• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, Tactical Comms, AI, Cyber, EW, Cloud Computing & Homeland Security

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

September 6, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

———————————————————————————————————————————————————————————————————————————————————————————————————————————————-

05 Sept 24. DOD Official Says Partnerships Are Key to U.S. Cyber Strategy.  Partnerships are critical to the Defense Department’s proactive cyber defense strategy, a senior official said yesterday.

Army Lt. Gen. William J. Hartman, deputy director of U.S. Cyber Command, said DOD’s ability to synchronize across agencies and with a range of foreign partners provides the U.S. with an asymmetric advantage in defending against a range of adversaries.

Hartman said Cybercom remains focused on aligning with geographic combatant commanders and government partners to support regional cybersecurity strategies.

Cybercom has also maintained close ties with key foreign partners using small team deployments throughout the globe. The teams aim to carry out defense operations, and Hartman said the demand for these deployments continues to grow.

“When you have smart young Americans that are working with a smart young foreign partner, nothing demonstrates more that the United States cares about cybersecurity,” Hartman said during a panel discussion at the Billington Cybersecurity Summit in Washington.

The Cybercom deputy director added that the demand for these engagements will likely not dissipate soon, and DOD’s ability to leverage technology and partnerships to continue to scale global engagements will be critical.

“Our adversaries have to know that we’re serious and that the ecosystem that they require in order to execute operations is not safe,” he said. “We’re going to work with allies and partners, and we’re going to do everything we can to get after them. We are most effective when we do that across the government and private industry.” (Source: U.S. DoD)

 

04 Sept 24. Murmurs of Murmansk. A deployed GT-01 Murmansk-BN system is seen here with all four of its jamming antennas. The Russian military is believed to use the system to target US and allied high frequency radios and networks. Recent reports state that an unknown number of Murmansk-BN systems have been acquired by Iran.

The Islamic Republic of Iran has received GT-01 Murmansk-BN communications jamming systems from Russia.

Media reports in early August disclosed that Russia has delivered its GT-01 Murmansk-BN Communications Jamming (COMJAM) system to Iran. The reports did not disclosed how many systems have been acquired although another article did hint that several have been delivered. These Murmansk-BN systems are not the first Russian Electronic Warfare (EW) capabilities acquired by Iran. As Armada has reported, Iran’s Cobra-V8 is thought to be a local version of Russia’s 1RL257E Krasukha-4 electronic warfare system. We have also disclosed that Iran has acquired Russia’s IL222M Avtobaza-M EW platform.

Murmansk-BN

Official Russian language documents seen by Armada, and sources close to the Russian EW industry, have provided indications of the Murmansk-BN’s capabilities. The system is mobile and housed on six trucks. Four trucks each accommodate one of the system’s 32-metre/m (102-feet/ft) high antennas. The antenna trucks are typically spaced across a 90-degree arc with 35m (114ft) of spacing between each. One truck houses the command post and another the generator which produces 400 kilowatts of power. Targets for the Murmansk-BN include High Frequency (HF: three megahertz/MHz to 30MHz) radios and networks. Emphasis is placed on targeting beyond line-of-sight HF skywave emitters. Effective ranges of between 5,000 kilometres/km (2,699 nautical miles/nm) and 8,000km (4,318nm) have been quoted for the Murmansk-BN.

Targets

The Murmansk-BN entered service with the Russian military in 2016. At least one system is thought to equip each of the Russian Army’s four independent electronic warfare brigades. A single system is likely to furnish the 15th Electronic Warfare Brigade which is directly subordinate to the Russian general staff. Armada has learned that a key target for the Murmansk-BN is the US military’s High Frequency Global Communications System (HFGCS). The HFGCS carries voice traffic across HF links and is a key channel for the carriage of Emergency Action Messages (EAMs). EAMs contain Command and Control (C2) information regarding the US nuclear deterrent. Attacking the HFGCS would be a key target of the Murmansk-BN in periods of high tension and war with the US and North Atlantic Treaty Organisation (NATO). Jamming HFGCS transmissions could help deprive US and NATO nuclear forces of C2 information. HF is also used for NATO and allied Link-11 (two megahertz to 29.9MHz, 225MHz to 399.975MHz) Tactical Datalink (TDL) traffic. Link-11 is a TDL which supports maritime operations.

Iran and Murmansk-BN

It is not surprising that the Iranian military has chosen to acquire the GT-01 Murmansk-BN. Tensions remain high between the Islamic Republic, Israel and the latter’s allies. On 13th April, Iran performed a large, combined missile, rocket and uninhabited aerial vehicle attack against targets in Israel. These attacks were launched from Iran and by Iranian proxies in Iraq, Lebanon and Yemen. A coordinated response by Israeli, US and allied air defences blunted the severity of Iran’s attack which resulted in no fatalities.

The success of the air defence effort was due in part to robust and resilient communications. While the precise details of the networks used have not been revealed, it would not be surprising if they included Link-11. The TDL would have assisted the battle management of the air defence effort. The Iranian military has an interest in degrading Link-11 should it find itself once again crossing swords with Israel and her allies. Meanwhile, Iran’s ongoing clandestine nuclear weapons programme makes the Islamic Republic a potential nuclear target. Any use of these weapons by Iran could bring a response in kind from Israel, the United States and/or their NATO nuclear-armed allies. Blunting the efficiency of the HFGCS is clearly in Iran’s interests.

Degrading US and allied HF networks maybe easier said than done. The US nuclear deterrent uses several communications links for EAM traffic. This is done to ensure redundancy so that the degradation or elimination of one network does not stop the flow of Emergency Action Messages. Link-11, and its Link-22 successor which uses the same frequencies, are both secure networks. While Murmansk-BN maybe effective against unsecured HF links, encrypted and secure networks may present challenges. Nonetheless, the recent Murmansk-BN acquisition illustrates that Iran’s appetite for Russian EW materiel shows little sign of abating. (Source: Armada)

 

05 Sept 24. September Spectrum SitRep. Concurrent Technologies’ new TR MDx/6sd plug-in card has been designed in accordance with SOSA standards and can support capabilities such as multispectral sensing and mission control.

