use mission threads focused on shortening the kill chain,” said Tech. Sgt. Jeylend Kitchen, lead non-commissioned officer in charge of group evaluations for the 552nd Air Control Group and acting as the weapons director for the experiment. “Current mission threads involve extensive communication to verify information, which can create delays. We aim to automate this process, enhancing decision advantage. AI-enabled software like STITCHES and MSS helps ensure operators have accurate, readily available information based on established TTPs.”

PC-C5 demonstrated the TOC-L MR1’s interoperability with Army command and control systems and other joint assets, a key aspect of the DAF BATTLE NETWORK, the systems-of-systems that provides resilient decision advantage.

“This experiment continues to show us the critical importance of human-machine teaming within the CJADC2 structure,” said Army Chief Warrant Officer 3 Matthew Middlebrooks, a member of the Army’s cross functional team for the 108th Air Defense Artillery Brigade and acting as a JICC operator for the experiment. “While we’ve made strides in system integration, we must equally prioritize training and procedures that optimize human-machine teaming. This experiment allows us to observe our procedures in action, identifying areas for refinement and gain a clear understanding of the joint air and ground defense picture.”

The lessons learned from PC-C5 will directly inform future readiness and modernization activities, ensuring the Air Force and its joint and coalition partners are equipped to address emerging threats. By analyzing data, refining TTPs, and identifying areas for improvement in technology, training and doctrine, the Air Force continues to evolve its capabilities to maintain its competitive edge in an increasingly complex global security environment. (Source: ASD Network)

 

11 Apr 25. ESSOR to enter stage 4. The European Secure Software Defined Radio (ESSOR) programme will enter stage 4 in July, a Rohde & Schwarz (R&S) spokesperson told Janes on 10 April. The stage 4 of the programme will involve the fielding of a high data-rate waveform (HDRWF) and development of a narrowband waveform (NBWF) with the aim of ensuring native interoperability among different types of radios for NATO and its Federated Mission Networking (FMN) capability. Andreas Boyd Buchin, operations director at the Alliance for ESSOR (a4ESSOR) joint venture, told journalists including from Janes visiting R&S at the beginning of April that the ESSOR programme seeks to enable interoperability of mission-critical radio connectivity assets for all domains by co-developing and standardising waveforms and the supporting infrastructure. It aims to develop pan-European software-defined radio (SDR) technology to improve the interoperability of armed forces participating in coalition operations. The participating countries are Germany, Finland, France, Italy, Poland, and Spain. The Bonn-based Organisation for Joint Armament Cooperation (Organisation Conjointe de Coopération en matière d’Armement: OCCAR) is the ESSOR programme office, which has contracted a4ESSOR made up of Bittium, Indra, Leonardo, Radmor, R&S, and Thales. The programme cost is EUR290m (USD323.7m) for 2008–25. ESSOR is the design authority and customer focal point tasked with the management, co-ordination, and control of the design and development of ESSOR products. In addition to the HDRWF and NBWF, these products include the ESSOR 3-Dimensional Waveform (3DWF) and ESSOR Satellite communication Waveform. There will be NATO Standardization Agreements (STANAGs) for all four waveforms. (Source: Janes)

 

16 Apr 25. US Navy adds Persistent Systems to FoS USV IDIQ contract. Company’s mobile ad hoc network (MANET) technology to support Navy’s vision of integrating manned and unmanned formations. Persistent Systems, LLC (“Persistent”), a leader in mobile ad hoc networking (MANET), announced today the U.S. Navy has selected the company as one of 88 participants for a $982.1 m, indefinite delivery/indefinite quantity (IDIQ) contract to support current and future data links for unmanned surface vessels (USVs). The USV Family of Systems (FoS) contract, first awarded in 2020, now includes 88 contractors supporting the Navy’s effort to integrate USVs into its fleet. Building on its experience working with the Unmanned Systems divisions of Naval Surface Warfare Centers and Naval Information Warfare Centers, Persistent Systems will supply its MANET solutions to Naval Sea Systems Command (NAVSEA) to enable secure, resilient data links for RDT&E efforts in support of the Navy’s USV program.

“As a leading provider of MANET solutions for this contract, we will serve as the critical data link for maritime unmanned reconnaissance vehicles, supporting numerous mission sets, including maritime domain awareness, sea control/sea denial, and swarming operations,” said Ed Leopold, Director of Business Development at Persistent Systems. “This is essential for maintaining real-time situational awareness for expeditionary forces and supporting collaborative autonomy of unmanned systems.”

The company’s MPU5 networking devices leverage their highly scalable Wave Relay® MANET to seamlessly connect users in a true peer-to-peer fashion, allowing for the high-throughput transfer of voice, video, text, sensor data, and GPS information without needing external infrastructure.

“As the U.S. Navy emphasizes the need for manned and unmanned formations, we are seeing the shift from pilot programs and proof of concepts towards the implementation of validated USV upgrades as part of their Unmanned Maritime Autonomy Architecture (UMAA),” says Leopold.

This IDIQ contract builds on Persistent’s ongoing work with the Navy. Over the past few months, the company has supported several naval efforts: In July, the U.S. Naval Information Warfare Center Pacific awarded Persistent a contract to network USVs, individual operators, ships, and ground control stations; Persistent Systems supported networking efforts during Valiant Shield, a joint exercise conducted every two years across the INDOPACOM Area of Responsibility and; During the Paris Olympics, the French navy used Persistent’s MANET technology on vessels and shore infrastructure to secure a sailing competition.

“We look forward to building on these relationships, and this selection reinforces our position as a trusted supplier for the U.S. Navy,” Leopold concluded. (Source: ASD Network)

 

11 Apr 25. Cyber Update Key points.

  • A large-scale, multi-pronged phishing campaign (‘PoisonSeed’) points to heightened financial risks for cryptocurrency users and our Technical analysis below).
  • The distribution of a highly sophisticated artificial intelligence (AI) cyber attack automation tool will increase long-term security risks facing global entities.
  • A spike in cyber attacks against Internet-of-Things (IoT) devices underscores heightened security risks stemming from botnet infrastructure.
  • Activist groups face long-term surveillance and data-theft risks from Chinese state-sponsored actors (see Sibylline Cyber Daily Analytical Update – 10 April 2025).
  • A cyber operation by the Russia-nexus group ‘Gamaredon’ highlights the prolonged security and espionage risks for Ukraine-based Western military entities and our Technical analysis below).

Technical analysis of weekly stories

Unidentified threat actors are targeting global cryptocurrency users in a multi-pronged financially motivated campaign (PoisonSeed). The campaign starts with the creation of fake login pages emulating high-profile email marketing providers; threat actors then distribute the fake pages via spoofed email domains, tricking victims into entering their credentials to hijack targeted user accounts. Threat actors then export existing marketing mailing lists from the compromised systems to identify potential targets. Subsequently, the actors disseminate mass cryptocurrency-related phishing emails, using compromised and spoofed email domains to appear legitimate and bypass security mechanisms. They also generate a new application programming interface (API) key to maintain prolonged access within compromised systems in the event of a credential reset, underscoring the actors’ moderate capabilities. The phishing emails contain a fake cryptocurrency seed phrase which is typically used to restore access to cryptocurrency wallets in instances where users lose access. The emails also contain a warning about a fake wallet migration to coerce victims into transferring funds into an actor-controlled wallet highlighting the actors’ social engineering skills. Threat actors can then use the fake seed phrases to steal funds by transferring them to an external account.  The Russia-nexus group Gamaredon has been targeting the military mission of an unnamed Western country in Ukraine in a cyber espionage operation since at least February. Gamaredon reportedly used external removable drives to infiltrate targeted systems and run an obfuscated .LNK file. The file contained a script that executed two files to establish command-and-control (C2) communication and deploy an information-stealing malware (‘GammaSteel’). Gamaredon implemented multiple new, advanced detection evasion techniques throughout the campaign, showcasing the development of its capabilities. This included the adoption of legitimate tools to initiate C2 communication as well as the migration to PowerShell-based tools to enhance detection evasion. Gamaredon used a PowerShell script before executing GammaSteel to gather information on the targeted system’s security protections and to facilitate detection evasion. Subsequently, GammaSteel then employed a PowerShell-based web request to exfiltrate sensitive documents from compromised systems.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

Our cyber word(s) of the week: PowerShell. (Source: Sibylline)

 

14 Apr 25. Global: New, stealthy phishing kit variant underscores long-term security, financial risks. On 12 April, international news outlets reported that threat actors are using a new, more advanced version of the Phishing-as-a-Service (PhaaS) kit ‘Tycoon2FA’. The kit primarily targets Microsoft365 and Gmail users and has been active since at least October 2023. This variant features enhanced capabilities to evade detection and bypass endpoint security protections, enabling the theft of user credentials and the hijacking of user accounts for financial gain. The new version of Tycoon2FA reportedly uses a new character encoding standard to conceal malicious code. It also contains a JavaScript that detects browser automation tools to hinder analysis, underscoring the development of Tycoon2FA’s detection evasion capabilities. Additionally, the new kit hosts a CAPTCHA challenge on actor-controlled infrastructure to further enhance obfuscation, highlighting the actors’ sophistication and resources. We assess that this report displays the long-term security and financial risks posed by the continuous innovation of cyber criminal tools and enterprises. (Source: Sibylline)

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

April 12, 2025 by

10 Apr 25. Careless Whispers. It is always good to check who is attending and participating in an online chat. A quick round-robin introduction can do the trick. Scrolling through the list of names should provide useful confirmation. Newcomers can be asked to identify themselves. Once all is tickety-boo, discussions can flow. Another good rule of thumb is to assume anything you say, or write, is being recorded and may live for eternity. By just obeying these simple rules, US vice president JD Vance, secretary of defence Pete Hegseth and the director of national intelligence Tulsi Gabbard would have saved themselves torrents of embarrassment. On 24th March it emerged that Jeffrey Goldberg, editor-in-chief of The Atlantic, had been added to a Signal group chat, which included the above, and several other government officials. Mr. Goldberg had been added erroneously by national security advisor Michael Waltz. Reports noted that, between 11th March and 15th March, the group discussed military operations directed against Houthi insurgents in Yemen. The discussions included significant disclosures of classified material. The affair has proven deeply embarrassing and possibly includes unlawful actions by the participants. Messaging software applications like Signal and WhatsApp have proven popular with some politicians in recent years. Former British Prime Minister Boris Johnson has been in hot water regarding messages he sent and received on WhatsApp concerning the Covid-19 pandemic during his tenure. Such software applications, convenient as they may be, are probably best avoided by politicians. Nothing is totally secure, but it is surely better to use bespoke, government systems designed for classified traffic? Perhaps that means carrying around an additional secure smartphone just for this traffic? Would that few extra seconds of due diligence to check chat group participants be such a slog? If in doubt, just refrain from sharing anything you think is classified during the conversation. These are all minor inconveniences, but they pale into insignificance vis-à-vis the scandal that erupts after a failure to follow basic due diligence. (Source: Armada)

 

07 Apr 25. New Operational Comms on the Horizon. The German Army will receive its TAWAN LBO tactical/operational level trunk communications systems over the next four years. TAWAN LBO will help connect the tactical SVFUA networking architecture to higher echelons. German land forces communications modernisation efforts continue a pace with the contract award for a new operational-level networking system. The Heer (German Army) is involved in a major communications modernisation effort. To date, much of this effort has focused on the Streitkräftegemeinsame verbundfähige Funkgeräteausstattung (SVFUA) initiative. SVFUA roughly translates as Joint Armed Forces Interconnectable Equipment and primarily focuses on rolling new tactical radios across the army’s manoeuvre force. As Armada has reported in the past, up to 30,000 new radios will be procured as part of the initiative. The principle transceiver fulfilling the requirement is Rohde & Schwarz’ Soveron-D Very/Ultra High Frequency (30 megahertz/MHz to three gigahertz/GHz) radio. Soveron-D will initially equip the German Army Krauss-Maffei Wegmann/Rheinmetall Puma tracked infantry fighting vehicles.

TAWAN LBO

The SVFUA radios will soon be complemented by the Heer’s new Tactical Wide Area Network for Land Based Operations, better known as TAWAN LBO. Whereas SVFUA enables tactical networking, TAWAN LBO will provide tactical/operational trunk communications. Rheinmetall won the contract to provide TAWAN LBO in February. According to a company press release, the programme could be worth several bn dollars over the next decade. The initial February order is worth circa $2 bn and will see TAWAN LBO equipping a single Heer division between 2026 and 2029.

Reports have noted that TAWAN LBO will be a vehicle-mounted system. General Dynamics’ Piranha-5 eight-wheel drive infantry fighting vehicle will form one of the platforms. A total batch of 256 TAWAN LBO-equipped Piranha-5s should be delivered to the Heer from 2026.

C-band SATCOM

In a written statement supplied to Armada, Rheinmetall said that the goal of the TAWAN LBO programme is to “provide an independent, tactically deployable, relocatable and interference-resistant transmission network.” To this end, the TAWAN LBO architecture will facilitate C-band (5.925GHz to 6.425GHz uplink/3.7GHz to 4.2GHz downlink) conduits, implying the system will be used for Satellite Communications (SATCOM). Interestingly, the Bundeswehr (German Armed Forces) possesses the SATCOMBw communications satellite constellation.

Constructed by Airbus’ defence and space subsidiary two satellites, COMSATBw-1 and COMSATBw-2, comprise the constellation. Both provide C-band and Ku-band (14GHz uplink/10.9GHz to12.75GHz downlink) connectivity. Open sources note that the Ku-band links are used for military communications within Germany while C-band links support expeditionary operations. Configuring TAWAN LBO to use C-band makes sense. German forces are deployed abroad to support North Atlantic Treaty Organisation (NATO) commitments and Germany already leads NATO’s multinational battlegroup in Lithuania. TAWAN LBO’s C-band connectivity would be vital should that battlegroup need to repel a Russian advance into the Baltic.

Route Planning

Rheinmetall stressed that the particulars regarding how TAWAN LBO would be deployed remain the responsibility of the Bundeswehr. The statement did say that communications routing can be planned with a software management system. Constituent TAWAN LBO components then deploy to their designated positions and the network is ready for use. While individual radio relays are static, communications routing can be organised and managed dynamically between these.

Once TAWAN LBO enters service in the coming four years, in cooperation with SVFUA, it will afford the Heer one of the most advanced communications architectures in Europe. This will be a welcome enhancement, not only for the Heer, but for allied European nations, as the threat from Russia intensifies. (Source: Armada)

 

08 Apr 25. Constellation Agnostic. The US Air Force’s DEUCSI programme envisages constellation-agnostic satellite communications terminals which can link with ease to disparate, commercial spacecraft to seamlessly send and receive traffic. In 2018, the US Air Force Research Laboratory launched its Defence Experimentation Using Commercial Space Internet (DEUCSI) programme, which has since achieved some major milestones. DEUCSI has a simple premise; to evaluate the capabilities of commercial Satellite Communications (SATCOM) constellations to improve military networking. Of particular interest, reports note, are commercial SATCOM constellations in geosynchronous, medium and Low Earth Orbits (LEO). In geosynchronous orbits, spacecraft largely remain over the same point on the planet. LEO satellites do not exceed orbits of 1,079 nautical miles/nm (2,000km). Medium Earth orbits occur at altitudes of between 1,079nm and 19,323nm (35,786km). Numerous companies have privately-owned SATCOM constellations using these orbits. DEUCSI is exploring the possibility of SATCOM terminals equipping military platforms using multiple constellations. In 2018, the year the project commenced, SpaceX won a DEUCSCI contract to evaluate that company’s Starlink network. The programme gained further momentum in 2023 when a host of companies won contracts to develop SATCOM terminals to perform accompanying tests and evaluations. A goal of the programme, as the reports continued, is for DEUCSI to be link agnostic. What this means in practice is that one terminal in one part of the world would communicate with ease with another somewhere else. This could be achieved without users needing to specify or designate a particular network to achieve this.

Commercial decisions

Dr. Brian Beal, DEUCSI’s head engineer, told Armada that the programme was realised “to start utilising the large commercial constellations that we saw coming down the horizon.” SpaceX is arguably the most famous, but others like Amazon’s Kuiper and EutelSat’s OneWeb are coming to the fore. Dr. Beal stresses that having the US Department of Defence (DOD) develop its own, similar, constellation, would have been expensive. Instead, DEUCSI develops the wherewithal to use these networks as and when they became available. Alongside Starlink, DEUCSI established contracts with Amazon to evaluate Kuiper and with Viasat to use the latter’s satellites. When the programme commenced, Dr Beal says that DEUCSI was focused on “relatively basic tests of the emerging constellations” with single vendor SATCOM terminals. Since then, the programme has evolved into looking at using “common hardware to communicate across many different constellations.” Alongside the companies mentioned above, Hughes has been involved in providing SATCOM terminal hardware and software in support of DEUCSI. Raghu Janardhan, vice president for Hughes’ defence and government systems division, told Armada that the company’s provisions “provide access to multiple commercial satellite constellations across the full scope of orbits. This means that interference or denial of access to one constellation does not inhibit the mission. The comms system simply switches to an alternate constellation and continues its work to stay connected. This switch is important as adversaries do not usually try to block all the available commercial options.”

Terminal building

Dr. Beal continued that DEUCSI is focusing on Ku-band (14 gigahertz/GHz uplink/10.9GHz to 12.75GHz downlink) and Ka-band (26.5GHz to 40GHz uplink/18GHz to 20GHz downlink) connectivity. This is “where the high capacity and proliferated constellations operate … We need to buy a service that is available, and (in those bandwidths is) really where it is available.” The primary focus of DEUCSI is to evaluate these constellations for the provision of wideband links with constellation-agnostic terminals. “We may add some narrow band links in the future, but that’s not currently something that we’re really working on.” Over the coming year, Dr. Beal expects to perform tests of multi-modem, multi-constellation capable SATCOM terminals developed via the programme. These tests will occur both on the ground and onboard aircraft. The DEUCSI programme should conclude by the first half of 2028 at the latest, says Dr. Beal. Beyond that, the multi-constellation, multi-modem terminals realised via the programme could evolve into architectures equipping current, and future, US military aircraft types.(Source: Armada)

 

09 Apr 25. Europe to the Rescue? Eutelsat’s constellation of low earth orbit communications satellites, a rendering of a constituent spacecraft is shown here, could provide Ka-band and Ku-band wideband communications in Ukraine as a supplement, or replacement, for the US Starlink system. European satellite communications providers could help to make up any future satellite communications shortfalls in Ukraine. The fallout from the disastrous meeting between Ukraine’s president Volodymyr Zelenskyy and his American counterpart Donald Trump on 28th February reverberated into March. Ukraine famously benefitted from access to SpaceX’s Starlink Satellite Communications (SATCOM) service in the immediate aftermath of Russia’s second invasion of the country on 24th February 2022. Starlink terminals began arriving in the country from 28th February. Since then, media reports note that thousands of terminals have been delivered. Ukraine’s government, military and civilian sectors are all using Starlink which provides wideband SATCOM links across Ku-band (14 gigahertz/GHz uplink/10.9GHz to 12.75GHz downlink) and Ka-band (26.5GHz to 40GHz uplink/18GHz to 20GHz downlink) channels. According to Starlink, users typically enjoy download speeds of between 25 megabits-per-second/mbps and 220mbps. Upload speeds of between five megabits-per-second and 20mbps are also achievable. Latency rates across the link range between 25 milliseconds/ms and up to 100ms. Starlink terminals are difficult to jam on account of their small antennas and narrow beams. Jammers must be relatively close to the terminal antenna, and pointing directly at it, to have a hope of success. Starlink has proven popular with the military. The link has been used to provide tactical and operational trunk communications. The low latency, high bandwidths and relatively resiliency of Starlink signals vis-à-vis jamming has also made the link attractive for Ukrainian Uninhabited Aerial Vehicle (UAV) operators.

Musk it always be like this?

Starlink’s provision has not been without controversy. In February 2023, SpaceX’s president Gwynne Shotwell complained about Ukrainian military use of Starlink arguing that it was “never meant to be weaponised.” She claimed that using the link to support Ukrainian UAV operations went beyond the scope of the agreement the company had with the Ukrainian government to use the network. Ms. Shotwell’s comments were reinforced by SpaceX founder Elon Musk that same month. Mr. Musk wrote on Twitter that “we will not enable escalation of conflict (sic) that may lead to World War Three.” Controversies have continued regarding the extent to which SpaceX denies coverage over Russian-occupied Crimea, in southern Ukraine. Claims have circulated that this is having a negative effect on Ukrainian military operations. In the wake of the meeting between Messrs. Trump and Zelenskyy, the former ordered a pause of all US military assistance to Ukraine on 4th March. Ostensibly, the move was intended to encourage the Ukrainian government to embark on peace negotiations. Reports on 11th March noted that this assistance would be resumed with immediate effect. The move followed Ukraine’s agreement to observe a 30-day ceasefire contingent on Russian agreement. As of the time of writing, in mid-March, the Russian government is yet to follow suit.

Enter Old Europe

The involvement of Mr. Musk and SpaceX in the ongoing conflict raises concerns. Starlink’s capabilities make it an indispensably useful system. However, Mr. Musk’s mercurial tendencies, and attraction to extreme right politics, raise questions as to the extent Starlink can be relied upon as a service. What if Mr. Musk decides once again to restrict, or end, the provision of Starlink to Ukraine? Such a decision could risk having a profoundly negative effect on Ukraine’s operational and tactical situation. Reports surfaced on 7th March that Eutelsat could increase its involvement in Ukraine, with the company saying that it could provide 40,000 civilian and military grade terminals into the country. Eutelsat continued that these terminals could be provided within a couple of months. The company’s shareholders include the French and UK governments, both staunch allies of Ukraine. In theory, this should make it harder for the company to threaten to terminate its services in Ukraine a la Mr. Musk. Sources close to Eutelsat confirmed to Armada that the company is already supplying low Earth orbit satellite connectivity in Ukraine. This connectivity is sold to Ukraine on a commercial basis via a distributor based in western Europe. In terms of capability, Eutelsat’s links have the same latency as those furnished by Starlink and provide similar geographical coverage. The source added that, whereas Starlink primarily sells on a business-to-consumer basis, Eutelsat provides business-to-business and business-to-government services. Like Starlink, Eutelsat’s constellation provides Ka-band and Ku-band links. Reports note that Eutelsat’s links support data rates of circa 150mbps. A deeper deployment of Eutelsat terminals and services in Ukraine could make up for any Starlink shortfall should the latter be restricted, or terminated, in the future: “We are actively collaborating with European institutions and business partners to enable the swift deployment of additional user terminals (in Ukraine) for critical missions and infrastructure,” the source shared. It seems highly likely that Eutelsat will increase its footprint in Ukraine in the coming months. This will also provide the company with a useful testing ground to evaluate the performance of its SATCOM links in a warzone. (Source: Armada)

 

10 Apr 25. April Radio Roundup. Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.

Post-Quantum Encryption

Himera’s G1 Pro handheld radio will benefit from post-quantum encryption techniques, and improved frequency-hopping performance, both of which will be delivered by a software upgrade.

News emerged in March that Himera’s G1 Pro handheld tactical radio will benefit from so-called post-quantum encryption. The company has partnered with Quantropi to deliver this capability via the company’s QEEP post-quantum encryption technology. Combining this encryption with the radio’s existing frequency-hopping spread spectrum protocols should further enhance its resilience to jamming. The radio uses ultra high frequency bands of 410 megahertz/MHz to 493MHz, and 700MHz to 900MHz. Jay Toth, Quantropi’s senior vice president for sales, told Armada that the development of post-quantum encryption is a response to the realisation of quantum computers that can potentially break current encryption schemes. Mr. Toth says that “to continue protecting important data, we need a new set of maths problems that are so difficult to solve that not even a future super powerful quantum computer can break them.” He adds that “post quantum encryption is based on new very difficult maths problems” that these computers will find challenging to solve. The quantum secure encryption that the G1 Pro radios will benefit from will be installed as a software upgrade. Mr. Toth continued that all existing and new G1 Pro users can benefit from these upgrades. In addition, Quantropi will enhance the radio’s frequency hopping performance to help mask the radio from detection. These new frequency-hopping algorithms will also be made available to G1 Pro users via a software update.

Taking PRRs into the Vehicle

Thales has developed its new Vehicle-Mounted SquadNet Radio from the company’s existing SquadNet personal role radio family. The new system has been designed to improve connectivity between a squad’s vehicle and its dismounted troops.

Thales has unveiled a vehicle-mounted version of its SquadNet Personal Role Radio (PRR). SquadNet radios are available in two variants: One uses using frequencies of 430 megahertz/MHz to 470MHz, and the other 865MHz to 880MHz wavebands, according to the company. Thales told Armada that the new Vehicle-Mounted SquadNet Radio (VMSR) is fully interoperable with SquadNet PRRs. The performance of the PRRs and VMSR is also identical. Nonetheless, the vehicle-mounted antenna of the latter “provides a significant range benefit.” The company is keen to emphasise that “the VSMR is not a substitute” for a standard vehicular radio. Instead, the new transceiver will “seamlessly link dismounted troops to the vehicle to enable better coordination during operations.” Troops using the PRR can share data and voice communications, and blue force tracking information. Communications and transmission security is provided using frequency hopping, and low probability of interception waveforms, Thales continued. Weighing around 500 grams (1.1 pounds) the VSMR “is designed to have a minimal impact on the vehicle installation.” VSMRs can equip standard military and commercial vehicles and can use the vehicle’s power supply. Moreover, the radio has dedicated audio and data connectors to ease integration with existing vehicle electronics. (Source: Armada)

 

10 Apr 25. Global: Activists face long-term surveillance, data-theft risks from Chinese state-sponsored actors. On 9 April, the UK’s National Cyber Security Centre (NCSC) published a joint alert warning that unnamed Chinese state-sponsored actors are targeting Falun Gong, Taiwanese, Tibetan and Uyghur activists in a surveillance operation. Threat actors distribute fraudulent mobile applications on legitimate application stores to infiltrate targeted iOS and Android devices. The applications contain two known spyware variants (‘BADBAZAAR’ and ‘MOONSHINE’) that exfiltrate sensitive information from compromised systems. Threat actors also use messaging and social media platforms to conduct social engineering attacks, tricking victims into downloading the spyware directly onto their systems. MOONSHINE has targeted Tibetan activist groups since at least 2019 while BADBAZAAR has been active since at least 2022. We assess that this underscores the longevity of China’s surveillance operations. China often targets perceived adversarial entities, including activists, in cyber surveillance operations to strengthen Beijing’s security posture. We assess that this report underscores the ongoing risks of long-term surveillance and information theft to activists. (Source: Sibylline)

 

09 Apr 25. Northrop Grumman developing new UAS multinode processor. Programme officials at Northrop Grumman are in the midst of testing and development of a new, multinode airborne processor for use aboard unmanned aircraft systems (UASs). The new processor is the latest variant under development for the company’s InSite family of battlefield edge processors, Rosa Salazar, program director of advanced communications at Northrop Grumman Mission Systems, said. The UAS-focused open architecture processor variant is currently in laboratory testing phase, with programme officials focused on hosting and integrating various modules, functions, and capabilities into the processor, Salazar told Janes during a March interview.

“We have not gotten to a point yet where we are integrating [capabilities] for flight,” she said, noting these efforts will likely take place later in 2025 or in early 2026.

The InSite family of processor variants runs the gamut in terms of capacity and form factor, ranging from the five-slot 3U OpenVPX chassis under development for UASs to a 22-slot chassis for large, fixed-wing aircraft, according to Salazar.

“Here is your 3U [electronic warfare (EW) card] and here is your 3U networking module” on top of all the cryptographic and messaging layer security (MLS) to allow data passback to higher command, she said. The reachback capability for InSite is focused on connecting these processors to the US Air Force’s (USAF’s) Battle Network, Salazar noted.

In December 2024 programme officials held an internal demonstration of an InSite multifunction airborne processor, featuring a 12-slot chassis, according to Salazar. The 12-slot version demonstrated also represented the minimum viable product (MVP) for the InSite programme. (Source: Janes)

 

09 Apr 25. Rohde & Schwarz Leads the Way in Secure Military Communications With SATURN. Rohde & Schwarz, leveraging its expertise in secure military communications, is poised to support the transition to SATURN, a NATO-designated, highly secure, and interoperable waveform technology, with a proven track record of deploying thousands of SATURN radios across various global platforms. Rohde & Schwarz today highlighted its pivotal role in being one of the first to implement the Second-Generation Anti-Jam Tactical UHF Radio for NATO (SATURN) standard. As NATO’s standard UHF coalition waveform, SATURN is offering highly reliable transmission of voice and data. It is expected to replace the legacy HAVE QUICK waveform in operational use. Rohde & Schwarz has extensive expertise in secure military communications, garnered from decades of developing cutting-edge waveforms. With the company’s commitment to delivering innovative, secure solutions for the world’s most critical communications, it has successfully supplied and commissioned thousands of SATURN radios and embedded solutions for NATO and allied partners. With SATURN/HAVE QUICK already installed and operational in thousands of radios across NATO, the company reaffirms its position as the European market leader in secure communications. SATURN has earned the distinction of being designated as a NATO Minimum Military Requirement (MMR) for maritime and air operations interoperability, ensuring seamless connectivity across allied forces. Its advanced fast frequency-hopping waveform provides superior jamming resistance, safeguarding critical military communications against evolving threats. Compliance with NATO STANAG 4372 facilitates SATURN’s integration across various platforms, including naval, air, and ground stations.

“As a trusted partner in secure communications and software-defined radios, we’re thrilled to support the transition from HAVE QUICK to SATURN, enhancing security and interoperability for our NATO and allied partners,” said Markus Dolfen, Vice President, Secure Communications, Rohde & Schwarz. (Source: ASD Network)

 

08 Apr 25. Compass Call electronic-attack plane makers eye overseas market. BAE Systems and L3Harris are halfway through delivery of the Air Force’s planned fleet of 10 EA-37B Compass Call planes and expect to deliver the final five in 2027 and 2028. The firms — co-prime contractors to create the next generation of electronic warfare aircraft — expect the market for Compass Calls to continue growing in years to come. In a Monday call with reporters, BAE and L3 officials said they see growing potential to sell Compass Calls to international customers and that the Air Force could increase its purchase of the planes. The EA-37B is a heavily adapted Gulfstream G550 business jet loaded with electronic warfare equipment. It is designed to jam enemy communications, radar and navigation signals and allow airmen to defuse roadside bombs wirelessly. It will also block the ability of enemy air defenses to transmit information between sensors, control networks and weapons, allowing U.S. and partner aircraft to get closer to their targets. It is replacing the Vietnam-era EC-130H Compass Calls, which were heavily used during the wars in Iraq and Afghanistan and are now being retired. The Air Force had 15 EC-130Hs in 2017, but that fell to four in 2024 and is set to keep dropping. The new Compass Call is projected to fly 40% faster than the EC-130H and cover twice the range, and have a top altitude that is nearly 15,000 feet higher than the older aircraft, L3Harris said. The growing sophistication of the potential adversaries the U.S. and its allies might fight requires an electronic attack aircraft like the Compass Call, which is capable of countering multiple threats, L3 and BAE officials said.

“The [potential battlefield] environment is getting more and more complex every day,” Dave Harrold, vice president and general manager for countermeasure and electronic attack solutions at BAE, said. “When you think about countering enemy kill webs, it’s no longer a one-versus-one thing — it’s about being to persecute a variety of threats simultaneously.”

The State Department in October 2024 approved a $680 m sale of Compass Call planes to Italy. Harrold pointed to that foreign military sale as a sign of the plane’s expanding market.

“This isn’t just an important United States Air Force platform,” Harrold said. “It’s an ideal platform for our important allies as well. … We see the opportunity for that to be even more prolific internationally.”

Jason Lambert, L3Harris’s president of intelligence, surveillance and reconnaissance, said other unnamed international partners have expressed interest in buying their own Compass Calls. This would help improve interoperability between the U.S. and NATO fleets, he said.

However, the government’s studies have shown the planned fleet of 10 Compass Calls may not be enough to counter the projected future threats facing the Air Force, L3 and BAE officials said, and may need to be doubled to 20.

“The common message that we’re hearing, regardless of the study or regardless of the customer organization we speak with, 10 is not enough,” Lambert said.

BAE, L3Harris and Gulfstream proposed adding four new Compass Calls to the planned fleet, with the first two of those included in the Air Force’s unfunded priorities list in 2026. Using the G550 business jet as the foundation of the Compass Call will make it easier to sustain and keep jets ready to fly, Lambert said. There are more than 600 G550s fielded worldwide, he said, and a well-established sustainment and spare parts network that can service planes in under 30 hours. He predicted this would result in aircraft availability in the high 90% range. BAE builds the electronic attack components for the new aircraft. L3Harris focuses on converting the G550 jets into Compass Calls and integrates the equipment at its Waco, Texas, facility. The final five Compass Calls are now having their outer mold lines modified to make room for the electronic attack equipment at Gulfstream’s Savannah, Georgia, facility, according to Lambert. The sixth Compass Call is expected to move to L3Harris’s Waco facility for further work in the second quarter of 2025. Aircraft six, seven and eight are projected for delivery to the Air Force in 2027, and the final two are on track for a 2028 delivery, Lambert said. The first two EA-37Bs that were delivered to the Air Force are now undergoing testing, according to Harrold. The third arrived at Davis-Monthan Air Force Base in Arizona — the new fleet’s future home — in August 2024, and airmen are now conducting pilot training with it. The fourth Compass Call is also now at Davis-Monthan, Harrold said. The fifth Compass Call has been delivered to the Air Force, Lambert said, but is now receiving an upgrade. (Source: Defense News Early Bird/Defense News)

 

09 Apr 25. Global: Spike in cyber attacks underscores heightened security risks from botnet infrastructure. On 7 April, the security company GreyNose reported that cyber attacks against TVT DVR video recording devices have spiked since at least the beginning of March. Threat actors exploit a known security flaw to bypass authentication and security measures to infiltrate targeted devices. The vulnerability provides threat actors with administrative-level privileges, allowing them to conduct malicious activity (including cryptocurrency mining and distributed denial-of-service (DDoS) attacks). The vulnerability was reportedly patched in May 2024, underscoring the importance of timely patch management policies to prevent compromises. The attacks originated from at least 6,600 IP addresses, highlighting the scale of this operation. The attacks also include the deployment of Mirai-based malware, suggesting that threat actors likely intend to incorporate infected devices into existing Mirai botnet infrastructure. This report underscores the heightened security, financial and disruption risks stemming from botnets following an uptick in botnet-related activity since at least the end of 2024. (Source: Sibylline)

 

08 Apr 25. Global: Distribution of highly sophisticated AI tool will increase long-term security risks. On 7 April, the cyber security company SlashNext reported that unnamed threat actors are distributing a sophisticated, multi-model artificial intelligence (AI) cyber attack automation tool (‘Xanthorox AI’) on the dark web. Xantharox AI contains several highly advanced data exfiltration capabilities including voice and image analysis modules. It can also automate command and control (C2) communication, highlighting Xantharox AI’s extensive capabilities. Additionally, the tool can autonomously generate malicious code, thereby enabling low-skilled threat actors to conduct sophisticated cyber attacks. Xantharox AI is composed of five custom-built large language models (LLMs). It is also stored within private actor-controlled infrastructure to enhance defence evasion, further showcasing the developers’ skillsets and knowledge. Threat actors are increasingly incorporating AI into cyber attacks to boost success rates, enhance sophistication and facilitate attack automation. As such, we assess that this report points to the long-term security risks posed by AI tools amid a broader increase in AI-led cyber attacks. (Source: Sibylline)

 

04 Apr 25. Global: Exploitation of vulnerable third-party tools points to elevated risks from Chinese threat actor. On 3 April, the technology company Google Mandiant reported that the Chinese-nexus cyber threat actor ‘UNC5221’ has been exploiting a critical software vulnerability as part of a likely cyber espionage operation since mid-March. The software vulnerability (CVE-2025-22457) impacts Ivanti Connect Secure virtual private network (VPN) applications and allows threat actors to execute code remotely. UNC5221 deploys to newly observed malware strains (‘TRAILBLAZE’ and ‘BRUSHFIRE’) to establish prolonged connection to actor-controlled infrastructure. The use of new malware through the employment of typical tactics by UNC5221 points to the group’s ongoing development. UNC5221 consistently abuses zero-day and existing software vulnerabilities to move laterally into targeted systems and to execute code remotely. CVE-2025-22457 is equipped with a patch that was released in February, underscoring the necessity for robust patch-management policies to prevent unnecessary exploitation. Threat actors often exploit vulnerable third-party tools to gain access to strategic networks, highlighting what we assess to be long-term security risks. (Source: Sibylline)

 

04 Apr 25. Cyber Update Key points

  • A new malware (‘Crocodilus’) is targeting Android users in Spain and Turkey to steal cryptocurrency wallet keys, elevating financial risks to users (see Sibylline Cyber Daily Analytical Update – 31 March 2025 and our Technical analysis below).
  • A wide-scale phishing operation will increase financial and information-theft risks to individuals (see Sibylline Cyber Daily Analytical Update – 1 April 2025 and our Technical analysis below).
  • A long-term operation injecting ‘fake workers’ into European businesses underscores a rise in espionage and information-theft risks.
  • A new backdoor (‘Anubis’) is being distributed by the cyber criminal group ‘FIN7’, underscoring heightened financial and security risks across the globe.
  • The Chinese-nexus group ‘UNC5221’ is exploiting a software vulnerability in a likely cyber espionage operation, raising third-party security risks.

Technical analysis of weekly stories

Crocodilus is a new mobile banking trojan containing highly sophisticated techniques to steal data and garner illicit funds. The malware is installed via a proprietary malware dropper that bypasses Android security restrictions and then enables Accessibility Services on the device. Once this is enabled, the malware connects to a command-and-control (C2) server to receive instructions such as the list of targeted applications and the fake login pages to overlay over legitimate pages to steal cryptocurrency wallet credentials. The malware will initially overlay a fake alert message on the user’s screen claiming that users must back up their cryptocurrency wallet within 12 hours or they will lose access to their wallet. If users move on to the next stage, the malware will then capture their login credentials and wallet keys to garner profit. By abusing accessibility services, Crocodilus can monitor all accessibility events and log anything displayed on the device, effectively becoming a keylogger. However, the trojan is also capable of overlay attacks, remote access and remote control to complete fraudulent transactions, underscoring the notable sophistication of this banking trojan. Additionally, Crocodilus can hide its remote access activity by overlaying blank screens on top of the activity, obfuscating its malicious behaviour.

‘Lucid’ is a sophisticated Phishing-as-a-Service (PhaaS) platform operated by a Chinese-speaking threat actor, ‘XinXin Group’, targeting 169 entities across 88 countries globally. It operates as a scalable, subscription-based service that allows cyber criminals to conduct large-scale phishing operations to harvest credit card credentials to directly exploit or sell on dark web marketplaces for profit. The phishing operations use text messages to lure victims into clicking malicious links; the phishing messages often contain payment and/or shipping themes to trick users into clicking links. The link will then redirect a user to a phishing webpage that appears to be a legitimate payment portal. Lucid will distribute the malicious text messages using Apple’s iMessage or Android’s Rich Communication Services (RCS) to bypass traditional text messaging spam detection mechanisms as these messaging services use end-to-end encryption and cannot be read by traditional spam tools. To enhance the operation’s detection evasion, the PhaaS platform will then block connections from IP addresses outside targeted regions or if users attempt to access malicious domains directly instead of clicking on the link in the phishing message. Additionally, a credit card verifying tool runs immediately following card details being entered to ensure that the offered details are legitimate.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

Our cyber word(s) of the week: Rich Communication Services (RCS) (Source: Sibylline)

 

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

April 4, 2025 by

01 Apr 25. New Anti-Jamming CRPA System by Inertial Labs Strengthens GPS & GNSS Security. Inertial Labs, a VIAVI Solutions company, unveils the M-AJ-QUATRO, an advanced anti-jamming CRPA system designed to enhance secure, interference-free navigation in GPS/GNSS-challenged environments Inertial Labs, a VIAVI Solutions Inc. company, has introduced its M-AJ-QUATRO anti-jamming antenna system for Assured Positioning, Navigation, and Timing (A-PNT) in GPS/GNSS-challenged environments. Leveraging advanced Controlled Reception Pattern Antenna (CRPA) and digital processing technologies, the M-AJ-QUATRO is suited for multiple platforms ranging from military operations to commercial aviation. The M-AJ-QUATRO operates seamlessly across the entire L1, L2, and L5 GNSS bands, providing robust interference mitigation and secure signal processing. Featuring adaptive digital nulling, it automatically suppresses jamming signals with over 34dB+ interference suppression (export-free version) and over 45dB+ interference suppression (export-controlled version), ensuring reliable performance in contested environments. The system’s jammer direction-finding capability identifies and isolates interference sources, enhancing situational awareness and operational effectiveness. Designed for multi-constellation support, the M-AJ-QUATRO is compatible with GPS, GLONASS, GALILEO, BEIDOU, and QZSS, providing robust global coverage. Secure signal processing powered by dual FPGA-based encryption and anti-spoofing technology facilitates strong data integrity, safeguarding mission-critical applications. Designed to endure extreme conditions, this system meets stringent MIL-STD-810G and MIL-STD-461F standards, making it an ideal solution for defense and aerospace operations as global reliance on PNT services grows. PNT services play an increasingly vital role in ensuring the reliable operation of various critical sectors, including transportation, AI hyperscale data centers, telecommunications, energy, finance, and defense. Government agencies and industry leaders are intensifying efforts to combat GNSS jamming and spoofing threats. The U.S. Federal Aviation Administration (FAA) and Naval Air Warfare Center Aircraft Division (NAWCAD) are accelerating the approval process for CRPA technology to enhance aviation safety and mitigate terrestrial-based GPS interference.

Jamie Marraccini, Vice President, Inertial Labs Products, VIAVI, commented, “As the FAA and NAWCAD push for CRPA integration into commercial aircraft, M-AJ-QUATRO is positioned as a market-ready solution for both military and civilian applications. With regulatory shifts streamlining CRPA adoption, this launch marks a significant step in ensuring secure, interference-free navigation for mission-critical operations.” (Source: https://www.defenseadvancement.com/)

 

03 Apr 25. C3 AI (NYSE: AI), the Enterprise AI application software company, and Arcfield, a leading government technology and mission support provider, announced a customer collaboration to accelerate the design, development, and operation of production-grade Enterprise AI applications to better serve defense and intelligence agencies. Together, Arcfield and C3 AI will leverage the C3 Agentic AI Platform and C3 Generative AI to support the development, deployment, and maintenance of Enterprise AI applications for Arcfield. With the capabilities of C3 AI solutions, Arcfield will enhance its service offerings to its mission partners, including the company’s proven systems engineering, modeling and simulation, supply chain optimization, predictive maintenance, mission assurance and mission acquisition solutions. -C3 AI (NYSE: AI), the Enterprise AI application software company, and Arcfield, a leading government technology and mission support provider, announced a customer collaboration to accelerate the design, development, and operation of production-grade Enterprise AI applications to better serve defense and intelligence agencies. Together, Arcfield and C3 AI will leverage the C3 Agentic AI Platform and C3 Generative AI to support the development, deployment, and maintenance of Enterprise AI applications for Arcfield. With the capabilities of C3 AI solutions, Arcfield will enhance its service offerings to its mission partners, including the company’s proven systems engineering, modeling and simulation, supply chain optimization, predictive maintenance, mission assurance and mission acquisition solutions. (Source: BUSINESS WIRE)

 

03 Apr 25. Global: New backdoor elevates financial, security risks to firms. On 2 April, international media sites reported that the cyber criminal group ‘FIN7’ is currently distributing a new backdoor, ‘Anubis’, which obtains complete control over targeted Windows systems. This campaign uses phishing emails to direct users to a compromised SharePoint website where the malware is hosted. At the time of writing, Anubis cannot be detected by most anti-virus security solutions, underscoring the potential long-term infection risks facing organisations. Additionally, Anubis contains multiple executables to obfuscate and install malware payloads on infected machines, demonstrating the malware’s adaptability and sophistication. FIN7 is a Russian-originated cyber criminal group that has been active since 2015, primarily targeting the gambling, hospitality and restaurant industries to garner illicit profit. As the group continuously develops its tactics and tools to sustain profitable information-theft campaigns, financial and security risks will remain elevated in the long term. (Source: Sibylline)

 

02 Apr 25. Viasat’s DARC-ssd™ 600 Approved for Securing NATO SECRET Data. Viasat’s DARC-ssd™ 600 encrypted SSD has been approved by the NATO Military Committee for securing NATO SECRET data, confirming its compliance with stringent security standards The DARC-ssd™ 600 data-at-rest (DAR) encrypted SSD from Viasat Inc. has been approved by the NATO Military Committee (MC) for securing NATO SECRET data when at rest and is now listed in the NATO Information Assurance Product Catalogue (NIAPC). The approval and inclusion in the NIAPC confirms that Viasat’s solution meets stringent requirements for securing NATO SECRET data, allowing NATO nations to protect classified information from theft or compromise. Viasat’s advanced DAR solution enhances legacy encryption systems, providing improved protection for classified data across multiple platforms. It features hardware-based encryption and a flexible M.2 form factor, ensuring continued assurance for high-risk operations. Utilizing the industry-standard Non-Volatile Memory Express (NVMe) interface and the common M.2 2280 form factor, the DARC-ssd™ 600 enables next-generation encryption integration with commercial off-the-shelf (COTS) and tactical military devices, including laptops, tablets, desktops, and network-attached storage. As part of Viasat’s Eclypt DAR encryption family, the DARC-ssd™ 600 combines military-grade 256-bit Advanced Encryption Standard (AES) hardware with full-disk encryption. Data is decrypted upon device startup using mandatory two-factor authentication and is re-encrypted immediately when powered off. This dual authentication and full-disk encryption are housed in a tamper-evident internal NVMe™ M.2 SSD to safeguard sensitive and classified data. In 2023, the U.K.’s National Cyber Security Centre (NCSC) completed its CAPS High Grade evaluation of the DARC-ssd™ 600 for protecting data up to the Top Secret classification. It is reportedly the only DAR encryption device using an NVMe interface and M.2 form factor that has been CAPS evaluated for securing data up to and including TOP SECRET.

Todd McDonell, President of Viasat International Government, commented, “As a trusted provider of cyber defence and information assurance solutions, we’ve seen the evolution of encryption technology and understand the growing challenge to protect sensitive and classified data across the many devices and platforms capturing data now used for government missions. DARC-ssd™ 600 is designed with the flexibility to address this challenge and deliver significantly improved performance compared to past data-at-rest solutions, continuing Viasat’s legacy of innovating to provide hardware encryption solutions at the highest levels to protect classified and sensitive information.” (Source: https://www.defenseadvancement.com/)

 

03 Apr 25. United States military communications satellite resilience is set to be enhanced via the Protected Tactical Satellite Communications Prototype initiative. Known by its PTS-P acronym, the Protected Tactical Satellite Communications Prototype programme has taken an important step forward with a contract award in January 2025 to Northrop Grumman. Reports state the company will install the PTS-P architecture onboard its ESPAStar satellite technology demonstrator bus. The PTS-P programme is led by the US Space Force’s (USSF’s) Space Systems Command’s Programme Executive Office for Military Communications, Position, Navigation and Timing. The PTS-P effort will mature anti-jam Satellite Communications (SATCOM) technology.

PATS

PTS-P is a child of Space Systems Command’s Protected Anti-Jam Tactical SATCOM (PATS) project which commenced in 2018. PATS is working to provide a tactical alternative to the Lockheed Martin/Northrop Grumman Advanced Extremely High Frequency (AEHF) constellation operated by the USSF. AEHF satellites provide uplink channels on a frequency of 20 gigahertz/GHz, and 40GHz downlinks. Open sources note that AEHF provides data rates of between 75 bits-per-second up to 8.192 megabits-per-second. Facilitating a new tactical SATCOM conduit makes sense. It will help reduce reliance on the AEHF constellation and introduce redundancy vis-à-vis kinetic or electronic attack against SATCOM links.

To the heavens

Reports in 2023 said that PATS will develop specific, secure SATCOM payloads, via PTS-P, providing encrypted signal processing that can be accommodated on both civilian and commercial spacecraft. Principally, the payloads will handle the Protected Tactical Waveform (PTW). A contiguous effort is ongoing, known as the Protected Tactical Enterprise Service, which develops a complementary ground segment. Abbreviated to PTES, this project integrates the PTW into SATCOM ground terminals. Reports continued that, cumulatively, these efforts could require $2.4bn of funding between 2024 and 2028. Alongside Northrop Grumman, Boeing will develop a PTS-P payload to equip its WGS-11 communications satellite. WGS-11 will join the US Air Force’s Wideband Global SATCOM constellation. The USSF told Armada, via a written statement, that WGS-11 is expected to be launched by the end of 2025. The Northrop Grumman satellite will be launched in early 2026. Both PTS-P payloads are expected to have a lifespan of between three and five years. Once aloft, the PTS-P payloads will help “mature advanced anti-jam SATCOM technology” the statement continued. This work will be done through studies and the development of technologies “to provide robust anti-jam satellite communications capability, reduced latency and increased capability to tactical users in contested theatres.” The statement continued that the PTS-P payloads will provide military Ka-band (26.5GHz to 40GHz uplink/18GHz to 20GHz downlink) connectivity. All that existing Ka-band SATCOM terminals will need to use these links is a PTW-compatible modem. Ultimately, the PTS-P work will play an important part in derisking technologies which will eventually adorn the future PTS-R (Protected Tactical SATCOM-Resilient) capability. PTS-R will provide a “larger anti-jamming capability” which can augment the US DOD’s other SATCOM constellations. (Source: Armada)

 

02 Apr 25. Arctic Meridians. Russian Aerospace Forces use truck-mounted R-441LM satellite communications systems to provide links with Russia’s Meridian constellation. Sources indicate that R-441LM trucks have been deployed to support Russia’s ongoing war in Ukraine. Recent open-source intelligence analysis provides more clues on how Russian Aerospace Force integrated air defence system communications are employed. In February, Armada published an article entitled ‘High Frequency in the High North’. In collaboration with EW Analytics LLC this looked at High Frequency (HF: three megahertz/MHz to 30MHz) links used by Russia’s strategic Integrated Air Defence System (IADS). The article identified an HF array at the Russian Aerospace Force (RASF) base at Nagurskoye on Alexandra Land in the Franz Josef archipelago. The archipelago is located in Russia’s Arctic region. EW Analytics LLC speculated that the HF radio and antenna array provide trunk communications to share track data gathered by 12A6 Sopka-2 S-band (2.7 gigahertz/GHz to 2.85 GHz) air surveillance radar located at the facility. AGPs are the Russian equivalent of an IADS control and reporting centre. HF links are thought to be used to help feed radar track data upwards to higher echelons of command. Individual AGPs may share their Recognised Air Picture (RAP) with regional IADS Command and Control (C2) centres, and/or Military District (MD) IADS headquarters. Military district RAPs may then be federated to form a national RAP at Russia’s National Defence Management Centre (NDMC) in Moscow. The NDMC is the Russian military’s supreme headquarters.

SATCOM Truck

As our article posited these HF links may form a back up to the trunk Satellite Communications (SATCOM) supporting routine track data sharing. Since we published our article, additional information has come to light from EW Analytics LLC regarding these SATCOM links. EW Analytics LLC says the AGP at Nagurskoye airbase contains an R-441LM SATCOM truck which houses the necessary antenna, modems and radios. Track data can probably be transmitted using multiple exchange protocols. EW Analytics LLC continues that track data are most likely transmitted to spacecraft from Russia’s Meridian constellation orbiting overhead. Open sources say Russia has at least eight Meridian variant satellites in orbit. Transmissions from the R-441LM truck are made on frequencies of 5.835GHz to 5.885GHz, and 7.250GHz to 7.750GHz. The company’s analysis continues that these data may be encrypted. The SATCOM and HF links maybe the only ways by which the Nagurskoye AGP can share its radar-generated tracks. There may be no undersea cable linking the archipelago to the Russian mainland which could carry fibre optic links. The AGPs in Russia’s northwestern Leningrad MD will be particularly important: Geography dictates that likely ingress/egress routes for North Atlantic Treaty Organisation (NATO) airpower will cross Arctic regions.

Air Defence Assets

The Nagurskoye AGP is subordinate to the 45th Air and Air Defence Forces Army (AADFA). AADFA are the highest echelon of airpower command allotted to each MD. The headquarters of the 45th AADFA is in Safonovo, Murmansk Oblast, northwest Russia. Any kinetic response made to threats detected by the Nagurskoye AGP would be made by several assets deployed with the 1st Air Defence Division (1ADD). The 1ADD has the following units based in Murmansk Oblast: The 531st Anti-Aircraft Missile Regiment (AAMR) deploying S-400 (SA-21 Growler) high-altitude, long-range Surface-to-Air Missile (SAM) battalions. The 583rd AAMR deploying S-300PM/PS (SA-10B Grumble-B) high-altitude, long-range SAM battalions. Also under 1ADD’s command is the 1528th AAMR deploying the S-400. This unit is based in Arkangelsk Oblast to the southeast of Murmansk Oblast. The 45th AADFA possesses the 98th Separate Mixed Aviation Regiment, located at Monchegorsk airbase, Murmansk Oblast. The regiment flies MiG-31BM (Foxhound) combat aircraft. Additional fighter defences are provided by Russian Naval Aviation Su-33 (Flanker-D) and MiG-29K/KUBR (Fulcrum) jets. These belong to the 279th and 100th Separate Shipborne Fighter Regiments deployed at Severmorsk-3 airbase. Severomorsk-3 is also in Murmansk Oblast. It would not be surprising if the RAP generated by the Leningrad MD’s AGPs are not only shared with the NDMC in Moscow, but also with adjacent military districts. The Leningrad MD has the Moscow MD to the south and Central MD to the west. This will help deepen the situational awareness of the latter two military districts, ensuring they can prepare their assets accordingly should a NATO attack arrive from the north. EW Analytics LLC’s latest analysis provides a timely insight into Russian Aerospace Force IADS connectivity. Readers who would like to learn more are advised to visit the company at https://www.ewanalytics.llc/. (Source: Armada)

 

01 Apr 25. April Spectrum SitRep. Hensoldt’s new GMJ9500 backpack jamming system is primarily designed to protect dismounts from remote-controlled improvised explosive devices but has additional utility to protect against uninhabited aerial vehicles, and to jam local communications systems and networks. Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.

A Jammer for all Missions

Hensoldt has launched a new remote-controlled improvised explosive device jammer in the form of its GMJ9500. A company press release said that the new product is primarily intended to equip dismounted infantry squads and can also be used to help protect explosive ordnance disposal teams. According to Hensoldt, the GMJ9500 covers bandwidths of 20 megahertz to six gigahertz. Radio Frequency (RF) threats are neutralised using “advanced jamming algorithms”. Users can configure the equipment according to their mission demands. New jamming waveforms can be integrated into the GMJ9500 as and when they are devised. A useful additional capability is that the equipment can be employed to jam Uninhabited Aerial Vehicle (UAV) RF control channels linking the aircraft with the pilot. Hensoldt told Armada that the GMJ9500 provides a jamming range of over 150 metres (492 feet). “In (UAV) countermeasure scenarios, an even greater range is achievable when operating with a clear line-of-sight.” Moreover, the system can jam radios and networks within range operating on these frequencies. The company is in the final stage of industrialisation for the GMJ9500 and hopes to commence deliveries from early 2026. The product is ready for pre-order. Hensoldt says that it is “in the final stages of securing a large order for an unnamed customer.”

GP-Jammer Unveiled

GPSPATRON has unveiled a new Radio Frequency (RF) simulator called the GP-Jammer. The GP-Jammer is a software tool which can be used to design simulated wideband RF jamming signals. According to the company, the software uses an open source Python library to develop a host of complex signal types. Signals using frequencies of 70 megahertz/MHz to six gigahertz/GHz can be designed. GPSPATRON adds that up to 56MHz signal bandwidth per channel is provided by the GP-Jammer. The number of transmission channels provided by the product is unlimited and based on the licence the customer concludes with the company. The systems library comes pre-loaded with 15 default interference and jamming signals. These include several Continuous Wave and Additive White Gaussian Noise signals. The company told Armada that the “simulator is designed for use in controlled environments for resiliency testing of systems.” The GP-Jammer “can be connected to multiple devices at any time with no limitations on amount.” Furthermore, “it can be used to simulate different types of modulation in interferences at the same time.” The product is available now and customers to date have included companies and academic institutions testing equipment.

Finding Directions

Rohde & Schwarz’ new ADD507 direction-finding antenna is being aimed at military and civilian users alike. The antenna can also be configured for mobile use with a vehicle adaptor. A new compact Direction Finding (DF) antenna has entered Rohde & Schwarz’ product portfolio in the form of the company’s ADD507. A company press release stated that the ADD507 is aimed at both civilian and military markets. Specifically, Rohde & Schwarz sees applicability for the product for spectrum regulators and military spectrum managers. The ADD507 covers a waveband of nine megahertz to eight gigahertz with a single, compact DF antenna, the company adds. A typical DF accuracy of two degrees route mean square is achievable with the ADD507. The compact antenna design enables a “significant reduction in complexity, along with enhanced capabilities and performance specifications.” An active-passive switch provides immunity to “strong, unwanted signals and can be adapted to the signal environment by a mouse click.” Although demurring from specifics, a company spokesperson shared with Armada that Rohde & Schwarz has already won several customers for the ADD507, and development is complete. The spokesperson added that the antenna can be mounted on a vehicle using the company’s ADD-VA2 adapter. (Source: Armada)

 

03 Apr 25. Allen-Vanguard delivers its latest EW product – RF Decoy (TURMOIL) to a NATO nation. Allen-Vanguard, the global leader in providing customised solutions and enabling technology across the Cyber and Electromagnetic Activities (CEMA) domain, has just announced delivery of their latest RF Decoy product TURMOIL to a long-standing NATO nation ahead of schedule.  Due to the nature of the technology and its potential roles, Allen-Vanguard is unable to disclose more specific details. Traditionally known for its RF Detect and Defeat capabilities especially against Unmanned Air Systems (UAS) and Radio Controlled Improvised Explosive Device (RCIED) threats employed by terrorists and extremists, Allen-Vanguard has deep expertise across the whole CEMA domain and has rapidly developed this new disruptive technology to meet a specific market demand and customer requirement.  This is a shift for Allen-Vangauard into EW activities and the team are excited by the potential being identified in the modern Electro Magnetic Spectrum Operational (EMSO) landscape.   Allen-Vanguard’s TURMOIL RF Decoy is an Electromagnetic Countermeasure that delivers tactical advantage against adversaries leveraging Electromagnetic Warfare (EW) capabilities.  TURMOIL creates false targets by accurately emulating friendly forces RF signatures and increasing electromagnetic activity to distract, disrupt and deceive during an enemy’s targeting phase. TURMOIL aides freedom of manoeuvre in the electromagnetic space and creates time and space for formations to deliver surprise offensive operations.

Bobby Strawbridge, President of Allen-Vanguard said: “It is an exciting period for Allen-Vanguard as we harness the vast technical experience and expertise we possess in the company to meet the CEMA demands of the modern battlefield.  I am extremely pleased that Allen-Vanguard has entered the EW arena with this new product, not only because it meets a customer’s specific requirements but it clearly demonstrates how we at Allen-Vanguard can quickly and effectively apply our existing knowledge and skills to deliver success in new areas of operation.”

 

02 Apr 25. MILTON Drones Get a Boost With Rohde & schwarz SIGINT Integration. Rohde&Schwarz and MILTON have partnered to integrate advanced signals intelligence technologies into MILTON’s drones, enhancing security and special force capabilities in surveillance and threat detection. Rohde & Schwarz is collaborating with MILTON, a leading provider of autonomous airborne systems. This strategic partnership has enabled the integration of advanced signals intelligence (SIGINT) technologies into MILTON’s drones, revolutionizing the way security forces conduct surveillance and intelligence missions. Through this collaboration, ongoing since 2021, Rohde & Schwarz has brought its expertise in electromagnetic surveillance to MILTON’s drones, allowing them to detect, locate, and analyze electromagnetic signals emitted by tactical or strategic communications equipment and malicious electronic devices. This technology has significantly enhanced the capabilities of MILTON’s drones, enabling them to identify transmission transmissions, such as clandestine radio communications or enemy drone broadcasts. The integration of SIGINT payloads on MILTON’s drones has numerous practical applications. For instance, in an urban environment, a MILTON drone equipped with a SIGINT payload can pinpoint the origin of a suspicious communications and provide this information to field units for targeted intervention. On a field of operations, it can detect jammers or electromagnetic warfare devices, allowing allied forces to adapt their strategy accordingly. This partnership has significantly strengthened the capabilities of security and special forces in terms of threat detection and anticipation. By reducing reliance on traditional airborne platforms, such as surveillance aircraft, this technology offers a more discreet, flexible, and cost-effective solution for intelligence and protection of sensitive infrastructure.

“At MILTON, we believe that technology should be at the service of operators, simplifying their missions and improving their safety,” said Charles Gillibert, Chief Operating Officer, MILTON. “Our partnership with Rohde & Schwarz is a testament to this approach, as we combine our expertise to bring cutting-edge surveillance capabilities.”

“We are delighted to collaborate with MILTON to bring cutting-edge surveillance capabilities to security and special forces,” explains Stéphane Bringue, Managing Director, Rohde & Schwarz France. “Our partnership is built on a shared commitment to innovation and expertise, with a focus on simplifying missions and improving the safety of interventions. Together, we are pushing the boundaries of what is possible in the field of autonomous airborne systems.” (Source: ASD Network)

 

02 Apr 25. Quaze Technologies successfully demonstrates its resilient wireless power transfer technology in the joint Norway/US Arctic Warrior Experiment. Quaze Technologies builds solutions to recharge any robot anywhere without human intervention and is the creator of wide-surface wireless power transfer (WPT), specifically optimized for use in remote and challenging environments. Quaze has recently taken part in the Arctic Warrior Experiment (AWE) 2025, a Norwegian Special Operations Command (NORSOCOM) arena to test cold-weather equipment capabilities in rugged terrain and arctic conditions. In 2025 NORSOCOM teamed up with United States Special Operations Command (USSOCOM) in an arctic technical experimentation in Norway to stress test a range of capabilities. As part of the capability demonstration, Quaze’s Surface Power Technology, with its magnetic resonance capabilities, was assessed in extreme arctic conditions to provide continuous wireless recharging to a range of deployed equipment. The adaptability of the technology was tested to the full, with Quaze and their partners Galvion being required to rapidly integrate the WPT systems to recharge ‘on-the-soldier’ systems on BRP Lynx snowmobiles and Zeal Motor FAT trucks off?road utility vehicle. The Galvion BATLCHRG™ wireless charging capability was integrated into each vehicle demonstrating that soldiers can charge multiple battery powered systems through safe for human wireless power transfer. There was also a successful demonstration of continuous remote drone charging over 3 days as part of AWE. The robust wireless solution utilizes a charging foldable light surface and receiver configuration that has excellent resiliency and power transfer rates. Quaze’s wide surface power transfer eliminates the requirement for precise alignment and successfully charges any robot in any conditions, proving it can operate efficiently with over 10cm of snow, or other debris, covering the surface. The Quaze technology was demonstrated in other different applications, which are at an early concept stage and have yet to be launched as products. In all applications tested, the technology proved to be reliable and robust in such a harsh environment.  The demonstrations conducted all performed beyond expectations proving that the technology can be used on the battlefield utilizing extreme conditions for tactical advantage, such as concealing equipment beneath debris such as snow, sand, water or soil without impairing charging performance. Coupled with the possibility to charge multiple systems simultaneously and wirelessly, Quaze is set to mark a significant leap in operational efficiency and endurance.

Xavier Bidaut, CEO of Quaze Technologies said, “Quaze continues to be at the forefront of the defence industry’s push towards untethered, cable-free power solutions. The AWE opportunity in Norway enabled us to showcase our unparalleled autonomous operational wireless charging solutions in the most extreme environments. As we look ahead to where this technology might be of future use across land, sea and air domains, we are excited to explore the endless options. We are delighted to continue to push the boundaries of our technology alongside our partners”.

 

01 Apr 25. Cypher Partners with U.S. Army 25th Infantry Division to Accelerate Military Decision Making Through AI-Agent, BATTLEMIND.Cypher, LLC, a leader in advanced Artificial Intelligence (AI) solutions for the national security sector, today announced it has entered into an agreement with the U.S. Army’s 25th Infantry Division. This strategic partnership integrates Cypher’s AI-Agent, Battlemind powered by the Guided Heuristic On-prem Support & Troubleshooting (G.H.O.S.T.) platform, into the 25th Infantry Division’s tactical environment, transforming the manual Military Decision-Making Process into a faster, more efficient process that saves time and enhances accuracy through dynamic human-machine teaming. Specifically tailored for U.S. Army planning operations, Battlemind rapidly synthesizes and analyzes battlefield intelligence, mission parameters, and courses of action to generate precise, actionable, and doctrinally sound outputs. A secure and scalable solution, Battlemind operates seamlessly at all classification levels, safeguarding sensitive data while ensuring real-time access to mission-critical intelligence. Engineered for immediate field acceptance, Battlemind’s adaptable architecture and modular design enable rapid integration across multiple echelons of command ensuring enhanced situational awareness, coordination and synchronization, operational agility, and risk mitigation.

“As a former U.S. Army Intelligence Officer, I’ve witnessed firsthand the immense cognitive burden placed on our warfighters and strategic planners. Battlemind does not replace human decision-making—Battlemind is a force multiplier ensuring our nation’s warriors have the definitive edge to execute quicker, smarter, and safer when it matters most,” said Joseph Anderson, Founder & CEO of Cypher, LLC.

The 25th Infantry Division recently activated Battlemind during Freedom Shield, a command post exercise executed alongside South Korean forces. The exercise validated Battlemind’s potential to optimize planning processes and expedite responses in a fast-paced military setting. The 25th Infantry Division now intends to extend its application across the Division and integrate the solution into forthcoming Indo-Pacific initiatives, further boosting overall combat readiness.

“AI-driven decision support is transforming how warfighters operate in complex environments,” said Colonel Peter Walther, Division Operations Officer, G3, U.S. Army 25th Infantry Division. “I have nearly two decades of operational planning experience and the decision advantage GHOST provides is unmatched. This AI planning tool is critical for planners to operate at the speed of modern conflict.”

Cypher will continue working with key Department of Defense stakeholders to refine and roll out Battlemind across a wider array of military applications. By matching front-line requirements with breakthrough technology, this initiative lays the foundation for data-driven approaches that bolster both tactical and long-range objectives.

For detailed information or to schedule a demonstration, visit https://www.ghostbattlemind.ai.

Cypher, LLC is at the forefront of delivering innovative high-value technology solutions and solving complex challenges across mission-critical environments. Our team has decades of experience supporting enterprise-level government programs—particularly within the Department of Defense and Intelligence Community. Whether delivering on a specific project or managing a long-term IT services contract, we focus on maximizing customer investment and improving organizational performance. From planning and architecture to execution and support, Cypher delivers secure, scalable, and sustainable solutions built for impact.

 

01 Apr 25. Testing begins for Royal Navy’s next generation electronic warfare system. Final tests and upgrades are being carried out on the first of the Royal Navy’s MEWSIC electronic warfare (EW) systems. The Maritime Electronic Warfare System Integrated Capability, known as MEWSIC Increment 1, will be installed on current and future warships, including the Queen Elizabeth-class aircraft carriers, Type 45 destroyers and the Type 26 and Type 31 frigates currently in build. Procured by DE&S, MEWSIC will enhance defensive capabilities by replacing the Navy’s existing EW system – the cornerstone of keeping threats at bay – including anti-ship missiles. The first production model of MEWSIC has been set to work at an Elbit Systems UK facility, while the first build of an updated Combat Management Software System has been delivered to Portsdown Technology Park in Hampshire to support ongoing development.

Dr Allan Paterson, DE&S’ Maritime Electronic Warfare Team Leader, said: “The Royal Navy (RN) has invested in an ambitious programme to deliver modern electronic warfare capabilities that will help its surface warships keep the UK and its allies safe around the world. It’s fantastic to see the first MEWSIC system being delivered by DE&S and our industry partners so that this crucial phase of testing and evaluation can be carried out, and the capabilities of MEWSIC can be proven.”

With Babcock International as the prime contractor working with Elbit Systems, MEWSIC is one half of the overarching upgrade to the Navy surface fleet’s EW capability under the Maritime Electronic Warfare Programme (MEWP). The other is a ‘trainable’ launcher for EW decoys to confuse anti-ship missiles called ‘Ancilia’, designed and built by Systems Engineering and Assessment (SEA) in Barnstaple, North Devon, which will replace Seagnat on existing destroyers and future frigates. The £135m system swivels rapidly and adjusts the angle at which decoy rounds are fired to maximise their effectiveness, which its predecessor cannot do. This means there is no need to manoeuvre the ship to counter the incoming threats as Ancilia will face them directly. Some things still need to be done manually, however, including loading and unloading Ancilia with decoy rounds. Navy electronic warfare specialists have been testing the practicalities of how this can be done best ahead of the system coming into service. This defensive combination will give Navy personnel in the operations room increased situational awareness, helping them to better understand the operational environment and deliver countermeasures to the right place at the right time. The integration of Ancilia with MEWSIC’s Command and Control system makes this anti-ship missile defence formidable. Two Ancilia systems will be fitted to Type 26, 31 and 45 when ready for installation, alongside MEWSIC. (Source: https://www.gov.uk/)

 

31 Mar 25. The French defence procurement agency (DGA) has awarded Thales a contract to provide hybrid networking kits for French Army vehicles, an innovative solution that can be installed without the need to make design changes to the platforms.

  • Installed on military vehicles such as the Griffon, VBCI and Serval, the kits provide access to commercial communication services (OneWeb1 and 5G), integrate them with theatre-wide networking capabilities and tie together communication systems at every level from combined/joint forces command to infantry fighting vehicles.
  • With developments in collaborative combat driving a growing need for connectivity, hybridisation solutions will complement existing hardened communications systems (SYRACUSE IV military satellite communications, CONTACT radios, HF radios) to provide higher data rates, longer range capabilities and improved resilience.

“Thales will be supporting the French Army in its strategic transition to hybrid communication networks. This latest stage in the ASTRIDE 3 programme will combine technological innovation with a deep understanding of operational requirements to provide the hyperconnectivity needed for collaborative combat in high-intensity conflict scenarios,” said Alexandre Bottero, Vice President, Networks and Infrastructure Systems, Thales.

This hybrid networking technology has been developed in an agile, incremental approach with the DGA and operational users to augment the communication capabilities of French Army vehicles. With current developments in collaborative combat, the ability of the armed forces to deploy operational networks of sensors and effectors calls for enhanced capabilities in terms of massification, usability and resilience of military communication systems. With this innovative hybridisation solution, commercial networks will complement existing hardened communication systems including the LOS radios developed for the ASTRIDE programme, the secure, high-data-rate, jam-resistant military satcom services provided by the SYRACUSE satellites, the latest-generation software-defined radios developed under the CONTACT programme and the MELCHIOR series of HF radios. The hybrid networking solution for OneWeb satcom and 5G services is packaged as a non-intrusive kit, overcoming the need for design changes to the vehicle. It offers significant improvements in connectivity to enhance operational capabilities in the theatre of operations by supporting more extensive data sharing and closer multi-domain collaboration. The hybrid networking kit offers a combination of high performance and usability, and its modular design is part of an end-to-end approach encompassing communication systems at every level, from combined/joint forces command to infantry fighting vehicles. Thales will provide an initial batch of 25 kits for field trials during the EXTO SJO 2025 exercise at the end of this year, with an additional 25 kits scheduled for delivery in 2026. Ultimately these hybrid networking kits are expected to equip all French Army vehicles that require them.

The ASTRIDE 3 programme’s central role in collaborative combat

Thales has been involved in the ASTRIDE 3 programme since 2022 and has designed a range of modular mobile communication stations offering the NATO-interoperable networking capabilities needed to provide a secure, resilient command infrastructure for deployed forces. The addition of this hybridisation solution further underscores the programme’s decisive role in making collaborative combat a reality while guaranteeing technological sovereignty.

1 OneWeb is a constellation of approximately 650 Low Earth Orbit (LEO) telecommunications satellites providing broadband Internet access to private and professional users in regions that are poorly served by terrestrial networks.

 

31 Mar 25. SES and SpeQtral Sign MoU to Advance Global Quantum-Secure Communications. An interoperable Optical Ground Station will provide a long-distance Quantum Key Distribution link between Asia and Europe to scale next-generation cybersecurity and services SES and SpeQtral signed a Memorandum of Understanding (MoU) to develop an interoperable Optical Ground Station (OGS) to establish long-distance satellite-based Quantum Key Distribution (QKD) between Asia and Europe. Under the agreement, the development of an interoperable OGS will enable SES and SpeQtral to connect both companies’ current and future QKD satellite missions, resulting in easier access to, and diversity in the supply of long-distance QKD to end users in Asia, Europe and other future compatible ground stations worldwide. The integration of this proposed OGS with Singapore’s fibre-QKD network will help future customers integrate their networks with satellite QKD networks and demonstrate a practical pathway towards enabling a global QKD connectivity once the QKD satellites are operational. SES and SpeQtral collaboration will reduce costs associated with quantum communication infrastructure, bridge a critical gap in the QKD service availability and lower barriers for global deployment and adoption. The first such OGS is anticipated to be built in Singapore which already hosts a vibrant seedbed of quantum-safe activities including the National Quantum Safe Network Plus (NQSN+) initiative driven by Singapore’s Infocomm Media Development Authority (IMDA).

SES and SpeQtral’s Expertise in QKD

Fibre-based QKD networks that are being deployed in major cities around the world will require a satellite-based QKD solution to form an interconnected global QKD network.

QKD satellites operate in Sun-Synchronous Orbits approximately 500 km away from the Earth’s surface, enabling global interconnectivity and laying the foundation for highly secure communications in the age of quantum computing.

SES, in collaboration with a consortium of European partners, is leading the development of the EAGLE-1 project to enable early access to long-distance QKD for ultra-secure data transmissions. The project, which includes both satellite and ground infrastructure, is co-funded by ESA national contributions and the European Commission, reinforcing Europe’s commitment to advancing quantum-secure communications.

SpeQtral is working on two QKD satellites, SpeQtre and SpeQtral-1, which are supported by the Office for Space Technology & Industry, Singapore (OSTIn). SpeQtre, a joint Singapore-UK mission set for launch later this year, will host SpeQtral’s space-qualified quantum-optics system which enables the establishment of quantum-secure encryption keys. OSTIn’s strong support for technological development in advanced space-based capabilities has played an important role in enabling local startups like SpeQtral, foster impactful international partnerships with the potential to shape the global quantum-security industry.

The MoU agreement was signed by the CEOs of both companies in Betzdorf, Luxembourg, during the State visit of Singapore’s President Tharman Shanmugaratnam to the Grand Duchy of Luxembourg.

Adel Al-Saleh, CEO of SES said, “Satellite-enabled Quantum Key Distribution is a fundamental technology for next-generation cyber security, allowing long-distance transmission of encryption keys. At SES we are delighted to bring our innovative expertise in developing secure, interoperable networked solutions, joining efforts with like-minded ecosystem partner SpeQtral in implementing the next milestone of our quantum-secure vision. The agreement allows SES to expand into non-EU markets and serve commercial customers, including facilitating secure exchanges between entities based across different geographies.”

Chune Yang Lum, CEO of SpeQtral, said: “Our partnership with SES represents a significant step towards realising commercially viable space-based QKD. It is important that we build on each other’s expertise, to unlock synergies in this initial phase of enabling the interconnection of localised fibre-based quantum networks. By developing a shared OGS infrastructure, we are reducing costs and strengthening the foundation for a truly global quantum-secure network.”

Mr Jonathan Hung, Executive Director at OSTIn said: “The collaboration between SpeQtral and SES marks a significant milestone in Singapore’s quantum technology landscape that will strengthen secure global communications for the future. The partnership leverages SpeQtral’s strengths as one of the first quantum key distribution (QKD) companies, together with SES’s satellite QKD expertise and position of a global content and connectivity solutions provider – to make quantum communications more accessible worldwide and allow seamless services for end-users in Asia and Europe. We welcome more partnerships with companies to strengthen Singapore’s position at the forefront of quantum communications innovation and commercialisation.” (Source: ASD Network)

 

31 Mar 14. L3Harris Technologies (NYSE: LHX) has signed a long-term agreement with the Dutch Ministry of Defence for delivery of advanced Falcon® IV radios for the FOXTROT program. The agreement is valued up to 1 bn euros.

“Our battle-proven communication systems will improve secure military communications by facilitating interoperability with other European and NATO forces to address current and future threats,” said Sam Mehta, President, Communication Systems, L3Harris. “These resilient devices will enable enhanced capability to strengthen homeland defenses, deter regional conflicts and provide direct support to coalition and security cooperation efforts.”

The Falcon IV radios will allow immediate interoperability with more than 1 m tactical devices already fielded globally. L3Harris Technologies’ in-country leadership – known as L3Harris Technologies’ Netherlands B.V. – has made a commitment to the long-term growth of the Dutch defense industry. It is investing in European technology partnerships; developing in-country technical maintenance and support facilities; and recruiting and training Dutch talent. (Source: BUSINESS WIRE)

 

31 Mar 14. CACI International Inc (NYSE: CACI) announced today that it has entered into a five-year Cooperative Research and Development Agreement (CRADA) with the United States Military Academy (USMA) at West Point to collaboratively advance electronic warfare (EW) technologies to support future U.S. Army missions.

“This groundbreaking agreement provides the Academy with exclusive access to CACI’s advanced EW technology stacks, offering valuable insights that can propel the Army’s capabilities into the future of digital signals processing,” said John Mengucci, CACI President and Chief Executive Officer. “CACI continues to adapt to the dynamic and growing EW threat landscape, as it has for more than two decades. Both CACI and the Army will reap significant benefits as we work together to continue to evolve this critical mission area.”

CACI, a leading signals intelligence (SIGINT) and EW technology provider to the Army and other government customers, has the largest signals threat coverage in the world and is unrivaled in collecting and countering more than 1,000 unique global signals today. CACI has designed and deployed this technology globally across more than 2,000 EW systems providing customers with the necessary capabilities to dominate the Electromagnetic Spectrum and maintain significant battlefield advantage in this critical warfighting domain. As software-defined radios are becoming more prevalent in technology, the ability to create new waveforms will continue to rise. The Army must be able to rapidly detect and counter these waveforms from adversaries in real time to protect systems or attack adversary systems in the future. The first project under this CRADA will focus on extending the applicability of the GRID technology stack as developed for the Program Executive Office – Intelligence, Electronic Warfare & Sensors (PEO IEW&S). GRID, or GPU Radiofrequency IQ Dataplane, is a cutting-edge technology used by the Army for EW systems, enhancing real-time signal processing, threat detection, and electromagnetic spectrum dominance on the battlefield. The Academy will bridge theory and practice by validating GRID data processing outside of a research lab and in the field. Cadets will test GRID firsthand by building Radio Frequency blocks to showcase its performance while also developing a modular framework and methods for extending GRID to support future waveforms. This hands-on experience will reinforce technical expertise in software-defined radio and EW applications and help shape the evolution of GRID for emerging operational needs. By showcasing its innovations and capabilities, CACI aims to strengthen the pipeline of future SIGINT and EW operators while also improving relationships with future customers and partners to support ongoing national security mission objectives, while West Point provides input as a leader in military innovation and education. Through this effort, CACI, working jointly with the USMA, will continue to drive innovation, expand technical impact, and deliver mission-critical solutions to support national defense. (Source: BUSINESS WIRE)

 

31 Mar 25. Serial production of high-tech sensor as Saab expands in Finland. Serial production of the passive electronic warfare sensor Sirius Compact has recently started at Saab’s new production facility in Tampere, Finland. The opening was attended by Finland’s Minister of Finance and Deputy Prime Minister, Riikka Purra, and Mayor of Tampere, Kalervo Kummola. The newly inaugurated serial production facility is a milestone both for Saab’s expansion in Finland and the development of Sirius Compact. Increasing demand for the passive electronic warfare sensor has driven the need for serial production. Saab has expanded strongly in Finland in recent years and sees a positive trend for the coming years with increased export, not least of Sirius Compact.