Play your cards right

Concurrent Technologies has launched its new TR MDx/6sd plug-in card which the company says is developed in alignment with SOSA (Sensor Open Systems Architecture) technical standards. A press release announcing the news revealed that the plug-in card “has enhanced features, including a wider operating temperature range, reduced weight, advanced networking capability and secure on-board storage.” The company told Armada in a written statement that the TR MDx/6sd “features a lightweight build and prime performance across thermal range, 40GBASE-KR4 or 100GBASE-KR4 Primary Ethernet Data plane and support for FIPS 140-3.” The statement continued that the new plug-in card can equip “land and airborne platforms that require multispectral sensing and mission control capabilities.”

US Army contract for SIGINT work

CACI International has been awarded a contract worth $416 m to “design, produce and deliver complex, customised radio frequency systems for US Army Signals Intelligence missions,” according to a press release. The news was revealed in early August. According to the press release, the company is to provide software, hardware and expert analysis to this end. The work forms part of the Exploit, Enhance, Enable and Influence Tactical Exploitation of National Capabilities (E3IT) initiative for the army. In addition, the company will help the force address evolving risks through SIGINT data analysis. Armada send CACI International questions concerning the contract, but received no response by the time this article went to press. (Source: Armada)

 

04 Sept 24. Northrop Grumman, L3Harris lock horns for Polish F-16 EW package. The two American firms are pitching competing electronic warfare platforms that they hope will be part of Warsaw’s planned upgrade from Block 50 configuration F-16s to Block 70. As Poland looks to make significant upgrades to its F-16 fleet, two American firms here are vying to offer their electronic warfare suites as part of the broader package.

While it’s still unclear exactly what Warsaw will require of its upgrade, meant to bring its aircraft from the Block 50 configuration to the more advanced Block 70, Northrop Grumman says it has pitched the AN/ALQ-257 Integrated Viper Electronic Warfare Suite (IVEWS), while L3Harris is offering the AN/ALQ-254(V)1 Viper Shield.

Both companies told Breaking Defense at the MSPO show today that Poland plans on making a selection for a new EW package in the next six months. (Poland’s Ministry of Defense did not immediately respond to an after-hours request for comment.)

IVEWS, the US Air Force’s F-16 EW program of record, uses an ultra wideband architecture designed to detect, identify and counter radio frequency threats. It is also “four times more sensitive and [able to offer] four times wider range than any previous system employed” in the fourth-generation aircraft, said Charles Blanks, fixed wing survivability manager at Northrop Grumman. “That allows detection of all of the new generation and future generation threats that have moved out of the typical electronic spectrum” of the past.

He added that the system “is needed on fourth-generation fighters against near-peer threats out there now, and Poland, more than any other country, knows [those threats] are on the doorstep.”

As it happens, IVEWS was formally cleared today to begin US Air Force F-16 flight testing, after three years of system level and anechoic chamber testing, mainly out of the Joint Preflight Integration of Munitions and Electronic Sensors (J-PRIMES) facility. Blanks claimed that based on those sorts of tests, which also included interference tests, IVEWS was credited with a “98 percent success rate.”

James Ryan, director of business development at L3Harris, said “a lot of different solutions are currently in play, [and] ours [Viper Shield] is the most mature of the group.” He stressed the system is the “only fully funded solution that is currently in production, and we’re looking forward to the selection [decision] from Poland.”

EXCLUSIVE: US giving Poland another $2B to buy American-made weapons

Viper Shield is an all-digital EW suite for the F-16 that, according to L3Harris company literature, offers “enhanced system performance, a smaller form factor, reduced weight and easier future upgrades.”

Ryan said Viper Shield meets all technical requirements set out by Warsaw and has been previously ordered by “multiple” export orders.

At a platform level, Poland has still to define the scope of the F-16 upgrade, but various reports in February said that it is preparing to strike an agreement with the US government. Northrop’s Blanks said that Warsaw had initially evaluated other EW solutions, but it has since “narrowed” the competitive field to IVEWS and Viper Shield. (Source: Breaking Defense.com)

 

04 Sep 24. Asia-Pacific: New highly sophisticated malware points to risks stemming from Chinese-nexus groups. Earlier on 4 September, the cyber security company Trend Micro reported that the Chinese-nexus group ‘Earth Lusca’ is using a new highly sophisticated backdoor (‘KLTVdoor’), likely as part of an ongoing cyber operation. The malware provides Earth Lusca with full control over compromised systems, allowing the group to manipulate files, to execute commands and to scan open ports remotely. Additionally, KLTVdoor’s code and communication mechanisms are highly obfuscated, which is likely intended to evade detection and hinder malware analysis. Notably, KLTVdoor’s command-and-control (C2) infrastructure comprises over 50 servers, pointing to possible large-scale future operations, as well as possible shared ownership among other Chinese-affiliated actors. Furthermore, the operation has reportedly thus far only targeted a trading company based in China, indicating that the malware is possibly still in its development phase. Earth Lusca has previously targeted government, technology and telecommunications sectors (mostly in Asia), underscoring the elevated security risks facing these sectors in the medium term. (Source: Sibylline)

 

02 Sep 24. Global: New ransomware operation points to elevated financial, disruption risks for organisations. On 2 September, international news outlets reported on the emergence of a new ransomware-as-a-service (RaaS) operation, ‘Cicada3301’, which has been targeting global VMware ESXi servers since June. The group reportedly first gains access to targeted organisations using stolen credentials for the remote access software ScreenConnect. Cicada3301 then encrypts a system’s files and downloads a ransom note, exfiltrating sensitive data from compromised systems prior to encryption in double extortion attacks. Cicada3301 also deletes the system’s data snapshots to further hinder data recovery, highlighting the group’s high sophistication and experience, as well as the widespread impact of its operations. Notably, the tactics, techniques and procedures (TTPs) on show resemble those of the defunct ransomware group ‘ALPHV’, which ceased operations in March. This suggests there is a possible overlap between the two groups. We assess this new RaaS operation will raise financial and disruption risks for global organisations in the short-to-medium term. (Source: Sibylline)

 

04 Sep 24. Northrop Grumman Corporation’s (NYSE: NOC) AN/ALQ-257 Integrated Viper Electronic Warfare Suite (IVEWS) has completed U.S. Air Force testing in the service’s Joint Preflight Integration of Munitions and Electronic Sensors (J-PRIMES) facility.

  • During a series of rigorous tests, AN/ALQ-257 IVEWS was subjected to accurate representations of complex radio frequency spectrum threats in the J-PRIMES anechoic chamber.
  • The system demonstrated the ability to detect, identify and counter advanced radio frequency threats while operating safely with other F-16 systems.
  • The successful completion of this regimen allows AN/ALQ-257 IVEWS to begin flight testing on Air Force F-16 aircraft.