“Our product-focused research and development work enables efficient production and a product-driven business model. This enables fast deliveries and performance of the latest technology for our customers, says Kristian Tornivaara, Managing Director of Saab Finland.

The new facility is already in operation and enables a high production pace, with the first serial-produced customer deliveries taking place in April 2025.  Sirius Compact is a family of modular and scalable passive sensors that provide enhanced situational awareness through detection, classification and geolocation of various emitters. The family includes Sirius Compact R-ESM for radar and datalink signals and Sirius Compact C-ESM for communication signals.

 

28 Mar 25. Cyber Update Key points.

  • A new Ransomware-as-a-Service (RaaS) operation (‘VanHelsing’) will elevate financial and operational risks for global businesses in the short-to-medium term.
  • A long-term cyber operation points to increased cyber espionage risks stemming from Chinese state-sponsored groups facing the telecommunications sector.
  • A cyber campaign targeting Android mobile users underscores short-to-medium-term information-theft risks for users in China and India.
  • A new malware variant highlights heightened security and disruption risks for critical national infrastructure (CNI) sectors stemming from hacktivist groups.
  • A new variant of existing malware (‘PJobRAT’) underscores the long-term security and data-theft risks facing Android mobile users.

Technical analysis of weekly stories

The Chinese state-sponsored group ‘Weaver Ant’ has been conducting a stealthy cyber espionage operation against an unnamed high-profile telecommunications company in the Asia-Pacific region since at least 2021. The group reportedly compromised a Zyxel-branded home router to infiltrate the company’s systems; the router then became part of an operational relay box (ORB) network that enabled threat actors to move covertly across compromised routers within the organisation. As a result, Weaver Ant’s infrastructure was able to remain obfuscated, and malicious traffic used the routers as a proxy, thus prolonging detection evasion. The group also combined several web shell variants employing the ‘web shell tunnelling’ technique to segment the victim’s network; this effectively created a covert command-and-control (C2) infrastructure inside the victim’s system while enabling Weaver Ant to establish persistence and bypass security restrictions. Weaver Ant then used port mirroring to exfiltrate sensitive data passively (including credentials and system information). The group also created administrative-level accounts to facilitate lateral movement and disabled activity-logging mechanisms to erase evidence of malicious activity. This operation highlights the efficacy and sophistication of Weaver Ant’s detection-evasion techniques, as the group was able to maintain a presence within the victim’s system for at least four years before detection.  A new Ransomware-as-a-Service (RaaS) operation (VanHelsing) has conducted ransomware attacks against global entities since at least 7 March. VanHelsing enumerates and encrypts a system’s local and shared files while deleting all back-up copies to hinder system recovery. Threat actors then demand a ransom payment of up to USD 500,000 for file decryption, underscoring the potentially lucrative nature of this operation. VanHelsing operators warn victims that the use of third-party decryption software will result in permanent data loss to further encourage a ransom payment. The ransomware also supports multiple commands to attune the encryption process to each system. Additionally, it provides a unified control panel to manage attacks across several systems, highlighting its sophistication. VanHelsing has successfully targeted three known victims since its inception and has developed a second (more advanced) version, showcasing its rapid development and possible impact.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering(Source: Sibylline)

 

28 Mar 25. Cuashub.com said today that Silvus Technologies introduces MAN-PC for secure comms in contested environments. Silvus Technologies has unveiled MAN-PC (MANET Power Control), a new capability designed to minimize radio frequency (RF) emissions while maintaining robust mesh network connectivity. The solution, integrated into Silvus’ StreamCaster MANET radios, aims to enhance the low probability of detection and low probability of intercept of military communication networks operating in contested environments.  MAN-PC dynamically adjusts the transmit power of StreamCaster radios based on real-time link conditions, reducing RF signatures when full power is not necessary. By doing so, the system improves operational security by making friendly forces less susceptible to electronic warfare threats, including RF detection and jamming.

“Modern battlefield operations require resilient, covert and adaptive communications,” said a Silvus Technologies spokesperson. “With MAN-PC, forces can significantly reduce their RF emissions without sacrificing network performance, ensuring secure and uninterrupted connectivity in electronic warfare environments.”

Application for counter-UAS operations

As UAS become increasingly integrated into both offensive and defensive military operations, electronic warfare and spectrum management have taken on heightened importance. Many counter-UAS solutions rely on RF detection to locate and track hostile drones. In environments where adversaries employ similar detection tactics, the ability to reduce RF emissions can offer a strategic advantage. By lowering the detectability of friendly forces’ communication systems, MAN-PC helps mitigate the risk of drone-based reconnaissance and targeting. Additionally, its anti-jamming features improve network resilience, ensuring that counter-UAS and other battlefield systems remain operational despite enemy electronic attacks. Silvus Technologies states that MAN-PC is now available as a software upgrade for StreamCaster radios and will be featured in upcoming field exercises to validate its effectiveness in real-world operational scenarios. As the battlefield becomes increasingly reliant on electronic warfare and UAS technology, capabilities like MAN-PC represent aim to ensure secure and resilient communications for military forces. https://cuashub.com/en/content/silvus-technologies-introduces-man-pc-for-secure-comms-in-contested-environments/ (Source: https://cuashub.com/)

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

March 28, 2025 by

27 Mar 25. New UAS Radio Launched for Secure GPS-Denied Communications. Rampart Communications has launched the StrataWave™ UAS Radio, a GPS-independent system designed to ensure secure, resilient drone communications in contested and GPS-denied environments. Rampart Communications has unveiled the Rampart StrataWave™ UAS Radio, engineered to operate without GPS and safeguard transmissions from jamming technologies. Developed for both Group 3 and Group 2 uncrewed systems, the StrataWave UAS Radio overcomes traditional vulnerabilities by ensuring persistent, secure connectivity even in the most hostile environments. Unlike conventional radios, which rely on GPS and can be susceptible to jamming, StrataWave UAS radio prioritizes stealth, resilience, and survivability, allowing UAS operators to maintain unwavering command and control (C2) even under direct electronic attack.

Advantages of the StrataWave UAS Radio:

* GPS-Independent Communication: Immune to GPS jamming attacks, ensuring uninterrupted mission connectivity.

* Electronic Warfare (EW) Resilience: Low probability of detection (LPD) and anti-jam capabilities for enhanced survivability in contested environments.

* Proven Core Technology: Rampart’s physical layer technology is independently validated by over 10 technical and operational tests from top defense research institutions.

As the U.S. military and allied nations rapidly expand their drone operations, the StrataWave UAS Radio addresses a recognized need for resilient and secure battlefield communications. For defense leaders and warfighters, it is designed to maintain C2 even in GPS-jammed environments.

Matt Ball, Chief Executive Officer at Rampart Communications, commented, “Electronic Warfare is disarming battlefield drones at alarming rates, creating an urgent need for next-generation connectivity. StrataWave UAS is the first drone radio built to survive the most hostile electronic warfare—enabling mission-critical drones to stay connected and operational when adversaries attempt to disable them with sophisticated EW systems.” (Source: https://www.defenseadvancement.com/)

 

26 Mar 25.  New malware highlights heightened security, disruption risks to CNI sectors. On 25 March, the cyber security company Flashpoint reported that the pro-Iran hacktivist group ‘Cyber Av3ngers’ has been targeting critical national infrastructure (CNI) organisations with a new custom malware (‘IOCONTROL’) since at least December 2024. IOCONTROL copies itself onto a system’s memory after obtaining access to targeted systems to establish persistence and remain obfuscated. It then establishes communication with command-and-control (C2) infrastructure and subsequently deploys a backdoor component to exfiltrate sensitive data and ensure prolonged persistence. Cyber Av3ngers has used IOCONTROL to infiltrate Internet-of-Things (IoT) and operational technology (OT) devices within fuel management companies in Israel and the US amid the resumption of hostilities between Israel and Hamas.  We assess that there is a realistic possibility that the group will use the malware to temporarily disrupt the provision of key services and/or damage compromised equipment in the short-to-medium term. This highlights heightened security and disruption risks to national infrastructure stemming from hacktivist groups.  (Source: Sibylline)

 

25 Mar 14. Everfox, a leader in cross-domain technology solutions, today announced a strategic partnership with Palantir Technologies (NASDAQ: PLTR), a pioneer in data analytics and artificial intelligence (AI), aimed at supporting customers operating software solutions in classified network environments, including software solutions for joint and integrated command and control. Utilizing approved data transformation formats, this partnership—already tested and deployed with existing customers—will now extend to additional clients with complex network and operational environment needs. By applying Everfox’s robust cross-domain solutions to Palantir’s AI capabilities, warfighters can rapidly process, decide and react to real-time intelligence streamed from multiple sensors, platforms, and networks, providing a comprehensive and unified data environment across domains. Everfox will also utilize Palantir’s Mission Manager in conjunction with its own cross-domain solutions. This empowers customers to efficiently field, manage, and maintain their commercial, open source and government off-the-shelf software (GOTS) baselines across complex classified networks. Built on commercial industry best practices and government standards, Mission Manager offers a secure and automated software infrastructure, delivering rapid fielding and continuous integration/continuous delivery (CI/CD) support models to any tactical and classified network environment. This suite of capabilities heralds a new era of software agility and reliability, bringing commercial software best practices to customers operating within the most complex and secure classified network environments.

“Joint command and control are crucial for the U.S. to keep pace with the volume and complexity of data in modern warfare. Access to this data is often the difference between mission success and failure,” said Sean Berg, CEO of Everfox. “Working with Palantir Technologies, we can better support our customers through innovative and highly secure cross-domain technology solutions.”

“We’re proud to partner with Everfox to enhance the warfighter mission,” said Akash Jain, President of Palantir USG. “Our combined efforts will provide our customers with transformative operational efficiency, ensuring they remain at the forefront of technological advancements in defense.”

Everfox and Palantir Technologies underscore a shared commitment to advancing national security through innovation. By combining their respective strengths, the two companies will deliver transformative solutions that will empower the warfighters with the necessary tools to maintain a strategic advantage on the battlefield. To learn more about Everfox, its collaboration with Palantir and work supporting command and control capabilities, visit www.everfox.com. (Source: BUSINESS WIRE)

 

24 Mar 25. British Army’s Project Asgard network enhancements revealed. Further details have emerged of the communications element of Project Asgard, the British Army’s programme to enhance the command-and-control (C2) capability of the force committed to the defence of Estonia, including the Forward Land Force (FLF) battlegroup from the 4th Armoured Brigade Combat Team (4 Armd Bde CT) that is deployed in theatre. Speaking at SAE Media’s Future Soldier Technology conference in London in March, Colonel Pete Brunton, programme manager for Land Environment Tactical Command Information Systems (LE TacCIS), said Project Asgard had resulted from the Chief of the General Staff’s directive that the FLF required a recce/strike complex and needed to be able to “see further, strike harder and cheaper, and decide much quicker”. Col Brunton said Project Asgard was providing enhanced intelligence, surveillance, target acquisition, and reconnaissance (ISTAR); one-way effectors; and networks. Focusing on the networks, Col Brunton said the project had been in progress since the fourth quarter of 2024. Equipment is being delivered, training is under way in the United Kingdom, and delivery into theatre will take place later in 2025. He explained that the networks effort had addressed three areas: range extension, dismounted communications, and national and international interoperability. New masts, higher than the existing 12 m equipment and with longer low-loss co-axial cables, have been procured to break the tree canopy for range extension without radio rebroadcast. DarkSky radio frequency reflectors from Phoenix C4i, which can be attached to the antennas, are intended to enhance directional gain and screen the antenna from advanced electronic warfare (EW) sensors. (Source: Janes)

 

25 Mar 25. Asia-Pacific: Covert operation points to raised espionage risks from Chinese state-sponsored groups. On 24 March, the cyber security company Sygnia reported that the Chinese state-sponsored group ‘Weaver Ant’ had been conducting a stealthy cyber espionage operation against an unnamed high-profile telecommunications company in the Asia-Pacific region since at least 2021. The group reportedly used an operational relay box (ORB) network (made up of several compromised Zyxel home routers) to infiltrate the company’s systems and to obfuscate infrastructure. Weaver Ant also combined several web shells to maintain access to compromised systems while bypassing security restrictions. It then used port mirroring to exfiltrate sensitive data and to enhance detection evasion at the same time. The group was able to steal information for at least four years before detection, showcasing the stealth and longevity of its operation. This campaign follows an uptick in the number of reports concerning cyber espionage operations conducted by Chinese state-sponsored groups against the telecommunications sector in the Asia-Pacific region, as well as in Europe and the US. We therefore assess that it highlights the long-term elevated cyber security and espionage risks amid ongoing geopolitical tensions. (Source: Sibylline)

 

21 Mar 25. Cyber Update Key points

* A spike in state-sponsored cyber attacks underscores the long-term security, cyber espionage and disruption risks facing the European telecommunications sector.

* A new remote access trojan (‘StilachiRAT’) has highlighted the elevated security and financial risks facing global cryptocurrency users.

* The use of fake artificial intelligence (AI) installers to distribute malware underscores the elevated security and financial risks stemming from cyber criminals. The Ukrainian military and defence sectors are facing increased security and cyber espionage risks from the cyber threat group ‘UAC-0200.’

* A cyber operation targeting Taiwanese national infrastructure will sustain long-term security and information-theft risks from the threat group ‘UAT-5918’.

Technical analysis of weekly stories

Cyber criminals are using fake software installers for the AI platform ‘DeepSeek’ to distribute malware in an ongoing financially motivated campaign. Threat actors typically use search engine optimisation (SEO) poisoning to direct traffic to threat actor-made malicious websites; the websites’ URL and general appearance emulate legitimate AI services to trick users into downloading fake DeepSeek installers. This covertly executes several malware strains onto victims’ systems to steal credentials and/or sensitive financial information. In some instances, threat actors re-created fake CAPTCHA challenges to feign legitimacy before infecting victims’ systems with information-stealing malware. This likely allows threat actors to hijack user accounts and initiate fraudulent money transfers. Alternatively, threat actors can download a Powershell script through process-injection techniques after establishing communication with command-and-control (C2) servers; this enables them to deploy crypto-mining software (‘XMRig’) while remaining obfuscated by hiding the crypto-miner within legitimate processes. Another iteration of the campaign covertly installs third-party software in a bid to increase the volume of downloads and to garner illicit profit as part of affiliate marketing programmes. This campaign highlights cyber criminals’ ability to capitalise quickly on evolving market trends. The cyber threat group UAT-5918 has targeted critical national infrastructure (CNI) organisations in Taiwan in an information-theft operation since at least 2023. The group typically exploits known software vulnerabilities on unpatched internet-facing servers to infiltrate targeted organisations; it then disables the security protections put in place by the cyber security service Microsoft Defender before conducting initial network reconnaissance to gather system information. UAT-5918 subsequently deploys several web shells to establish persistence within compromised systems, to escalate privileges and to execute remote commands. The threat actors likely create administrative-level user accounts to enhance persistence. The group also installs information-stealing malware (such as ‘Mimikatz’, ‘LaZagne’ and ‘BrowserDataLite’) to exfiltrate login details and browser information, enumerating local and shared files to identify data of interest. Additionally, UAT-5918 consistently conducts network reconnaissance throughout its operations to identify and infect additional devices, highlighting the prolonged nature of this campaign. The group uses reverse proxies to establish and obfuscate C2 communication, underscoring its detection-evasion capabilities.

Non-exhaustive recommendations to mitigate against these threats include:

* Monitor devices and networks for suspicious activity

* Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware

* Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise

* Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

Our cyber word(s) of the week: Reverse proxy (Source: Sibylline)

 

24 Mar 25. New RaaS variant points to financial, disruption risks for businesses in short-to-medium term. On 23 March, the technology company Check Point reported that a new Ransomware-as-a-Service (RaaS) operation (‘VanHelsing’) has targeted global entities since at least 7 March. VanHelsing identifies and deletes all backup files to hinder system recovery before encrypting a system’s files. Threat actors then demand a ransom payment of up to USD 500,000, warning that the use of third-party decryption software will result in permanent data loss to coerce victims into paying the ransom. VanHelsing supports multiple commands to attune the encryption process to victims’ systems, underscoring its sophistication. Additionally, VanHelsing affiliates cannot target members of the Commonwealth of Independent States (CIS), suggesting the threat actors are possibly of Russian origin. The ransomware has successfully targeted three known victims since its inception and has developed a second (more advanced) version, highlighting its rapid development and possible impact. We assess this points to the elevated security, financial and disruption risks facing global entities in the short-to-medium term. (Source: Sibylline)

 

21 Mar 25. Persistent Systems Supports CJADC2 Operations at Project Convergence-Capstone 5 Experiment. Company demonstrates the maturity of its networking capability in line with U.S. military.  Persistent Systems, LLC (“Persistent”), a global leader in mobile ad hoc network (MANET) technology, announced today that its secure, highly scalable network successfully supported Project Convergence-Capstone Five (PC-C5), a Combined Joint All-Domain Command-and-Control (C-JADC2) experiment. Hosted by U.S. Army Futures Command, PC-C5 brought together all branches of the U.S. Armed Forces—along with foreign military partners from Australia, Canada, France, Japan, and New Zealand—for an operationally relevant, two-phase experiment at locations around the West Coast and the INDOPACOM theater.

“Over three days, we successfully integrated our transport-agnostic global communications fabric – the Wave Relay® MANET – into the Army’s existing Mission Command applications architecture, uniting decision-makers, tactical teams, and systems,” said Brian Spurlock, Vice President of Growth and Strategy at Persistent. “At PC-C5, Persistent networked a wide range of units and platforms—from Army armored vehicles to the Air Force’s Tactical Operations Center-Light (TOC-L) and high-altitude balloons – bringing the vision of C-JADC2 to life.”

For the Army component of PC-C5, Persistent Systems provided the Wave Relay® MANET connectivity for tactical combat formations executing one of the most challenging military operations – a combined arms breach of a mined wire obstacle. This marked the first time Persistent’s MANET connected M1A1 tanks and Bradley Fighting Vehicles with dismounted soldiers, enhancing the Army’s ability to execute complex combat maneuvers.

“In combined arms breaches, rapid mobility and large-scale communication can be a challenge,” Spurlock said. “At PC-C5, the Wave Relay® MANET provided a highly mobile, scalable communication fabric – from the edge to the enterprise.”

Accelerating Decision Making

Persistent also provided networking support to the Futures Directorate of Air Force Combat Command. The company integrated its MANET-Cloud High Mobility Radio (MCHMR) – previously validated in June at Valiant Shield – with the new Air Force battle management system, TOC-L.

“By combining MCHMR with the TOC-L, the Air Force was able to move radar and high-bandwidth sensor data to Army shooters in seconds,” said Adrien Robenhymer, VP of Air Force and Intelligence programs at Persistent. “This marks a dramatic shift from large, fixed, and expensive legacy systems.”

Additional Testing and Integration

Beyond core experiments, Persistent engaged in additional networking opportunities at PC-C5:

* Collaboration with the Joint Chiefs of Staff’s J6 Directorate, using the event as a technology risk-reduction opportunity ahead of Northern Edge.

* Transmitting data from high-altitude balloons back to Fort Irwin, demonstrating Persistent’s ability to link distributed assets across large operational areas.

“At PC-C5, Persistent showed that its robust, secure, scalable networking technology can meet U.S. military CJADC2 requirements today,” Spurlock said. (Source: ASD Network)

 

20 Mar 25. Taiwan: Cyber operation underscores long-term security, information-theft risks facing CNI. On 20 March, the technology company Cisco reported that the cyber threat group ‘UAT-5918’ has targeted critical national infrastructure (CNI) organisations in Taiwan in an information-theft operation since at least 2023. The group typically exploits known software vulnerabilities on unpatched internet-facing servers to infiltrate targeted organisations; it then disables security protections before conducting initial network reconnaissance. UAT-5918 subsequently deploys multiple web shells to establish persistence within compromised systems, as well as to escalate privileges and execute commands remotely. It also installs credential-stealing malware to obtain sensitive information, and consistently conducts network reconnaissance to infect additional systems, highlighting the long-term nature of its campaign. UAT-5918’s modus operandi and choice of targets overlap with those of several Chinese state-sponsored groups, suggesting this operation is possibly aligned with China’s strategic objectives. We assess the operation will sustain long-term security and information-theft risks for Taiwanese CNI sectors amid ongoing regional tensions. (Source: Sibylline)

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

March 21, 2025 by

20 Mar 25. Spectra Group train Armed Forces of the Philippines (AFP) to use Troposcatter MTTS. Spectra Group (UK) Ltd, a specialist provider of secure voice, data and satellite communications systems, has been supporting the Armed Forces of the Philippines (AFP) to enhance their strategic communications expertise, particularly by maximising the capabilities and hence benefits of using Comtech’s Troposcatter Modular Transportable Transmission System (MTTS). Spectra Group acquired the global distribution rights for Comtech’s Troposcatter Family of Systems (less USA, Canada and Mexico which is retained by Comtech) in 2024 and late last year Spectra Group also announced opening their Australia office to better support the Asia region. Tropospheric scatter is a communications capability that uses the Troposphere (up to about 13km altitude) to provide high bandwidth communications. It is satellite independent and works in a GPS/GNSS denied environment, so is suitable for use in a Peer-on-Peer conflict/Multi Domain Integration. Troposcatter inherently has very low latency and can provide huge bandwidth, potentially enabling analysis and manipulation of large data, which combined with its low operating cost makes it suitable for strategic down to tactical headquarters. Troposcatter MTTS is the most flexible, rapidly deployable, modular transit case troposcatter system available for when the operational situation demands high power, typically 500W. Key benefits for the AFP include rapid deployability, exceptional mobility and robust performance in challenging environments, enabling critical voice, data, and video communications in situations where traditional infrastructure is unavailable. Throughout March, Spectra Group has been providing a comprehensive familiarisation and training package to the AFP to ensure that they are not only able to unlock the full capability of their MTTS Troposcatter systems but also embed indigenous knowledge and expertise to maintain the capability for the future.
Shaun Barry, Business Development Manager at Spectra Group said: “We have been working hard over the last couple of years to develop opportunities in the Asia region and this training programme is a good example where we are directly supporting our customers to not only get the best from their equipment now but also sustain that capability into the future. The region is extremely geographically complex which presents multiple strategic communication challenges for security forces and Spectra Group has have a number of superb systems including Troposcatter, SlingShot and soon GENSS that provide the perfect solution to these challenges.”

 

19 Mar 25. Thales reveals new vehicular version of SquadNet radio. Thales UK has released a vehicular version of its SquadNet dismounted soldier radio called the Vehicle Mounted SquadNet Radio (VMSR), for which it has an unspecified NATO member launch customer.
Speaking at the product launch on 12 March at SAE Media’s Future Soldier Technology Conference in London, Ciaran McCloskey, product line manager, tactical products for Thales UK, said that the radio provides seamless integration of secure voice and data between dismounted troops and the vehicle platform. Like the handheld (HH) version of the radio, which measures 20×10×6 cm and weighs 250 g, the VMSR operates in the 431–470 MHz and 865–880 MHz frequency bands and has an output power of 250 mW. A mobile ad hoc network (MANET) radio, it utilises a standard waveform with automatic 3-hop networking, providing simultaneous voice and data services. It also runs the same waveforms as the HH SquadNet including low probability of detection, anti-jam frequency hopping, multipole voice mode (four simultaneous voice nets), full duplex, and dual voice net. McCloskey said that the VMSR form factor has been specifically designed to enable fitting in as wide a range of vehicles as possible, both traditional military platforms and commercial vehicles. It can be dashboard, bulkhead, or seatback mounted. (Source: Janes)

 

19 Mar 25. Ulefone Armor 28 Ultra Series Unveiled with Dimensity 9300+, Pioneering AI Thermal Imaging.
Ulefone launched the performance powerhouse Armor 28 Ultra Series. Dimensity 9300+ global debut, 16GB+ 1TB massive storage. its Thermal Version features next-gen AI-powered thermal imaging.
Ulefone celebrates its 10th anniversary with the launch of the Armor 28 Ultra series, a lineup of rugged smartphones designed to deliver unparalleled performance and innovation. The series includes the standard
Armor 28 Ultra and the exclusive Armor 28 Ultra Thermal Version, which introduces next-generation AIpowered thermal imaging capabilities. Both models are powered by the groundbreaking Dimensity 9300+ chipset, feature AMOLED dual-screen technology, a Sony IMX989 1-inch main camera, 1TB storage, and Wi-Fi 7 support. With an Antutu score exceeding 2.3 m, these devices set a new benchmark for rugged smartphones.
Exclusive Next-Gen Thermal Imaging in Armor 28 Ultra Thermal Version
The Armor 28 Ultra Thermal Version offers professional-grade thermal imaging empowered by AI. It features a next-gen ThermoVue T2 thermal sensor, enhanced by SharpenAI and FusionAI technologies, which reduce image processing time by 50%. With an ultra-high thermal sensitivity of <40mk and a professionalgrade accuracy of ±2%, the device achieves a super thermal resolution of 640 x 512, delivering exceptional image quality and detail. The ThermoVue Pro app introduces new image modes and features. This makes the Thermal Version ideal for professionals in fields such as construction, engineering, and emergency response.

 

18 Mar 25. ALQ-167 Angry Kitten electronic warfare pod in testing on C-130s. The US Air National Guard Air Force Reserve Command Test Center (AATC) is testing the ALQ-167 Angry Kitten electronic warfare (EW) pod aboard Lockheed Martin C-130 Hercules transport aircraft, the centre announced on 12 March. Angry Kitten has completed testing aboard the F-16, its primary platform. The pod was developed by the Georgia Tech Research Institute as a simulated threat emitter pod, such that F-16s with Angry Kitten aboard could simulate potential enemy systems without modifications to their internal systems. Angry Kitten’s software proved easy to update, leading the US Air Force to modify it for use as a combat-capable jamming pod.
“We had minimal hopes for what we could do for larger body aircraft, but it’s showing that we actually have good effects,” Chris Culver, an EW engineer attached to the project, said in the announcement.
Testing aboard the C-130 involved real-time updates, such that operators onboard the aircraft could hone jamming techniques during flight; tests aboard the F-16 entailed such modifications on the ground following flights, the announcement noted. The Angry Kitten pod was mounted to an AS-7 Special Airborne Mission Installation & Response (SABIR) retractable arm attached to the C-130’s left paratrooper door, which was lowered below the aircraft for operation.
“They are making changes real time to the techniques and pushing updates to the pod, seeing the change in real time,” Culver said. (Source: Janes)

 

18 Mar 25. Smiths Detection, a global leader in threat detection and security Screening, has signed an agreement with Deepnoid, a Korean specialised AI software company led by CEO Choi Woo-Sik, to test AI integration within its security screening systems. Deepnoid’s AI technology will undergo rigorous testing with Smiths Detection’s HI-SCAN 6040-2is carry-on baggage X-ray scanner, with future trials exploring its potential in Computed Tomography (CT) screening to increase detection speed, precision and efficiency.
This collaboration supports Smiths Detection’s responsible open architecture, ensuring third-party AI solutions work seamlessly within its technology while maintaining the highest security standards. It is part of the Ada Initiative, Smiths Detection’s structured process for onboarding suppliers to ensure their hardware, software, and algorithms integrate flawlessly. By introducing AI-driven tools, this partnership strengthens threat detection while keeping security infrastructure adaptable to future risks.
Cymoril Metivier, Global Digital Portfolio Director, Smiths Detection, commented: “We are excited to collaborate with Deepnoid as we explore new advancements in security screening. Advancing threat detection has been a key focus for Smiths Detection for years, with our iCMORE AI-driven algorithm suite using advanced object recognition to accurately detect prohibited items, weapons, lithium batteries and other dangerous goods. Driving responsible open architecture strengthens these capabilities, enabling greater flexibility to integrate new technologies. This partnership reinforces our commitment to high-performance security solutions that stay ahead of evolving threats.”
Sunghoon Eom, Country Manager – Korea, Smiths Detection Asia-Pacific Pte Ltd, commented: “We are honoured to partner with Deepnoid to advance AI-driven security screening solutions. This collaboration strengthens our regional ties and enables us to better respond to the specific AI demands of the local market. By combining expertise, we can deliver more sophisticated and effective security solutions, benefiting both Korea and the wider global market.”
Jae-Ik Cho, Executive Vice President, Deepnoid, stated: “This collaboration is a significant milestone for Deepnoid as we aim to become a game-changer in the security AI market. We will leverage our partnership with Smiths Detection to position ourselves as a leading provider of innovative AI technology in the global security screening industry.”
Deepnoid continues to expand its global footprint, developing AI solutions for healthcare and security. This partnership accelerates AI-powered security screening, ensuring faster, smarter, and more precise threat detection.
By ensuring seamless interoperability between cutting-edge hardware, software, and AI-driven solutions, Smiths Detection continues to set the standard in global threat detection, safeguarding people and critical infrastructure worldwide.
Through our open architecture approach, we create tailored third-party integrations, and with iCMORE, our in-house engineered suite of AI-driven threat detection solutions, we redefine security operations. Seamlessly integrated with our X-ray screening systems, iCMORE enhances detection accuracy for prohibited items, currency, weapons, lithium batteries, and other dangerous goods. By reducing operator workload, streamlining workflows, and cutting false alarms, it empowers security teams to make faster, more confident decisions. Designed to scale and evolve, iCMORE ensures that security operations stay ahead of emerging threats.

14 Mar 25. EDA Conducts 1st CBRN Live Agent Training. The European Defence Agency (EDA) has conducted its first-ever chemical, biological, radiological, and nuclear (CBRN) live agent training for specialised defence units.
Hosted at the CBRN Test and Training Centre in Zemianske Kostolany, Slovakia, the training took place from 2 to 7 March 2025, with participants from eight EU Member States facing scenarios on qualified and forensic CBRN sampling.
As part of efforts to increase the safety of European armed forces and the wider population, EDA is also committed to strengthening CBRN defence through advanced threat detection projects, such as the ‘Chemical, Biological, Radiological, Nuclear Surveillance as a Service’ (CBRN SaaS).
The training in Slovakia was not a simulation. Real radioactive materials, such as Caesium-137, and highly toxic chemical warfare agents, including VX and Sarin, were used in accordance with the highest safety standards. Every step and every procedure had to be executed in full CBRN protective gear. This hands-on experience strengthened specialists’ ability to detect, contain, and neutralise threats.
An eight-member evaluation team, comprising experienced CBRN defence personnel from five Member States and led by EDA, assessed the course in real time, enabling the immediate identification of lessons learned for future projects.
Bridging civil-military gaps
Training defence specialists under real CBRN conditions also helps bridge gaps between civilian and military sectors. In a crisis, coordination is key, and expertise and resources must be deployed without delay. Strengthening Europe’s preparedness contributes to a faster, more effective response framework that protects both soldiers and civilians. “A soldier’s gear isn’t always a rifle. Sometimes, it’s a gas mask, gloves, and a protective suit,” said EDA Project Officer for CBRN Friedrich Aflenzer.
EDA’s broader role
Founded in 2004, the Agency helps foster defence cooperation across Europe. It serves as the central hub for EU countries aiming to develop their defence capabilities together. EDA’s activities span from harmonising requirements and developing operational capabilities to research, technology, innovation, training, and supporting Common Security and Defence Policy operations. The agency also works closely with the European defence industry to strengthen Europe’s technological and industrial base. (Source: ASD Network)

 

14 Mar 14. Cyber Update Key points.
* The adoption of the ‘Qilin’ Ransomware-as-a-Service (RaaS) by the North Korean state-sponsored actor ‘Moonstone Sleet’ will sustain elevated financial risks for global organisations (see Sibylline Cyber Daily Analytical Update – 10 March 2025).
* A stealthy operation has elevated the cyber espionage risks stemming from the suspected Indian advanced persistent threat (APT) group ‘SideWinder’ for the global maritime, logistics and nuclear sectors (see Sibylline Cyber Daily Analytical Update – 11 March 2025 and our Technical analysis below).
* A cryptocurrency-theft operation by the North Korean state-sponsored group ‘Lazarus’ will sustain long-term financial risks for global entities (see Sibylline Cyber Daily Analytical Update – 12 March 2025 and our Technical analysis below).
* A breach at an electricity utility company in Massachusetts (US) highlights the long-term security risks facing CNI sectors stemming from the Chinese state-sponsored group ‘Volt Typhoon.’
* US critical national infrastructure (CNI) will face heightened financial and disruption risks stemming from the RaaS group ‘Medusa.’
Technical analysis of weekly stories
The suspected Indian advanced persistent threat (APT) group SideWinder has targeted the maritime, logistics and nuclear sectors across Africa, Asia and Europe in cyber espionage operations since H2 2024. The group uses spear phishing emails to trick potential victims into opening a malicious .DOCX attachment. The emails purport to provide information on governmental decisions and/or diplomatic issues pertaining to nuclear power plants, maritime infrastructure and port authorities to enhance legitimacy and bolster infection rates. The attachment downloads an additional file containing malicious JavaScript code using a remote template injection technique; it then exploits a known software vulnerability (CVE-2017-11882) to execute the code, initiating a multi-stage malware execution process. The JavaScript loads a downloader module to collect information on installed security protections, highlighting SideWinder’s detection-evasion capabilities. If no security mechanisms are detected, the group deploys a first-stage malware loader (‘Backdoor Loader’) that subsequently installs information-stealing malware (‘StealerBot’) to exfiltrate sensitive information from compromised systems. If SideWinder’s tools are discovered on an infected system, the group will deploy modified versions of the malware within hours; this highlights the persistence and sophistication of SideWinder’s techniques.
The North Korean state-sponsored group Lazarus is exploiting a legitimate open-source software repository to conduct a cryptocurrency-theft operation. The group advertises malicious software packages on the repository, using typo-squatting techniques to enable the files to appear legitimate; this tricks developers into downloading the malicious packages, allowing Lazarus to infiltrate targeted systems. The group uses several techniques to obfuscate the malicious code contained in the packages, showcasing the group’s detection-evasion capabilities. The code collects sensitive information from compromised systems (including login credentials) and exfiltrates cryptocurrency assets, before transferring stolen data to command-and-control (C2) infrastructure. It also deploys a backdoor (‘InvisibleFerret’) and additional malware (‘BeaverTail’) to achieve prolonged persistence on compromised systems and to execute additional commands remotely. Additionally, the group has created GitHub pages for several of the malicious packages to feign legitimacy, underscoring Lazarus’ continued exploitation of legitimate platforms in malicious operations.
Non-exhaustive recommendations to mitigate against these threats include:
* Monitor devices and networks for suspicious activity
* Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
* Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
* Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering
Our cyber word(s) of the week: Remote template injection technique
(Source: Sibylline)

 

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

March 7, 2025 by

06 Mar 25. Leonardo DRS, Inc. (NASDAQ: DRS) announced today the delivery of its first next-generation Integrated Voice Communication Systems (IVCS) in support of the U.S. Navy’s Arleigh Burke DDG51-class destroyers. The state-of-the-art systems provide mission-critical ship-wide communications vital for ensuring effective operations across all surface navy missions. IVCS is the latest generation shipboard communications technology that provides reliable, tactical communications for Navy operators. The computer-controlled telephone system connects to a ship’s announcing system, shore telephone lines, radio communications and battle sound-powered telephone circuits. The advanced IVCS was designed, built, tested, and delivered as an upgrade to its long line of voice communication systems, including the company’s Shipboard Integrated Communications Systems and Secure Voice Switching systems. These systems are in use on destroyers and frigates of the US, Canadian, Australian, New Zealand, Japanese, and South Korean navies underscoring the company’s leadership in delivering cutting-edge secure naval communications solutions.

“This delivery marks a significant milestone in the ongoing partnership between Leonardo DRS and the U.S. Navy, reaffirming the company’s commitment to supporting global naval operations with advanced, reliable and secure communication technologies,” said Cari Ossenfort, senior vice president and general manager of the Leonardo DRS Naval Electronics business unit. “We are proud to continue to answer the call by fielding modern network communications supporting our warfighters today and into the future.”

Leonardo DRS has been a key supplier for the U.S. Navy Cruiser and Destroyer Aegis Modernization program providing mission-critical, tactical communications systems supporting command and control operations on the ships. It is another example of the company’s deep experience as a leader in complex design and manufacturing supporting a wide range of missions and capabilities. Leonardo DRS’s abilities extend across all domains to support naval, ground, air, space, and cyber missions in areas of sensing, force protection, computer networking, as well as naval power and propulsion systems. (Source: BUSINESS WIRE)

 

06 Mar 25. Intracom Defense (IDE) signed a Memorandum of Understanding with ETIMAD Strategic Security Solutions (ESSS) in the sector of Tactical Communication Systems, with the aim to enhance operational availability and efficiency, and elevate service quality towards the Armed Forces of the United Arab Emirates. The agreement was signed by Mr. Khaled Al Ali, CEO of ETIMAD Holding Group and Mr. George Troullinos, CEO of Intracom Defense, during the International Defense Exhibition IDEX 2025 in Abu Dhabi, where IDE participated in the frame of the Hellenic Pavilion. This agreement focuses initially on providing end-user industrial support and security of supply, related to Tactical Communication and Information Systems of IDE, currently under deployment process at the UAE, as well as to jointly addressing future market opportunities, utilizing ETIMAD’s advanced industrial capabilities. ESSS is a UAE-based company, as part of ETIMAD Holding under the EDGE GROUP, specialized in advanced technology solutions and services, with a dedicated focus on security systems integration and project fulfillment. ESSS has established itself as a leading project manager for strategic projects, such as Safe City, Border, Coastal & Critical Infrastructures globally, delivering efficient and high-quality services across various sectors. (Source: ASD Network)

 

04 Mar 25. Common Sense. The stark reality is that Europe may soon face a new adversary. As matters stand at present, US President Donald Trump is acting in a way that is directly hostile to Europe’s interests. The Trump Administration began ‘peace talks’ with Russia to try to end the war in Ukraine on 15th February. None of Europe’s democracies, including Ukraine, have been invited to attend. Mr. Trump’s behaviour is akin to that of UK Prime Minister Neville Chamberlain on the eve of the Second World War. Mr. Chamberlain’s 1938 Munich Agreement with Nazi Germany ceded parts of Czechoslovakia to Adolf Hitler. The agreement was concluded without the participation or signature of the country most affected. Subsequent news reports indicated that the US is seemingly willing to cave into nearly all of Russia’s demands. Will the world see a Nazi-Soviet Pact, a la Messrs. Trump and Putin in the coming years? We all know how well that turned out. In time the Trump administration will realise, contrary to its delusions, that alliances go both ways. At some point in the future, that administration will need diplomatic and/or military support from Europe. Unlike requests to this end in the aftermath of the 11th September 2001 attacks on New York and Washington DC, this support may no longer be automatic. Witness the furore in parts of Europe regarding the Iraq War of 2003, and the post-9/11 diplomatic goodwill the Bush Administration squandered as a result. Europe has a long to do list to nullify the impact of Mr. Trump’s neo-isolationism: Defence spending must rise in an economically sustainable way. European nations must strike an increasingly hawkish and aggressive tone with Russia. It should be made clear that attempts to destabilise democracies through online, or other means, could merit a conventional military response against the organisations responsible. Defence industrial consolidation is another important area. Why does Europe have two competing sixth-generation combat aircraft programmes? One is surely enough, and the least expensive option. Some consolidation should be happening in the electromagnetic environment. France, Germany, Norway and the United Kingdom all have existing requirements for land force Electronic Warfare (EW) capabilities. These requirements typically focus on large vehicle-mounted systems to provide EW at circa brigade level. Each nation is pursuing its own efforts, no doubt at great expense. There is a case to be made for a common European land warfare EW system which focuses on a modular solution tailored to a range of vehicle types. Armies could order the modules and hardware they need and configure their platforms as they wish. Europe’s combined EW industries and expertise could create a common system that nations could then customise with proprietary threat libraries, jamming waveforms and supporting infrastructure. After all, this is already done in the combat aircraft sector. Moreover, Europe will be fighting together to repel any future Russian aggression against the continent. Commonality in the EW kit that will be unleashed on the battlefield makes sense. If Europe is to create a real and lasting continental defence, new solutions and approaches are needed. A common, European land EW system could be just what the continent’s armies, and taxpayers, need. (Source: Armada)

 

04 Mar 25. No Pasarán. Kvertus’ Atlas counter-uninhabited aerial vehicle system includes electronic support measures to detect the radio signals linking these aircraft to their controller, and allowing the aircraft to transmit video, plus a jammer to attack such links. Plans are afoot to roll counter-uninhabited aerial vehicle defences across the entirety of the frontline in Ukraine. The intensity of Russian Uninhabited Aerial Vehicle (UAV) kamikaze attacks against targets in Ukraine was laid bare in a report from the Centre for Strategic and International Studies (CSIS) in February. CSIS is a defence and security thinktank based in Washington DC. Calculating the Cost Effectiveness of Russia’s Drone Strikes said Russia had launched over 19,000 missiles against targets in Ukraine between 28th September 2022 and 28th December 2024. The report continued that, of these 19,000 projectiles, over 14,700 were kamikaze UAVs. Most of these weapons were Shahed-136 kamikaze UAVs supplied by the Islamic Republic of Iran and designated the Geran-2 by the Russian military. Figures released by the United Nations in February stated that in January alone, 139 civilians were killed by such weapons, with 738 injured. In Ukraine’s southern Kherson region, kamikaze UAV attacks accounted for 70 percent of casualties that month. To be fair, Ukrainian air defenders enjoy success in detecting, intercepting and destroyed a good number of Russian UAVs. Figures produced by the Institute for Science and International Security, another Washington DC-based think tank, say that between 75 percent and almost 100 percent of the Shahed-136s were successfully intercepted by air Ukrainian defenders between April 2023 and June 2024. Nonetheless, efforts are continuing in Ukraine to devise mechanisms to detect and intercept drones. Such aircraft can be tricky targets. They tend to be physically small, meaning they have a small Radar Cross Section (RCS), making them difficult to detect by some ground-based air surveillance radars. Figures seen by Armada have stated that the Shahed-136 may have an RCS as small as 0.01 square metres. Ornithologically speaking, this RCS is smaller than a European blackbird and comparable to a warbler. The risk is that the radar may dismiss targets with small RCSs as birds, and hence clutter, and ignore them. That said, radars are now incorporating software to recognises the flight dynamics of UAVs compared to birds. For example, the radar characteristics of an aircraft’s propellers, compared to a bird’s flapping wings, helps target discrimination.

Holding the line

Ongoing efforts in Ukraine to improve UAV defences have resulted in Kvertus’ Atlas Counter-UAV (CUAV) system. The company has a reported goal of rolling out a CUAV architecture which could eventually furnish the entire the frontline between Ukraine and areas occupied by Russia in the south and southwest. This is a distance of circa 1,200 kilometres (746 miles) according to reports by Ukrainska Pravda. Atlas combines several technologies: Kvertus’ Azimuth UAV Electronic Support Measure (ESM) detection and tracking system, and the company’s Mirage jammer. These sensors and effectors can be distributed across the frontline to create an integrated network of CUAV systems. These apparatuses are controlled by a single operator, their console and server.

Kvertus told Armada that the Azimuth sensor can detect UAVs at a range of 16.2 nautical miles/nm (30 kilometres/km) when the sensor is on the ground and 27nm (50km) when mounted on an airborne platform. Azimuth will detect radio links carrying a UAV’s video feed and the control channel linking the pilot to the aircraft and vice versa. These links typically inhabit frequencies of between 900 megahertz/MHz up to 5.8 gigahertz/GHz. Once a threat is detected, the operator activates the Mirage jammer to attack these channels. Kvertus added that Atlas can allow the detection and jamming cycle to occur automatically sans human intervention.

Architecture

The Atlas architecture typically has one control station, one Azimuth ESM and four Mirage jammers, although this can be scaled up according to the user’s wishes. As well as deploying Atlas ensembles across the frontline, Kvertus said that federated systems could eventually protect the whole country. Although some Atlas components are sourced from the People’s Republic of China, the software is indigenously developed. The immediate intention is for Atlas systems to be deployed across the entirety of the Ukrainian frontline. This process could take several months. (Source: Armada)

 

03 Mar 25. March Spectrum SitRep.

C-GEM Live Firing

Rafael’s 130mm C-GEM radio frequency decoy rocket can be used with 130mm trainable naval countermeasures launchers including the Mk.36 SBROC system.

On 28th January, Rafael Advanced Defence Systems announced it had performed a successful live fire test of the company’s 130mm C-GEM offboard active radio frequency decoy rocket. These rockets are designed to work with the company’s Deseaver series trainable naval countermeasures launchers. According to the company, C-GEM uses an active electronically scanned array transmitter. Providing 360 degrees of coverage, the rocket employs a digital radio frequency memory to generate jamming waveforms. These waveforms can be employed against anti-ship missile active radar homing systems. C-GEM can work with Rafael’s Wizard corner reflector decoy to help protect warships. Other naval countermeasures in the company’s portfolio include the Smoke Trap infrared smoke decoy and the Beam Trap chaff decoy. Boris Katsman, Rafael’s business development director, told Armada that C-GEM is an affordable decoy not covered by US International Traffic in Arms Regulations. Beyond Deseaver, C-GEM can be employed in other trainable launchers like BAE Systems’ Mk.36 Super Rapid Bloom Offboard Countermeasure, known as SBROC. C-GEM is in service with the Israeli Navy and has been supplied to other undisclosed customers in recent years.

New Counter-GNSS Jamming Module

InfiniDome’s new GPSdome-Sunstone GNSS PNT jamming and spoofing resilience module is optimised to equip small UAVs or similar space and weight constrained platforms. InfiniDome has launched its new GPSdome-Sunstone next-generation Global Navigation Satellite System (GNSS) Position Navigation and Timing (PNT) jamming and spoofing resilience module. According to a press release announcing the news GPSdome-SunStone can equip small Uninhabited Aerial Vehicles (UAVs). The module weighs between 50 grams/g (0.11lb) and 100g (0.22lb). In addition to UAVs, the company says the module can provide GNSS PNT jamming protection for other space and weight constrained platforms. InfiniDome told Armada that GPSdome-SunStone uses “null steering to mitigate the jamming attack.” Although null steering is not a new technique, InfiniDome claims their new product is “revolutionary in form factor, weight, price and flexibility (compared) to anything else in the market today making anti-jamming accessible for lower-end platforms as well.”

The company says the module can be retrofitted onto existing platforms: “Any of our customers could take their existing GNSS receiver, disconnect its antenna, connect (our module to the UAV’s GNSS antennas) thus making the platform about 100 times more resilient to an attack than without it.” InfiniDome says it has already won orders for its new product from customers in the European Union, Israel and the United States, “some of which have already began testing in some of the harshest environments with very promising results.”

Blue Jay Mobile Unveiled

Mellori Solution’s new Blue Jay Mobile electromagnetic testing system can replicate emissions across wavebands of between 500 megahertz/MHz and 40 gigahertz/GHz, and mimics multiple threats in the 500MHz to six gigahertz band. Blue Jay Mobile is a new mobile electromagnetic through-air testing system launched by Mellori Solutions in February. The company says Blue Jay Mobile can test and validate sensor performance in any environment. The product covers frequencies from 500 megahertz/MHz up to 40 gigahertz, offering up to 50MHz of bandwidth, according to the Blue Jay Mobile product brochure. The brochure continued that the system can be made ready for use in 15 minutes, and is operated from a laptop or tablet. Remote operation is possible using either a WiFi or ethernet connection. Blue Jay Mobile can mimic both real world signals and In-phase and Quadrature (IQ) data. Ranges of between one kilometre (0.6 miles) and three kilometres (1.9 miles) are achievable. David Devine, Mellori Solutions’ general manager, told Armada that “Blue Jay Mobile has a scenario mode for programming emitters and libraries to simulate real-world radar signals and replay IQ data. These are controlled via a laptop or tablet (by) remote control.” Multiple emitters can be simulated as Blue Jay Mobile “has a dual-channel output that allows transmission across two frequency bands at the same time with no antenna swaps required. This is limited to one channel per band, except for the 500MHz to six gigahertz band, which supports dual-channel capability by default.” Meanwhile, an optional add-on “allows simultaneous dual-channel capability in all bands (and the) system can be upgraded to support a third transmission channel.” (Source: Armada)

 

06 Mar 25. Shifting cyber tactics will elevate security risks from Chinese state-sponsored groups. On 5 March, the technology company Microsoft reported that the Chinese state-sponsored group ‘Silk Typhoon’ has been exploiting the software supply chain in order to infiltrate targeted systems since at least December 2024. Silk Typhoon typically conducts cyber espionage operations against global defence, government, healthcare, education and non-governmental sectors. The group searches GitHub repositories to find credentials and authentication keys stolen from software providers; it subsequently uses the stolen data to conduct password spray attacks, breaching providers’ systems to pivot into downstream customer environments. Furthermore, Silk Typhoon has also continued to exploit software vulnerabilities to infiltrate on-premises environments. Threat actors subsequently attempt to steal credentials, escalating privileges to access cloud environments. Silk Typhoon reportedly no longer uses web shells and malware to steal data and erase evidence, underscoring the continuous development of the group’s techniques. As such, we assess this highlights the elevated long-term security risks facing the aforementioned sectors. (Source: Sibylline)

 

05 Mar 05.  US Army has selected Keysight’s CyPerf network design and verification solution to validate performance, resiliency, and zero trust security for their Unified Network Program during Cyber Quest ’25 (CQ25). Organized by the U.S. Army Futures Command, CQ25 is a crucial event for national security, bringing together the private sector, government, and academia to evaluate, develop, and benchmark cutting-edge technologies to address critical gaps in cybersecurity, electronic warfare, intelligence, and signal operations. As cyber threats, electronic warfare, and Multi-Domain Operations (MDO) evolve, the nature of warfare is forever changed. MDO, a military concept developed by the U.S. Army, focuses on integrating and synchronizing operations across multiple domains — land, sea, air, space, and cyberspace, to achieve strategic and operational advantages over adversaries. The U.S. Army’s Unified Network Program is a key driver for achieving MDO by 2028, enabling the creation of a seamless, resilient, and secure end-to-end network that supports operations across all domains from the office to complex, contested, or hostile environments. The program will equip U.S. forces with the technologies they need to operate effectively and securely in any environment, with access to necessary data anytime, anywhere, regardless of where it is stored.

Keysight CyPerf supports the goals of CQ25 with capabilities that include:

* Assessing zero trust architecture – Integrates zero trust verification principles for continuous authentication and authorization to access network resources, without granting implicit trust based solely on network location. This includes validating networks that require Identity, Credential, and Access Management (ICAM), a framework and component of zero trust that manages digital identities, credentials, and resource access. CyPerf verifies zero trust policies and ICAM in lab settings and live production networks. It can also assign user credentials and navigate ephemeral ICAM procedures to establish secure network connections.

* Simulating real-world scenarios – Creates realistic operational scenarios to evaluate network performance in distributed environments (physical, virtual, cloud, or container) under various conditions. CyPerf deploys lightweight agents that generate high-volume, real-world traffic, applications, and workloads. The solution replicates actual networks, elastically scaling up and down to enable resiliency and chaos simulation. With support for ms of concurrent users and ms of connections per second, CyPerf helps ensure the U.S. Army’s Unified Network can handle the rigorous demands of MDO, validating assets from the tactical edge to cloud-based resources.

* Enhancing network security – Detects potential security vulnerabilities and implements measures to address and mitigate weaknesses. CyPerf simultaneously generates legitimate traffic mixes as well as malicious activities and cyber threat traffic across a complex network of proxies, software-defined wide area networks, Transport Layer Security (TLS) inspection, elastic load balancers, and web application firewalls. CyPerf creates a comprehensive and efficient replication of actual U.S. Army network deployments by uniquely interleaving applications and attacks that model user behavior and actual security breaches.

* Validating network performance – Ensures the U.S. Army Unified Network can support high-speed data transfer and seamless, reliable communication across all domains. CyPerf quantifies and delivers deep insights into the efficacy of network performance, the end-user experience, and security posture. It identifies potential performance bottlenecks and assesses how well the network can handle different types of traffic while still maintaining performance and security objectives – even under extremely high traffic loads or cyber-attacks.

Major James Harryman, Action Officer, CQ25 said: “As we rapidly advance to an increasingly complex battlefield, understanding how we will implement zero trust principles at the tactical edge is imperative. Agility of deployed networks, increased security of assets, and greater interoperability are all potential results of this implementation, and CQ25 is excited to team up with Keysight and use its CyPerf capabilities to prove these underlying principles.”

Ram Periakaruppan, Vice President and General Manager, Network Test & Security Solutions, Keysight, said: “Keysight is honored to collaborate with the U.S. Army at Cyber Quest ’25, bringing our advanced design and verification capabilities to assess and monitor the Unified Network’s performance and security. CyPerf empowers the U.S. Army to confidently navigate the complexities of zero trust architectures and their Multi-Domain Operations, ensuring the network remains resilient, secure, and mission-ready in any environment.”

Resources

* Product page: Keysight CyPerf

* Data sheet: Keysight CyPerf

* Application Note: Performance and Security Testing for Zero Trust in Distributed Cloud

* Flyer: Zero-trust network architecture and CyPerf

About Keysight Technologies

At Keysight (NYSE: KEYS), we inspire and empower innovators to bring world-changing technologies to life. As an S&P 500 company, we’re delivering market-leading design, emulation, and test solutions to help engineers develop and deploy faster, with less risk, throughout the entire product lifecycle. We’re a global innovation partner enabling customers in communications, industrial automation, aerospace and defense, automotive, semiconductor, and general electronics markets to accelerate innovation to connect and secure the world. Learn more at Keysight Newsroom and www.keysight.com. (Source: BUSINESS WIRE)

 

05 Mar 25. BAE Systems working on new version of AN/ALQ-250 EPAWSS. BAE Systems is working on a new version of its AN/ALQ-250 Eagle Passive Active Warning and Survivability System (EPAWSS), intended to equip US Air Force (USAF) Boeing F-15EXs, BAE’s director for Tactical Aircraft Electronic Warfare Lindsay Gallagher told Janes on 4 March at the 2025 Air & Space Forces Association (AFA) Warfare Symposium. The new version, called EPAWSSv2, which features an increase in the system’s processing power, has been under development for two years, Gallagher said. It is in the engineering, manufacturing, and development (EMD) phase, with critical design review – the last such review before prototype production – expected in April. The original EPAWSS, now being fielded on newbuild F-15EXs and retrofitted aboard F-15E Strike Eagles, can no longer be built due to diminishing manufacturing sources, Gallagher said. Several components of EPAWSS – which Gallagher declined to specify – are no longer being constructed, and BAE took the opportunity to upgrade the system’s design.

“We were at a point where we couldn’t build the current version, and so we had to upgrade. And in the process, by doing that, we were able to take some of the newer technologies and upgrade the capability of the system as well at the same time,” Gallagher said.

EPAWSSv2 is not under contract, and Gallagher deferred questions about integration with the F-15 to Boeing.

EPAWSS, which entered service in 2023, replaced the F-15’s Tactical Electronic Warfare Suite, which dates from the 1980s. The system is interoperable with the F-15’s AN/APG-82 active electronically scanned array (AESA) radar and both chaff and flares countermeasure systems. (Source: Janes)

 

06 Mar 2025. EOLO partners with Thales to bring ultrafast broadband to underserved Italian communities.

* Thales’ eSIM solution enables seamless 5G connectivity for EOLO’s new Internet offerings, based on Fixed Wireless Access (FWA) technology.

* This initiative supports the EU’s goal of ‘universal 1Gbps broadband by 2030’ as well as EOLO’s and Thales Commitment to Digital Inclusion and to Innovation.

The European Union aims to ensure that all citizens have access to 1Gbps broadband by 2030 and EOLO selected Thales for its leading connectivity solutions. Achieving this vision requires innovative solutions like Fixed Wireless Access (FWA), which delivers high-speed internet to areas lacking traditional fiber or copper networks. FWA is crucial for connecting people in small towns and rural regions, supporting economic growth, and bridging the digital divide.

EOLO’s Vision for Faster Connectivity

As Italy’s leading FWA provider, EOLO has been pioneering radio technology to deliver affordable, high-speed internet. Currently, the company serves more than 700.000 households and FWA connectivity can reach speeds of up to 300 Mbps in download. To furtherly improve customer experience and reach Italian territories with a service able to bridge digital speed divide, EOLO is launching a 1Gbps FWA service in 2025, combining 5G and millimeter wave (mmWave) technology. This rollout will include a new 5G antenna network and thousands of eSIM-enabled devices installed at customer locations.

Thales’ Expertise in Secure Connectivity

Thales is playing a key role in this expansion by providing its eSIM Management platform, Thales On-Demand Subscription Manager (OSM). This technology allows EOLO’s 5G Routers to be pre-configured with mobile subscriptions, making installation faster and easier. Customers will benefit from instant activation as soon as they power on their devices, ensuring seamless connectivity.

“The infrastructure that we are building together will play a pivotal role by complementing fiber coverage in our country. With a connectivity able to reach 1 Gbps, we will meet the ambitious goals of both European and Italian agendas, helping citizens and enterprises to overcome digital divide and digital speed divide”, commented Guido Garrone, CEO at EOLO.

“Reliable, secure connectivity is essential for digital transformation,” said Eva Rudin, VP Mobile Connectivity Solutions at Thales. “By supporting EOLO with our advanced eSIM technology, we are enabling faster broadband deployment and helping to bridge the digital divide across Europe.”

 

04 Mar 25. Lockheed Martin has developed a software solution that is ready to start connecting America’s advanced warfighting systems, accelerating the realization of the Department of Defense’s vision of Combined Joint All-Domain Command and Control (CJADC2). Lockheed Martin’s self-funded CJADC2 Interoperability Factory is producing an open-architecture, software stack designed to connect the machine languages of our nation’s existing advanced weapon systems, in a way that is message standard agnostic. This “connection” is key to increasing data exchanges, advancing interoperability and greatly improving situational awareness between systems and system operators. The CJADC2 Interoperability Factory has already passed company internal demonstrations. Over the next few months, the Lockheed Martin team will be demonstrating the system to customers. The company will be looking to test the system out in the field during future government exercises.

Why This Matters for Combat Readiness

Interoperability, a long-standing cornerstone of defense strategy, now more than ever enables the DoD and its allies to maintain overmatch and deter peer and near-peer adversary aggression in the 21st century. While future weapons systems are being developed with interoperability in mind, products like Lockheed Martin’s CJADC2 Interoperability Factory will connect new systems with existing DoD and allied systems.

“The challenge is to deter aggression, we need to maintain overmatch now and many of our nation’s existing advanced weapon systems were not originally designed to connect and ‘talk’ with each other this way,” said Ron Fehlen, Vice President, Mission Architecture, National Security Space. “Most of our defense systems communicate using about a dozen different software languages. This is where the CJADC2 Interoperability factory comes in.”

The CJADC2 Interoperability Factory leverages a “systems of systems” approach to rapidly share data across weapons systems — like AEGIS, F-35, HIMARS, and SDA Transport Layer satellites — decreasing kill chain timelines to machine speed.

How The CJADC2 Interoperability Factory Works

As a modular, open-architecture software stack, Lockheed Martin’s CJADC2 Interoperability Factory is designed to simplify and accelerate platform interoperability across all domains.

Lockheed Martin’s goal has been to leverage its mission knowledge and access to operational systems to introduce cross-domain interoperability for both historical platforms already in operation and newly developed and fielded platforms. This ensures that existing platforms can seamlessly connect and integrate with new technologies, enhancing overall system compatibility and effectiveness.

The CJADC2 Interoperability Factory:

* Provides an eco-system of approved, verified and validated translators – from programs across Lockheed Martin’s broad portfolio – as well as more mesh-oriented interoperability approaches, such as DARPA STITCHES (SoS Technology Integration Tool Chain for Heterogeneous Electronic Systems). Platforms have easy-access to this ecosystem, regardless of their operating environment, allowing for faster progression to deployment.

* Is designed with industry-standard interfaces, Application Programming Interfaces, and cloud capabilities, allowing other developers to easily integrate their own platforms.

* Can, when deployed to a DevSecOps environment, help weapon systems developers achieve seamless interoperability with a wide array of industry-standard data formats and interfaces.

* Has a modular, open-architecture design that ensures it is highly adaptable to specific platforms and missions.

* Is built on a software stack that is straightforward to adopt, update, and maintain, being similar to other commercial open-source software and mobile Operating System ecosystems.

* Includes Lockheed Martin’s Smart translator apps, which incorporate integrated cyber controls and multi-level security from the start.

* Ensures that platforms can effortlessly connect and share data with any other systems, whether developed by Lockheed Martin or other industry providers, thereby fostering a cohesive and integrated defense ecosystem.

“Lockheed Martin is committed to open standards and interoperability drives innovation and operational efficiency, empowering our customers to maintain strategic superiority,” Fehlen said.

Automation and AI-Assisted Development and Operations

Lockheed Martin’s investments in Artificial Intelligence are being leveraged to increase the speed of integration, reduce the time to develop new apps, and translate complex unstructured data for improved interoperability. The Lockheed Martin AI Center (LAIC) has developed a framework combined with a series of tools that serve as an integration layer for the Interoperability Factory enabling systems-of-systems interoperability and AI-infused services:

* Developer tools and Software Development Kits (SDKs) enable the creation of tailorable decentralized applications, data services, and hardware integrations that can deploy to the tactical edge with industry standard interfaces, and open frameworks and APIs enable interoperability for both new and legacy services.

* Model-based system engineering is used throughout the Interoperability Factory to automate and accelerate software code generation such as generating STITCHES transforms. This significantly reduces the time, labor and risk of this process, compared to current methods.

* The LAIC is incorporating Generative AI throughout the Interoperability Factory tech stack to scale AI-enabled C2 agents that can orchestrate thousands of entities in real time.

* In mission services, powered by Generative AI, can consume textual and unstructured information, assess the information considering relevant mission context, then translate that information into tactical messages, such as Open Mission Systems-Universal Command and Control Interface (OMS/UCI).

* An AI-enabled control plane is being developed to advance beyond static translation software towards a solution that interprets new standards at machine speed.

“AI plays a significant role in operations, but humans are always in the loop,” Fehlen points out. “Humans have the final say in refining, assessing and validating a solution – but they can do it in an extremely rapid timespan.”

Successful Early Internal Demos

In less than five months, a Lockheed Martin team from across the company’s four Business Areas came together and developed a DevSecOps pipeline, unifying diverse software capabilities and integrating multiple 21st Century Security investments like AI/ML, using Model-Based Systems Engineering.

To ensure operational alignment for the CJADC2 Interoperability Factory, an Anti-Surface Warfare (ASuW) mission was used to prioritize the most common translator nodes, as defined by the Joint Industry Standards Working Group (JISWG).

Initial demonstrations showed the integration of the Open Mission Systems-Universal Command and Control Interface (OMS-UCI) and the TADIL-J standard, a variant of Link 16.

“Our initial demonstration was very successful,” Fehlen said. “With the successful connection of OMS-UCI and TADIL-J, we’re confident that we’ll be able to build off this success to connect other translators.”

Future translators will support Integrated Broadcast System (IBS) messages and the Multifunction Advanced Datal Link (MADL).

Next Steps: Customer Demos & Exercises

In the months ahead, Lockheed Martin plans to host a series of operational Interoperability Factory prototype experiments leading to Initial Operational Capability later this Spring.

“We’re done talking about CJADC2 and connectivity. Our next step is to show some key customers what we’ve done to connect these advanced warfighting systems and our path forward to show how this open-architecture design could be used to greatly enhance our warfighters’ capabilities,” Fehlen said.

 

04 Mar 25. wolfSSL Unveils Post Quantum Cryptography and Security Solutions at Embedded World 2025. wolfSSL Inc., a global leader in cryptography and network security, is excited to announce its participation in Embedded World 2025, taking place March 11–13 in Nuremberg, Germany. Attendees can visit Booth #4-201A to explore wolfSSL’s latest advancements in embedded security.

“We are thrilled to showcase our latest innovations at Embedded World 2025,” said Larry Stefonic, CEO of wolfSSL Inc. “As a leader in cryptography and network security, we remain committed to equipping developers with the tools they need to build secure, resilient embedded systems. We look forward to engaging with attendees and demonstrating how our solutions address the ever-evolving cybersecurity challenges across industries worldwide.”

Key Highlights from wolfSSL at Embedded World 2025:

  1. wolfSSL support for Post Quantum

wolfSSL’s post-quantum cryptographic solutions are designed to work efficiently and seamlessly with embedded systems, offering robust security, CAVP certification,  minimal resource consumption, and bare metal support. They enable embedded devices to remain secure as we transition into the quantum computing era, all while ensuring compatibility with current technologies.  We enable our users to achieve CNSA 2.0 support quickly and efficiently.

Integration with wolfCrypt

* wolfSSL now includes support for post-quantum cryptographic algorithms in TLS, enabling embedded systems to use PQC schemes alongside traditional algorithms (like RSA and ECC). This means developers can add quantum-resistant algorithms to their applications without completely overhauling existing cryptographic systems.

* Supported algorithms, such as ML-KEM (for public-key encryption) and ML-DSA (for digital signatures), are implemented to offer practical security in resource-constrained environments, maximizing security and performance.

Lightweight and Optimized for Embedded Platforms

* WolfSSL focuses on optimizing its libraries for embedded environments. This includes ensuring that the PQC algorithms are lightweight enough to run on microcontrollers and other resource-limited devices. WolfSSL makes these solutions highly configurable to cater to different hardware capabilities, ensuring efficient use of memory and CPU power.

Hybrid Cryptography Support

* WolfSSL supports hybrid cryptography, meaning both traditional and post-quantum algorithms can be used together. This approach allows embedded devices to maintain backward compatibility with legacy systems while gradually transitioning to quantum-resistant algorithms. For instance, a system could use classical algorithms for today’s security and PQC algorithms for future-proofing.

Security Agility for Embedded Applications

* Post-quantum algorithms in wolfSSL allow developers to choose the right security protocols based on their embedded device’s needs. As quantum computing advances, these algorithms can be updated or replaced without disrupting the system, ensuring long-term protection. This adaptability is crucial for embedded devices with extended lifecycles, like automotive or industrial IoT systems.

Cryptographic Acceleration

* Many embedded systems use hardware acceleration for cryptographic operations to improve performance. WolfSSL’s post-quantum solutions can be integrated with hardware-based accelerators, ensuring the PQC algorithms can perform efficiently, even in constrained environments.

Compliance and Certification

* For embedded systems that need to meet specific compliance standards (e.g., ISO 26262 for automotive, DO-178 for Aviation or FIPS 140-3, FIPS 203/204 and CNSA 2.0 for government applications), wolfSSL’s post-quantum cryptography solutions can be used in conjunction with existing certified cryptographic modules, maintaining high security standards while enabling forward-looking protection against quantum attacks.

  1. Release of wolfHSM 1.1.0

wolfHSM provides a portable, open-source abstraction for hardware cryptography, enabling secure key management, non-volatile memory protection, and isolated secure processing. It is primarily used with Automotive HSM hardware

Features include:

* Seamless integration with Infineon Aurix Tricore TC3XX for enhanced automotive security.

* Support for China’s mandated cryptographic algorithms (SM2, SM3, SM4).

* Post-quantum cryptography (Kyber, LMS, XMSS) for future-proof security.

* Automatic utilization of available hardware cryptographic processing to optimize performance.

  1. Release of wolfBoot 2.4.0: Enhanced Secure Bootloader with wolfHSM Integration

The latest version of wolfBoot delivers expanded platform support, new features, and significant performance enhancements, reinforcing its role as the premier secure boot solution.

Key Enhancements:

* Integration with wolfHSM – Enables secure key management, seamless public key revocation, and post-quantum ML-DSA support.

* Enhanced Delta Updates – Improved base image detection for more reliable firmware updates.

* Expanded Hardware Support – Now compatible with NXP Layerscape LS1028A, with updates for ARMv7-M/ARMv8-M, x86-FSP, Xilinx UltraScale+, and Intel TigerLake.

* Performance Boost – New wolfCrypt assembly optimizations significantly reduce boot times across all ARM devices.

  1. Post-Quantum Cryptography with wolfHSM

wolfSSL’s wolfHSM now supports post-quantum cryptographic algorithms through wolfCrypt, ensuring long-term security against emerging quantum threats.

* ML-KEM – A key encapsulation mechanism for secure key establishment.

* ML-DSA – A post-quantum signature scheme, offering a secure alternative to ECDSA and RSA.

* LMS & XMSS – Stateful hash-based signature schemes ideal for firmware and software signing, with wolfHSM ensuring proper state management.

By integrating post-quantum algorithms, wolfSSL empowers developers with cutting-edge cryptography without requiring deep expertise in post-quantum security.

 

04 Mar 25. Highly sophisticated phishing operation underscores increased security risks facing users. On 3 March, the cyber security company Fortinet reported that a new cyber campaign is exploiting legitimate Microsoft tools to maintain persistence within targeted systems. The campaign starts with phishing emails to trick potential victims into clicking on a malicious attachment. The attachment then displays a fake error message to persuade users to execute malicious code on their devices. A malware loader is then deployed covertly before a modified version of an open-source red team tool is installed onto compromised systems to establish communication with threat actor-controlled infrastructure. Subsequently, threat actors can exploit the Microsoft Graph application programming interface (API) and SharePoint to conceal malicious traffic; they can then also deploy additional malicious payloads and exfiltrate sensitive data. This highlights the continued exploitation of legitimate Microsoft tools for malicious purposes. We assess this campaign underscores the continuous advancement of threat actors’ capabilities, and therefore the increased security risks facing global users in the long term. (Source: Sibylline)

 

04 Mar 25. Goldilock, the NATO-backed network isolation specialist, has today announced significant enhancements to its flagship FireBreak™ product. These upgrades, designed to meet the diverse needs of businesses and evolving network environments, make Firebreak™ the first complete network isolation solution to combine high-speed fibre connectivity, dual power and SIM redundancy, and comprehensive API access. This new and unique combination delivers enhanced speed, availability, control, and flexibility. As a result, businesses can quickly and effectively isolate critical assets in the event of a cyber-attack.   Ransomware attacks cripple businesses daily, making the ability to instantly sever compromised systems from the network a necessity. FireBreak™ is a critical component in robust cybersecurity strategies, providing a first line of defence that empowers organisations to contain attacks, minimise damage, and protect customer data. Goldilock’s continuous investment in research and development ensures Firebreak™ remains a trusted solution at the forefront of cybersecurity innovation.

The hardware refresh enables businesses to:

Choose the connection type that best suits their network infrastructure and bandwidth requirements

Experience faster connectivity and improved network performance, especially those who rely on data intensive applications

Continue operating and protecting systems, even during power outages or network disruptions

Benefits of the software enhancements include:

Simplified and integrated security management

Faster and more effective cyber threat response, reducing the need for manual intervention

Greater control over network security, enabling customisation

Broadband Testing independently validated the performance, reliability and flexibility of FireBreak™’s security features, deployment and management capabilities. “Our testing proved FireBreak™’s line-speed performance and millisecond port disabling via Ethernet and SMS, both in manual and automated modes” commented Steve Broadhead, Founder and Head Analyst at Broadband Testing. “API integrations demonstrated full automation for all tasks, including port shutdowns upon threat detection with 3rd party tools. To our knowledge, there is no other product on the market that carries out true physical isolation.”

“Organisations are facing increasingly sophisticated and persistent cyber threats. Protecting against the potential consequences of a compromised network – from data breaches and financial losses to operational disruption and reputational damage – is therefore more critical than ever,” said Richard Bate, CTO, Goldilock.  “By supercharging our FireBreak™ solution, we’re giving organisations more tools at their disposal to proactively protect critical assets, maintain business continuity, and put the power of control back into their hands.”

 

02 Mar 25. Lockheed Martin (NYSE: LMT), Nokia (NYSE: NOK), and Verizon (NYSE: VZ) announced the successful integration of Nokia’s industry-leading, military-grade 5G solutions into Lockheed Martin’s 5G.MIL® Hybrid Base Station (HBS). The technology advances new capabilities to integrate commercial 5G connections with military communications systems to provide decisive information for national defense. 5G is playing an expanding role in supporting tactical military missions, seamlessly complementing existing battlefield solutions.

Expert Perspectives

“The United States and its allies increasingly depend on fast, secure and advanced communications to access critical information and ensure effective deterrence against threats,” said John Clark, senior vice president, Lockheed Martin Technology & Strategic Innovation. “5G.MIL® integrations like this strategic relationship with Nokia and Verizon will help ensure data is seamlessly routed throughout the battlespace in ways that make future mission success possible.”

“This successful integration highlights the flexibility of Nokia’s cutting-edge, 5G solutions to meet the unique demands of defense, ensuring robust security, optimized size, weight, and power efficiency, while supporting O-RAN and open, interoperable technologies,” said Tommi Uitto, President of Mobile Networks at Nokia. “Through our work with Lockheed Martin and Verizon, we are bringing the transformative power of 5G to mission-critical defense operations, enhancing situational awareness, speeding up decision-making, and reinforcing mission success.”

Dive Deeper

In a series of recent demonstrations, Lockheed Martin integrated Nokia’s military-grade 5G solutions into the 5G.MIL Unified Network Solutions ecosystem, including interoperability with Verizon’s network operations and management solutions. These tests successfully integrated traditional tactical communications solutions with 5G using open systems architecture and commercial standards. Leveraging open standards in this way allows for rapid integration of new, advanced capabilities into HBS configurations, ensuring new products and technology solutions are drop-in ready with no risk of vendor lock.

Initial integration was completed with equipment from Nokia’s leading 5G portfolio at Verizon’s Boston Innovation Center and HBS components at Lockheed Martin’s Valley Forge laboratory in Pennsylvania. Final systems integration, testing and demonstration were accomplished at Lockheed Martin’s facility in Ft. Worth, Texas.

The demonstration included HBS connectivity to hybrid user equipment (HUE) that allows users to switch access links between commercial 5G and tactical LPx waveforms while maintaining uninterrupted user application sessions on an Android user device. LPX designates low-probability-of-detection, interception, exploitation, jamming, geolocation and spoofing. By integrating the 5G.MIL HBS with Nokia’s 5G solutions, as well as demonstrating interoperability with Verizon’s public 5G network and leveraging their network operations management software, Lockheed Martin and its strategic collaborators are well positioned to bring new levels of performance, scalability, and reliability to military, national security wireless, and ally international defense networks.

What’s Next?

This strategic collaboration for Lockheed Martin, Nokia, and Verizon will enable continuing integration of new technology advancements, including incorporation of Nokia’s 5G technology at Lockheed Martin’s 5G.MIL Experimental Network site in Orlando, Florida, joining Verizon’s capabilities already available on-site. With 5G’s low latency, high bandwidth, and secure connectivity, warfighters can leverage real-time data and advanced situational awareness in dynamic operational environments. The team will continue to refine and enhance technical offerings, including expanding hybrid network testing to include additional user device types, broader tactical communication system interoperability, and secure public-private network configurations. This will create new ways for customers to apply enhanced capabilities to global military, national security, and homeland defense mission areas, giving operators greater connectivity, faster and more reliable wireless networks, and enhanced interoperability in support of Joint All Domain Operations.

 

28 Feb 25. Cyberlux Corporation Expands Datron Presence in Asia-Pacific Market with Phase One High-Power HF Communications Contract Now Shipping and Secures Phase Two Award of Over $1m, Bringing Total to $2.5m. Cyberlux Corporation (OTC: CYBL), a leader in advanced defense technology and tactical communications solutions, announced that Phase One of its Datron order for the Asia-Pacific market has been fully secured and is now in the shipping phase. This milestone underscores Datron’s continued expansion in the region and reflects the growing demand for Datron’s high-power HF communication systems. Building on this success, Cyberlux has secured a Phase Two award valued at just over $1m, bringing the total program value to $2.5m for the provision of additional High Power HF equipment for the same Asia-Pacific partner nation. This follow-on contract highlights the partner’s continued trust in Datron’s solutions and the growing strategic importance of the region. This series of contracts underscores Cyberlux’s commitment to providing state-of-the-art high-frequency (HF) communication solutions tailored to meet the evolving needs of military and defense organizations worldwide. Known for their reliability, security, and long-range operational effectiveness, Datron’s HF systems continue to be a trusted choice for tactical communications.

“We are excited to announce that our latest Phase One is now shipping, marking another significant milestone in Cyberlux’s strategic expansion within the Asia-Pacific region,” said Christopher Barter, General Manager – Datron Military Communications. “The follow-on Phase Two award of just over $1m is a testament to the confidence our partners have in our solutions and highlights the increasing demand for high-power HF communications in military and security applications.”

The Asia-Pacific market presents significant opportunities for Cyberlux and Datron, driven by defense modernization initiatives and a growing need for resilient, secure communication networks. These contracts demonstrate Cyberlux’s ability to deliver cutting-edge solutions that align with the complex requirements of global defense customers. As Cyberlux continues its international expansion, the company remains committed to innovation, technological excellence, and providing best-in-class communication systems that strengthen national security and operational effectiveness. Cyberlux is actively pursuing additional opportunities within the region, leveraging its expertise in secure, high-frequency communications to address the needs of military and governmental agencies. The company’s ability to deliver reliable and field-proven solutions positions it as a key partner for strategic defense initiatives in Asia-Pacific. With a growing footprint in international defense markets, Cyberlux aims to continue expanding its product offerings and services to better support its clients worldwide. The company is dedicated to ensuring operational success for its partners by delivering next-generation communication systems designed for the most demanding environments. For more information about Cyberlux Corporation and its tactical communication solutions, visit www.cyberlux.com. (Source: BUSINESS WIRE)

 

28 Feb 25. Cyber Update Key points.

  • A new spyware variant (‘SpyLend’) underscores elevated security and financial risks to Android users in India and our Technical analysis below).
  • A series of botnet-operated password-spray attacks raises security risks for Microsoft 365 users.
  • Unnamed threat actors have targeted GitHub users in an ongoing campaign (‘GitVenom’), sustaining elevated information-theft and financial risks to users of the platform.
  • A cyber campaign by the Belarus-aligned threat group ‘Ghostwriter’ poses ongoing security risks for Belarusian activists and Ukrainian government organisations and our Technical analysis below).
  • Ransomware operations against the construction and real estate sectors in Saudi Arabia highlight sustained security and financial risks to the country.

Technical analysis of weekly stories

A new spyware variant (SpyLend) is targeting global Android users in a financially motivated campaign. Threat actors distribute a malicious application (‘Finance Simplified’) which purports to offer low-interest loans via the Google Play Store to infiltrate victims’ systems. The application redirects users to an external WebView to complete the installation without being detected by Play Store security protections. It also uses an additional external web page to display a privacy policy, covertly allowing threat actors to arbitrarily modify the policy without needing any permissions. The application can dynamically change its user interface (UI) depending on the victim’s location, highlighting the targeted nature of this campaign. It specifically displays a different UI for India-based users to showcase a list of low-interest loan options, underscoring the sophisticated social engineering techniques. Finance Simplified subsequently requests extensive user permissions to gather sensitive information from victims’ devices (including call logs, contacts, messages and user location). The application also enables threat actors to exfiltrate data to command-and-control (C2) servers and inject additional malicious code into compromised devices. Threat actors then use stolen data to coerce victims into paying high interest rates after tricking them into applying for a loan.

The Belarus-aligned threat group Ghostwriter has been targeting Belarusian activists and Ukrainian government organisations in a cyber operation since at least the end of 2024. Ghostwriter uses phishing emails as initial attack vectors to trick potential victims into clicking on a Google Drive link claiming to contain a list of political prisoners. The link contains a malicious Excel file that displays a decoy list of political prisoners while covertly installing a modified version of the ‘PicassoLoader’ malware. The file checks the device’s location before downloading the main PicassoLoader payload via a modified .JPG file.  Alternatively, if the victim is located outside of Belarus and/or Ukraine, the file downloads a legitimate .JPG file to enhance detection evasion. PicassoLoader is stored and modified in a system’s memory to establish persistence, remain obfuscated and avoid detection by security analysts. Ghostwriter also used an additional open-source obfuscator tool in cyber attacks against Ukrainian government organisations. The tool was initially developed for red team and penetration test exercises, highlighting the group’s exploitation of legitimate tools for malicious activity.