Experts:       U.S. Air Force Colonel Michael Rigoni, director, F-16 International Electronic Warfare Systems: “J-PRIMES marks the culmination of three years of extensive U.S. government IVEWS system-level testing that’s encompassed multiple Integration Demonstrations and Applications Lab (IDAL) events, flight demonstration on a surrogate platform during NORTHERN LIGHTNING 2021, Laboratory Intelligent Validated Emulator (LIVE) closed-loop testing and full integration into the Hill Air Force Base F-16 Block 50 avionics system integration lab. I am optimistic the upcoming operational assessment flight test events will yield positive results and look forward to seeing this important capability continue to mature for U.S. and international F-16 operators around the world.”

James Conroy, vice president, navigation, targeting and survivability, Northrop Grumman: “Building on multiple IDAL events, flight demonstration on a surrogate platform and LIVE closed loop testing, this successful completion of J-PRIMES testing confirms the maturity of IVEWS and its readiness to protect the U.S. and international F-16 fleets.”

Details: The AN/ALQ-257 Integrated Viper Electronic Warfare Suite (IVEWS) is designed to give F-16 electronic warfare capabilities on a par with fifth-generation aircraft, significantly enhancing survivability for operations in contested and congested electromagnetic spectrum environments. Its ultra-wideband suite can detect, identify and counter advanced radio frequency threats, including millimeter wave systems. IVEWS’s full pulse-to-pulse interoperability with the AN/APG-83 SABR AESA radar provides capability without compromise. It was selected as the U.S. program of record for F-16 electronic warfare in 2019.

 

02 Sep 24. Global: Exploitation of zero-day vulnerability points to raised risks from North Korean-nexus groups. On 30 August, the technology company Microsoft reported that the North Korean-nexus group ‘Citrine Sleet’ exploited a zero-day vulnerability (CVE-2024-7971) to target financial and cryptocurrency organisations. The vulnerability affects Chrome browsers and enables threat actors to execute code remotely on compromised systems. Citrine Sleet possibly employed social engineering tactics to direct potential victims to a malicious actor-controlled domain. The group then exploited CVE-2024-7971, showcasing its remote code execution capabilities by deploying a rootkit on compromised systems. Notably, Citrine Sleet also deployed sandbox evasion code during execution to avoid detection by security mechanisms. The rootkit provides the group with prolonged access and control over compromised Windows operating systems, highlighting the elevated sophistication of the group’s tactics. Citrine Sleet is likely targeting financial institutions for illicit profit to bolster North Korea’s weapons and missiles programmes, thus sustaining elevated risks for global financial institutions in the long term. (Source: Sibylline)

 

30 Aug 24. Cyber Update Key points.

  • The exploitation of a zero-day vulnerability to infiltrate downstream customer networks will sustain elevated supply chain risks stemming from the Chinese state-sponsored group ‘Volt Typhoon’ (see Sibylline Cyber Daily Analytical Update – 27 August 2024 and our Technical analysis below).
  • The identification of a new backdoor, ‘HZ Rat’, points to elevated security risks for Chinese messaging platform users (see Sibylline Cyber Daily Analytical Update – 28 August 2024).
  • The ransomware group ‘BlackByte’ is exploiting a new software vulnerability, which will elevate security and financial risks for multiple sectors (see Sibylline Cyber Daily Analytical Update – 29 August 2024 and our Technical analysis below).
  • A new backdoor will increase espionage risks for global firms stemming from Iranian state-sponsored groups (see Sibylline Cyber Daily Analytical Update – 30 August 2024).

Technical analysis of weekly stories

The Chinese state-sponsored group Volt Typhoon has been exploiting a zero-day vulnerability (CVE-2024-39717) in the third-party security management platform Versa Directory since at least June. The group first obtains access to targeted systems via an internet exposed port used by a platform’s services. Volt Typhoon then exploits CVE-2024-39717 to deploy the custom ‘VersaMem’ web shell (disguised as a PNG image) onto compromised systems. VersaMem enables the threat actors to harvest the plaintext credentials of legitimate users via Versa’s authentication functionality, subsequently allowing Volt Typhoon to breach an organisation’s system. VersaMem is also stored and executed in the compromised system’s memory, thereby enhancing the threat actors’ ability to evade detection by traditional security tools. Notably, the threat actors primarily target internet and managed service providers (ISPs and MSPs) to widen their target pool by moving into downstream customer networks. Additionally, Volt Typhoon is only able to gain access to targeted systems that neglect to implement the vendor’s system-hardening and firewall guidelines, highlighting the importance of timely and strict security policies.

The cyber criminal group BlackByte is exploiting a VMware ESXi vulnerability (CVE-2024-37085) to deploy ransomware against manufacturing, transport, technology and public administration sectors. The threat actors infiltrate organisations via the legitimate login credentials for their virtual private network (VPN) services. Compromising VPN services notably allows the threat actors to access targeted systems through insecure third-party tools and to obfuscate their activity. This campaign marks a possible shift in their tactics, techniques and procedures (TTPs), as BlackByte typically exploits software vulnerabilities as initial attack vectors rather than using legitimate login credentials. Upon initial access, the threat actors hijack administrative-level accounts to create additional accounts on compromised ESXi hosts. BlackByte then exploits CVE-2024-37085 to bypass authentication processes and to establish elevated administrative privileges to modify configurations and access system data. The group subsequently deploys ransomware and the custom exfiltration tool ‘ExByte’ to encrypt and exfiltrate data. Notably, the ransomware is able to self-propagate within compromised systems as it contains stolen credentials in its code, highlighting the highly targeted nature of this malware. This further underscores the group’s rapid adaptability and high sophistication. BlackByte exploits CVE-2024-37085 within days of publication.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Routinely check for newly created user accounts and other abnormal files. Audit existing user accounts, often rotating credentials.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices; include personal devices connected to corporate networks or applications.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: Password spray attack

(Source: Sibylline)

 

30 Aug 24. Global: New malware highlights elevated espionage risks from Iranian state-sponsored groups. On 28 August, the technology company Microsoft reported that the Iranian state-sponsored group ‘Peach Sandstorm’ used a new custom backdoor (‘Tickler’) in several cyber espionage operations between April and July. Peach Sandstorm specifically targeted the education sector to acquire command-and-control (C2) infrastructure. It also targeted the government, satellite and defence sectors to gather strategic intelligence. The group used social engineering techniques and password spray attacks to gain access to targeted systems and to hijack Microsoft user accounts. Peach Sandstorm subsequently deployed the Tickler backdoor to establish persistence, to capture database information, to move laterally and to install remote management tools. Notably, Peach Sandstorm’s use of password spray attacks and new custom malware highlights the continuous development and sophistication of its capabilities. Another Iranian state-sponsored group, ‘Smoke Sandstorm’, also recently used similar tactics in its cyber operations, thus elevating the espionage risks facing the aforementioned global sectors from Iranian state-sponsored groups. (Source: Sibylline)

 

29 Aug 24. U.S. Intelligence Community Expands Private Sector Collaboration. The U.S. Intelligence Community (IC) is intensifying its efforts to collaborate with the private sector through a series of strategic initiatives aimed at enhancing national security capabilities. Director of National Intelligence (DNI) Avril Haines announced these measures during her address at the Intelligence and National Security Summit in Bethesda, Maryland, underscoring the growing need for intelligence agencies to access specialized expertise and technological innovations available in the private sector.

Haines emphasized the necessity for a “systemic, strategic, whole-of-IC approach” in fostering government-industry partnerships. This approach is driven by the recognition that private companies possess unique skills and knowledge in critical areas such as artificial intelligence, cybersecurity, space, and supply chain management of rare earth elements—domains where the government needs more in-house expertise. To facilitate this, the Office of the Director of National Intelligence (ODNI) has established an Office of Partnership Engagement, which will spearhead these collaborative efforts.

Key among the new initiatives is the revision of performance evaluations for intelligence officers to include objectives related to private sector engagement. This reflects a broader push to integrate private sector collaboration into the daily operations of intelligence agencies. Additionally, the ODNI is developing a curriculum focused on emerging technologies, which will train acquisition professionals on how to effectively leverage innovations from private firms.

The initiatives also include practical measures to improve information sharing between the intelligence community and private companies. For instance, the IC is working to downgrade certain classified information to make it accessible to private sector partners. A library of cleared intelligence products for the private sector is also being developed, mirroring successful models like the NSA’s Cybersecurity Collaboration Center, which facilitates information exchange on cyber threats.

Public-private partnerships have become increasingly critical since the September 11 attacks, with private firms often providing the technology and tools needed to counter threats. However, Haines acknowledged that these new efforts might face initial challenges, requiring patience and ongoing refinement. (Source: https://www.sofx.com/)

—————————————————————————————————————————————————————————————————————————————————————————————————————————————–

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

 

————————————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

August 30, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

———————————————————————————————————————————————————————————————————————————————————————————————————————————————-

27 Aug 24. Handheld Radio for Mission-Critical Applications Launched. TrellisWare launched its TW Shadow 750 radio, a rugged and highly integrated handheld solution to address mission-critical communications challenges, to the U.S. DoD market. TrellisWare Technologies, Inc. has launched the TW Shadow™ 750 radio (TW-750) to the U.S. Department of Defense (DoD) market at the AFCEA TechNet Conference in Augusta, August 20-22.

The TW-750 expands TrellisWare’s family of radios with a highly integrated handheld solution to address mission-critical communications challenges, putting Mobile Ad Hoc Networking (MANET) capability directly in the users’ hands for simplified operation.

The multi-waveform TW-750 radio operates the industry-leading TSM® Mobile Ad Hoc Networking (MANET) waveform, the modern electronic counter-countermeasure (ECCM) Katana™ narrowband MANET waveform, and the Narrowband Line-of-Sight (NB LOS) waveform to provide maximum reliability, resiliency, scalability, security, and interoperability.

The TW-750 was designed to deliver next-generation capabilities at a competitive price point without sacrificing performance or customization.

TrellisWare is a leader in highly advanced algorithms, waveforms, and communications systems that range from small form factor radio products to fully integrated solutions.

The TrellisWare® TSM® and Katana™ waveforms are incorporated into a wide range of systems, including TrellisWare radios and trusted industry partner radios. TrellisWare is delivering the next generation of communications for public safety, defense, uncrewed, and commercial markets.

Reid Kinder, senior director of DoD business development, said, “The TW-750 ensures ease of use and cost-effective access to our leading TSM and Katana waveforms down to the lowest levels of a tactical formation.

“The TW-750 radio is customer-informed, tightly integrated, and purposely built to deliver assured voice and critical data communications to the most valuable warfighters.”

Larry Greenstein, senior product manager, said, “We are excited to add the TW-750 radio to the TrellisWare TW Shadow product family to meet the growing needs of our diverse military and public safety users worldwide who do not want to compromise features or communications capability.” (Source: https://www.defenseadvancement.com/)

 

28 Aug 24. TPG partners with Starlink rival for ‘straight-to-mobile’ service. The agreement will, uniquely, not require customers to obtain any specific hardware and will instead work on all compatible handsets.

TPG told The Australian the service would eventually provide “near-100 per cent mobile coverage” across the country, eliminating “dead zones” in remote areas.

However, unlike its larger telco rival, TPG has agreed to work with Starlink-rival Lynk Global, which uses a smaller number of LEO satellites than its SpaceX-owned opposition.

TPG chief technology officer Giovanni Chiarelli said Australia’s vast geography and sparse population pose unique challenges for deploying commercially viable mobile networks in remote communities.

“Combining innovative technologies like sat2phone with our mobile network would bring much needed connectivity to those living and working in remote and rural locations and could play a critical role in delivering lifesaving services,” he said.

Lynx’s service provides emergency alerts and texts worldwide, but it’s currently testing SMS in Australia with a view to eventually introducing voice and data services. The telco, Australia’s third largest, hopes to start a text message trial in 2025.

Lynk last launched two satellites, which it dubs cell towers in space, on SpaceX’s Transporter–10 rideshare mission in March. It’s now working with “40 plus mobile network operator partners” globally.

The ‘straight-to-mobile’ plans are one of several innovative new services that have launched or are soon to begin in Australia.

Last month, for example, Starlink launched a portable satellite dish that allows users to access reliable internet on the go.

The device, which resembles a large laptop, works like a traditional dongle but allows users to go online without needing to be within the range of a phone mast.

The new mini dish costs $799 and can be paired with two plans: “Mobile Regional”, which costs $174 per month and offers unlimited mobile data, or “Mini Roam”, which costs $80 per month for 50GB of data.