Some non-exhaustive recommendations to mitigate these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communication to malicious IP addresses associated with known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

(Source: Sibylline)

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

February 28, 2025 by

26 Feb 25. Radisys® Corporation, a global leader of open telecom solutions, today announced a new partnership with SEMPRE, specializing in hardened digital infrastructure made in the USA. This partnership focuses on developing advanced and ruggedized technology to deliver secure and resilient O-RAN networks for military and civilian use. Radisys’ cutting-edge open RAN solution and proven expertise in network modernization are seamlessly integrated with SEMPRE’s state-of-the-art design to deliver a robust tactical network designed to connect authorized devices within highly secure environments, ensuring unparalleled reliability and protection. Together, they are delivering secure, resilient 5G networks designed to keep defense and commercial operations connected when it matters most. SEMPRE revolutionizes connectivity with an easy-to-deploy and manage decentralized network. From hardware to software, the architecture is built on an uncompromising security-is-everything principle. Designed for global scalability, this solution leverages Radisys’ 3GPP and O-RAN compliant 5G RAN software, supporting multiple frequency bands to deliver secure, high-capacity, high-performance networks for defense and commercial customers. SEMPRE provides integrated private 5G, edge computing, hybrid cloud access and satellite connectivity in a hardened enclosure that is designed to operate independently or with existing networks. SEMPRE’s patented satellite-based control plane and air-gapped management system ensure secure data transmission and real-time monitoring in any environment. This guarantees uninterrupted, secure communication for defense and commercial users—anytime, anywhere. Radisys 5G CU/DU software won the final stage awards in the U.S. DoD/NTIA 5G Challenge 2022 and 2023 editions, including the award for best SBOM in 2022. Radisys has been a trusted RAN vendor for many ruggedized defense and public safety deployments with highly optimized footprint and ready portability on multiple platforms leveraging hardware and software security features to provide secure and robust 5G connectivity.

“Over the past year, SEMPRE has worked closely with Radisys to optimize its O-RAN stack for security and survivability, ensuring it can operate in both centralized and decentralized configurations,” said Rob Spalding, CEO of SEMPRE. “This collaboration expands the boundaries of survivable cellular networks, and we’re excited about the innovations ahead.”

“Securing communications infrastructure and ensuring its availability at all times is absolutely critical to defense and public safety networks, and we are delighted to partner with SEMPRE in delivering this promise,” said Arun Bhikshesvaran, CEO of Radisys. “Our partnership ensures continued service, even under adverse conditions, offering both immediate and long-term value in terms of security, uptime, and operational continuity, essential for defense and national security operations. We look forward to continuing this collaboration to deliver innovative and security-hardened solutions for defense and commercial networks.”

About Radisys

Radisys is a global leader in open telecom solutions and services. Its disaggregated platforms and integration services leverage open reference architectures and standards combined with open software and hardware, enabling service providers to drive open digital transformation. Radisys offers an end-to-end solutions portfolio from digital endpoints to disaggregated and open access and core solutions to immersive digital applications and engagement platforms. Its world-class and experienced network services organization delivers full lifecycle services to help service providers build and operate highly scalable and high-performance networks at optimum total cost of ownership. For more information, visit www.Radisys.com.

About SEMPRE

SEMPRE delivers mission-critical connectivity with private 5G, high-performance edge, hybrid cloud access and a SATCOM gateway—all in one easy-to-operate, hard-to-destroy system. Whether the mission requires a permanent network or transportable one that’s fully operational in 10 minutes, SEMPRE ensures resilient, secure communication when it matters most. SEMPRE ensures you can deploy anywhere and operate everywhere. For more information, visit www.sempre.ai.

Radisys® is a registered trademark of Radisys. All other trademarks are the property of their respective owners. (Source: BUSINESS WIRE)

 

26 Feb 25. ‘Zero Trust’ Architecture Could Prevent Adversary Data Theft, Protect Warfighters. Without the right level and right kind of cybersecurity architecture in place, adversary nations will continue to infiltrate U.S. military and partner networks, including contractors within the defense industrial base, and steal important information, which may include details on weapons systems.

The Defense Department’s Zero Trust architecture, expected to reach “target level” implementation in fiscal year 2027, will protect military networks from adversaries. By that time, DOD anticipates having implemented 91 of the 152 target activities that were identified in the department’s Zero Trust Strategy and Roadmap, which was released in 2022.

A Zero Trust architecture is one that assumes no one who uses the network can be trusted. In such a setup, users might be allowed access only to information and applications they are authorized to use. Past network security might have put a wall around the whole network, and once inside, a user would have free rein within the system. In a Zero Trust environment, users must regularly prove they are authorized to see and interact with data, applications and resources.

With just over 2.5 years left before fiscal year 2027, the department has made progress toward reaching its Zero Trust goals — but more has to be done, said Marine Corps. Col. Gary Kipe, chief of staff of DOD’s Zero Trust Portfolio Management Office.

“We have 31 months until we hit FY27,” Kipe said Feb. 19, 2025, during the Zero Trust Summit in Washington. ” the latest analytical review of the implementation plans that we have received back from across the enterprise, we’re doing well, but we’re not anywhere close to being done.”

According to the Zero Trust PMO, current data shows that across all 58 components, 14% of target level Zero Trust activities have been completed across DOD.

Two areas where Kipe said the department needs to get ahead, and soon, involve implementation of a federated identity, credential and access management, or ICAM, solution as well as adoption of data tagging standards and their implementation.

“If we don’t have that, we’re going to get all the way to the end and not have the final push across the finish line,” he said.

A data tagging and labeling standard is a structured framework that defines consistent metadata, classification and access-control attributes for actors across the enterprise. When data owners appropriately tag data, it becomes possible for appropriate data access controls to be put in place. A federated ICAM solution allows the identities of users to be centrally managed to ensure authorized and authenticated access across DOD platforms.

According to the Zero Trust PMO, several funded efforts are underway to advance both a federated ICAM solution and a data tagging and labeling standard.

While Zero Trust is meant to protect Defense Department networks, it’s not just about protecting data. It’s also about protecting those who use and depend on data, including warfighters.

“Zero Trust ensures warfighters receive secure, real-time mission data while denying adversaries access to critical systems, even if networks are compromised,” Kipe said. “By enforcing continuous authentication and microsegmentation, it prevents unauthorized access, insider threats and cyberattacks from disrupting operations. This means faster, more reliable intelligence, communications and logistics, directly enhancing combat effectiveness and survivability in contested environments.” (Source: U.S. DoD)

 

25 Feb 25. Botnet-operated password-spray attacks point to raised security risks for Microsoft 365 users. On 24 February, the security company SecurityScorecard reported that a botnet (defined as a network of personal/private devices infected with malicious software and operated as a whole without the owners’ knowledge) is conducting password-spray attacks against global Microsoft 365 (M365) accounts. The botnet uses stolen credentials (likely previously obtained via information-stealing malware) to attempt to infiltrate a large number of user accounts. The attacks specifically target accounts using basic authentication processes (entering plaintext login credentials). This enables the threat actors to log into accounts without the need for any additional identity verification (such as multi-factor and other token-based authentication methods). The botnet’s infrastructure and time zone suggest it is possibly operated by China-based threat actors, though the motivation behind the attacks remains unclear. The botnet comprises approximately 130,000 compromised devices, underscoring the scale of the operation. Microsoft plans to disable basic authentication for most M365 services in September in an attempt to mitigate against long-term security risks. However, we assess there remains short-to-medium-term security risks facing global M365 users operating with basic authentication processes. (Source: Sibylline)

 

25 Feb 25. Thales launches cortAIx in the UK with 200 experts in AI for critical systems.

  • Thales marks a new major milestone in its global acceleration in trusted AI with the launch of cortAIx in the UK to address defence and security domains.
  • With 200 new highly skilled AI and data specialists, this local antenna of cortAIx will support the UK Government’s vision for AI-driven growth and productivity, thus contributing to a global workforce of 800 experts in AI within the Group.
  • This initiative will strengthen the AI ecosystem, serving the performance of sovereign advanced systems and sensors in the most challenging and constrained environments.

The new centre will reinforce Thales’ commitment to advancing the ethical and effective use of AI to address complex challenges. It will enhance domestic AI capability in line with the UK Prime Minister’s recent announcement of the AI Opportunities Action Plan.

AI is transformational and pervasive, providing incredible new capabilities that are reshaping our daily lives. However, it can also be exploited by hostile actors, creating instability and undermining our society. The UK seeks to embrace the opportunities offered by AI, deploying it as a force for good to uncover valuable hidden insights in the vast swathes of data that surround us and leveraging it to provide security and deterrence against adversaries.

Thales Group’s global cortAIx initiative already employs over 600 AI and data specialists, being the first patent applicant in AI for critical systems in Europe with more than 200 patents filed to date. With more than 100 products integrating AI, the Group accelerates the development and deployment of trusted AI-powered systems in the most complex and challenging environments. cortAIx in the UK builds on this success and will serve as a focal point for AI innovation, bringing together cutting-edge technology, talent, and research to deliver AI solutions that are ethical, transparent, explainable, and operationally effective.

A Centre for Innovation and Sovereign Capabilities

Thales will leverage its deep expertise in defence and security to create AI solutions tailored to the UK’s specific operational needs – from the edge to the cloud.

cortAIx in the UK will develop AI solutions that will:

  1. enhance decision-making for human operators, even under the most challenging and constrained circumstances;
  2. improve the performance of the most advanced systems;
  3. ensure AI is deployed ethically, securely, and transparently.

Driving Skills, Jobs, and Opportunities

Thales is committed to growing the UK’s AI talent pipeline. By the end of 2025, cortAIx in the UK will sustain 200 highly skilled AI and data specialist roles, supporting the UK Government’s vision for AI-driven growth and productivity.

The Group’s R&D already represents £4bn annually, with a significant focus on AI. cortAIx in the UK will leverage this to:

  • identify and develop the most promising AI-based technologies;
  • support the next generation of AI professionals;
  • expand upskilling initiatives with academia and industry;
  • ensure the UK retains a sovereign AI capability for national security and industrial growth.

AI in Action

Thales is already deploying AI across multiple systems, including:

  • Maritime Mine Countermeasures (French and UK programme MMCM) – AI-powered systems enabling ten times faster area coverage and four times faster detection and classification of mines than traditional crewed systems.
  • Digital Crew Computer Vision System – Machine learning-driven object classification and prioritisation to enhance mission support and operational efficiency.
  • Maritime Sensor Enhancement (MSET) contract – Enhancing data-driven analytics to maximise system availability and increase operational effectiveness at sea.

“cortAIx in the UK is a major step forward, building on the AI capabilities we already deploy and significantly accelerating the time needed to integrate AI into Thales systems. By aligning with the UK Government’s AI Opportunities Action Plan, cortAIx in the UK will drive innovation, enhance skills, and sustain high-value jobs. It will champion the ethical deployment of AI in regulated environments, ensuring transparency and trust. This will have a very positive impact on the UK security and defence industry” said Phil Siveter, CEO of Thales UK.

Strategic Partnership with Faculty AI

As part of the cortAIx launch in the UK, Thales is strengthening its partnership with Faculty AI, a leader in AI safety and data science. Together, this partnership will:

  1. accelerate AI research exploitation in critical environments;
  2. industrialise deep learning for pattern analysis, starting with maritime security;
  3. enable AI deployment across defence, infrastructure, and public sectors.

“We’ve used AI to solve frontline problems for a decade and are world-leading experts in this field. That’s why we’re trusted by defence clients as well as governments to apply AI safely and ethically to keep citizens safe. We’re excited and proud to be working with Thales’ cortAIx in the UK Centre on mission-critical AI systems” said Marc Warner, CEO of Faculty AI.

Strengthening the UK AI Ecosystem

Thales recognises that a thriving AI ecosystem is essential for the UK to remain globally competitive. Through cortAIx in the UK, we are actively working to build a collaborative AI network that brings together industry, academia, SMEs, and government partners.

By working together, we can:

  1. drive AI innovation that supports sovereign UK capabilities;
  2. ensure AI is developed and deployed in a trusted, ethical, and explainable manner;
  3. strengthen the UK’s position as a leader in AI for national security and industrial growth.

Thales invites partners, customers, and stakeholders to join us in shaping the future of AI in safety-critical and high-security environments, ensuring the UK maintains its edge in trusted AI innovation.

About Faculty AI

Faculty is a leading applied AI company dedicated to delivering impactful artificial intelligence solutions across multiple industries. They partner with organisations to enhance performance through cutting-edge AI, driving real-world impact in mission-critical applications.

 

24 Feb 25. As a company that has been present in the United Arab Emirates for over 40 years, ELT Group today participated, through its President and CEO Enzo Benigni, in the Italy-United Arab Emirates Business Forum with a speech on the panel ‘Shaping Innovation: Shaping the Future. Strategic Industries’, dedicated to the topic of technological innovation for solutions to global security challenges.

In this context, the long path of collaboration with the country and ELT’s strategic vision have been reaffirmed and underscored by a major step forward at the recent IDEX defence exhibition. This has been realised over time through three milestones: a partnership with ETIMAD, an agreement with Khalifa University, and finally an MOU with EDGE Group. Through these partnerships, the company aims to increase local expertise in knowledge, technical support, maintenance, production and supply chain with reference to the Electronic Defence sector. The ultimate goal is to contribute to the building of a sovereign UAE ecosystem by fostering the growth of local infrastructure.

Cy4Gate, a Group investee with a reputation for excellence in cyber intelligence and cyber security, is also involved in this journey as a strategic enabler in all domains, where the acquisition, management and protection of information are decisive factors for defence and security.

In 2023, ELT had already signed an MOU with ETIMAD, an Emirates-based advanced technology solutions and services company, for an integrated logistics support (ILS) hub for electronic defence (EW) systems, which was inaugurated just a few days ago at the IDEX defence exhibition.

In 2024, an agreement was signed with Khalifa University of Science and Technology to establish the Electro-Magnetic Spectrum Application (EMSA) Lab. This lab will play a central role in knowledge enhancement and research and development in the field of electromagnetic spectrum applications.

Furthermore, also at the recent IDEX exhibition, an MOU was signed with EDGE to pursue the possible establishment of a JV for joint activities related to electronic defence across multi-domains.

At the Italy-UAE Business Forum, this collaboration was further reaffirmed in a Letter of Intent (LOI) signed in the presence of the highest representatives of the two countries, the Prime Minister of Italy, Giorgia Meloni and the President of United Arab Emirates, Sheikh Mohammed bin Zayed Al Nahyan.

Enzo Benigni, CEO of ELT Group, said: “The recent agreements reinforce an already solid partnership and create the opportunity for common growth in the search for challenging solutions to modern global security challenges. At the same time, they allow ELT Group to return to the country a complete product in terms of knowledge and critical technologies”.

 

21 Feb 25. Cyber Update Key points.

  • A new and highly sophisticated malware variant (‘FinalDraft’) has elevated the cyber espionage risks facing global government and telecommunications sectors (see Sibylline Cyber Daily Analytical Update – 17 February 2025).
  • The Chinese state-sponsored group ‘Earth Preta’ is targeting Thai-speaking Windows users in a cyber operation, thus raising long-term security and espionage risks .
  • A new version of the ‘Snake’ keylogger malware has elevated the security and information-theft risks facing Windows users in the Asia-Pacific and Europe regions.
  • A new ransomware variant (‘NaiLaoLocker’) has underscored the long-term security and disruption risks facing the European healthcare sector.
  • A new custom tool (‘JumbledPath’) has underscored the long-term elevated security and cyber espionage risks stemming from the Chinese state-sponsored group ‘Salt Typhoon.’

Technical analysis of weekly stories

Unnamed threat actors are targeting Windows users in the Asia-Pacific and Europe regions with a new version of the Snake keylogger malware. Threat actors typically distribute Snake via phishing emails to trick potential victims into opening a malicious link and/or attachment. The attachment contains malicious code that executes the malware via process hollowing; namely, it replaces the original code within a legitimate process with Snake’s malicious code, thus executing the payload while remaining obfuscated. Snake is written in the AutoIt scripting language, allowing threat actors to automate deployment within Windows environments and to hinder detection by anti-virus tools. The keylogger subsequently embeds a copy of the payload within the system’s startup folder, establishing persistence in the event of a system reboot. Snake can steal sensitive information from infected systems and browsers, including credentials, screenshots and credit card details. It then uses Simple Mail Transfer Protocol (SMTP) and Telegram bots to exfiltrate stolen information to the actors’ command-and-control (C2) infrastructure; this enables the threat actors to evade security mechanisms by assimilating with legitimate network traffic. This new version of Snake has made at least 280m blocked infection attempts on devices globally, highlighting the scale and persistent nature of the campaign.

The Chinese state-sponsored group Earth Preta (also known as ‘Mustang Panda’) is targeting Thai-speaking Windows users in a new cyber operation. Earth Preta reportedly uses spear phishing emails to infiltrate targeted systems and to deploy a malicious file containing a malware dropper. The group displays a PDF document requesting users’ co-operation in compiling a government-led anti-crime platform to enhance legitimacy. The dropper then installs a legitimate application from the video game company Electronic Arts (EA) to trigger the covert deployment of a modified variant of the ‘TONESHELL’ backdoor. TONESHELL checks compromised systems prior to execution to identify potential anti-virus tools employed by the security company ESET. Earth Preta subsequently exploits a legitimate Microsoft tool (‘waitfor.exe’) to inject TONESHELL’s code into a legitimate running process by proxy, highlighting the group’s sophistication. This allows Earth Preta to evade detection and establish persistence, as well as to exfiltrate strategic data and conduct additional malicious activities. Alternatively, if no ESET anti-virus tool is identified, the group executes the backdoor directly into the selected running process.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communication to malicious IP addresses associated with known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

Our cyber word(s) of the week: Process hollowing

(Source: Sibylline)

 

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

February 21, 2025 by

20 Feb 25. Spectra Group announces the award of a contract to supply Troposcatter COMET to the Irish Defence Force. Spectra Group (UK) Ltd, the specialist provider of secure voice, data and satellite communications systems, has announced a contract award to supply the Irish Defence Force with Comtech’s Troposcatter Compact Over-the Horizon Mobile Expeditionary Terminals (COMET).  Spectra Group acquired the global distribution rights to supply Comtech’s Troposcatter Family of Systems (FoS) in February 2024 (less USA, Canada and Mexico which Comtech retains).  This procurement is the next in a series of overseas sales under this agreement.   The Irish Defence Force has procured a number of COMET systems, with more systems and the associated training and support package in the pipeline, including aspirations to deploy the new Troposcatter on the Move (TOTM) enhancement; more news on this exciting new capability coming soon.   Spectra Group is attending EnForce Tac in Booth 7-360 showcasing their specific communication capabilities, including GENSS.  Troposcatter COMET will also be on display at the JK Defence booth (10-521).

Tropospheric scatter is a communications capability that uses the Troposphere (up to about 13km altitude) to provide high bandwidth communications.  It is satellite independent and works in a GPS/GNSS denied environment, so is suitable for use in a Peer-on-Peer conflict/Multi Domain Integration.  Troposcatter inherently has very low latency and can provide huge bandwidth, enabling analysis and manipulation of large data, which combined with its low operating cost makes it suitable for strategic and tactical headquarters.   In the past, Troposcatter technology required large power-hungry equipment unsuitable for expeditionary or manoeuvre warfare.  However, modern technology and significant development by Comtech has revolutionised the size, weight and power of the Troposcatter Family of Systems, of which, COMET is the smallest and most lightweight.

COMET is specifically designed for rapid deployments and mobile operations, delivering high bandwidth (5-60Mbps) and long-range connectivity (70km+) while operating efficiently with just 10 Watts of power—currently the only low-power Troposcatter system available.  The COMET system uses a single 1-metre dish and the COMTECH CS67Plus Modem capable of up to 210Mbps, which takes the IP stream and directly converts to two RF outputs in the range 4.4-5Ghz to provide two frequencies, amplified by Dual 10W GaN amps (Dual LNA on the receive path).  This allows for dual frequency/polarisation diversity that compensates for any fading/multi-path effects and ensures low latency (typically 9-20mS). In suitable conditions, the bandwidth, range and data transfer speeds can be much greater than specified.  The COMET system is simple, intuitive, and easy to set up and does not require the use of vulnerable and expensive satellites. It has been developed to be man-portable and the whole system can be established and operational within 15 minutes. The COMET system comes packed in two small cases (25kg each) that can be transported on civilian aircraft if required.

Michael Davies, Business Development Manager at Spectra Group said: “This is a continuation of what we hope to be many procurements under our Troposcatter global distribution agreement with Comtech.  We have been working closely with the Irish Defence Force for some time to find suitable solutions to their strategic communications challenges and help meet their national defence commitments.  With many NATO countries already operating Troposcatter systems, COMET is the perfect solution for its reliability, capacity, deployability and interoperability both on the land and for maritime vessels.”

 

20 Feb 25. Creomagic Showcasing High-Performance Wireless Solutions for Tactical UAVs. At IDEX 2025 and the EnforceTac trade fair, Creomagic showcased its next-gen of compact wireless solutions, including the CreoAir Pro, designed to meet the demanding communication needs of aerial operations. Central to this launch will be CreoAir, Creomagic’s advanced Software-Defined Radio (SDR) technology, which promises to deliver exceptional security and connectivity even in the most challenging environments. As UAVs and aerial systems become integral to modern military operations, the demand for robust and secure communication solutions grows. These systems are crucial for gaining tactical advantages, but they face unique challenges. They must operate in environments prone to interference, spectrum limitations, and adversarial threats, while simultaneously enabling seamless interoperability across diverse platforms. Real-time video and data are becoming increasingly essential for tactical decision-making, heightening the need for communication systems that are not only reliable but also low-latency and secure. Creomagic’s CreoAir technology is specifically engineered to address these challenges. It offers robust communication solutions tailored to aerial operations, from lightweight UAVs to full-scale military missions. The CreoAir product line boasts high-performance data links with exceptional data rates, optimized for a variety of aerial applications. These solutions are powered by SDR and Mobile Ad-Hoc Network (MANET) technologies, providing data rates of up to 40 Mbps, adaptive video encoding, and seamless integration with multiple interfaces. This capability allows for simultaneous support of multiple data sources, ensuring smooth control of numerous platforms in dynamic operational environments. Security is a core focus of CreoAir. The system is equipped with advanced Communication Security (COMSEC) and Transmission Security (TRANSEC) features, ensuring resilient, uninterrupted communication in hostile settings. Continuous spectrum scanning, AES-256 encryption, frequency hopping, and automatic interference avoidance powered by cognitive SDR technology all contribute to safeguarding against interception and detection (LPI/LPD). These features enhance protection against Electronic Warfare (EW) threats, making CreoAir a reliable solution for mission-critical communications. The CreoAir Pro combines the advantages of its predecessors with next-generation computational power and advanced algorithmic processing. Optimized for AI-driven operations, it supports dynamic spectrum allocation, real-time decision-making, and cognitive networking. This new generation is lighter, more compact, and designed for multi-domain applications, from tactical UAVs to autonomous systems and integrated battle networks.

A standout feature of the CreoAir Pro is its open architecture, which facilitates faster development cycles, easier integration with third-party systems, and more customization options for end users. This open framework also allows for rapid software updates, ensuring that the system remains adaptable to the evolving needs of the modern battlefield. Whether used in manned and unmanned aerial networks, personal tactical radios for special forces, first responders, or unmanned ground robotics, Creomagic continues to push the boundaries of communication technology to meet the demands of its diverse clientele.

Alex Shapochnik, CEO of Creomagic, said, “We are very proud to introduce this latest addition to our range of innovative CreoAir transceivers. We believe the advanced computational technology and superior SWaP-C provides an even greater offering for our clients, especially for unmanned aerial systems, while maintaining a competitive price point. Creomagic focuses on long-term partnerships in strategic markets to meet the growing global demand for locally produced equipment. Europe remains a key priority for our marketing and sales, where we aim to establish the right partnerships for joint production, development and tailored solutions.” (Source: https://www.defenseadvancement.com/)

 

20 Feb 25. ADSB joins forces with Indra to equip the FA-400 offshore patrol vessel with advanced naval systems.

  • EDGE Group’s naval arm, Abu Dhabi Ship Building (ADSB), signed the agreement with Spain’s Indra at NAVDEX 2025
  • Advanced radar, electronic warfare, and counter-UAS solutions to be delivered through PULSE, the Abu Dhabi-based joint venture between EDGE and Indra

EDGE Group entity, ADSB, a regional leader in the design, construction, repair, maintenance, refit, and conversion of naval and commercial vessels, has formed a strategic partnership with Indra, a world-leading information technology and defence systems company headquartered in Spain. The collaboration, supported by PULSE, the joint venture between EDGE, ADSB’s parent company, and Indra, will equip ADSB’s FA-400 offshore patrol vessel with Indra’s advanced 3D Radar, Radar Electronic Support Measures (R-ESM), Communications Electronic Support Measures (C-ESM), and Counter-Unmanned Aerial Systems (C-UAS) jammers, significantly enhancing its operational effectiveness. The agreement was signed by Mr. Ángel Escribano, Executive Chairman of Indra Group and Khaled Al Zaabi, President – Platforms & Systems, EDGE and Chairman of ADSB, at the Naval Defence Exhibition & Conference (NAVDEX 2025) in Abu Dhabi, which runs until 21st February.

Speaking on the occasion, Khaled Al Zaabi said: “As a vessel entirely designed and constructed in the UAE, the FA-400 reinforces our objective of building a portfolio of world-class platforms, fully aligned with the needs of modern defence. Integrating Indra’s advanced radar and electromagnetic systems enhances the FA-400’s capabilities, ensuring resilience and adaptability to meet a range of operational challenges.”

For his part, Ángel Escribano said: “Indra brings decades of expertise in developing high-performance defence technologies, with its 3D Radar, EW, and C-UAS solutions widely recognised for their robust capabilities across challenging operational environments. The integration of our proven systems ADSB’s FA-400 reflects a shared vision to elevate naval defence standards and introduce a new level of sophistication to UAE-built naval vessels.”

The FA-400, equipped with Indra’s advanced radar, electronic warfare, and counter-UAS solutions, is on display at the NAVDEX mooring, providing attendees with an in-depth look at its capabilities. Designed and built entirely in the UAE, the vessel demonstrates exceptional operational versatility, reinforcing its role as a strategic asset in modern naval operations. The integrated naval suite is being delivered through PULSE, the Abu Dhabi-based joint venture between EDGE and Indra, further enhancing local industrial expertise and capability development.  (Source: ASD Network)

 

19 Feb 25. Armada Systems, Inc. (Armada), a provider of technology solutions for the most challenging remote locations around the world, today announced the delivery of a Galleon, its cutting-edge deployable mobile data center, to Naval Information Warfare Center (NIWC) Atlantic in support of a cooperative research and development agreement (CRADA) aimed at advanced network management, command and control, and edge computing solutions.

“With Armada, we believe the Navy will gain a decisive edge in developing technology solutions that directly enhance warfighter readiness,” said Dan Wright, CEO of Armada. “Our mission is to fortify U.S. national security by delivering resilient computing and communications platforms that excel in the most challenging and unpredictable operational environments.”

Armada’s Galleon modular data center will undergo testing and evaluation through a partnership with NIWC Atlantic for U.S. Naval Forces Southern Command / U.S. Fourth Fleet (C4F). Throughout this time, Armada will support the Navy’s testing of the Galleon while providing necessary training to ensure its optimal operation.

“Investments in advanced computing on the edge are crucial to supporting the mission of USNAVSOUTH/FOURTHFLT,” said LCDR Timothy Schettino, 4th Fleet’s Data and AI/ML Innovation Officer. “We are eager to test possible technological solutions working with Navy, Joint, and private industry partners in an effort to identify tactical advantages that will support the warfighter in the most challenging of operational conditions.”

The strategic partnership between Armada and C4F via NIWC Atlantic underscores the shared commitment to fostering technological advancements and operational excellence to support national defense and ensure the U.S. military remains prepared for any future conflict.

 

19 Feb 25. Cubic DTECH Vocality, Instant Connect Software, and Rally Tactical Systems (RTS) are breaking new ground with the integration of Instant Connect EnterpriseTM (ICE) as the encrypted end-to-end and transport layer security wrapper for tactical push-to-talk traffic. The Joint Interoperability Test Command (JITC)-certified software platform is included on the DoD Information Network (DoDIN)-approved product list. The ICE platform is a proven, military-grade tactical communications solution that integrates with RTS’ Engage Engine and Cubic’s Radio Over IP (RoIP) gateways, including the DTECH Vocality RoIP, M3X and M3-SE, enabling special operations teams worldwide to leverage the blended solution capability for multilingual missions.

“The ICE platform eliminates language barriers, providing real-time communication across 70+ languages to accelerate and clarify crucial communications,” said Anthony Verna, Senior Vice President and General Manager of DTECH Mission Solutions. “The combined solutions remove delays and other drawbacks associated with human translators in the field, thus creating a new standard in coalition interoperable tactical communications.”

“Our platform is secure and accurate, giving warfighters a decisive advantage in coalition peacekeeping, enforcement, and other missions,” said Forrest Claypool, Instant Connect CEO. “Special operations teams know that ICE allows them to extend the language translation capability to remote environments at the tactical edge. It’s about providing teams with the communications flexibility they need when seconds matter.”

 

19 Feb 25. Global: Keylogger variant points to elevated security, information-theft risks facing Windows users. On 18 February, the cyber security company Fortinet reported that unnamed threat actors are targeting Windows users across the Asia-Pacific and Europe regions with a new version of the ‘Snake’ keylogger malware. Threat actors typically distribute Snake via phishing emails to trick potential victims into opening a malicious link and/or attachment. The attachment contains malicious code that executes the malware as part of a legitimate process, enabling threat actors to remain obfuscated. Snake boasts several additional new and highly sophisticated techniques to evade detection and establish persistence; for instance, it uses the Autolt scripting language to automate deployment and hinder detection by anti-virus tools, underscoring the threat actors’ skillset. This new version of Snake has made at least 280 m blocked infection attempts, highlighting the scale and persistent nature of the campaign. As such, we assess that the security and information-theft risks facing Windows users across the Asia-Pacific and Europe regions will be elevated in the short-to-medium term. (Source: Sibylline)

 

18 Feb 25. Thailand: Chinese state-sponsored group will raise security, espionage risks for Windows users. Earlier on 18 February, the cyber security company Trend Micro reported that the Chinese state-sponsored group ‘Earth Preta’ (also known as ‘Mustang Panda’) is targeting Thai language-speaking Windows users in a new cyber operation. Earth Preta reportedly uses spear phishing emails to infiltrate targeted systems and to deploy a malicious file containing a malware dropper. The dropper then installs a legitimate application from the video game company Electronic Arts (EA) to plant a modified variant of the ‘TONESHELL’ custom backdoor. TONESHELL checks victims’ systems so as to identify potential anti-virus tools from the security company ESET, exploiting legitimate Microsoft tools to execute the payload. This allows Earth Preta to evade detection and establish persistence, subsequently exfiltrating strategic data and conducting additional malicious activities. We assess this operation showcases the development of the group’s detection-evasion capabilities, underscoring the increased security and espionage risks facing Thailand-based businesses in the long term. (Source: Sibylline)

 

17 Feb 25. Creomagic Ltd., a leading developer of advanced communication technologies, is set to introduce its latest generation of ultra-compact, high-performance wireless solutions at the upcoming EnforceTac trade fair in Germany. Designed for the demanding requirements of aerial operations, CreoAir advanced Software-Defined Radio (SDR) technology delivers advanced security and connectivity performance across challenging environments. UAVs and aerial systems have become indispensable on the modern battlefield, offering significant tactical advantages but facing unique challenges. These systems require robust, long-range control and seamless interoperability with other units. Compounding this, they often operate in environments prone to interference, spectrum limitations and adversarial threats. Tactical decision-making has become increasingly dependent on real-time video and data from multiple platforms and sensors. As such, reliable, low-latency and secure communications have become critical.

Creomagic’s communication solutions are tailored to meet these needs, providing robust and resilient communication solutions for aerial operations. The CreoAir product line includes high-performance data links with superior data rates designed for various aerial applications, from lightweight, short-range operations to full, military-standard, long-range missions. Leveraging Software-Defined Radios (SDRs) and Mobile Ad-Hoc Network (MANET) technologies, the solutions offer data rates of up to 40 Mbps, adaptive video encoding, seamless integration with diverse interfaces, and simultaneous support for multiple data sources and control of multiple platforms. From a security point of view, CreoAir provides advanced COMSEC and TRANSEC features to ensure resilient, uninterrupted communication. The system incorporates continuous spectrum scanning and analysis, AES-256 encryption, sophisticated frequency hopping, and automatic interference avoidance powered by cognitive SDR and advanced waveforms. These features reduce the likelihood of interception and detection (LPI/LPD) and deliver robust protection against EW threats.

CreoAir Pro, the company’s latest generation of tactical transceivers, meets the ongoing need for compact communication solutions adapted to smaller platforms, along with enhanced performance with regard to range, power, security and video transmission. The new CreoAir Pro merges all the advantages of its predecessors while delivering enhanced computational power and advanced algorithmic processing. CreoAir Pro is fully optimized for future AI-driven operations, enabling dynamic spectrum allocation, real-time decision-making and cognitive networking. Its superior performance with expanded features now comes in a more lightweight and compact form too.

With this minimal form factor and maximum flexibility, the new transceiver is ideal for multi-domain systems, from tactical UAVs to advanced autonomous systems and integrated battle networks. A notable new feature of the CreoAir Pro is its transition to open architecture, which enables shorter development cycles, easier integration with third-party systems, and improved customization options for end users. This framework also allows for smoother and faster software updates, enhancing interoperability and adaptability to meet the dynamic needs of the modern battlefield.

“We are very proud to introduce this latest addition to our range of innovative CreoAir transceivers,” said Alex Shapochnik, CEO of Creomagic. “We believe the advanced computational technology and superior SWaP-C provides an even greater offering for our clients, especially for unmanned aerial systems, while maintaining a competitive price point. Creomagic focuses on long-term partnerships in strategic markets to meet the growing global demand for locally produced equipment. Europe remains a key priority for our marketing and sales, where we aim to establish the right partnerships for joint production, development and tailored solutions,” Shapochnik concluded.

From manned and unmanned aerial networks to personal tactical radios for special forces and first responders, and unmanned ground solutions for robotics, Creomagic continues to develop advanced technologies to support the needs of its diverse client base.

 

17 Feb 25. Anduril Showcases Advanced Edge Computing and Communications Capabilities at USMC Steel Knight Exercise. Anduril Industries ©Anduril integrated its Menace Family of Systems (FoS) — a suite of edge computing and communications solutions — during the U.S. Marine Corps’ Steel Knight exercise. The exercise sought to integrate multi-domain sensor data to improve maritime domain awareness. Anduril provided the software-enabled sensor aggregation platform and family of Edge Computing and Communications nodes. This demonstration supported the integration of strategic data collection and tactical operations, providing warfighters at the edge with real-time access to data and capabilities once confined to centralized command centers. Traditionally, small tactical units have operated with limited situational awareness, unable to access high-value data streams in a timely manner. Strategic information often passed through slow, top-down processing chains, leaving warfighters without actionable information. Steel Knight changed this paradigm. The Menace FoS enabled seamless data sharing that broke down these barriers, allowing Marines on the ground to access accurate sensor data across multiple domains. This accelerated the decision-making processes for closing complex kill chains in dynamic combat scenarios required on the modern battlefield.

At the heart of this exercise were three expeditionary Menace systems, each tailored to unique operational needs: a command-and-control (C2) shelter, an expeditionary vehicle, and a new man-portable variant. Together, these systems demonstrated their roles in supporting the Marine Corps’ Expeditionary Advanced Base Operations (EABO) concept. The C2 shelter system was transported via KC-130 and became operational within minutes of being unloaded on the airfield, enabling aviation units to securely plan and execute intelligence, surveillance, reconnaissance, and counter-reconnaissance missions. The expeditionary vehicle system, designed for rapid deployment aboard the MV-22 Osprey, empowered Marines to aggregate and process multi-domain sensor data into actionable information. Complementing these, the man-portable variant, integrated on a maritime reconnaissance platform, delivered rugged communications and computing capabilities, ensuring seamless integration of critical data across the tactical combat network.

Steel Knight marked the first time the Menace FoS operated as a unified network, integrating strategic and tactical nodes into a cohesive data mesh, the Lattice Mesh. Unlike traditional systems that isolate command and control, communications, and operational data into separate silos, Menace unifies these capabilities into an agile, expeditionary and scalable solution. This integration not only reduced logistical complexity but also expedited deployment timelines and enhanced situational awareness, all of which are vital for operations in contested environments. The exercise demonstrated how warfighters can now conduct mission planning and integrate sensors to achieve real-time maritime domain awareness across austere and disconnected environments — scenarios previously thought too challenging for such capabilities. By proving that complex data aggregation can be executed directly at the tactical edge, Menace redefines what is possible for modern warfare. Whether deployed as a secure facility, mobile platform, or man-portable system, the Menace FoS offers scalable, expeditionary solutions tailored to the evolving needs of the joint force. As the U.S. military continues to innovate in force design and operational concepts, Anduril remains at the forefront, committed to delivering advanced technologies that meet the demands of today’s warfighters while anticipating the challenges of tomorrow. (Source: ASD Network)

 

14 Feb 25. Cyber Update Key points.

  • A surge in cyber attacks against high-profile large language model (LLM) platforms underscores the increased security and financial risks facing firms.
  • A large-scale data breach has sustained the elevated security and disruption risks stemming from the pro-Iran hacktivist group ‘Handala.’
  • A cyber espionage operation against Windows users in Ukraine underscores the increased security risks stemming from the Russian state-sponsored group ‘Sandworm.’
  • A cyber campaign against global suppliers within the manufacturing sector points to the heightened security and espionage risks stemming from an unnamed Chinese state-sponsored group.
  • A long-term cyber operation has increased the security and operational risks for firms stemming from an unnamed sub-group of the Russian state-sponsored group Sandworm.

Technical analysis of weekly stories

The Russian state-sponsored group Sandworm has targeted Windows users in Ukraine in a cyber espionage operation since at least late 2023. The campaign comprises at least seven activity clusters displaying similar tactics. The latest activity reportedly used typo-squatted domains to emulate legitimate websites to infiltrate targeted systems, though it is unclear how the group first distributed the malicious domains. Sandworm then uses a fake Microsoft Key Management Service (KMS) activation tool to display a fake Windows pop-up; this is used to trick victims into unknowingly downloading a malware loader onto their systems (‘BACKORDER’) while feigning legitimacy. BACKORDER subsequently disables Windows Defender security mechanisms to evade detection, before deploying the ‘Dark Crystal’ remote access trojan (RAT) payload. This enables Sandworm to establish communication with command-and-control (C2) infrastructure and exfiltrate sensitive information (including screenshots, keystrokes, browser cookies, credentials and credit card details). In some instances, the group has also deployed a new custom backdoor (‘Kalambur’) onto compromised systems via fake Windows updates to establish communication with C2 servers and download additional malicious payloads. The backdoor uses The Onion Router (Tor) for C2 communication to obfuscate its traffic, highlighting the sophistication of the group’s detection-evasion techniques. This operation signals a continuation in the creation of fake services emulating legitimate providers by Russian state-sponsored actors amid ongoing cyber espionage operations against Ukraine-based businesses as the war in that country persists.

An unnamed sub-group of Sandworm has conducted a long-term cyber operation (‘BadPilot’) to infiltrate global organisations since at least 2021. The subgroup reportedly obtains access to targeted organisations on behalf of Sandworm, establishing persistence, command execution and lateral movement before passing access over to Sandworm. During 2022, the sub-group primarily focused on infiltrating Ukraine-based companies in the energy, retail, consulting and education sectors, while in 2023, it expanded its operations to include Central Asia, Europe, the Middle East and the US. The threat actors have also exploited several software vulnerabilities to compromise vulnerable organisations indiscriminately, oscillating between broad-scope and more targeted operations. Other initial attack vectors have included social engineering techniques, trojanised software and supply chain compromises. In 2024, the sub-group also started deploying remote management and monitoring (RMM) tools to achieve persistence and deploy additional malicious payloads. Unlike other malware types, the sub-group’s RMMs are disguised as legitimate files to evade detection. The threat actors also use web shells to maintain persistence and communicate with C2 servers, pointing to the group’s capabilities. Some of the sub-group’s other techniques include the post-compromise exploitation of sign-in portals to steal credentials and facilitate lateral movement, as well as using Tor to remain obfuscated.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communication to malicious IP addresses associated with known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering
  • Enact robust vulnerability management policies to manage and patch software vulnerabilities

Our cyber word(s) of the week: Web shell (Source: Sibylline)

 

14 Feb 25. Global: Long-term cyber operation raises security risks posed by Russian state-sponsored groups. On 12 February, the technology company Microsoft disclosed that an unnamed sub-group of the Russian state-sponsored group ‘Sandworm’ has conducted a long-term cyber operation to infiltrate global organisations since at least 2021. The sub-group reportedly obtains access to internet-facing infrastructure by exploiting software vulnerabilities, social engineering techniques, supply chain compromises and trojanised software. The group then uses web shells and other tools to maintain persistence, communicate with actor-controlled infrastructure and move laterally within compromised systems to streamline Sandworm’s cyber operations. In 2022, the sub-group primarily helped facilitate cyber espionage and disruptive operations against infrastructure in Ukraine amid the ongoing war. The sub-group’s victimology and arsenal have since shifted, showcasing its resources and ability to rapidly adapt to Moscow’s strategic objectives. As the sub-group has most recently targeted entities in Australia, Canada, the UK and the US, long-term security and operational risks to organisations remain. (Source: Sibylline)

 

 

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

February 14, 2025 by

14 Feb 25. Patria has signed an agreement with Airbus Defence and Space for SIRTAP datalink solution. Patria has signed an agreement with Airbus Defence and Space in Spain to participate in SIRTAP High capability Tactical UAS delivering a wide band line-of-sight datalink solution, covering aerial vehicles and ground systems in series production.  The wide-band datalink solution is based on Patria CANDL products. Patria CANDL is designed for secure and jamming resistant communication for applications requiring robust high speed data transfer between UAVs and ground control stations even in the most demanding missions in challenging operational environments.

“We are convinced that Patria CANDL will provide high value for the SIRTAP end-users around the globe. We are glad to be a part of the Airbus’ value chain in the SIRTAP programme“, says Hugo Vanbockryck, Senior Vice President, Market Area Europe of Patria.

Furthermore, Patria CANDL offers low probability of intercept and detection, dynamic networking and beyond line-of-sight capabilities between multiple assets, making it superior also in manned-unmanned teaming. Native IP (Internet Protocol) communication for both payload data and the control protocol enables seamless integration with modern Operational Flight Programs and ground control applications. Patria CANDL is qualified for operation in harsh environments and it is easy to integrate with a wide range of aerial and ground platforms.

 

12 Feb 25. Doing it for Themselves. Armada’s February Military Communications Newsletter includes an article entitled Supporting Space Autonomy. The piece looks at the European Union’s new Infrastructure for Resilience, Interconnectivity and Security by Satellite programme. IRIS2, as the initiative is known, will provide secure, wideband government and military communications to European Union (EU) member states, both inside and beyond the EU area. Commercial Satellite Communications (SATCOM) services also form part of the IRIS2 remit. The IRIS2 constellation should start providing these services from 2030. The programme will cost the EU taxpayer $6.7bn, the remaining $4 bn required will come from the private sector. This works out at around $15 per EU inhabitant. The advent of IRIS2 could not come at a better moment. Militaries can never have enough connectivity, and EU armies, navies and air forces are no exception. Secure, broadband SATCOM provides line-of-sight and beyond-line-of-sight communications. Better communications mean better and quicker decision-making, translating into better and quicker strategic, operational and tactical action. Strategically, IRIS2’s realisation makes sense. The so-far tepid support of NATO by the new US administration makes it vital that the EU can go it alone if Uncle Sam choses not to help out in the event of a continental crisis. Part of this autonomy is European Union sovereign ownership of force enablers like broadband SATCOM which will help deepen EU military interoperability. Relying on the provision of private sector broadband SATCOM can have its own challenges. Starlink terminals have been provided by SpaceX to Ukraine and have been vital on the battlefield. Nonetheless, SpaceX’s founder, CEO and chief engineer Elon Musk has threatened in the past to deactivate Starlink provision to Ukraine. On at least one occasion the order was allegedly carried out. There are clear and present dangers in allowing secure military SATCOM to be at risk of such capricious actions. Fortunately, IRIS2 places the reigns firmly in the hands of the EU. (Source: Armada)

 

12 Feb 25. Comtech Telecommunications Corp. (NASDAQ: CMTL) (“Comtech” or the “Company”), a global communications technology leader, today announced the launch of the Company’s new multipath radio (“MPR”) platform. As the first-ever terrestrial high data rate over-the-horizon integrated radio of its kind, MPR will empower first responders, warfighters, and commercial operators with new high data rate communications capabilities on a single antenna agnostic platform. Built on the proven success of Comtech’s next-generation Troposcatter systems, the MPR platform’s multimode functionality, diverse antenna support, and advanced signal processing techniques empower users to establish secure, reliable and resilient communications links in challenging environments where traditional radios struggle. Today, MPR supports line-of-sight (“LOS”), obstructed-line-of-sight (“OLOS”), and beyond-line-of-sight (“BLOS”) scenarios.

“Comtech’s MPR is optimized for on-the-move, at-the-halt, and fixed applications in a flexible, low Size Weight and Power (“SWAP”) terrestrial over-the-horizon communications platform,” said Daniel Gizinski, President of Comtech’s Satellite and Space Communications Segment. “MPR’s functionality and ease of use is a true game-changer for end users, demonstrating the ability to be set up and deployed in less than 10 minutes as well as delivering industry-leading data rates continuously over long distances. The software-defined nature of Comtech’s MPR platform also enables the system to adapt and incorporate new capabilities over time.”

In the past, terrestrial BLOS communications systems were limited due to large size, high-power requirements, and complexity of operation. Leveraging over 40 years of multipath radio technology leadership, Comtech’s MPR is revolutionizing high data rate communications capabilities by providing a rapidly deployable, transportable, low SWAP solution for military and commercial operators.

Comtech’s Multipath Mitigation Technology Advantage:

Today, reliable communications in diverse environments are essential for military and critical infrastructure applications. However, multipath propagation, where radio signals travel along multiple paths before reaching the end user, disrupts signal integrity, causing a drop in communications or total loss of connectivity. Comtech’s MPR solves multipath disruption by a unique combination of diverse techniques, advanced forward error correction, and adaptive coding and modulation, that represent a first for the industry.

Operational Value for End Users:

  • BLOS without SATCOM: MPR provides real-time data connectivity over-the-horizon up to 150 miles; this capability can be critical in satellite contested environments or when limited space segment is available.
  • Reliable Communications: The MPR ensures clear and consistent communications across echelons, overcoming signal degradation caused by terrain or obstacles.
  • Enhanced Situational Awareness: Reliable data exchange facilitates a shared understanding of a variety of scenarios ranging from military operations to disaster response, which is crucial for informed decision-making.
  • Improved Interoperability: The MPR is over the air compatible with Comtech’s entire Family of Troposcatter Systems. To enhance network and information interoperability, MPR provides an easy-to-use Layer 2 interface integration package for all IP based MESH and MANET radio networks.
  • Common Digital Architecture: MPR is designed to leverage a common digital architecture across the Company’s other product lines, including Comtech’s Digital Common Ground modems.
  • Low SWAP: The MPR provides users maximum SWAP flexibility against varied environments. The small footprint and rapid set up provide users with a true expeditionary capability.
  • Enhancements: Comtech’s MPR has a series of planned enhancements, including point-to-multi-point, which will allow simultaneous communications to multiple on-the-move platforms and stationary sites, eliminating the need for multiple systems at the hub location.

Recent U.S. Department of Defense Demonstrations Validate MPR Capabilities:

During an initial Joint Service demonstration along Florida’s panhandle, Comtech’s MPR delivered 14 megabits of data continuously over a 101-mile BLOS link using no vertical lift.

During the U.S. Navy’s Silent Swarm 2024 exercise, Comtech’s new MPR platform completed a long-range ship-to-shore connection for an unmanned surface vessel-revolutionizing at-sea command, control, communications, computers, cyber, intelligence, surveillance, and reconnaissance mission support. For more information Comtech’s new MPR platform, please visit our webpage: https://comtech.com/capability/mpr-platform/.

 

11 Feb 25. High Frequency in the High North.  New analysis comes to light regarding high frequency trunk communications used by Russia’s strategic integrated air defence system. Regular Armada readers will be aware of our deep interest in Russian military radar, electronic warfare and communications systems. Our fascination with these capabilities is enabled in no small measure by the work of EW Analytics LLC. Based in the United States, the company uses publicly available information to produce highly respected analysis of Russian military electromagnetic capabilities. EW Analytics LLC regularly shares its analysis, which we summarise for our readers, and you can find some previous examples of our summaries here. The company shared its recent analysis of two High Frequency (HF: three megahertz/MHz to 30MHz) antenna arrays located in Russia’s Arctic region. The Russian military has an Arctic Trefoil installation in the Franz Josef archipelago in the north of the region. Arctic Trefoil installations follow a similar design, ‘Trefoil’ being a reference to the installation’s three-wing building design. Next to the installation are two fenced fields each covering an area of one square kilometre (0.38 square miles). Each field contains an antenna array that EW Analytics LLC has discovered is connected to RPDRUM-1/5 HF radios, the antenna array of interest being referred to as Vh-60/12 in Russian. The analysis continued that these antennas have been installed in a distinctive sloped/inclined configuration intended to increase the directionality of the transmitted signal as compared to conventional HF antenna performance which can be especially problematic in the Arctic. EW Analytics LLC has found that this distinctive sloped/inclined HF antenna array was part of a Russian Arctic-wide HF communication architecture that was proposed circa 2017. This was around the time that Arctic Trefoil became operational.  Given that the antennas of this distinctive array are 60 metres (197 feet) in length it is likely that they handle traffic on frequencies of around five megahertz. The orientation of the antennas suggests them pointing south to areas like the Kola Peninsula. The peninsula is 1,550 kilometres (963 miles) to the southwest. It is home to several Russian military installations including Russian Naval Aviation’s Olenya airbase and the Zapadnaya Litsa naval base.

Arctic Trefoil

The Arctic Trefoil facility under examination is collocated with the airbase at Nagurskoye on Alexandra Land, one of the largest islands in the Franz Josef Land archipelago. Adjacent to the Arctic Trefoil is a set of three radomes; the one atop a mast containing a 12A6 Sopka-2 S-band (2.7 gigahertz/GHz to 2.85 GHz) air surveillance radar. EW Analytics LLC speculates that one of the HF radios/antenna arrays may provide trunk communications to share track data gathered by the Sopka-2 radar. The company believes the HF antenna array nearest the Sopka-2 radar is used for this role since it is collocated with an Aviation Guidance Point (AGP). AGPs are the Russian equivalent of Integrated Air Defence System (IADS) control and reporting centres. This HF link could help feed track data into the Leningrad Military District’s (MD’s) IADS. The Leningrad MD’s IADS will develop a Recognised Air Picture (RAP) of the airspace above the military district, and air approaches to it.

This RAP will be shared at the national level to help populate Russia’s strategic RAP covering the air and space above and around the country as far as the radar horizon allows. Whether this HF link is used all the time is unknown. EW Analytics LLC posits that the link may form a back up to trunk satellite communications which may support routine track data sharing. Interestingly, the analysis states that unlocated Russian air defenders have been reported to share track data across HF using Morse Code. Such transmissions are occasionally detected by European-based radio amateurs monitoring Russian high frequency channels. The other HF radio/antenna array at the base is close to the facility’s administrative and accommodation building. EW Analytics LLC deduces that this latter HF radio/antenna array may be used to carry non-tactical traffic.

Future deployments

Additional Arctic Trefoil bases have been constructed for the Russian military; one on Wrangel island in Russia’s far east Arctic region and one on Kotleny island in the country’s central Arctic region. EW Analytics LLC states that, so far, only the Arctic Trefoil facility at Nagurskoye appears to have been equipped with the Vh60/12 HF antenna array; an indication perhaps that this Arctic Trefoil has unique communications requirements. It will be interesting to see if other Arctic Trefoil facilities receive similar HF equipment in the future. Armada will share further details on this subject, and others, as and when they become available from EW Analytics LLC. (Source: Armada)

 

12 Feb 25. Polish Comms Modernisation. WB Group’s Perad-6010 handheld tactical radio has been approved for use by the Polish military. The transceiver forms part of the Tytan infantry soldier system. The Polish Army is overhauling its tactical radio inventory with a new domestically designed, developed and produced handheld transceiver. The Wojska Lądowe (Polish Army) is moving forward with the modernisation of its tactical communications. In late December, defence24.com revealed that WB Group’s Perad-6010 handheld radio has been approved for acquisition by the country’s Armaments Group procurement agency. The reports continued that the Perad-6010 forms part of Tytan infantry soldier system equipping the army. WB Group’s literature says that the Perad-6010 radio is an ultra-high frequency (300 megahertz to three gigahertz) transceiver. The radio produces one kilowatt of output power. Its narrowband waveform handles data at rates of 75 kilobits-per-second. The integral and universal wideband waveforms move data at rates of between one-megabit and four megabits-per-second. Communications security protocols include frequency hopping at rates of up to 700 hops-per-second plus embedded encryption. The Perad-6010 is cleared to handle North Atlantic Treaty Organisation (NATO) traffic with a restricted classification. As well as equipping the Tytan ensemble WB Group told Armada in a written statement that the radio furnishes the company’s Gladius Uninhabited Aerial Vehicle (UAV). The statement added that initial Perad-6010 deliveries will furnish army manoeuvre units including mechanised infantry and armoured formations. Deliveries will also be made to the force’s missile and artillery units. The company expects the radio to be used by dismounted infantry and specialist troops including UAV crews.

Vehicle programmes

According to WB Group the Perad-6010 is the first individual handheld radio to be introduced into Poland’s armed forces, excluding transceivers equipping the country’s special forces. Plans are afoot by the Polish military to order several thousand of the radios. The company expects deliveries to commence in the middle of 2025, adding that some schedules will depend on other programmes. For example, the Polish military is receiving PGZ Borsuk amphibious infantry fighting vehicles. These vehicles will include Perad-6010 radios, as will forthcoming KTO Rosomak wheeled armoured personnel carriers. The Perad-6010 will become the standard handheld radio in the Polish Army in the coming years. This marks an important modernisation milestone as the force enhances its strength on NATO’s eastern flank. (Source: Armada)

 

13 Feb 25. Supporting Space Autonomy. The European Union’s (EU) IRIS2 satellite constellation is an important step forward in enhancing the EU’s strategic autonomy while helping to deepen European military interoperability, and command and control. 16th December 2024 marked an important date in the evolution of European Union satellite communications strategic autonomy. That day, the European Commission, the EU’s executive body, signed a concession contract for constructing the Infrastructure for Resilience, Interconnectivity and Security by Satellite provision. Better known as IRIS2, the European Space Agency (ESA) will procure and operate the capability. ESA signed the contract with an industrial consortium known as SpaceRISE. The consortium comprises a trio of companies namely Eutelsat, Hispasat and SES. The satellite constellation will provide secure government and military communications, and commercial links with IRIS2 costing circa $11bn. The EU will provide $6.2bn, $4.2bn will be provided by the private sector with $570.4m coming from ESA. Defence and security considerations are front and centre of IRIS2’s philosophy. The EU’s own documents foresee the constellation playing a “crucial role in transforming the defence and security field, improving border and maritime surveillance, crisis management such as humanitarian aid and protection of essential communications and infrastructure.” The constellation will help support EU external operations while providing deeper European Union military connectivity. The latter point is particularly important from a strategic, operational and tactical Command and Control (C2) perspective. Improving EU military C2 is vital for external operations and for protecting the European Union against external aggression. The EU currently leads military missions in Mozambique, the Central African Republic, Somalia and Ukraine. EU military operations are underway in Bosnia-Herzegovina; the Red Sea, Indian Ocean and the Persian Gulf, in the Mediterranean and off the Horn of Africa.

Architecture

Laurent Jaffart, ESA’s director of connectivity and secure communications and head of the ESA’s European Centre for Space Applications and Telecommunications, told Armada that launches of the IRIS2 satellites will start in 2029, with full provision of SATCOM services commencing one year later. Mr. Jaffart added that development of the satellites and their accompanying infrastructure is already underway. Satellite production should commence in 2026. IRIS2 will have use a multi orbit constellation of 292 satellites with 264 satellites in a high Medium Earth Orbit (MEO). MEO orbits are between 1,079 nautical miles/nm (2,000 kilometres/km) and 19,323nm (35,786km) above sea level. A further 18 satellites will be in standard MEO orbits with ten in Low Earth Orbit (LEO). LEO satellites typically orbit at altitudes below 1,079nm. Mr. Jaffart says that the constellation will carry secure military/government K-band (18 gigahertz/GHz to 27GHz) links. Government communications will also be possible using Ka-band (26.5-40GHz uplink/18-20GHz downlink) transmissions. Commercial SATCOM services will be provided using Ku-band (14GHz uplink/10.9-12.75GHz downlink) links. He continued that IRIS2 encompasses the development of military Ka-band terminals. Development of these terminals will be in addition to the ground infrastructure that will be rolled out to support the constellation. Bandwidths in the order of tens of megabits-per-second are expected to be provided by the constellation. Mr. Jaffart stressed that government and military link provision includes a transparent mode. This means that existing secure waveforms used by militaries on the frequencies above can be carried across the constellation. He says that robust communications and transmission security has been built into the IRIS2 architecture from the outset. This provision includes state-of-the-art cryptography and cyber resilience. As the capability is owned and operated by the EU this will guarantee service provision. Privately-owned SATCOM is at the mercy of the markets, or of the owner deciding to cease service provision. Over the longer term, Mr. Jaffart adds that techniques like quantum key encryption could be used to enhance security. (Source: Armada)

 

10 Feb 25. February Radio Roundup. Persistent Systems’ new PT5 module enables the company’s MPU5 handheld radios to access 5G cellular and WiFi connectivity, the latter of which can be used to connect external devices to the transceiver. Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains. A January press release from Persistent Systems announced the launch of the Personal Transport-5 (PT5) accessory for the company’s MPU5 mobile ad hoc networking handheld radio. The PT5 connects with the MPU5 to provide simultaneous local network, or deployed, fifth-generation (5G) and Wi-Fi connectivity. Users can then perform line-of-sight and beyond-line-of-sight cellular communications over these 5G networks. Two WiFi 6e access points facilitate a personal area network to connect external devices like computers, cameras and sensors. Legacy 2.4 gigahertz/GHz WiFi-enabled devices can be linked to the PT5 along with five gigahertz and six gigahertz 6e systems. The press release stated that the PT5 has two layers of accredited encryption. This communications/transmission security protocol allows traffic to move securely across third party 5G networks. The company trialled PT5 devices with the US Army Special Operations Command and the US Department of Energy. Persistent Systems told Armada that the PT5 continues to be used by these organisations and is now available for wider acquisition. The PT5 connects directly with the MPU5 via any of the latter’s ports and can also be connected via cable if preferred.

Terminal Upgrades

Gilat DataPath, a subsidiary of Gilat Satellite Networks, recently won a contract to provide field services, upgrades and maintenance for DKET Series 2000 satellite communications terminals, and other similar products, in use with the US military and with other armed forces around the world. On 21st January, Gilat Satellite Networks announced that the company’s Gilat DataPath subsidiary in the United States had won a contract worth over $5 m from the US Department of Defence (DOD). The contract covers maintenance, upgrades and field services for the company’s Satellite Communications (SATCOM) terminals. Recipients for these services include SATCOM terminals used by the US military and allied forces around the world. Nicole Robinson, Gilat DataPath’s president, told Armada that the company had already delivered over 6,000 SATCOM terminals to customers globally. The company will provide the services for its DKET SATCOM terminals, and related systems “in support of defence users from the US as well as allied nations in Europe and the Asia-Pacific.” Ms. Robinson added that one upgrade covers the provision of beyond-line-of-sight satellite communications capabilities to an undisclosed US uninhabited aerial vehicle manufacturer. Additional upgrades will be provided to the company’s DataPath 3000 series and DKET 2000 series terminals. Numerically, most improvements are being conferred on terminals employed by the US Army. (Source: Armada)

 

13 Feb 25. Allen-Vanguard launches its next-generation RF Multi-Function Cyber Electromagnetic Activities (CEMA) Platform at IDEX 2025. Allen-Vanguard, a global leader in providing customised solutions and enabling technology for Radio Frequency (RF) spectrum monitoring and RF defeat of Unmanned Air Systems (UAS) and Radio Controlled Improvised Explosive Device (RCIED) threats employed by terrorists and extremists, is launching its next-generation core technology at IDEX 2025.  As modern battlefield threats evolve, Allen-Vanguard is responding by launching the cornerstone of their latest RF multi-function CEMA platform that provides the necessary flexibility and adaptability for front-line troops to quickly and easily dominate the CEMA space; a capability that is particularly important when providing security in the Middle East. Allen-Vanguard is very excited to announce at IDEX 2025, the advanced core that will underpin its next-generation family of multi-function CEMA platforms.  This new capability leverages the very latest in analogue signal processing technology and is the culmination of significant strategic investment and massive engineering development that the company has placed in its future program of systems, the ‘NXT’ family.  This technology delivers a highly integrated mixed-signal front-end technology, combined with enhanced RF processing power to deliver increased flexibility and improved detect and defeat capability for the end user.  This new technology enables direct RF sampling, without the use of tuners, across the entire RF spectrum used by UAS and RCIED devices.  Allen-Vanguard has engaged best-in-class experts to collaborate on this exciting new project which enables this new more powerful software-defined radio (SDR) platform to form the core of their new products and help dominate the EW space.  The new platform comprises of an RF System on Module (SOM) and a customisable product-specific application interface card which means users can detect, protect and defeat a wider range of threats from each system.  Allen-Vanguard will be showcasing this and its current range of products at IDEX 25 on stand C3-006 from 17-21 February at the ADNEC Centre, Abu Dhabi.

Bobby Strawbridge, President of Allen-Vanguard said: “The Middle East has been a core market for Allen-Vanguard for a long time, and we have used our experience gained from supporting our clients in the region to help design and develop this new technology.  Not only is it exciting from an engineering perspective and enables the EW capabilities that our customers demand, but it also should be of interest to any OEM in the EW sector.  This card delivers best of breed metrics in a small, customisable footprint at a fraction of the price of standardised formats.  I am very grateful to our partners and our in-house design team, who together, have pushed the boundaries of what is possible in the CEMA space.”

 

13 Feb 25. Global: Attack elevates security, cyber espionage risks from Chinese state-sponsored groups. On 11 February, international news outlets reported that an unnamed Chinese state-sponsored group is conducting a cyber espionage campaign against global suppliers within the manufacturing sector. The campaign reportedly exploits zero-day and/or existing software vulnerabilities to infiltrate network edge devices (such as routers and virtual machines). The group then likely deploys malware onto compromised systems to steal intellectual property and other sensitive information. Chinese state-sponsored actors routinely exploit vulnerable network edge devices as initial attack vectors to target organisations and exfiltrate sensitive data to bolster China’s economic and security posture. The campaign primarily targets suppliers of chemical products and physical infrastructure components, highlighting the elevated security and espionage risks facing these sectors amid long-term bilateral hostilities and economic competitiveness. The impact of this campaign will likely persist in the short-to-medium since it is likely that this cyber operation remains ongoing. (Source: Sibylline)

 

11 Feb 25. L3Harris, KSSL partner to enhance C4ISR capabilities in India. The two-year agreement will see both companies working closely and contributing to national security. L3Harris Technologies has signed a memorandum of understanding (MoU) with Bharat Forge’s subsidiary Kalyani Strategic Systems Limited (KSSL), setting the stage for joint efforts to deliver advanced defence and security systems within India.   The agreement, which spans two years, will see both companies working closely to explore opportunities in command, control, communications, computers, intelligence, surveillance, and reconnaissance (C4ISR) technologies.  Through this MoU, L3Harris gains a robust partner in KSSL to enhance its operational capacity within the Indian market.  The partnership aims to leverage L3Harris’s extensive experience in tactical communications networks and its significant global presence, which includes more than one m deployed radios used by the US Department of Defense and allied forces worldwide.

L3Harris International vice president Dave Johnson said: “This MoU sets the stage for future partnerships and opportunities in India, where the combined strengths of L3Harris and KSSL can contribute to bolster national security for the country.   We are excited to move forward and increase our delivery speed in advanced tactical radios and equipment to the Indian Armed Forces.”

The partnership, designed to focus on the Indian market, also aims to build supply chains for global commitments outside of India.

KSSL president and CEO Neelesh Tunger said: “This collaboration unlocks new strategic capabilities and will lead to harnessing new opportunities for quick delivery of sophisticated defence products to the Indian Armed Forces.  Aligned with the evolving doctrines and emerging warfare paradigms, this collaboration between KSSL and L3Harris is aimed at serving future strategic requirements, including joint and integrated ISR capabilities.”

L3Harris has been operating in India for 21 years, with established facilities in New Delhi and Bengaluru.  The company’s contributions to India’s defence include advanced tactical radios, crewed airborne electro-optic/infrared systems.  The collaboration between L3Harris and KSSL also aligns with the US-India Defense Industrial Cooperation, which promotes the advancement of defence technologies and capabilities.  In the year 2016, India attained the status of a “Major Defence Partner” in relation to the US.   Subsequent to this designation, the two nations proceeded to execute a sequence of fundamental accords spanning from 2016 through 2023. These agreements encompassed areas such as military logistics, secure communications, and geospatial intelligence cooperation.  (Source: army-technology.com)

 

13 Feb 25. The Munich Security Conference (MSC) – founded in 1963 – is the world’s leading forum for intensive dialogue on international security policy issues. From 2023, ESG Elektroniksystem- und Logistik-GmbH is responsible for implementing secure TETRA communication for the Munich Security Conference, which this year takes place from 14 to 16 February, and for the following main conferences until 2025. With ESG, which has been part of HENSOLDT since April 2024, as the contract holder and the experienced team of HENSOLDT’s Multi Domain Solutions division, secure TETRA communication will also be guaranteed at the 61st MSC. Together with Stadtwerke München, HENSOLDT is contributing to the success of the conference under the most demanding security requirements: on behalf of HENSOLDT, Stadtwerke München are setting up two TETRA base stations in the Hotel Bayerischer Hof and integrating them into their highly available and secure TETRA network. This ensures uninterrupted and secure TETRA communication in the hotel itself and in the relevant surrounding area. Due to the constant growth of the conference, a record number of TETRA terminals and their accessories will be used for the employees of the Munich Security Conference, the German Armed Forces and the participating security organisations at this year’s security conference. Furthermore, the realisation also includes comprehensive on-site service and support by HENSOLDT and Stadtwerke München specialists. As in previous years, they are specially designed to be worn discreetly and are therefore ideally suited for the range of applications during the conference. The project once again highlights the outstanding capabilities of HENSOLDT’s Multi Domain Solutions division and Stadtwerke München, particularly in the areas of IT and communications and system integration, in a highly complex security-critical environment. The MSC traditionally takes place in the renowned Hotel Bayerischer Hof and due to the constant further development of the conference, also in parts in the neighbouring Rosewood Hotel. Once again, a large number of participants from all over the world will be attending. Heads of state, members of government, leaders of international organisations, and leading representatives from business, the media, research and civil society are expected to exchange their perspectives and ideas on international security. Accordingly, the requirements for ensuring the security of all participants are high.​

 

12 Feb 25. Cyber Update Key points.

  • The increased intensity of botnet-operated distributed denial-of-service (DDoS) attacks will heighten disruption risks to global operational technology (OT) and information technology (IT) environments, as well as Internet-of-Things (IoT) devices.
  • The increasingly large volume of software vulnerabilities affecting OT and IoT environments will facilitate the proliferation of botnet operations, elevating operational and disruption risks in the medium term.
  • Botnets will continue to provide cyber criminals with several avenues of profit; this will likely raise financial and second-order security risks amid the increased commercialisation of cyber criminal enterprises and the evolving cyber threat landscape.

Context

In January, the security company Cloudflare reported that varying cyber threat actors used known botnets to conduct 73% of detected HTTP DDoS attacks, highlighting the potentially disruptive impact of these tools. This followed a general uptick in the number of reports concerning botnet activity since the end of 2024; cyber criminals increasingly exploited software vulnerabilities to create new botnets and/or expand existing ones alongside conducting cyber attacks via known botnets for financial profit. Botnets allow threat actors to propagate cyber attacks via a network of infected devices, underscoring the sophistication of botnet-operated cyber campaigns. We assess that this will elevate security, disruption and financial risks to global entities in the medium-to-long term amid the spike in botnet operations and the evolving cyber threat landscape. (Source: Sibylline)

 

12 Feb 25. New investment in Royal Navy fleet communications to boost jobs.  A £250m upgrade to naval communications will support more than 100 high-skilled UK jobs, delivering on the Government’s Plan for Change. More than 100 high-skilled jobs will be secured in the UK thanks to a new £250m contract to upgrade the communications systems of the Royal Navy’s warship and submarine fleet. Jobs at Thales sites in Portsmouth, Plymouth, Crawley, Reading and Bristol will be supported after the company was awarded the largest-ever contract for the provision of naval communication capabilities. This large-scale investment helps to support the objectives of the upcoming Defence Industrial Strategy – to drive investment to UK-based businesses and boost defence jobs in every nation and region of the country. The 10-year long contract for Maritime Communications Capability Support (MCCS), awarded by Defence Equipment & Support, will upgrade the Royal Navy’s internal and external fleet communications, strengthening the UK’s continuous at sea deterrent and supporting global operations. Contracts like this one are a key part of the UK Government’s Plan for Change, safeguarding national security whilst raising living standards across the UK with good, skilled, productive jobs. It is estimated the new contract will also save the Royal Navy up to £30m in costs over the next decade.

Minister for Defence Procurement and Industry, Maria Eagle MP, said: “This new contract is a vital step in ensuring our forces remain secure at home and strong abroad. By enhancing the capabilities of our naval operations, we are reinforcing the UK’s ability to respond to threats wherever they arise.  In an increasingly volatile world, robust communication is the backbone of operational success. In the face of global threats, the upcoming Defence Industrial Strategy will ensure defence is an engine for growth, boosting British jobs, and strengthening national security. Communication systems on Royal Navy Units are a critical component of a platform’s ability to operate and fight. To meet and sustain global commitments requires resilient and enduring support contracts to maintain mission-critical equipment at the highest levels of operational capability and availability. ”

The MCCS arrangement replaces the previous Fleetwide Communications contract which Thales UK has overseen for the past seven years. Thales UK will also provide “waterfront” office services, recovery for ageing equipment and inventory management, ensuring spare part availability and ongoing defect repairs as required.

A key element to the contract is fostering closer collaboration between DE&S, the Royal Navy, and Thales UK, effectively delivering a ‘one defence’ team which reduces bureaucracy while boosting efficiency.

Commodore Phil Game, Director of Sense, Decide & Communicate at DE&S, said: “First and foremost, this announcement ensures the Royal Navy continues to have effective and secure communications equipment with continuous support from Thales, which has Europe’s largest team of marine communications engineers, supporting its vital work keeping the UK and our allies safe.  Crucially, we have looked at outcomes from other successful defence programmes and applied the lessons learned from those, in particular cutting unnecessary red tape and bureaucracy allowing Thales much more freedom to get the job done. We estimate that the scope of this contract will save between £25m and £30m in through life costs to the Royal Navy over the 10-year support period by working in a much more collaborative way with Thales UK, underlining our ‘one defence’ philosophy. This investment demonstrates the government’s commitment to national security and follows the launch of the consultation for the Defence Industrial Strategy – which will place deterrence at the heart of a new approach and ensures the defence sector is an engine for growth in every region and nation of the UK.”

Phil Siveter, CEO Thales in the UK, said: “At Thales we are delighted to continue supporting the Royal Navy in its vital mission to protect our nation. This long-term fleetwide support framework reflects our unwavering commitment to ensuring the Royal Navy remains combat-ready and equipped with world-class communications capabilities, today and into the future.  Building on seven years of trusted partnership, we are proud to provide the technical excellence and on-the-ground support that keeps ships, submarines and installations operational and mission-ready. By working as ‘one team’ across the Naval Enterprise, we are driving innovation and systems integration to place the Royal Navy at the cutting edge of defence technology for the next decade.” (Source: https://www.gov.uk/)

 

11 Feb 25. USMC seeking new modular tactical radio. US Marine Corps (USMC) programme officials are soliciting industry options on development of a new modular, advanced-architecture combat radio to support tactical command-and-control (C2) voice and data networks. Service officials issued a request for information (RFI) for the Modular Advanced Radio Architecture (MARA) Small Form Factor radio, to meet the USMC’s standing requirement for a new small tactical modular radio. System requirements include an eight-hour operating span off a single X90 lithium battery, while in support of “manportable and on-the-move capability”, according to the January RFI. Fielded MARA tactical radio systems will utilise a 3U VPX computing core, or a VNS+ variant, with a total operating load of 10 lb, the RFI stated. Once developed, the new MARA radios will support C2, communications, and fire-support missions carried out by USMC units at the operational and tactical levels. “The MARA will provide tactical edge communications as the radio frequency (RF) transport on tactical voice radio networks and tactical data networks”, service officials noted in the RFI. The MARA radio will be able to support secure, encrypted voice and data communications up to top secret classifications, the officials added. The MARA architecture standards on which the new small form factor radio will operate will mimic army’s Common Modular Open Suite of Standards (CMOSS) for electronic warfare (EW) and command, control, communications, computers, cyber, intelligence, surveillance, and reconnaissance (C5ISR) operations. (Source: Janes)

 

11 Feb 25. British Army pins communications upgrade hopes on new procurement model. The British Army is hoping to change its procurement processes in the digital space in the wake of problems with the Morpheus programme in order to take advantage of rapid technological developments that offer easily incorporated capability improvements. Speaking at the SAE Media Group’s Mobile Deployable Communications conference held in London in late January, Brigadier Jez Sharpe, head of the tactical system service executive, Defence Digital, said that the Digital Strategy for Defence had identified that the delivery of digital capability needs to be different. He noted the recent statement by the chief of the general staff of the need for an “any-to-any network” and highlighted the assumption that “data centricity is no longer an enabler but is the ‘vital ground’”. Brig Sharpe explained that the new service executive model (SEM) for procurement represented a shift of mindset, with constant reiteration through the life of a programme to maintain and improve capability. He said that the aim “is to leverage the technology environment in the digital space … so that capability is in the soldier’s hands earlier, and you keep iterating on that capability so it improves over time”. He contrasted that with the project approach, where capability tends to degrade from the moment of launch, and said that the aspiration is to achieve better capability over the life of equipment for equal budget and effort. (Source: Janes)

 

11 Feb 25. New UK sanctions target Russian cybercrime network. A key Russian cybercrime syndicate responsible for aiding merciless ransomware attacks around the world has been targeted by new UK sanctions.

  • UK sanctions target Russian cyber entity, ZSERVERS responsible for facilitating crippling ransomware attacks globally
  • targets also include 6 ZSERVERS members who are part of a prolific cybercrime supply chain, and their UK front company XHOST
  • action on illicit Russian cybercrime syndicate is latest step to strengthen UK national security

Fresh sanctions are targeting ZSERVERS, a key component of the Russian cybercrime supply chain, and 6 of its members, as well as its UK front company, XHOST Internet Solutions LP. ZSERVERS provide vital infrastructure for cybercriminals as they plan and execute attacks against the UK.

The illicit supply chain protects, supports and conceals the operations of some of the world’s most ruthless ransomware gangs. Ransomware actors rely on these services to launch attacks, extort victims and store stolen data.

In the modern digital-first economy, cyber security is a non-negotiable cornerstone of business success. A secure digital economy is a less attractive target for cybercriminals and a more attractive home for investment, generating jobs and putting more money into hardworking people’s pockets, delivering on this government’s Plan for Change.

Foreign Secretary, David Lammy, said: “Putin has built a corrupt mafia state driven by greed and ruthlessness. It is no surprise that the most unscrupulous extortionists and cyber-criminals run rampant from within his borders.   This government will continue to work with partners to constrain the Kremlin and the impact of Russia’s lawless cyber underworld. We must counter their actions at every opportunity to safeguard the UK’s national security and deliver on our Plan for Change.

Predatory ransomware groups pose a clear and persistent threat to national security, public services and privacy. These attacks threaten critical national infrastructure, disrupt essential services, compromise sensitive data and generated $1 bn from their victims globally in 2023 alone.”

Minister of State for Security, Dan Jarvis, said: “Ransomware attacks by Russian affiliated cybercrime gangs are some of the most harmful cyber threats we face today and the government is tackling them head on. Denying cybercriminals the tools of their trade weakens their capacity to do serious harm to the UK.  We have already announced new world-first proposals to deter ransomware attacks and destroy their business model.  With these targeted sanctions and the full weight of our law enforcement, we are countering the threats we face to protect our national security, a foundation of our Plan for Change, and our economy.

ZSERVERS explicitly advertise themselves to illicit actors as a Bulletproof Hosting (BPH) Provider. Some BPH are known to host hackers, misinformation, child exploitation material, spam and hate speech. BPH providers like ZSERVERS, protect and enable cybercriminals, offering a range of purchasable tools which mask their locations, identities, and activities. Targeting these providers can disrupt hundreds or thousands of criminals simultaneously.  Today’s action is the latest in a series of coordinated steps alongside US and Australian partners, and comes off the back of recent sanctions against notorious ransomware groups LockBit and Evil Corp.”

LockBit affiliates are known to have used ZSERVERS as a launch pad for targeting the UK, enabling ransomware attacks against various targets, including the non-profit sector.

Protecting the nation from threats both physical and digital sits at the foundation of the government’s Plan for Change. That is why we are moving through the entire ransomware pipeline step by step, cracking down on Russian cybercriminals that threaten the UK’s security, integrity, and prosperity.

Background

The full list of those sanctioned today:

  • ZSERVERS
  • XHOST Internet Solutions LP
  • Aleksandr Bolshakov (employee)
  • Aleksandr Mishin (employee)
  • Ilya Sidorov (employee)
  • Dmitriy Bolshakov (employee)
  • Igor Odintsov (employee)
  • Vladimir Ananev (employee)

Further information on how our actions align with the UK government’s overall strategy to disrupt cybercrime, and how these actors support the broader cybercrime ecosystem: Ransomware, extortion and the cyber crime ecosystem, NCSC.GOV.UK

An overview of Bulletproof Hosting (BPH) providers from our Australian partners: “Bulletproof” hosting providers, Cyber.gov.au (Source: https://www.gov.uk/)

 

10 Feb 25. The next battlefield is invisible and the fight for electromagnetic dominance has begun. The battlefield is changing, and the fight for dominance is shifting into a new, unseen realm. With the rapid evolution of drone warfare and electronic surveillance, the electromagnetic spectrum has become as critical as air, land, and sea.

Mastering electronic warfare (EW) is now essential – not just to jam enemy signals and intercept intelligence, but to defend systems from interference.

The rise of Pulsar

To meet this challenge, Anduril Industries has unveiled Pulsar, a modular system designed to adapt in real-time to emerging electronic threats. Using radio frequency machine learning (RFML), Pulsar can read and reconfigure itself in real-time against enemy EW systems. To put simply, it can read the electromagnetic room and reconfigure itself to counter enemy EW systems as they update themselves to try to shake the threat of detection or disruption. Traditional EW methods often struggle to keep pace with rapidly shifting signals, but Pulsar’s machine learning capabilities allow it to instantly counteract new threats.