Crucially, the plan can be paused or unpaused anytime, opening it up to hikers and travellers who only want to use it for limited periods of the year.

Starlink only launched in Australia in 2021 but was previously only available via a permanent, fixed connection.

There are currently thought to be more than 6,000 Starlink satellites in orbit, though the company eventually hopes it can support more than 40,000.

Finally, Telstra became the first of the big two telcos this year to make Starlink available to residential homes in remote areas.

Previously, access to the SpaceX-backed internet service was only available through Starlink directly or via smaller third-party providers such as Sky Mesh, Activ8me, or Ipstar.

However, the firm has now opened the service up to home users after “months of comprehensive testing”, with typical peak speeds of 50Mbps download and 10Mbps upload. It follows the telco releasing it to business customers late last year. (Source: Space Connect)

 

27 Aug 24. US Navy’s new EW jammer variant goes operational in Middle East. The new variant of the US Navy’s AN/ALQ-249(V)1 Next Generation Jammer Mid-Band (NGJ-MB) electronic warfare (EW) pod is now operational, fielded aboard US fighter jets deployed in the Middle East.

EA-18G Growler aircraft, outfitted with the new NGJ-MB variant, were deployed aboard the USS Abraham Lincoln Carrier Strike Group (CSG). The CSG was recently tasked to the Middle East by the US Department of Defense amid growing tensions between Iran and Israel.

This is the first operational deployment of the NGJ-MB pods, which have yet to be tested in actual combat. The system could be pivotal in mitigating possible attacks by Iran on Israel or US assets in the region.

The EA-18G Growler is a two-seat, electronic attack variant of the F/A-18E/F Super Hornet, which can provide stand-off, escort, and self-protection jamming. The Growlers attached to the CSG were part of Electronic Attack Squadron (VAQ) 133.

The NGJ architecture is a pod-mounted jamming capability that is designed to augment and replace the legacy AN/ALQ-99 Tactical Jamming System (TJS) onboard the EA-18G electronic attack aircraft. The NGJ-MB is a fully self-sustained pod that generates its own power, cooling, and transmission and comprises an excitation chain that would include direct digital synthesis, high-speed memory (HSM)/digital radio frequency (RF) memory (DRFM), and field programmable gate array (FPGA) technology.

“NGJ provides enhanced airborne electronic attack (AEA) capabilities to disrupt, deny, and degrade enemy air defence and ground communication systems. It brings increased power and jamming capability at longer ranges,” according to a statement by Naval Air Systems Command (NAVAIR). (Source: Janes)

 

27 Aug 24. Hughes Network Systems and Boost Mobile, EchoStar (Nasdaq: SATS) companies, successfully demonstrated optimized, multi-transport network management for the U.S. Navy. The demonstration, which took place earlier this year, tested remote network orchestration, wide area network (WAN) resiliency, and secure Radio Access Network (RAN) sharing between standalone Private 5G networks operating at the U.S. Navy Air Station, Whidbey Island, Washington, and a base in Hawaii.

Hughes collaborated with Boost Mobile, both of which are part of the EchoStar family of companies. Boost Mobile’s innovative Open-RAN-based 5G networking technologies for US-wide public network deployment experience provided a rich heritage for the standalone, secure 5G networks on each base. In addition, Hughes implemented its intelligent network orchestration capabilities, Smart Network Edge (SNE) mission-planning technology, and Network Management System (NMS). Together, these technologies maintained communications in contested and congested environments.

“The combined team successfully demonstrated a flexible and resilient mission network that dynamically switched communications paths to ensure uninterrupted situational awareness,” said Dr. Rajeev Gopal, vice president of Advanced Programs for the Defense Division at Hughes. “We are ready to implement smart network orchestration and secure Private 5G networks, for the U.S. Department of Defense to ensure that users have critical command and control information when they need it most, even in disrupted, occasionally disconnected, and low-bandwidth conditions.”

The network supported Automated PACE planning, leveraging the powerful Hughes NMS and SNE technologies that dynamically utilize multiple transport paths to deliver situational awareness. These advanced automation techniques optimize capacity, QoS, and various time/space-based resource commitments to speed up changes and access to SATCOM resources. With command-in-the-loop, the Hughes technology can process new service requests in less than 5 seconds to accommodate new threats in the theatre and automatically distribute information across paths orchestrated by Hughes SNE. The NMS and SNE are critical enablers for state-of-the-art resilient communications utilizing multiple diverse transports, including GEO, MEO, LEO, and 5G systems.

The demonstration confirmed that the EchoStar Private 5G ORAN network can maintain secure connectivity for devices and applications when users travel outside the naval base. This capability supports a concept of operations where a device running on the Whidbey Island NAS 5G network can travel to another location and still securely access applications that reside at Whidbey Island. The Navy can use this secure internet access for missions requiring a user to relocate from one base to another.

To learn more about how Hughes delivers secure communications, anytime, anywhere, please visit the Hughes website.

About EchoStar

EchoStar Corporation (Nasdaq: SATS) is a premier provider of technology, networking services, television entertainment and connectivity, offering consumer, enterprise, operator and government solutions worldwide under its EchoStar®, Boost Mobile®, Boost Infinite, Sling TV, DISH TV, Hughes®, Hughesnet®, HughesON™, and JUPITER™ brands. In Europe, EchoStar operates under its EchoStar Mobile Limited subsidiary and in Australia, the company operates as EchoStar Global Australia. For more information, visit www.echostar.com and follow EchoStar on X (Twitter) and LinkedIn.

About Boost Mobile

Boost Mobile offers the best value in wireless with simple, flexible and transparent plans starting at $25 for unlimited 5G. Boost’s nationwide cloud-native O-RAN 5G network delivers lightning-fast speeds, reliability and coverage on the latest 5G devices. Customers enjoy no annual service contracts and the freedom to upgrade their devices anytime without a trade-in. Experience Boost Mobile’s risk-free 30-day money-back guarantee and learn more about our services on Facebook, Instagram, and YouTube. Boost Mobile is the nation’s newest nationwide mobile carrier in the U.S. and a brand under EchoStar Corporation (NASDAQ: SATS).

About Hughes

Hughes Network Systems, LLC, an EchoStar (Nasdaq: SATS) company, provides broadband equipment and services; managed services featuring smart, software-defined networking; and end-to-end network operation for ms of consumers, businesses, governments, airlines, and communities worldwide. The Hughes flagship internet service, Hughesnet®, connects ms of people across the Americas, and the Hughes JUPITER™ System powers internet access for tens of ms more worldwide. Hughes supplies more than half the global satellite terminal market to leading satellite operators, mobile network operators and military customers. Hughes products and services have helped bring in-flight video and broadband to thousands of aircraft for over twenty years. A managed network services provider, Hughes supports approximately half a m enterprise sites with its HughesON™ portfolio of wired and wireless solutions. To learn more, visit https://www.hughes.com/ or follow HughesConnects on Twitter and LinkedIn. (Source: PR Newswire)

 

27 Aug 24. US Army announced radio frequency pilot in May after lessons learned from Russia’s invasion of Ukraine. The Army’s radio, which officially began in July, is off to a good start, and the service is aiming to bring industry more into the fold in the coming weeks, according to Steven Rehn, Army Cyber Command chief technology officer and director of the program.

The pilot, previously called the electronic warfare data pilot, is going “so far so good,” in its initial testing phase, otherwise known as Phase 1, Rehn told Breaking Defense after a Thursday speech at the TechNet conference in Augusta. The service’s radio frequency pilot was created with the goal to allow the Army to operate in the electromagnetic spectrum (EMS) with “agility to maneuver and deliver effects at the operational pace,” according to an Armed Forces Communications & Electronics Association handout.

The service announced the pilot in May after learning how Russia’s invasion of Ukraine has changed the status of electronic warfare. This is due to a number of factors, Rehn said, including rapid technological growth, an increase in threat actors with a lower barrier of entry and the increased ability to be seen in the EMS.

“That ability to be seen in the EMS is lethal. Lethal from a standpoint [of], if I can see it, I can kill it,” Rehn said. “[Do] the capabilities we have today allow a unit to understand their EMS posture, not just right now in the moment, but over time, to be able to also do trend analysis?”

Rehn also explained the importance of being able to maneuver quickly within the EMS, especially being able to change a soldier’s signature, which he called on industry to help fix.

“So as I’m moving out on a movement to contact, if I were to take a snapshot of it, every time I did a movement to contact, do I look the same? Is it a signature thing? Are there signatures inside of there that, if somebody was just watching EMS spectrum, and they knew that when I do certain signatures in there, I’m doing certain events?” Rehn asked.

“How do we change? How do we inform the commanders to understand that? So then they can potentially do different [movement to contact] procedures to understand how to how to get better survivability.”

Rehn said that the pilot will enter into Phase 2 by September or October, at which point he will call on industry partners to help develop technologies for the pilot. Right now, during Phase 1, the service is gathering data to determine what it needs to quickly reprogram systems while on the battlefield.

“That’s the ask for the vendors is, as we go forward in about the September, October time frame through our research lab — the Army Cyber Technology and Innovation Center — we’ll put a call out and say, ‘Hey, [these are] the challenges. What are the things we should be thinking about that we’re not thinking about?” Rehn asked.

Rehn continued to expand on how industry partners can be of use in the pilot including: adopting a Modular Mission Payload (MMP) concept, identifying challenges with MMP concepts and supporting architecture, identifying areas that should be standardized, but are not yet and lastly identifying ways to create a radio frequency development ecosystem.

“If we set the right standards and the data, and understand the data that needs to be associated with it, we can get there now talking with industry partners,” Rehn said. “So for those in the industry, I would argue that we need your help.”  (Source: Breaking Defense.com)

 

27 Aug 24. US: Exploitation of zero-day vulnerability by Chinese-backed group highlights risks to supply chain. On 26 August, the technology company Lumen Technologies reported that the Chinese state-sponsored group ‘Volt Typhoon’ has been exploiting a zero-day vulnerability (CVE-2024-39717) for several months to target US-based internet and managed services providers, as well as the IT sector more broadly. The vulnerability affects the security management platform Versa Directory and enables threat actors to gain access to targeted systems via an exposed internet-connected management port. This subsequently allows Volt Typhoon to install malware and harvest credentials from infected organisations to move into downstream customer networks. Additionally, the vulnerability was first exploited in early June, highlighting the likelihood of undetected long-term infections. CVE-2024-39717 only impacts customers who have not implemented 2015 and 2017 system-hardening and firewall guidelines, underscoring the importance of strict security practices. Chinese state-sponsored groups routinely exploit software vulnerabilities to compromise strategic targets in the supply chain. We assess this will sustain elevated security and third-party risks, especially as the campaign is likely ongoing. (Source: Sibylline)

 

23 Aug 24. Cyber Update Technical analysis of weekly stories. The advanced persistent threat (APT) group ‘BlindEagle’ has targeted entities in Latin America in financially motivated and espionage campaigns since at least 2018. The group obtains access to targeted systems via phishing emails where the threat actors impersonate governmental, financial and banking institutions. Specifically, they lure potential victims with a fake issue reportedly requiring immediate action, thus tricking them into clicking on a malicious link. The user is then redirected to an actor-controlled website where malicious payloads are downloaded via a multi-stage process. The group often uses links with geographical detection and redirection capabilities to evade detection. Victims are automatically redirected to the spoofed organisation’s legitimate website if an unexpected connection is detected from a country outside the group’s target pool to prevent detection by security analysts. BlindEagle typically uses custom malware droppers, while simultaneously adopting open-source remote access trojans (RATs). The group also modifies the RATs to suit campaign objectives, underscoring its rapid adaptability and high sophistication. Notably, BlindEagle often uses process injection techniques to execute RAT payloads, hiding within legitimate native processes to obfuscate its activity and prolong detection evasion.

Unnamed cyber criminals have implemented a new phishing technique to target Android and iOS mobile users; it has been in use since November 2023. The campaign starts via smishing, vishing (voice call phishing) and malvertising. Threat actors send potential victims a link pertaining to an update for their mobile banking application. Targets are then redirected to a phishing page mimicking the legitimate application and/or banking service to download a fraudulent progressive web application (PWA). PWAs are delivered through the web and enable threat actors to create malicious fake banking applications while bypassing existing application security. Furthermore, the malicious actors can operate in any operating system using the same codebase, allowing them to reach a wider target pool. Upon installation, victims are prompted to enter their login credentials which are subsequently sent to the actors’ command-and-control (C2) infrastructure. Notably, the malicious PWAs communicated with two distinct C2 infrastructures, suggesting that two separate cyber criminal groups might be conducting similar operations.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices; include personal devices connected to corporate networks or applications.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: Process injection. (Source: Sibylline)

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

 

————————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

August 23, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

—————————————————————————————————————————————————————————————————————————————————————————————————————————————–

23 Aug 24. Global: Evolving TTPs will sustain elevated espionage risks from Chinese state-sponsored groups. On 22 August, the cyber security company Sygnia reported that the Chinese state-sponsored group ‘Velvet Ant’ exploited a zero-day vulnerability (CVE-2024-20399) to inject malware into compromised Cisco Nexus switches. The vulnerability enables the group to access its victims’ main operating systems, facilitating the injection of malicious code into compromised systems while bypassing native security mechanisms. The group subsequently deployed new malware to inject arbitrary code and to exfiltrate data, likely for espionage purposes. Notably, this operation signals a shift in Velvet Ant’s tactics, techniques and procedures (TTPs) as it migrates from infecting endpoints and legacy servers. Additionally, the group was able to maintain persistence within compromised systems for several years before detection, underscoring the high sophistication of its evasion capabilities. Chinese state-sponsored groups routinely exploit software vulnerabilities and develop new tactics as they seek to bolster their security and economic posture in the face of their adversaries, sustaining espionage and third-party risks for global firms. (Source: Sibylline)

 

22 Aug 24. US Army not sold on new approach to radio acquisition. An Army pilot program testing a new acquisition strategy to purchase radios as a service has seen “mixed results,” according to one official.

The Army kicked off the effort late last year and this spring issued a request for information from industry about the project, which would be a departure from the service’s traditional approach to buying and sustaining radios.

Mark Kitz, the Army’s program executive officer for tactical command, control and communications, said Wednesday the service hasn’t determined how to proceed with the effort.

“I think we’re still struggling with, what are the upfront investments the Army needs to make, and then what’s the return on investment for you, industry, with radio as a service,” he said during a presentation at AFCEA’s TechNet conference in Augusta, Georgia. “I think lukewarm would be my assessment right now.”

The Army initiated the pilot as a cost-effective option for modernizing its hundreds of thousands of radios — an inventory too large to quickly upgrade.

The model would operate like a subscription service in which the Army leases capability when it needs it rather than buying and maintaining radios outright as the service does today.

Vendors would provide a limited number of radios as needed for training and operations and then would upgrade their software to match modernization requirements.

Officials have varying views on the prospects of the program, meanwhile. Army Undersecretary Gabe Camarillo, for example, has said he finds the idea compelling, while Kits said he remains committed to the effort and “believes we’re going to get a strong return on investment.”

“I don’t necessarily see that from the pilot, and so I think that’s going to be a continued conversation with industry,” he said.

Kitz was optimistic, however, about two other “as-a-service” pilots for satellite communications and IT. He said the Army is committed to making the pilot work for SATCOM and expects the service to begin a pilot for IT at the edge over the next 18 months. (Source: Defense News Early Bird/Defense News)

 

22 Aug 24. Global: New tactics by North Korean nexus group will sustain elevated security, espionage risks. On 21 August, the cyber security company Cisco Talos disclosed that the North Korean nexus actor ‘UAT-5394’ is employing a new custom remote access trojan (RAT), ‘MoonPeak’. The malware is reportedly an evolution of the open source RAT ‘XenoRAT’, and wields more sophisticated detection-evasion techniques. UAT-5394 shifted from hosting its servers in third-party cloud infrastructure to using its own infrastructure to prevent possible shutdowns by cloud providers. This highlights the evolution of the group’s tactics, techniques and procedures (TTPs), as well as the likely expansion of its operations. Notably, UAT-5394’s modus operandi resembles that of the North Korean state-sponsored group ‘Kimsuky’, suggesting that there is possibly an overlap between the two groups and their TTPs. North Korean nexus groups typically target organisations in order to steal intellectual property and other sensitive information to bolster their own research and development (R&D) programmes, elevating the security and espionage risks facing global firms. (Source: Sibylline)

 

20 Aug 24. Successful Test Flights of Rugged Airborne Radio & Antenna.

Starlink and uAvionix’s muLTElink airborne radio has been successfully integrated in recent test flights, aiming to achieve advanced LEO-satellite-based C2 communications for sUAS. Since the successful completion of test flights integrating Starlink and uAvionix’s muLTElink airborne radio, uAvionix has made a significant step forward in its integration efforts.

At the start of 2023, uAvionix began testing the first versions of Starlink’s antennas and connectivity, exploring the possibilities for advanced LEO-satellite-based command and control (C2) communications for small unmanned aerial systems (sUAS).

The Starlink results were encouraging, and uAvionix has continued its efforts throughout this past year as a leading provider of airborne radios and Command, Navigation, and Surveillance technologies for sUAS.

The integration work continues the company’s commitment to offering the best possible connectivity solutions for small UAS, and the recent flight tests demonstrated unprecedented connectivity for both C2 and payload communications, delivering data rates in the megabits per second with latencies below 100 milliseconds.

This milestone is an extension of uAvionix’s integration with L-band satellite connectivity solutions that have been implemented across various platforms to ensure assured C2 communications.

uAvionix has consistently promoted multi-modal connectivity solutions to support both assured C2 and high-bandwidth payload communications. By integrating various connectivity methods, the company provides path and frequency diversity, ensuring reliable operation everywhere.

By introducing Starlink to the company’s connectivity suite, uAvionix will enhance its capability to provide both assured C2 and high-bandwidth payload communications, such as streaming video or ISR data, back to the operator. (Source: https://www.defenseadvancement.com/)

 

21 Aug 24. DISA eyes more vendors, faster contracts for joint cloud successor. As the Pentagon maps out the next phase of the Joint Warfighting Cloud Capability, officials are prioritizing speed, a streamlined contracting process and a broader vendor pool, according to the director of the Defense Information Systems Agency.

The Defense Department in 2022 awarded contracts to Amazon Web Services, Microsoft, Oracle and Google to provide cloud computing, storage and other services through the enterprise cloud contract known as JWCC. Under the arrangement, the companies compete for task orders worth up to $9 bn through June 2028.

JWCC is viewed as a key component of the department’s Combined Joint All-Domain Command and Control initiative, with the military services directed to prioritize using the enterprise contract. DISA Director Lt. Gen. Robert Skinner, whose agency manages the effort, said Tuesday that all four services are taking advantage of the program and, to date, the department has awarded $996 m in contracts with another $20 m in the pipeline.

Less than two years into that effort, officials have already begun to plan for the program’s next iteration. Former Pentagon Chief Information Officer John Sherman revealed in December that the work was underway, but offered few details on what changes it could bring.

Speaking at the AFCEA TechNet conference in Augusta, Georgia, Skinner said the planning work for what he called JWCC Next is in its early days, but opportunities have already emerged to improve the capability.

He highlighted three early focus areas for the effort: improving speed to contract, increasing the number of companies and bringing on more capabilities like AI.

Skinner said that while the JWCC process is already moving faster than other traditional programs — awarding contracts within weeks of releasing a task order — DISA is looking at ways to make the process more efficient.

JWCC is the successor to a failed Pentagon cloud effort known as the Joint Enterprise Defense Infrastructure program. The department canceled the effort in 2021 after allegations of political interference.

Beyond JWCC, Skinner highlighted progress on an effort known as DODNET, a secure network for agencies outside of the military departments, including DISA and the Defense Technical Information Center. The system will replace multiple stovepiped, legacy networks with a more modernized capability.

DISA has onboarded about 32,000 users to DODNET and in October will begin a six- to nine-month push to bring on another 100,000 personnel, Skinner said. Those new users will come from multiple organizations including the Defense Contract Audit Agency, the Defense Contract Management Agency and the Defense Finance and Accounting Service. (Source: Defense News)

 

21 Aug 24. Military ‘silent hangar’ to help protect against foreign GPS jamming. A new test facility, one of the largest in Europe, will help military kit to be better protected from attempts to jam GPS devices.

Aircraft inside current anti-jamming facility. Credit: Qinetiq

The facility will provide a key capability to develop UK assets that can perform in the harshest electromagnetic environments on operations.

Under the new £20m contract, QinetiQ will build a radio frequency, anti-jamming test facility at the Ministry of Defence’s Boscombe Down site in Wiltshire.

The ‘silent hangar’ will be large enough to fit some of the biggest military assets, including Protector drones, Chinook helicopters, and F-35 fighter jets – a far greater capacity than existing UK facilities.

Due to open in 2026, the anechoic hangar creates the perfect environment to test the integrity of the UK’s military equipment. The hangar also prevents testing affecting other users, such as the emergency services and air traffic control.

The facility will support new roles over the next two years for the local area around Boscombe Down, further enhancing the UK’s pool of electromagnetic expertise, and skilled technical jobs.

It will also offer a range of opportunities beyond defence, to wider government, industry and to critical national infrastructure.

Minister for Defence Procurement and Industry, Maria Eagle, said:

Hostile threats jamming GPS to disorientate military equipment has become increasingly common.

This cutting-edge test facility will help us eliminate vulnerabilities from our platforms, protect our national security and keep our Armed Forces better protected on global deployments.

It will be one of the largest facilities in Europe and roughly the size of an aircraft hangar, simulating hostile environments and putting the UK’s most advanced military equipment through its paces.

The specialist hangar will reduce reflections, echoes or the escape of radio-frequency waves. The GPS simulators and threat emulators inside the chamber will provide the ability for the UK to create a number of hostile environments to test how well equipment can withstand jamming, and other threats, that attempt to confuse or disrupt military assets.

Will Blamey, Chief Executive, UK Defence, QinetiQ, said: “On an increasingly digital battlefield, the debilitating effects of electronic warfare are a persistent threat.  The testing we will conduct using this new facility will be integral to strengthening the resilience of military equipment, which in turn enhances the safety and security of our Armed Forces and the United Kingdom.”

Richard Bloomfield, Head of Electronic Warfare (CBRN) Space at Defence Equipment & Support, said: “The subject of GPS jamming has been well documented in the press, making this new facility all the more vital to help us keep our armed forces safe while protecting the nation and our allies.  Not only will this be one of the largest such chambers in Europe, but it will also be one of the most up to date and high-tech in the world, where hostile environments can be safely recreated to put military equipment, such as fighter jets and drones, through testing to understand their performance in challenging environments representing the many external threats that may be faced.” (Source: https://www.gov.uk/)

 

20 Aug 24. Cuashub.com said today that NSWC Crane hosts NATO’s electronic warfare exercise. The Naval Surface Warfare Center, Crane Division (NSWC Crane), played host to the 2024 Thor’s Hammer NATO military exercise in May and June, marking the first time this biennial electronic warfare event has been held in the United States. The exercise, which took place at Camp Atterbury and Muscatatuck Urban Training Center in Indiana, focused on testing the compatibility and effectiveness of Counter-Radio Controlled Improvised Explosive Devices (C-RCIED) and Counter-Small Unmanned Aerial Systems (C-sUAS).

Thor’s Hammer, which began in 2015 and has previously been held in Norway, Sweden and Australia, is designed to assess and improve the interoperability of electronic countermeasures (ECM) systems across NATO member states. The 2024 iteration of the exercise was especially significant as it provided the first opportunity for testing in an urban environment, offering a more realistic simulation of operational battlefield conditions.

“One of the best aspects about picking NSWC Crane is that they have worked on their test infrastructure over the years,” said Michael Alperi, Deputy Program Manager of Expeditionary Missions Program Office and Chairman of NATO Subgroup One. “Camp Atterbury, and specifically Muscatatuck Urban Training Center, provide the first opportunity for countries to test in an urban environment. This is the most realistic test we’ve ever done since starting the event in 2015. This application of testing allows us to really understand how our systems work in real operational battle.”

The exercise at Camp Atterbury focused on enhancing the effectiveness of systems against small UAS and IED threats, while the Muscatatuck Urban Training Center facilitated simultaneous testing in a complex urban environment. This setting enabled better collaboration among NATO partners and provided insights into optimising the deployment of diverse ECM systems.

“Thor’s Hammer presents the opportunity to understand how systems will behave when operating together,” said Thomas Talbert, Trial Manager for the 2024 exercise and an NSWC Crane employee. “The understanding gained concerning the compatibility and interoperability of the multiple nations’ systems has saved lives and will continue to save lives into the future. The ability to collaborate with other engineers, scientists, and operators allows for the improvement of each countries’ ECM systems performance.”

The need for international collaboration

With the threat of UAS and IEDs becoming increasingly prevalent, particularly in environments characterised by electronic warfare, the need for effective ECM de-confliction has become a crucial pre-deployment activity. Thor’s Hammer aims to address these challenges by allowing systems from different nations to be tested side by side, identifying opportunities for collaboration and performance enhancement in