A new era of warfare

The importance of EW is growing as modern armies become more reliant on interconnected systems. A new report from the Royal United Services Institute (RUSI) highlights the need for the British Army to prepare for this evolving threat landscape. The report warns that while not every soldier can be trained as an EW operator, all must become spectrum-aware. The increasing use of electronic devices in combat makes troops more vulnerable to jamming, hacking, and detection. In future conflicts, dominance won’t just be measured in firepower – it will be decided in the invisible battles of the electromagnetic spectrum. The question now is whether UK Armed Forces can adapt fast enough to keep up. (Source: forces.net)

 

10 Feb 25. Global: Surge in attacks targeting AI platforms underscores increased security, financial risks. On 8 February, international news outlets reported that a new cyber criminal business model is selling access to high-profile large language model (LLM) platforms for financial profit; it is reportedly doing so at an increasing rate. Threat actors allegedly use stolen credentials and/or exploit software vulnerabilities in third-party cloud storage platforms to infiltrate targeted LLM services. They then exploit legitimate OpenAI Reverse Proxies (ORP) servers to store application programming interface (API) keys before selling them on the dark web. This enables cyber criminals to sell unauthorised access to compromised platforms to users seeking to avoid high LLM service subscription fees. Earlier in February, cyber criminals also integrated the artificial intelligence (AI) platform DeepSeek into this model, showcasing their ability to capitalise on existing and emergent markets quickly. We assess this points to the increased security and financial risks for LLM entities in the short-to-medium term amid the increased commercialisation of cyber criminal enterprises. (Source: Sibylline)

 

10 Feb 25. Thales is taking part in the Artificial Intelligence Action Summit in Paris on 10th and 11th February 2025 to showcase its latest advances in the field of trusted AI for critical systems. At a time when much is expected of AI and its contribution to the security and sovereignty of nations, Thales offers a hybrid, explainable, cybersafe and frugal AI, which is already incorporated into more than 100 of its products. This technology is already delivering significant advances in the protection of infrastructure, optimisation of energy consumption and defence systems.

“Thales is a key player in the field of trusted AI: our experts have developed a hybrid AI, which offers transparency, cybersecurity, energy efficiency and an ethical approach — unlike many AI systems that rely exclusively on large amounts of data and are particularly energy-intensive. Thales offers an augmented intelligence, which is capable of changing society,” said Patrice Caine, Chairman and CEO of Thales.

Patrice Caine, Chairman and CEO of Thales, will take part in the dialogue between heads of state and government and business leaders at two roundtable sessions on AI and national security and on Europe’s AI champions.

  • On Tuesday 11th February, experts from cortAIx, Thales’s AI accelerator, will conduct exclusive demonstrations of the practical impacts of AI in 15 critical fields for official French and international delegations at the Thales Digital Factory. These AI-enabled solutions are designed to boost the performance of the most advanced systems and help humans make better decisions in crisis situations and high-stakes environments where data security and sovereignty are critical.

These solutions are already available and show how AI can reduce the environmental footprint of air traffic, protect airports and major events, protect maritime traffic and infrastructure, and, in the defence sector, increase the effectiveness of operational assets/resources and accelerate the OODA loop (observe, orient, decide, act).

Other events

  • On Tuesday 11th February, Thales’s Friendly Hackers team will take part in the Cyber Crisis Management Exercise organised by ANSSI, France’s national agency for information system security, at the Cyber Campus in Paris.
  • On Tuesday11th February, Thales will take part in two events:

o Empowering AI Ecosystems through Strategic Autonomy: Lessons from Finland and France at Finnish Embassy in Paris.

o Building Trust: Anticipating and Managing AI Risks, organised by the HEC Hub Digital and Axys in Paris.

  • On Monday 10th February, Thales will take part in Military Talks, organised by the French Ministry of the Armed Forces and the Ministerial Agency for Defence AI (AMIAD), dedicated to AI for defence applications.
  • As part of the Confiance.ai consortium, Thales is contributing to actions to expand the programme’s role internationally.
  • On Sunday 8th February, Thales took part in the AI Luminate conference: Evolving AI Safety for Economic Growth in Uncertain Times, ML Commons, AI Verify, LNE and Prism, in Paris.
  • On Thursday 6th February, Thales took part in the Presentation of AI Deliverables for Major French Groups, organised by French Tech Grand Paris and Wavestone in Paris.
  • On Friday 24th January, Thales took part in the French-German AI Industry Executives Dialogue, organised by the French Embassy in Berlin. This event resulted in a Call for Action, which will be presented at the AI Action Summit.
  • On Tuesday 21st January, ahead of the AI Action Summit, Thales organised a visit to its cortAIx research laboratory in Palaiseau with a presentation of its latest innovations for institutional stakeholders.

 

07 Feb 25. Cyber Update Key points.

  • A spyware operation points to heightened surveillance risks for journalists and civil society.
  • A malware operation against small-scale government and private organisations in Ukraine underscores security and information theft risks posed by a newly-identified zero-day vulnerability (CVE-2025-0411) (see Sibylline Cyber Daily Analytical Update – 4 February 2025).
  • The Chinese state-sponsored group ‘Evasive Panda’ targeted global entities in a reconnaissance and information-theft operation, elevating long-term security risks.
  • Highly sophisticated cryptocurrency theft campaign elevates security, financial risks to Android and iOS mobile users.
  • Evolving tactics will sustain heightened security, information theft risks posed by the North Korean state-sponosred group ‘Kimsuky’ (see Sibylline Cyber Daily Analytical Update – 7 February 2025).

Technical analysis of weekly stories

Unnamed threat actors are targeting Android and iOS mobile users in a highly sophisticated cryptocurrency theft campaign (‘SparkCat’). Threat actors covertly infiltrated victims’ systems by infecting legitimate applications available on the Google Play Store and Apple App Store with malicious components. This includes a software development kit (SDK) known as ‘Spark’ that establishes communication with actors’ command-and-control (C2) infrastructure and decrypts and installs additional malicious payloads onto compromised devices. The main payload is a wrapper comprising several optical character recognition (OCR) stealers to extract sensitive information (such as credentials) from images and photo libraries. Namely, it contains a DictProcessor and a WordNumProcessor module to filter images by localised dictionaries and word length respectively, pointing to the sophistication of this operation. Spark then encrypts conforming images and sends them to the actors’ C2 servers, likely enabling threat actors to use stolen information to locate and hijack cryptocurrency wallets for financial profit. The modules specifically searched for terms in Chinese, Czech, English, French, Italian, Japanese, Korean, Polish and Portuguese, suggesting that the campaign’s targets may be primarily located in Europe and East Asia. However, there is also a realistic possibility that it may have also targeted entities in Indonesia, Kazakhstan, the UAE and Zimbabwe as some applications allowed users to sign up with phone numbers associated with these locations. Additionally, the infected applications boast more than 242,000 downloads from the Google Play Store, underscoring the scale and impact of this campaign. Threat actors often mimic legitimate services to communicate with C2 infrastructure and disguise malicious payloads as legitimate system packages, showcasing the sophistication of the actors’ obfuscation techniques to hinder analysis and reverse-engineering efforts. This operation marks an uncommon successful attempt at bypassing security restrictions in the Apple App Store to infect legitimate applications, elevating security and financial risks to both iOS and Android mobile users.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communication to malicious IP addresses associated with known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

(Source: Sibylline)

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

February 7, 2025 by

07 Feb 25. Evolving tactics sustain raised security risks from North Korean state-sponsored groups. On 4 February, the cyber security company AhnLab Security Intelligence Center reported that the North Korean state-sponsored group ‘Kimsuky’ is using a new custom remote desktop protocol (RDP) wrapper in an information theft campaign. The campaign starts with spear phishing emails to trick potential victims into opening a malicious attachment disguised as a legitimate PDF and/or Word document. The attachment then executes a PowerShell script to deploy malicious payloads onto compromised systems. This includes the custom RDP wrapper which enables remote desktop connections and prolongs detection evasion because RDP connections are often viewed as legitimate traffic by security tools. The wrapper also facilitates external access by bypassing firewall and network address translation (NAT) restrictions, showcasing the tool’s sophistication. Kimsuky subsequently deploys information-stealing malware and exfiltrates credentials from web browsers. We assess that this new wrapper underscores Kimsuky’s continuously evolving tactics, thus raising long-term security and information-theft risks to global firms. (Source: Sibylline)

 

07 Feb 25. OPTIMAS Starts European Project for Cybersecure Communications in Free Space with Collaboration of Schiebel. OPTIMAS, a European project led by “monodon by Navantia”, has begun with the aim of developing an advanced free-space optical communication system for multi-domain defence applications in collaboration with Schiebel. OPTIMAS is an ambitious project that seeks to provide high-speed data transfer communications with an exceptional level of security, integrating cutting-edge encryption technologies, such as quantum key distribution (QKD). OPTIMAS will mark a milestone in the development of airborne laser communication systems, providing secure and high-speed communications. It is designed to operate in satellite constellations with applications for space, air (drones), naval and ground units. The project’s final demonstrator will focus on achieving high-speed, secure, bidirectional optical communications. It will enable advanced satellite pointing, acquisition and tracking capabilities in Low Earth Orbits (LEO). Application in Medium Earth Orbits (MEO) and Geostationary Orbits (GEO) will be also explored, expanding the scope and possibilities of the system. OPTIMAS is a European consortium with Spanish leadership. It is a powerful group made up of 12 entities from 7 countries, highlighting a strong Spanish presence with 6 organizations involved. Among these, monodon by Navantia assumes the role of project coordinator, reaffirming Spain’s leadership in advanced defence and communications technologies. Schiebel’s CAMCOPTER S-100 will be the dedicated Unmanned Air System (UAS) for this project and the company is in charge of integrating a novel optical laser communication technology into the S-100, enabling the communication between the air segment and a satellite. The project is developed within the framework of the 2023 work programme of the European Defence Fund (EDF), consolidating international cooperation in technological innovation for defence.

OPTIMAS is formed by:

  • monodon by Navantia (Spain) as coordinator
  • CAILABS (France)
  • Centro de Láseres Pulsados – CLPU (Spain)
  • TECNOBIT SLU (Spain)
  • GMVIS SKYSOFT SA (Portugal)
  • Instituto de Astrofísica de Canarias (Spain)
  • MBRYONICS LIMITED (Ireland)
  • ODYSSEUS Space SA (Luxemburg)
  • REFLEX AEROSPACE GMBH (Germany)
  • SCHIEBEL ELEKTRONISCHE GERAETE GMBH (Austria)
  • SENER (Spain)
  • Universidad de Valencia (Spain)
  • Universidad de Vigo (Spain)

OPTIMAS is positioned as a key project in the advancement of cyber-secure laser communications, consolidating European collaboration and the technological leadership of Schiebel in the field of multi-domain defence.

Project funded by the European Union. (Source: UAS VISION)

 

06 Feb 25. $8m boost to develop next-gen AUKUS electronic warfare tech. Australian Minister for Defence Industry and Capability Delivery Pat Conroy has announced Advanced Strategic Capabilities Accelerator contracts worth more than $8m for Advanced Design Technology and Penten in support of AUKUS Pillar II objectives. The government announced that Advanced Design Technology (ADT) and Penten have entered into contracts with the Advanced Strategic Capabilities Accelerator (ASCA) following their successful participation in the inaugural AUKUS Innovation Challenge to continue developing electronic warfare technology under a program designed to produce critical capabilities for all three AUKUS nations. This initiative forms part of a broader strategy to modernise Australia’s defence capabilities and support homegrown technological advancements, ensuring the armed forces remain at the forefront of global security innovation. This challenge is a key element of the AUKUS partnership, which brings together Australia, the United Kingdom, and the United States to pool their expertise and resources, leveraging each nation’s strengths to develop cutting-edge defence solutions.

Minister Conroy said, “I look forward to seeing the cutting-edge capabilities ADT and Penten will deliver for the Australian Defence Force and AUKUS to secure a competitive advantage and deter potential threats to regional security.”

The contracts – worth more than $8 million – will provide essential financial support to both companies, enabling them to continue their groundbreaking work while also creating over 150 local jobs. This investment not only boosts the domestic defence industry but also strengthens Australia’s capacity to contribute to multinational projects and maintain its competitive edge in high-tech warfare.

In addition to fostering innovation, the funding will support the development and demonstration of electronic warfare prototypes that meet the operating requirements of the Australian Defence Force (ADF). These prototypes are critical for enhancing situational awareness and ensuring robust communication across all domains, even in contested environments where adversaries may attempt to impair Australia’s capabilities. By addressing these challenges, Australian industry is playing a vital role in building the advanced electronic warfare capabilities outlined under AUKUS Pillar II.

“The AUKUS Innovation Challenge Series is a powerful example of how ASCA is accelerating advanced capabilities for our ADF while ensuring local innovators are at the forefront of Australia’s growing sovereign industrial base,” Minister Conroy said. (Source: Defence Connect)

 

06 Feb 25. Royal Navy delivers first next-gen electronic warfare system. The Royal Navy has rolled out the first in a series of enhanced electronic warfare systems, known as the Maritime Electronic Warfare System Integrated Capability (MEWSIC), for installation on current and future warships, according to a press release. MEWSIC is described as “a sensor upgrade to the Navy’s existing EW capability, which is a cornerstone of identifying enemy forces, equipment and movement” in the press release. It will be fitted to the Queen Elizabeth-class carriers, Type 45 destroyers, and the new Type 26/31 frigates. The first production model is now undergoing final checks at Elbit Systems UK in Bristol, while its updated Combat Management System is being tested at Portsdown Technology Park near Portsmouth. This development is part of the broader Maritime Electronic Warfare Programme (MEWP), which also includes Ancilia, a trainable launcher for electronic warfare decoys intended to “confuse anti-ship missiles.” Ancilia can swivel to “face threats directly,” removing the need to manoeuvre a ship to counter incoming missiles. It replaces the Seagnat system on older vessels and is set for installation on the Royal Navy’s newest warships. (Source: News Now/https://ukdefencejournal.org.uk/)

 

06 Feb 25. LM Supports USMC Exercise with Advanced 5G Capabilities. Lockheed Martin (NYSE: LMT), along with support from Intel Corporation and Radisys Corporation (NASDAQ: RSYS), conducted 5G military demonstrations during the U.S. Marine Corps (USMC) exercise, Steel Knight 2024. In partnership with USMC, the Office of the Under Secretary of Defense for Research and Engineering’s (OUSD(R&E)) FutureG Office, and various industry partners, the Open Systems Interoperable and Reconfigurable Infrastructure Solution (OSIRIS) system was deployed as a standalone 5G network to support operations across all domains. Led on the ground by the Marine Corps Tactical Systems Support Activity (MCTSSA) 5G team, the capstone event was an effort to test tactical wireless capabilities in support of Expeditionary Advanced Base Operations (EABO). During the exercise, the OSIRIS testbed integrated with unmanned air vehicles (UAVs), both free-flying and tethered. The system allowed operators to establish and host a secure connection through the OSIRIS testbed to multiple UAVs simultaneously, and a wireless connection, over 5G, between a USMC Ground/Air Task-Oriented Radar (G/ATOR) and a USMC Air Command and Control System (AC2S). Operators were able to send and receive battlefield data to enable realtime decision making in a variety of operational scenarios.

The Big Picture

  • Steel Knight is an annual real-world military exercise using at-scale test facilities to enable rapid experimentation to address multiple Department of Defense (DoD) mission areas.
  • The OSIRIS testbed deployed with Marine Air Control Group (MACG) 38 to Marine Corps Base Camp Pendleton to showcase 5G capabilities tested throughout the experiment to include: persistent Intelligence, Surveillance, and Reconnaisance (ISR) using UAS platforms; 5G failover capability using tactical radios; aerial 5G base station and a domestically produced 5G solution.
  • The exercise provided valuable insight as to how 5G capabilities can be used to support the USMC’s goals for Littoral Operations in a Contested Environment (LOCE) and the complementary EABO efforts.

o LOCE aims to to develop the capability to conduct expeditionary, distributed, and networked naval and ground operations in the littorals, or the coastal regions.

o EABO refers to USMC’s ability to rapidly deploy and operate expeditionary advanced bases in support of naval and joint operations. These bases can be established on land or at sea, and are designed to provide flexible and scalable logistical, command and control, and firepower capabilities to support a range of military operations.

  • The OSIRIS testbed consists of three configurations used during the exercise:

o Nomadic Tower

o Mobile Relay

o Stand-alone Integrated Access and Backhaul (IAB)

  • IAB, which was demonstrated at tactical relevant distances for the first time during the Steel Knight exercise, enabled expanded 5G mesh coverage between nodes.
  • The OSIRIS system is an ORAN compliant private 5G system, consisting of Intel FlexRAN™ reference software, Intel Xeon processors, Radisys software, and other 5G subsystems integrated by Lockheed Martin, and further enhanced to address USMC expeditionary requirements.

Strategic Perspectives

“The OSIRIS demonstration during exercise Steel Knight was an important proof point in showing Lockheed Martin’s 5G.MIL® capabilities,” said Erika Marsall, vice president, Lockheed Martin C4ISR. “Conducting demonstrations with our partners is a critical final step to understanding how these applications can be applied to real-world missions. We will continue to invest in commercial technologies, to develop solutions that can be tailored in a variety of ways, and bring the best capabilities to our warfighters.”

“Nomadic wireless backhaul enables real-time communications in environments where physical infrastructure is either lacking or disabled,” said Cristina Rodriguez, vice president and general manager, Communication Solutions Group at Intel. “This Lockheed Martin-led demonstration utilizing Intel 5G technologies showed the advancements we’ve made together in creating a robust testbed capable of enabling 5G connectivity across multiple domains.”

The Steel Knight exercise is a critical milestone for the Lockheed Martin led OSIRIS program to provide secure, reliable connectivity for 5G.MIL use cases,” said Munish Chhabra, Radisys Head of Software and Services Business. “Radisys is proud to support Lockheed Martin 5G.MIL objectives with our suite of commercial technologies, starting with 5G FR1/FR2 Connect RAN IAB Donor-Relay Node, 5G Core software and in future via 5G NTN, enabling reliable connectivity in challenging environments.”

What’s Next?

The OSIRIS program will complete its delivery of the supporting equipment and remaining documentation to include test results, user guides, and final reports from the experiment. Further testing and experimentation with infrastructure will also allow for the connection of various 5G-ready user devices, sensors, vehicles and endpoints to explore the military utility of commercial 5G technologies and pave the way for onboarding of new technologies.

Background

  • Lockheed Martin was awarded the OSIRIS contract in 2021 as a $19.3 million Prototype Project Agreement (PPA) to create a 5G communications network infrastructure testbed for expeditionary operations experimentation for OUSD (R&E) and the U.S. Marine Corps.
  • The OSIRIS testbed is a key initiative of Lockheed Martin’s 5G.MIL® programs which are positioned to help its customers field, scale and integrate 5G technology rapidly and affordably across all operations on land, water, in air, space and cyber.
  • The delivery of the Phase 1 Initial Prototype 5G testbed marked the beginning of 20 months of mobile network experimentation.
  • In Phase 2, the USMC and Lockheed Martin team leveraged the 5G testbed to conduct four distinct experiments, called mission sprints, using different 5G use-case applications within the context of EABO doctrine.
  • Throughout Phase 2, lessons learned during the mission sprints were used to drive further 5G application enhancements to address opportunities for improved performance and utility in anticipation of Phase 3 and the Steel Knight capstone demonstration.
  • Phase 3, the Steel Knight demonstration, added elements of field user assessments by Fleet Marine Forces to complement the data captured in previous phases.

(Source: ASD Network)

 

06 Feb 25. No Excuses. Christmas Day turned to disaster last December when Azerbaijan Airlines flight 8243 slammed into the ground. 67 souls were aboard the Embraer E190AR airliner and 38 died when the aircraft crashed near Aktau International Airport on Kazakhstan’s Caspian Sea coast. The flight had commenced from Heydar Aliyev International Airport in Baku bound for Grozny, southwest Russia. In this month’s newsletter we analyse the electromagnetic elements of the disaster in our Someone had Blundered article. Worryingly, the crew of flight 8243 reported losing GNSS (Global Navigation Satellite System) PNT (Position, Navigation and Timing) signal reception after entering Russian airspace. Survivors reported an explosion with shrapnel striking the aircraft; consistent with a Surface-to-Air Missile (SAM) detonation. The crew declared an inflight emergency and headed to Aktau. Tragically, the aircraft never made its destination, crashing three kilometres (1.6 nautical miles) from the airport. Reports noted that Azerbaijani investigators blamed a Russian Pantsir-S1 (NATO reporting name SA-22 Greyhound) for attacking the aircraft. GNSS PNT jamming was also blamed for disrupting the aircraft’s Automatic Dependent Surveillance-Broadcast (ADS-B) transponder transmissions. Russia’s President Vladimir Putin apologised, calling the crash a “tragic incident” but took no responsibility. Instead, he blamed Ukrainian air attacks targeting Grozny as necessitating high levels of alert by Russian air defenders. Russia has form when it comes to shooting down airliners: On 17th July 2014, Malaysian Airlines flight 17 was destroyed down by a Russian 9K37 Buk (SA-11 Gadfly/SA-17 Grizzly) SAM system over Ukraine. All 298 people onboard were killed. The 9K37 had been deployed into Ukraine in support of Russia’s initial 2014 invasion. It is hard to find any excuses for Russia’s latest destruction of a civilian airliner. That air defenders are on a state of alert because of Russia’s invasion and occupation of Ukrainian territory is understandable. However, enhancing local defences cannot be done at the expense of civil air navigation safety. Jamming GNSS PNT signals, which badly affects GNSS-dependent ADS-B transmissions, is reckless. Launching a SAM at an airliner is unforgivable. (Source: Armada)

 

04 Feb 25. Not Listening Anymore. Controlled Reception Pattern Antennas are important capabilities in the fight against GNSS PNT jamming. They can null areas where GNSS jamming maybe coming from reducing the degradation such attacks can cause to navigation. Controlled Reception Pattern Antennas (CRPAs) have been removed from the United States government’s International Traffic in Arms Regulations (ITAR) control, official documents have revealed. Having been removed from ITAR strictures, CRPAs will now be classified under less restrictive Export Administrative Regulations (EARs). Whereas ITAR is administered by the US Department of State, EARs are the responsibility of the Department of Commerce. The news is a step forward in helping safeguard users against Global Navigation Satellite System (GNSS) Position, Navigation and Timing (PNT) signal spoofing and jamming. GNSS jamming refers to electronic attack tactics to deny a PNT signal to a GNSS receiver. GNSS spoofing relates to the signal’s manipulation to convey false information. Deliberate disruption to GNSS PNT signals is a growing problem. On 20th January Nkom, Norway’s telecommunications regulator, revealed it had detected incidents of GNSS spoofing in the country’s airspace.

Low power signals

CRPAs are an innovative technology. An informative article by everythingrf.com explains that CRPAs are adaptive beam steering antennas. This means the antenna can adjust the direction from which it receives signals. Known as creating ‘nulls’ this process lets the antennas ignore dubious signals coming from a specific direction. Suppose an unusually powerful PNT-like signal is detected by a GNSS receiver coming from a bearing of 45 degrees. PNT signals are notoriously weak by the time they reach Earth, usually with an amplification of circa -125 decibels/dB. An unusually powerful signal should trigger suspicion.

Decibels measure signal amplification. In RF engineering, the closer a signal is to zero decibels, the stronger it is and hence the easier it can be for a radio antenna to receive. GNSS PNT signals use radio waves usually on frequencies of between 1.1 gigahertz/GHz and 1.6GHz. One GNSS PNT jamming technique involves transmitting much stronger, but fake, PNT signals towards a targeted GNSS receiver. The strength of these false PNT signals can wash out the real signal, preventing the receiver from obtaining the latter. False PNT signals can also be modulated with fake information, primarily false timing signals. Navigation is a function of measuring speed and direction over distance. An accurate timing signal derived from atomic clocks equipping GNSS satellites and transmitted as part of the PNT transmission is essential. Transmitting fake PNT signals into a GNSS receiver can cause the system to develop and display navigation errors.

In our above example, we have assumed that the GNSS receiver is obtaining false PNT signals from a bearing of 45 degrees relative to the receiver’s position. The unusually high power level of the false PNT signal is eliciting suspicion from the GNSS receiver’s processor. The system takes remedial action and blocks out a ‘slice’ of coverage between 40 degrees and 50 degrees allowing the receiver to ignore the fake signal. The CRPA simply no longer monitors that azimuth for PNT signals. The GNSS receiver can still obtain PNT signals, but not from the direction of where the fake transmissions are coming from. The asset of the CRPA is it performs this blanking electronically, making it highly responsive to the appearance of a fake signal. US government documents say such antennas can response thus in less than one second. Moreover, other directions from where additional fake signals maybe coming from can be blanked out.

Share and share alike

In the words of the official US government documents lifting the ITAR restrictions on CRPAs, “certain anti-jam antennas no longer provide a critical military advantage.” Some CRPAs will remain under ITAR restrictions as the US Department of Defence “seeks to control only the most sensitive and effective anti-jam antennas in (the) USML (US Munitions List).” Furthermore, “in removing CRPAs for PNT (from ITAR restrictions), the Department intends to facilitate civil global navigation system resiliency.”

As illustrated by recent incidents involving GNSS jamming, the danger of such occurrences is not limited to military GNSS users. Civilians are also at risk and air travel can be particularly affected. Air Traffic Control (ATC) secondary surveillance radar protocols like the Federal Aviation Administration’s Automatic Dependent System-Broadcast (ADS-B) depend on GNSS PNT signals. These signals help an aircraft determine its position when out of ATC primary surveillance radar range. Protocols like ADS-B let the aircraft’s position be shared with air traffic controllers via its transponder following SSR interrogation.

Unavailable or false PNT signals do not prevent an aircraft from navigation safely. Other techniques like radio navigation and dead reckoning are provide redundancy and prevent single points of failure. However, false PNT signals may hinder ATC efficiency with the risk of attendant flight delays. Some airports also require GNSS PNT signals for approach and landing procedures. This was the case for Tartu Airport in southern Estonia. In April 2024 Finnair was forced to suspend flights between Tartu and Helsinki as Russian GNSS jamming was affecting the PNT signals pilots relied upon to land at the airfield. The airport has since modified its landing and approach procedures so they no longer depend on GNSS transmissions.

Sharing the availability of CRPAs will help improve navigation safety by outflanking GNSS PNT attacks. Moreover, US companies who provide formally ITAR-controlled CRPAs can now do so under a much less restrictive regime. (Source: Armada)

 

05 Feb 25. Architectural Award. The ISA programme is focused on sensor fusion by simplifying the protocols sensors use to share their data, while breaking down stovepipes to ease data sharing and improving data sharing security. US Army electronic support capabilities will take an important step forward with the realisation of the Integrated Sensor Architecture. The US Army’s Integrated Sensor Architecture (ISA) first emerged in the public domain in 2014. In the words of official US government documents explaining ISA, the architecture is “an interoperable solution that allows for the sharing of information between sensors and systems in a dynamic tactical environment.” Sensor fusion and intelligence sharing is a vital element of the US Department of Defence’s (DOD) ongoing Combined Joint All-Domain Command and Control (CJADC2) initiative. CJDAC2 is the manifestation of the DOD’s embrace of the Multi-Domain Operations (MDO) philosophy. Disparate sensors can plug into ISA and share their information. Information shared with ISA can be fused into intelligence and distributed to those who need it.

Programme goals

The ISA effort is managed by the Army’s Programme Executive Office for Intelligence, Electronic Warfare and Sensors (PEO IEWS). PEO IEWS documents seen by Armada summarised the existing challenges concerning Army sensor data sharing. Firstly, sensors might use different proprietary protocols to move data from the sensor to the user. This can create stovepipes as information shared using one protocol might not be easily compatible with another. As the PEO IEWS document notes, data may be encoded in Variable Message Format (VMF), Joint Interface Control Document 4.2 (JICD 4.2) or CMOSS languages to name three. CMOSS translates as the Command, Control, Communications, Computer and Cyber Intelligence, Surveillance, Reconnaissance Modular Open Suite of Standards. JICD 4.2 is used for intelligence sharing by the Five Eyes nations of Australia, Canada, New Zealand, the United Kingdom and the United States. VMF is a tactical military information message format used by NATO (North Atlantic Treaty Organisation). Connections between sensors and command and control systems might not always have redundancy should links become congested or contested. Sensor data protocol security classification levels may also differ.

These concerns are being addressed by ISA’s realisation which will develop sensor data sharing protocols that are, in the words of the PEO IEWS document, “modular and adaptable”. Encryption and authorisation will help enhance sensor data security, sensor alerts and dynamic data processing. The later relates to the pace at which data can be received, analysed and shared. At the heart of the ISA approach is a desire to improve sensor-to-shooter response times. The documents stress that the ISA approach will be suitable for all sensors, including those collecting Signals Intelligence (SIGINT).

Work is underway getting ISA capabilities into the hands of troops. In early January QinetiQ was awarded a task order worth $31.5 by the PEO IEWS to advance the ISA sensor and system interoperability. The company told Armada, via a written statement that the “ISA is fundamentally a data model and application programming interface framework that allows for sharing sensor and system data dynamically across networks.” Essentially, ISA “operates with a single semantic data model across all sensor types and security enclaves, enabling sensors to be interoperable without requiring point-to-point connections. This provides dynamic discovery of sensor capabilities without requiring pre-knowledge of the systems.” The gooddata.com website provides a useful definition of semantic data models which “describe objects in a database and their relationship to one another in their specific application environment.”

Into service

PEO IEWS documents continued that ISA’s full operational capability is expected in 2025. QinetiQ said it will support “the design, development and integration activities for the ISA programme.” Specifically, “we are collaboratively working to enhance sensor management, collection management, data reduction, and intelligent processing capabilities that enable seamless data sharing across battlefield networks. The task order is expected to last five years and will be responsive to US Army needs: “The work will evolve based on the needs of the U.S. Army customer and future requirements for enhanced data sharing across battlefield networks.” The company added that it will perform this work in the United States in conjunction with the US Defence and Counterintelligence Security Agency.

The ability to easily federate and distribute disparate data from disparate sensors marks an important step forward for US Army sensor fusion, particularly regarding SIGINT data. Accelerating the pace at which this data can be captured and shared is vital if hostile emitters are to become aimpoints. ISA’s realisation will be an important capability in the quest for operational and tactical electromagnetic superiority and supremacy. (Source: Armada)

 

06 Feb 25. Someone had Blundered. The loss of an Azerbaijan Airlines aircraft during a routine flight from Baku to Grozny on 25th December raises some troubling questions about Russian air defence command and control.  Azerbaijan Airlines flight 8243 from Baku to Grozny in southwest Russia never reached its destination. Instead, the Embraer E190AR airliner crashed at 10.28 Azerbaijan (AZT) time on 25th December, hitting the ground three kilometres/km (1.9 miles) from Aktau International Airport on Kazakhstan’s Caspian Sea coast. The aircraft had left Baku at 07.55AZT, according to reports, bound for Grozny International Airport in southwest Russia. At around 08.20AZT the aircraft entered Russian airspace and soon after the crew reported the loss of Global Positioning System (GPS) PNT (Position, Navigation and Timing) signal reception. GPS, like most Global Navigation Satellite Systems (GNSSs), transmits PNT signals on frequencies of between 1.1 gigahertz/GHz and 1.6GHz.

Theirs not to make reply

The loss of the GPS signal had a knock-on effect on the aircraft’s Automatic Dependent Surveillance-Broadcast (ADS-B) transmissions. ADS-B responds to interrogation challenges from Air Traffic Control (ATC) Secondary Surveillance Radars (SSRs). When challenged the aircraft’s SSR transponder will squark on frequencies of between 978 megahertz/MHz and 1.090GHz. ADS-B information conveys several details about the flight including the aircraft’s identity, route and position. The latter factor is derived from the aircraft’s GNSS PNT receiver. With this information unavailable, it appears the aircraft was unable to share information on its location. The loss of the GPS signal was reported by the crew to air traffic controllers. According to flightradar24, the aircraft stopped sending GPS data between 08.25AZT and 08.37AZT. From 08.37AZT until 08.40AZT flight 8243 was transmitting incorrect position information. GPS transmissions stopped once more between 08.40AZT and 09.03AZT. They briefly reactivated between 09.03AZT and 09.04AZT before another gap in transmissions which lasted until 10.07AZT. From 10.07AZT until the crash at 10.28AZT the aircraft was transmitting correct GNSS information. Reports on 26th December by the Associated Press alleged that GPS jamming may have been a contributing factor for the crash.

Analysis performed by the gpsjam.org website reveals that Grozny, and its surrounding area, was subjected to high levels of GNSS interference on 25th December 2024. Grozny International Airport is to the north of the city and would have been subjected to that interference. The interference has been blamed on Russian GNSS jamming above the city and its environs. Russian authorities acknowledged that GNSS jamming was being performed at the time to protect the city against Ukrainian kamikaze Uninhabited Aerial Vehicle (UAV) attack. Jamming and spoofing the incoming GNSS PNT signals UAVs may rely on to navigate to their targets is a standard counter-UAV tactic. This may explain why flight 8243 lost the GNSS signal, possibly because of jamming, and then transmitted incorrect GNSS information, possibly because of Russian GNSS spoofing.

Theirs not to reason why

GPS jamming may not have been the only contributing factor. Pictures of the aircraft’s wreckage show the fuselage pockmarked with holes consistent with shrapnel. Fragmentation warheads employing shrapnel are commonly used in Surface-to-Air Missiles (SAMs). Euronews reported on 24th January that the aircraft was downed by a 96K6 Pantsir-S1 (North Atlantic Treaty Organisation reporting name SA-22 Greyhound) series short-range air defence system. Open sources state that the Pantsir-S1 employs 57E6 radio frequency/optically guided SAMs equipped with high-explosive fragmentation warheads.

The Pantsir-S1 is equipped with two radars; one of which is used for target acquisition and the other for fire control. Target detection is provided by the system’s 2RL80 S-band (2.3GHz to 2.5GHz/2.7GHz to 3.7GHz) radar which has a range of circa 27 nautical miles/nm (50km). Once a target is detected, engagement is managed using the system’s 1RS2-1 X-band (8.5GHz to 10.68GHz) and Ku-band (13.4GHz to 14GHz/15.7GHz to 17.7GHz) radar. The 1RS2-1 has a 15nm (28km) range. Sources suggest that the Pantsir-S1 is fitted with an integral Identification Friend or Foe (IFF) interrogator embedded within the 2RL80 radar. The interrogator operates in the Ultra High Frequency (UHF: 300MHz to three gigahertz) waveband. This should mean that the 2RL80, and hence the Pantsir-S1, easily receives ADS-B transmissions. However, if these ADS-B transmissions are being disrupted through jamming, can they still be received by the IFF?

Was there a man dismayed?

If the track on the radar screen of a Pantsir-S1 air defender is showing no ADS-B information, or that information is shown as incorrect, is that air defender going to presume the track is hostile? Armada has performed analysis of Russia IFF systems in the past and noted some of their shortcomings. For example, Russia’s Parol IFF system was said to be unable to receive civilian SSR squarks. Friendly military aircraft will have their Parol IFF transponders activated and will be responding positively to friendly interrogations. Hence, all aircraft not responding to the Parol interrogations are assumed as hostile, even if they cannot answer a challenge.

If GNSS jamming did prevent the Pantsir-S1 crew receiving ADS-B squarks, there are other ways that an aircraft’s identity can be verified. Simply having a laptop with a feed from a site such as flightradar24 could be helpful. Matching radar track data of the local area with the website feed may have informed the Pantsir-S1 crew that the aircraft was friendly. However, if the airliner’s transponder was unable to relay correct ADS-B information, this could have affected the quality of track data the website was showing. When playing back the flight on flightradar24, there is a gap between 08.07AZT and 10.07AZT. During this time no information regarding the flight appears to be available. Does this mean that the aircraft simply looked like an unidentified track to Russian air defenders and hence a potential target?

This image from flightradar24.com’s website shows the path of flight 8243’s journey from take-off in Baku until its crash near Aktau International Airport. The white box in the top lefthand side of the picture shows where the aircraft’s ADS-B data become unreliable possibly because of suspected GNSS PNT jamming and spoofing.

Even if this had been the case, why was someone in the local Russian air defence command and control structure responsible for protecting Grozny and its locale not monitoring ATC chatter? A simple air-band radio, with a suitably sited antenna, would have picked up radio traffic between the aircraft and air traffic controllers in range. Flight 8243’s crew warned that they had lost GPS navigation after entering Russian airspace. Surely this should have prompted an immediate ‘weapons tight’ order to Russian air defenders given that either incorrect ADS-B information was being shared, or that this information was unavailable for a particular flight? Were local air defenders warned that GNSS jamming was taking place and that this may affect civilian ADS-B transmissions? The loss of flight 8243, and 38 of its souls, has prompted many questions, whether Russian authorities provide answers remains to be seen. (Source: Armada)

 

05 Feb 25. Fast-track armed forces recruitment launched to boost UK cyber defence. Armed forces recruits will be fast-tracked into specialist roles to tackle the growing cyber threat to the UK via a new recruitment scheme.

  • New ‘cyber pipeline’ will see recruits complete bespoke training within a matter of weeks.
  • Successful applicants will be in operational roles by the end of 2025, strengthening UK response to emerging cyber threats and national security.
  • The scheme is the latest government action to tackle recruitment and retention challenges in the armed forces and deliver on the Plan for Change.

The new, bespoke entry route for aspiring cyber professionals and those with existing digital skills will see basic training reduced from 10 weeks to around one month, after which recruits will undergo 3 months’ specialist training. This will be conducted at the Defence Cyber Academy in Shrivenham.

By the end of 2025, new recruits will be embedded into operational roles, either securing defence’s networks and services at the digital headquarters in Corsham, or conducting cyber operations to counter those who would do the UK harm as part of the National Cyber Force.

Serving to enhance the UK’s ability to conduct operations in cyberspace, specialist recruits will receive one of the highest armed forces starting salaries of over £40,000, with opportunities for additional skills-based pay as they gain expertise and experience.

It comes as the Ministry of Defence has had to protect UK networks from increasing numbers of ‘sub-threshold’ attacks – more than 90,000 in the last two years.

In an increasingly volatile world where technology is rapidly advancing, the nature of warfare is changing. Cyber capabilities present the threat of hybrid attacks which the UK must be able to protect against to ensure our national security and deliver on the government’s Plan for Change. It is paramount that the armed forces are fit to face the threats of the future.

Minsters will argue today that cyber represents “a new front line”, with UK military systems targeted every day by adversaries. The new recruitment programme has been developed to bolster capabilities in response to these growing threats amid a global shortage of cyber talent. Looking ahead, the government’s Strategic Defence Review is closely assessing the threats we face, including the technological developments of the future.

The launch of the new scheme is the latest action by the government to tackle the recruitment and retention crisis in the armed forces.

Secretary of State for Defence, John Healey MP, said:

Fast tracking cyber warriors into our military will help ensure our Armed Forces are better equipped to face our adversaries in the 21st century and defend the country from the changing threats we face.

After years of hollowing out, our government is making Britain secure at home and strong abroad, delivering on our Plan for Change and the hardworking British people.

Launching the scheme on a visit to Corsham, the Minister for the Armed Forces, Luke Pollard MP, said: “With more than 90,000 cyber-attacks on UK military networks over the last two years, it is essential that we step up our cyber defence, fast-tracking the brightest and the best cyber specialists to help protect the UK and our allies.  We are in a new era of threat, with cyberspace as a new front line. Our government will deliver for defence by boosting recruitment efforts, cementing our national security as the foundation of our Plan for Change.”

The new initiative seeks to attract individuals with relevant aptitude, interest, or existing skills into cyber careers, while still offering the unique benefits of a career in the armed forces.

Since July last year, ministers have delivered the largest pay rise for service personnel in over 20 years – including a 35% pay increase for new recruits – scrapped more than 100 outdated policies that slow down or block recruitment, and progress through Parliament legislation to establish an Armed Forces Commissioner to champion Service Personnel and their families.

Recruitment into cyber roles in 2025 will initially be through the Royal Navy and Royal Air Force, with the British Army joining for subsequent recruitment campaigns from early 2026.

 

04 Feb 25. Cyber operation highlights elevated security risks from Chinese state-sponsored groups. On 4 February, the cyber security company Fortinet reported that the Chinese state-sponsored group ‘Evasive Panda’ has been conducting a reconnaissance and information-theft operation against global entities since at least November 2024. Upon obtaining access to targeted systems, Evasive Panda deploys a malware dropper to check whether the device is already compromised before executing its own malware. It then checks the system’s privileges to execute additional malicious payloads including a secure shell (SSH) library that acts as a backdoor. The backdoor conducts system reconnaissance, exfiltrates sensitive information and then remotely executes commands after establishing communication with actor-controlled infrastructure. Evasive Panda injects the backdoor into the system’s SSH daemon to obfuscate malicious traffic and evade detection, showcasing the sophistication of the group. The group typically conducts cyber espionage operations as well as supply chain attacks to obtain strategic information, highlighting elevated security and information theft risks in the long term. (Source: Sibylline)

 

05 Feb 25. Assac Networks, a member of the Aspis Technologies Group, and a specialized provider of cyber solutions for the comprehensive protection of communication devices used by government agencies, defense, and commercial organizations, announced today the acquisition of a significant contract from a government organization in South America. The agreement involves the implementation of ASSAC’s cutting-edge ShieldiT system, designed to provide robust cyber defense for the organization’s entire communication infrastructure. The ShieldiT system will deliver a comprehensive security solution, including managed secured communications for smartphones and desktop devices, a monitored threat-safe messaging system, and integration with the organization’s telephony switch, creating an all-encompassing secure environment. As Assac Networks’ flagship product, ShieldiT offers unified, managed anti-hacking and anti-tapping capabilities for smartphones, recognized as the most vulnerable points in organizational networks. Its advanced features include real-time link analysis, behavioral analysis, network layer protection, and application risk analysis, protecting against prevalent mobile threats such as mobile phishing and QR code phishing.

Shimon Zigdon, CEO of Assac Networks, emphasized the critical nature of mobile security: “Recent studies indicate that most ransomware attacks on organizations originate through employees’ mobile phones connected to management systems and organizational emails. ShieldiT stands as the only application offering complete protection against both tapping and hacking attempts, addressing the urgent need for comprehensive mobile security in government and enterprise environments. This agreement underscores our commitment to expanding ASSAC’s solutions in the governmental market. As a company specializing in cyber protection services for government, corporate, and cellular subscribers, we are delighted to extend our offering globally and strengthen our position in the South American market.”

The implementation of the ShieldiT system is scheduled to commence in the coming months, marking a significant step forward in the organization’s cybersecurity posture. This contract reinforces ASSAC Networks’ position as a leading provider of cybersecurity solutions for government and enterprise clients worldwide.

About Assac Networks

Established in 2011 by seasoned veterans of the Israeli defense and security industries, Assac Networks develops and implements unique end-point security solutions. The company develops, integrates, and markets network-forensic and security products and solutions in the fields of mobile and landline communication – as well as cyber protection systems for ISPs, mobile carriers, governmental agencies, and commercial organizations. Among its clients are law enforcement and intelligence agencies and large enterprises around the world.

 

04 Feb 25. The L3Harris Technologies (NYSE: LHX) all-digital electronic warfare (EW) suite, Viper Shield™, has completed its first flight in a single-seat Block 70 F-16 operated by the 412th Test Wing at Edwards Air Force Base, California. Viper Shield provides the most advanced EW capability to F-16 fighter fleets for six international partners.

“This flight launches the latest capability enhancement for the F-16 and our warfighters. The Viper Shield system combined with a Block 70 airframe creates a leap in capability compared to the traditional Block 50 Viper I grew up flying,” said Maj. Anthony Pipe, F-16 Experimental Test Pilot, U.S. Air Force. “The EW advancements this system brings will ensure pilots flying these aircraft continue to make it home.”

The flight included a series of risk reduction tests related to the mission computer and other avionic subsystems compatibility, as well as interoperability with the APG-83 active electronically scanned array (AESA) fire control radar.

“Our building block approach to test hardware and software in labs, demonstrate functionality in dense radio frequency environments and validate the EW system on the ground prepared us for Viper Shield’s successful first flight,” said Ed Zoiss, President, Space and Airborne Systems, L3Harris. “With this milestone, we are ready to continue flight testing and deliver systems in late 2025 as Viper Shield is the only advanced EW solution that is funded and in active production for international F-16 partners.”

Viper Shield is a low-risk, low-cost system that counters modern radar threats with immediate detection and advanced jamming responses to disrupt the adversary’s kill chain. Unlike other EW system providers, Viper Shield will integrate across all F-16 Blocks with minimal modifications to the aircraft, and it is fully configurable with both the current Mission Modular Computer and the Next Generation Mission Computer. (Source: BUSINESS WIRE)

 

31 Jan 25. South Asia: Data-theft campaign highlights elevated security, information-theft risks from APT group. On 29 January, the cyber security company Palo Alto reported that a new advanced persistent threat (APT) group (‘CL-STA-0048’) targeted high-value government and telecommunications organisations in South Asia in an information-theft campaign between May and October 2024. CL-STA-0048 reportedly exploited software vulnerabilities in three internet-facing services as initial attack vectors. The group then deployed the ‘PlugX’ backdoor to achieve persistence within compromised systems, before executing a structured query language (SQL) query for data exfiltration. It also employed domain name system (DNS) requests to send stolen data to threat actor-controlled infrastructure, as well as multiple simultaneous payloads to enhance detection evasion. The rarity of these techniques points to the group’s resources and high sophistication. CL-STA-0048’s targets and modus operandi resemble those of the Chinese-speaking group ‘DragonRank’, which suggests a possible affiliation with Chinese state-backed cyber threat actors. The report underscores the elevated long-term security and information-theft risks facing high-value entities in the South Asia region. (Source: Sibylline)

 

04 Feb 25. Rheinmetall successful with TaWAN LBO for the Bundeswehr – digitalisation of the armed forces is picking up speed. Rheinmetall has been awarded a contract in another important large-scale project for the Bundeswehr in the field of digitalisation. As the prime contractor, Rheinmetall Electronics GmbH will be responsible for setting up an integrated communication network, the so-called ‘Tactical Wide Area Network for Land Based Operations’ (TaWAN LBO). The volume of the awarded framework-contract for a deployable, platform-based communication/directional radio management system is worth several billion Euro. The framework-contract for the procurement of TaWAN LBO has a term of 10 years and was signed by representatives of the Federal Office for the Equipment, Information Technology and In-Service Support of the Bundeswehr (BAAINBw) and Rheinmetall Electronics GmbH. At the same time, an initial order worth €1.88bn gross was placed under the framework-contract to equip a division of the Bundeswehr. Delivery of this communications network will take place between the end of 2026 and the end of 2029.

Armin Papperger, CEO of Rheinmetall AG: “We are thankful for the great trust that the Bundeswehr is placing in us regarding its ambitious digitalization efforts. Now that the Bundeswehr will be receiving TaWAN LBO and D-LBO from a single source, the conditions for a synchronized coordination concerning the introduction of both systems are given. It is our ambition to provide the Bundeswehr with a seamless and reliable communication network within the given timeframe – one which can be considered a flagship of digitalisation in Germany”.

The core function of TaWAN LBO is to provide an open transport network for Federated Mission Networking (FMN) based on Protected Core Network (PCN) to connect the forward tactical D-LBO networks to the rear-echelon core network CIR. Following the contracts awarded at the end of 2024 as part of the Bundeswehr’s Digitalised Land-Based Operations (D-LBO) programme, TaWAN LBO will be a further milestone for the end-to-end command capabilities of the armed forces. In connection with D-LBO, the TaWAN LBO network is to ensure connectivity deep into the rear area at high data rates. As part of the TaWAN LBO project, Rheinmetall is also supplying protected 8×8 HX trucks from Rheinmetall MAN, which serve as carrier vehicles for the large directional radio systems and are equipped with mobile high extendable antenna masts. One of the vehicles will hold the mast system, another will carry the 20-foot functional container with workstations, servers and other equipment. Rheinmetall MAN will be delivering a total of 102 vehicles. Other vehicle platforms are used in conjunction with smaller mobile extendable antenna masts (small directional radio system). A software-based directional radio management system is part of the overall solution which will ensure the functionality of the directional radio system, and can be used to plan and execute operations.

 

04 Feb 25. Thales Unveils its Cyber Trends 2025 Report.

In its latest report on 2025 cybersecurity trends, Thales’ Cyber Threat Intelligence team highlights the main trends that will shape cybersecurity in the coming year and calls on organizations to strengthen their resilience against these new threats.

Increased sophistication of attacks and growing threats to businesses: Key cybersecurity trends for 2025:

  • Targeted ransomware and extortion: Cybercriminals refine their strategies by exploiting sensitive company data to maximize their financial gains.
  • Supply chain vulnerabilities: Attacks against suppliers and partners are multiplying, endangering entire business ecosystems.
  • Exploitation of connected devices (IoT): With the proliferation of connected devices, hackers have a broader attack surface, necessitating enhanced network protection.
  • Threats from state actors and hacktivists: Espionage and political destabilization are becoming key strategies for some states, while hacktivists exploit vulnerabilities to amplify their ideological messages.
  • Artificial intelligence, opportunities and risks: AI is a major lever for both attackers and defenders. Its use in cyberattacks requires appropriate countermeasures.
  • Software vulnerabilities and exploitation: Attacks targeting open-source software and unpatched vulnerabilities remain a major concern.

In the face of escalating cyber threats, an adaptive and multi-layered approach is essential. The adoption of new technologies, continuous monitoring of IT and OT systems, and increased collaboration between the public and private sectors will be crucial pillars to preserve the integrity of IT systems.

To download our Cyber Trends 2025 report: White Paper – Cyber Trends 2025

https://lp.thalesgroup.com/cybertrends2025

 

31 Jan 25. Cyber Update Key points.

  • A large-scale cyber operation underscores the elevated information-theft risks stemming from the Russian cyber criminal group ‘Crazy Evil’ (see Sibylline Cyber Daily Analytical Update – 27 January 2025 and our Technical analysis below).
  • A spike in third-party data breaches underscores the elevated security and information-theft risks facing various key sectors (see Sibylline Cyber Daily Analytical Update – 28 January 2025).
  • A new highly advanced backdoor (‘TorNet’) points to the elevated security and financial risks facing users in Germany and Poland (see Sibylline Cyber Daily Analytical Update – 29 January 2025 and our Technical analysis below).
  • A new multi-pronged cyber operation (‘Phantom Circuit’) highlights the heightened security and financial risks stemming from the North Korean state-sponsored group ‘Lazarus’ (see Sibylline Cyber Daily Analytical Update – 30 January 2025).
  • A data-theft campaign against South Asian telecommunications and government entities highlights the increased security and information-theft risks from the advanced persistent threat (APT) group ‘CL-STA-0048’

Technical analysis of weekly stories

The Russian cyber criminal group Crazy Evil has targeted high-value cryptocurrency, technology and gaming influencers in at least ten highly sophisticated scam operations. The operations typically start with the promotion of fake services (such as fake asset management platforms, artificial intelligence (AI)-operated productivity and/or virtual meeting software) on social media to trick potential victims into clicking on a malicious link and/or a malicious file installer. This then covertly installs malware onto compromised systems, enabling threat actors to steal credentials and digital assets, as well as to hijack user accounts for financial profit. The group’s toolkit encompasses highly advanced information-stealing malware such as ‘Stealc’ and ‘Atomic macOS Stealer (AMOS)’. Crazy Evil comprises six sub-groups (‘AVLAND’, ‘TYPED’, ‘DELAND’, ‘ZOOMLAND’, ‘DEFI’, and ‘KEVLAND’) that manage their own phishing pages, pointing to the overall sophistication of the group’s enterprise. The group boasts approximately 3,000 followers on two public Telegram channels; it uses three separate channels as discussion forums and to organise operations. It also continues to recruit more affiliates via a complex recruitment process which we assess further highlights the scale and complexity of Crazy Evil’s operations.

A new backdoor (TorNet) has been used to target users in Germany and Poland in a financially motivated campaign since at least July 2024. The campaign uses phishing emails as initial attack vectors to trick potential victims into opening a malicious .GZIP attachment. The email impersonates financial institutions, logistics firms and/or manufacturing companies, purporting to send money transfer confirmations and/or order receipts. Once opened, the attachment executes the ‘PureCrypter’ malware onto compromised systems to establish persistence and covertly download the main TorNet payload. PureCrypter loads directly onto the system’s memory and conducts several anti-analysis checks upon deployment. It also disables network connections before executing TorNet, underscoring the sophistication of its detection-evasion capabilities. Subsequently, TorNet establishes communication with command-and-control (C2) infrastructure and connects to the Tor network. It also conducts additional anti-analysis checks similar to those of PureCrypter, emphasising the highly obfuscated nature of this operation.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communication to malicious IP addresses associated with known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

Our cyber word(s) of the week: The onion router (Tor) network. (Source: Sibylline)

 

31 Jan 25. Ready for the Future NAVWAR: IAI has Successfully Integrated its ADA GNSS Anti-Jamming System With the M-Code GPS Receiver. IAI achieved a major milestone with the successful integration of the ADA Anti Jamming system, with the new M-code GPS military receiver for International customer. This integration enables the ADA system to deal with evolving and emerging threats to GPS signals. The ADA system, designed to protect GPS signals from RF interference, has successfully integrated with M-Code GPS receiver, providing a powerful combination for enhanced GPS immunity. In ground tests and flight tests, the ADA system together with M-code receiver has demonstrated its effectiveness in suppressing attacks on GPS, making it a trusted choice for military users all over the world.

President and CEO of Israel Aerospace Industries, Boaz Levy: “The modern battlefield is saturated with increasingly sophisticated Global Navigation Satellite System (GNSS ) jamming systems that are posing a growing threat to military operations worldwide. As Israel’s Center of Excellence for Navigation, we take pride in our ADA system, a resilient navigation solution to meet emerging GNSS jamming challenges. Like the Arrow-3 system developed some years ago, which is still relevant to current threats, ADA was designed flexibly to address both current and future challenges. Achieving the milestone of M-Code compliance will enable our customers to have a robust navigation solution for their most up-to-date operational requirements. Systems produced by IAI have demonstrated excellence in handling the challenges of the modern battlefield, and we are confident in their ability also to optimally deal with those in the future.”

Guy Barlev, Executive Vice President of IAI’s Systems, Missiles & Space Group: “By combining the ADA system with M-Code, our solution offers unparalleled protection against both GPS jamming and spoofing threats and takes GPS immunity to the next level. In recent modern conflicts, the ADA GNSS anti-jamming system has proven itself as a reliable and combat-excellence solution. Its robustness and effectiveness have been tested in various operational scenarios, ensuring the continuity of GPS-based operations and maintaining assured Position, Navigation and Time (PNT) for the military platforms. With its proven track record in modern conflicts with thousands of flight hours and the integration with M-Code receiver, this system offers unmatched GPS immunity and combat-readiness, making it the ideal choice for military users.”

The ADA product portfolio, developed by IAI, is compatible with a broad range of satellite navigation systems (GNSS). Its state-of-the-art technology implements multiple mitigation methods and specialized digital signal processing algorithms. The system’s versatility facilitates the integration in numerous platforms. IAI has over 20 years of proven experience in supplying a wide range of GNSS Anti-Jam solutions for the most demanding requirements, and vast experience in integration immune navigation solutions into airborne (manned and UAV), surface, maritime and guided munitions. (Source: ASD Network)

 

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

January 31, 2025 by

30 Jan 25. Revolutionising Tactical Communications Security in Defence.

Funded by DASA, PhoenixC4i, delivers game-changing antenna technology that reduces radio frequency (RF) footprint to enhance stealth and safety

  • Innovative clip-on antenna technology reduces RF footprint by up to 80%, enhancing operational security
  • Successfully deployed with over 75 units purchased by the British Army for evaluation
  • Cost-effective solution providing significant tactical advantage in electronic warfare environments

Picture this scenario: armoured vehicles move through contested terrain. The mission is complex, with multiple units coordinating across a battlefield that spans tens of miles. But there’s a catch: every radio transmission needed to coordinate these forces could become a beacon for enemy targeting systems. Units face a difficult challenge between maintaining communications with one another and potentially revealing their positions to the adversaries hunting them, particularly when static.

Stealth by design: DarkSky Clip-On Antenna

From individual soldier radios to armoured vehicles and headquarters command posts, military forces rely on tactical Ultra High Frequency (UHF) antennas for communications. But these systems broadcast signals in all directions, making them easier to detect. Recent conflicts have provided stark evidence of how devastating electronic warfare can be, with forces suffering significant losses when their communications are detected and targeted.

PhoenixC4i’s DASA-funded solution is elegantly simple: a clip-on antenna that directs radio signals only where needed, like a spotlight rather than a floodlight. This not only makes communications harder to detect but also improves signal quality. Whether mounted on vehicles, command posts, or carried by soldiers, the system improves survivability with minimal training required.

“We developed the DarkSky Clip-On Antenna after realising that existing systems were unable to effectively reduce the detectable signal,” explains Douglas Celerier, founder of PhoenixC4i. “Our solution needed to be ultra-portable, easy to train and versatile enough to be deployed on different platforms, such as vehicles, masts or soldier platforms.”

Benefits for Defence:

  • improve link quality for robust HQ-to-HQ communications
  • doubling the baseline communication range
  • extending links within the network, particularly to isolated nodes
  • providing better quality links to enhance data performance reducing up to 80% unwanted RF signature in identified directions: reducing
  • vulnerability of intercept
  • susceptibility to disruption from jamming or co-site interference
  • easily retrofitting to existing UHF comms systems with low system and network impact

Impact and implementation

On completion of their DASA project, the British Army purchased 75 DarkSky Clip-On Antennas for evaluation. The PhoenixC4i innovation offers a cost-effective solution for protecting static vehicles, headquarters, and infantry radio communications.

Beyond the British Army’s purchase, PhoenixC4i also secured significant contracts, including several units for UK MOD specialist users. The system has proven its worth in multiple trials, including WESSEX Storm and MARWORKS, and is being considered for frameworks such as SERAPIS and humanitarian support to Ukraine.

“When the tactical antenna system was first designed, it was based on a mesh network where the signals all supported each other,” says Celerier. “However, in reality, it doesn’t work like that – small groups go out with long links between organisational units. The DarkSky Clip-On Antenna supports actual operational requirements while keeping users covert.”

DASA and PhoenixC4i: On the same wavelength

The journey from innovative idea to battlefield-ready technology requires more than just engineering talent – it needs the right support. Since 2020, DASA’s expertise has transformed PhoenixC4i’s initial concept into a field-tested reality.

“Working with DASA has provided multiple advantages,” notes Celerier. “The DASA team are always available to assist with everything from admin, commercial, technical direction or helping to open doors to the right customers for our technology. Their support has allowed PhoenixC4i to expand and employ additional personnel.”

The results speak for themselves. What began as antenna modelling in a workshop in Gloucester has evolved into technology tested by British forces, with PhoenixC4i expanding both their team and their ambitions.

“We’ve created something that’s not only innovative but also practical and affordable,” says Celerier.

A growing defence portfolio

The DarkSky Clip-On Antenna is just one part of PhoenixC4i’s growing defence innovation portfolio. Through continued DASA support, the company has been funded to develop technologies including:

SPARTACUS: Tactical Deception Made Simple

This electronic warfare system creates convincing radio signatures that protect forces by generating digital ‘decoys’. The system can simulate various military assets while remaining simple enough for rapid deployment.

Infrared Heat-Mat: Digital Camouflage Evolution

Using advanced materials including silicone and graphene, these heat mats replicate thermal signatures of vehicles and personnel to add clutter and degrade adversary sensor capabilities.

Clever Clutter: Small Units, Big Impact

Available in portable and larger variants, these units create confusion across infrared, visual, and audio spectrums. The technology is cost-effective and requires minimal training, making it ideal for rapid deployment.

D-DIAB: Integrated Deception at the Push of a Button

The ‘Digital Deception in a Box’ combines radio frequency and infrared deception in a single, trailer-mounted unit. It can simulate an entire headquarters location while keeping personnel safely away from harm.

DarkSky, bright future

Building on the success of the DarkSky Clip-On Antenna, PhoenixC4i continues to work with DASA on other electronic warfare solutions, including the SPARTACUS RF deception system and IR heatmat capabilities. These developments demonstrate the ongoing value of DASA’s support in bringing innovative defence solutions to market.

The success of the DarkSky Clip-On Antenna proves that innovative SMEs, with the right support, can deliver critical capabilities to defence users. As electronic warfare continues to evolve, solutions like the DarkSky Clip-On Antenna can play an important role in protecting military communications and ensuring operational success. (Source: https://www.gov.uk/)

 

30 Jan 25. Global: Campaign highlights elevated security risks from North Korean state-sponsored groups. On 29 January, the security company SecurityScorecard reported that the North Korean state-sponsored group ‘Lazarus’ has been targeting developers in the cryptocurrency sector in a multi-pronged information-theft campaign (‘Phantom Circuit’) since at least November 2024. In January, Lazarus reportedly concealed multiple backdoors within legitimate software available on free software development platforms. Developers unknowingly executed the backdoors onto their systems alongside the legitimate software, enabling Lazarus to exfiltrate sensitive data. We assess that the group will likely use stolen data to conduct unauthorised activities for financial gain; this highlights heightened financial risks in the medium term. The operation also signals a potential shift in the group’s tactics since it typically uses social engineering techniques and the exploitation of software vulnerabilities as initial attack vectors. This will raise security and financial risks to the cryptocurrency sector in the long term amid a sharp uptick in cryptocurrency theft operations from North Korean state-sponsored actors in 2024. (Source: Sibylline)

 

29 Jan 25. Sudanese Armed Forces finds electronic warfare system at major RSF base. The Sudanese Armed Forces (SAF) discovered what was identified as a Belarusian-made electronic warfare system when it captured a major Rapid Support Forces (RSF) base north of Khartoum. The system was seen in a video showing SAF Commander General Abdel Fattah al-Burhan visiting the El-Gaili (Al-Jaili) and Garri (Qarri) areas. The general’s helicopter landed outside a gate with a sign that said it was the RSF’s Garri Military Base, which satellite imagery shows is located just to the west of the Garri Refinery, north of Khartoum, and is unusually large and sophisticated by Sudanese standards.

Gen Burhan met soldiers at the base before inspecting a burned-out van with mast-mounted antennas that Sudanese sources identified as the Groza-S, an electronic warfare system that Belarus’s KB Radar developed to counter unmanned aerial vehicles (UAVs).

The antennas appeared to be identical to the ones seen in photographs that Belarus’s State Authority for Military Industry released in October 2020 to announce that an improved version of the system had already been exported. However, the layout of the operators’ station was slightly different.

The Groza-S uses signals intelligence equipment to detect and locate UAVs, an optional electro-optical system to track them, and jammers to block or spoof their communications and satellite navigation signals at ranges of up to 30 km, according to the brochure. (Source: Janes)

 

28 Jan 25. New Signals officers have completed their Troop Commander training and are now ready to take on their first roles in the British Army. After graduating from Sandhurst last year, they spent six months specialising in the Royal Corps of Signals, mastering the technical and leadership skills required to command troops on the battlefield. Their final test, a two-week tactical exercise known as Mercury Validation, ensured they are ready to lead their teams in high-pressure situations.  The exercise included setting up and troubleshooting communications networks while responding to simulated battlefield scenarios, ensuring they are fully prepared for the demands of their new roles. Among the graduates is Second Lieutenant Tegan Shone, who is following in the footsteps of her father and grandfather, although she is the first in her family to go in at officer rank.

Reflecting on her training, she said: “This is the first time we’ve ever staffed the working environment ourselves, as well as setting up the radios ourselves… it’s been working through, fault-finding and, in the end, we’ve managed to get full working nets and data in.”

She added that she is “massively excited” about the challenges ahead.

The new troop commanders will now lead around 30 soldiers each in Signals units across the UK, playing a critical role in ensuring communication on the battlefield – something 2Lt Shone sums up with their motto: “No comms, no bombs.” (Source: forces.net)

 

28 Jan 25. Global: Spike in third-party data breaches raises security, information theft risks to key sectors. On 27 January, the security company Obsidian Security reported that cyber attacks against software-as-a-service (SaaS) environments increased by 300% between September 2023 and September 2024. Targeted sectors included financial services, government and healthcare, likely due to the highly sensitive and lucrative nature of the data they handle. At least 85% of breaches during this period used identity takeover and account hijacking as initial attack vectors. Threat actors also reportedly exploited weak password configurations and multi-factor authentication (MFA) protections to infiltrate targeted systems. We assess that this highlights the security risks associated with inadequate security and password managementmeasures related to third-party software use. Businesses are increasingly relying on third-party cloud providers to store larger volumes of sensitive data and scale up and streamline operations. As such, we assess this points to heightened third-party security and information theft risks to the aforementioned sectors since SaaS environments remain a key target for threat actors.  (Source: Sibylline)

 

27 Jan 25. As part of the Italy-Saudi Arabia institutional round table, in the presence of the President of the Council of Ministers, Giorgia Meloni and the Saudi Minister of Investment H.E. Khalid A. Al Falih, ELT Group signed a Memorandum of Understanding (MoU) with Shamal, a Saudi-owned Limited Liability Company that provides services also in the defense domain. The agreement represents a concrete proof of the strong commitment of ELT Group towards KSA’s Vision 2030 strategic objectives, aiming at implementing solid and long lasting partnership in the aerospace and defence sectors.

Through this MOU, ELT and Shamal will work together for providing training solutions in the crucial field of Defence Electronics and Cyber. The latter activity will see the involvement of Cy4gate the

ELT group investee company specialized in Cyber Intelligence & Cyber Security. One of the ambitious goals of this collaboration is to support and expand the capacities already present in the Kingdom, thanks to the expertise developed by the ELT Group in all domains and thanks to its

continuous research and development activities to cope with current and new threats. ELT Group established a strong relation with the Kingdom, offering its 70 years of experience in managing the electromagnetic spectrum and developing electronic defence systems. Recently the

Group established a Saudi-law company, Elettronica for Industry Saudi Arabia LLC, focused on localizing logistic support and, more extensively, the entire value chain.

 

29 Jan 25. Germany-Poland: New backdoor raises security, financial risks to users. On 28 January, the security company Cisco Talos reported that a new backdoor (‘TorNet’) has targeted users in Germany and Poland in a financially motivated campaign since July 2024. The campaign uses phishing emails impersonating financial institutions, logistics companies or manufacturing companies to trick potential victims into opening a malicious .GZIP attachment. This executes ‘PureCrypter’ malware onto compromised systems (establishing persistence) and then deploys the TorNet backdoor after conducting initial anti-detection checks. PureCrypter boasts highly sophisticated detection evasion capabilities as it disables network connections before installing TorNet to evade anti-malware solutions. TorNet establishes communication with command-and-control (C2) infrastructure and connects to the Tor network to enhance obfuscation on victims’ devices. We assess this incident signals the continued development of new, highly advanced malware to prolong detection evasion while bolstering attack success rates. This highlights elevated security and financial risks to users in the aforementioned countries in the short-to-medium term. (Source: Sibylline)

 

27 Jan 25. New NAO report – cyber resilience.

Report by the Comptroller and Auditor General.

Cyber threat to UK government is severe and advancing quickly, spending watchdog finds

  • Cyber threat to UK government is severe and advancing quickly.
  • 58 critical government IT systems independently assessed in 2024 had significant gaps in cyber resilience, and the government does not know how vulnerable at least 228 ‘legacy’ IT systems are to cyber attack.
  • Skills gaps are the biggest risk to building cyber resilience, with one in three cyber security roles in government vacant or filled by temporary staff in 2023-24.
  • Please read the Government cyber resilience report
  • Please read the PAC Chair’s statement

The cyber threat to UK government is severe and advancing quickly; government must act now1 to protect its own operations and key public services, according to a new report published by the public spending watchdog.

The National Audit Office (NAO) evaluated2 whether government was keeping pace with the rapidly evolving cyber threat it faces from hostile actors.

It identified that the government’s new cyber assurance scheme, GovAssure, which independently assessed 58 critical departmental IT systems by August 2024, found significant gaps in cyber resilience with multiple fundamental system controls at low levels of maturity across departments.

At least 228 ‘legacy’ IT systems3 were in use by departments as of March 2024, and the government does not know how vulnerable these systems are to a cyber attack.

If successful, cyber attacks4 can have devastating effects on government organisations, public services, and people’s lives. In June 2024, a cyber attack on a supplier of pathology services to the NHS in south-east London led to two NHS foundation trusts postponing 10,152 acute outpatient appointments and 1,710 elective procedures. The British Library, which experienced a cyber attack in October 2023, has already spent £600,000 rebuilding its services and expects to spend many times more as it continues its recovery work.

Successive governments have been working for at least a decade to build the UK’s cyber resilience, including publishing a strategy for improving government organisations’ cyber security in January 2022. This strategy included a target for key government organisations to be “significantly hardened to cyber attack by 2025”. But government has not improved its cyber resilience fast enough to meet this aim.

One reason for this is shortages of cyber skills within government. In 2023-24:

  • one in three cyber security roles in government were vacant or filled by temporary staff (contingent labour);
  • more than 50% of cyber roles in several departments were vacant; and
  • 70% of specialist security architects in post were temporary staff.

Departments reported that the salaries they can pay and civil service recruitment processes are barriers to hiring and keeping people with cyber skills.

Other concerns include a lack of coordination within government jeopardising effective cyber defence. The respective roles of departments and organisations at the centre, such as the NCSC, are insufficiently understood. Departmental leaders have not consistently recognised the relevance of cyber risk to their strategic goals5.

Financial pressures have also meant that some departments have significantly reduced the scope of their work to build cyber resilience, which could increase the severity of an attack when it happens. In March 2024, departments did not have fully funded plans to remediate around half of government’s legacy IT assets (53%, or 120 out of 228), leaving these systems increasingly vulnerable to cyber attack. Under-investment in technology and cyber was a key factor in the British Library cyber incident.

The NAO is urging the government to act now to build its cyber capabilities and defences. It recommends government:

  • Within the next six months:

o develops, shares and starts using a cross-government implementation plan for the Government Cyber Security Strategy.

o sets out how the whole of government needs to operate differently, and what is needed for this transformation to be effective, so that it can achieve its goals for government cyber security and resilience.

  • Within the next year:

o make and enact plans to fill cyber skills gaps in workforces.

Gareth Davies, head of the NAO said:  “The risk of cyber attack is severe, and attacks on key public services are likely to happen regularly, yet government’s work to address this has been slow.

“To avoid serious incidents, build resilience and protect the value for money of its operations, government must catch up with the acute cyber threat it faces.

“The government will continue to find it difficult to catch up until it successfully addresses the longstanding shortage of cyber skills; strengthens accountability for cyber risk; and better manages the risks posed by legacy IT.”

  1. We have undertaken this report at this time because the government: has assessed that the cyber threat is rapidly increasing; has started collecting detailed and reliable data on its cyber resilience in 2024; and planned to achieve key parts of the Strategy by 2025. This report focuses on the cyber resilience of the ministerial and non-ministerial departments and their arm’s-length bodies (which we refer to in this report as ‘departments’). This report does not cover the cyber resilience of local government, public corporations, businesses or UK society more widely. This report focuses on the cyber resilience of IT systems at the ‘official’ level of security classification and not systems classified as ‘secret’ or above.
  2. This report examines whether the government’s efforts to improve its cyber resilience are keeping pace with the cyber threat it faces. The report aims to: hold government to account for its performance; increase transparency about how cyber resilient government is; and help government improve its cyber resilience. To do this, we examined:

o the threat to government cyber security;

o progress with implementing the Government Cyber Security Strategy;

o the government’s cyber resilience position in 2024; and

o the challenges for departments in building cyber resilience.

  1. Legacy systems are often more vulnerable to cyber attack because: their creators no longer update or support their use; few people have the skills to maintain them; and they have known vulnerabilities. The government estimated that it used nearly half of its £4.7 bn IT expenditure in 2019 to keep legacy systems running. Risks to public services posed by legacy technology have built up over many years.
  2. Between September 2020 and August 2021, around 40% (around 310) of the 777 incidents managed by the NCSC because of their potential severity, were aimed at public sector organisations, including central and local government; emergency and health services; and law enforcement. The NCSC assessed that 89 of the 430 incidents it managed because of their potential severity, between September 2023 and August 2024, were “nationally significant”. Cyber attacks can affect every aspect of an organisation’s operation and recovery is often lengthy and costly.
  3. In April 2024, the Government Security Group (GSG) recommended to ministers that departments strengthen their accountability for cyber risk through improved reporting and risk management. In 2024, GovAssure data showed that departments were not meeting their responsibility to be cyber resilient. Additionally, the government did not have sufficient oversight of the cyber resilience of the wider public sector, which lead government departments are responsible for. In April 2024, GSG reported that departments cited insufficient funding, number of staff, and oversight mechanisms as barriers to understanding and improving cyber resilience across the bodies they oversee. Some departments have been reluctant to share information about their cyber incidents with other parts of government, which has limited the opportunities for other organisations to learn and improve their own cyber resilience.

 

24 Jan 25. Power generation challenges could overshadow Stargate AI initiative. While the Defense Department is likely to benefit from OpenAI’s announcement this week that it would invest half a trillion dollars to build new artificial intelligence data centers around the country, Pentagon officials warned that the U.S. lacks the energy resources and computing power to support the new infrastructure — and solving that problem won’t be easy.

OpenAI announced the project, dubbed Stargate, on Tuesday, pledging an initial $100 bn — plus another $400 bn over the next five years — to build new AI infrastructure across the U.S. and create “hundreds of thousands of American jobs” in the process. Early funders include Softbank, OpenAI, Oracle and MGX — a technology investment firm based in the United Arab Emirates — and OpenAI will partner with Oracle, Microsoft, Arm and NVIDIA on technology development.

During a press conference Tuesday at the White House, President Donald Trump called the effort a “monumental undertaking” and said the White House would support the project, in part, through issuing emergency declarations, though he didn’t expand on details.

The Defense Department has an ambitious vision for using AI across a range of military missions, including data collection, intelligence analysis, campaigning and logistics. But running those tools and applications takes more computing power and space than DOD has access to.

Roy Campbell, deputy director of advanced computing in the Office of the Undersecretary of Defense for Research and Engineering, said Thursday that many times, bases outside of the U.S. don’t have the computing power they need to retrain new AI tools.

“In some cases, for you to be able to handle a situation a forward operating base can’t handle, you have to kick that back to [the continental United States] and use the DOD supercomputing centers that we have there,” he said during a panel at the Potomac Officers Club’s annual Research and Development Summit in McLean, Virginia.

Jeff Waksman, who’s leading an effort in the Pentagon’s Strategic Capabilities Office to develop a mobile nuclear reactor, said the strain that technologies like AI and high-power computing place on the electric grid raises questions about who should have access to data and how to mitigate the risk of blackouts.

“This is not a problem that industry or the DOD can figure out by itself. It’s about the nation’s grid as a whole,” said Waksman, who spoke on a panel with Campbell. “It’s probably the most underrated challenge of this huge $500 bn announcement.”

Waksman’s nuclear reactor program, known as Project Pele, offers one answer to that challenge: using nuclear power to source energy for AI computing.

The effort, initiated in 2019, aims to demonstrate the first-ever U.S. prototype of a portable nuclear reactor within five years. The mobile reactor, which the department estimates could deliver one to five megawatts of electrical power over a minimum three-year operating life, would support DOD’s growing energy needs by providing power to austere locations.

The Pentagon broke ground at the Project Pele test site at the Idaho National Laboratory last September and plans to begin assembling the reactor — built by BWXT Advanced Technologies — as soon as next month. The department aims to demonstrate the technology in 2026.

“It’s going to be the first generation portable nuclear reactor built anywhere in the world, outside of China,” Waksman said. “It’s very much not a paper project anymore.”

Another potential solution to the AI power problem is making processors more effective at crunching data. Steven Meier, associate director of space technology at the Naval Research Center, said his lab is exploring the use of more efficient neuromorphic processors that can be 100 times more efficient than a standard processor. Essentially, neuromorphic processors take up less space, work faster and use less energy.

“There’s huge gains to be made in terms of neuromorphic processors making AI and [machine learning] more accessible on autonomous vehicles of all shapes and sizes,” Meier said at the conference. (Source: Defense News)

 

24 Jan 25. Cyber Update Key points

  • A large-scale distributed denial-of-service (DDoS) attack against Internet-of-Things (IoT) devices will elevate disruption risks via a newly discovered botnet.
  • A new Phishing-as-a-Service (PhaaS) operation (‘Sneaky 2FA’) points to elevated data theft and security risks for Microsoft 365 users (see Sibylline Cyber Daily Analytical Update – 21 January 2025 and our Technical analysis below).
  • Improved social engineering techniques impersonating Microsoft Teams Help Desk will raise security risks posed by ransomware groups (‘STAC5143’ and ‘STAC57777.’
  • A supply chain attack targeting a South Korean virtual private network (VPN) service highlights increased espionage and third-party risks posed by a new China-nexus group (‘PlushDaemon.’
  • A new information-stealing campaign highlights heightened security risks posed by the information-stealer malware ‘LummaStealer’ (see Technical analysis below).

Technical analysis of weekly stories

A new PhaaS kit, ‘Sneaky 2FA’, is targeting Microsoft 365 account holders in an information-theft campaign. The campaign reportedly starts with phishing emails containing a fake payment receipt that can be accessed by scanning a malicious QR code. This then redirects users to phishing websites emulating legitimate Microsoft login pages. The fraudulent pages first display a Cloudflare Turnstile reCAPTCHA challenge (the process whereby users are asked to confirm that they are human operators) to enhance the site’s legitimacy and simultaneously eliminate bots. Subsequently, victims are tricked into entering login credentials and two-factor authentication codes by displaying a blurred image of legitimate Microsoft login interfaces. This effectively enables threat actors to conduct an adversary-in-the-middle (AiTM) attack to steal sensitive user information. It is likely that threat actors then sell stolen information on the dark web for financial profit or proceed to exploit it in follow-on social engineering attacks. Sneaky 2FA uses browser developer tools to prevent debugging by security analysts, underscoring the sophistication of the kit’s detection evasion capabilities. The PhaaS kit can also check whether threat actors are subscribed in real-time; it is also centrally managed on the messaging platform Telegram, underscoring the scale of this operation.

Unnamed threat actors are exploiting the social media platform Reddit and the file-sharing service WeTransfer in a new information-stealing campaign. The campaign likely starts with malvertising, search engine optimisation (SEO) poisoning and/or direct messages on social media to distribute fake Reddit discussion pages. The fraudulent forum pages stage a conversation between three users purporting to provide advice on how to download a specific tool. This enhances the legitimacy of the discussion while tricking potential victims into clicking on a WeTransfer link in the comments. Users are then redirected to a separate page where they unknowingly install the ‘LummaStealer’ information-stealing malware under the guise of a legitimate file installer. The actor-designed pages also contain a string mimicking those of the company they impersonate in the URL to further increase users’ sense of legitimacy. Threat actors likely use LummaStealer to exfiltrate sensitive data from compromised systems to sell stolen information on the dark web for profit.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communication to malicious IP addresses associated with known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering
  • Implement password management policies to prevent compromises via stolen and/or exposed credentials

Our cyber word(s) of the week: SEO Poisoning (Source: Sibylline)

 

24 Jan 25. Global: New campaign highlights heightened security risks via information-stealing malware. On 23 January, international news outlets reported that unnamed threat actors are exploiting the social media platform Reddit and file sharing service WeTransfer in a new information-stealing campaign. Threat actors have created fake Reddit discussion pages, purporting to provide advice on how to download a specific tool. The forum includes a WeTransfer link, tricking potential victims into unknowingly installing the ‘LummaStealer’ information-stealer malware under the guise of a legitimate file installer. The campaign reportedly comprises approximately 1,000 fraudulent pages and links, pointing to the scale and possible widespread impact of this operation. Threat actors likely use LummaStealer to exfiltrate sensitive data from compromised systems, which they then sell on the dark web for illicit profit. We assess this will increase the risk of follow-on social engineering attacks in the short term. Additionally, this operation underscores the heightened security and information-theft risks facing users amid a general uptick in the adoption of information-stealing malware since 2024. (Source: Sibylline)

  • « Go to Previous Page
  • Page 1
  • Page 2
  • Page 3
  • Page 4
  • Page 5
  • Page 6
  • Go to Next Page »

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT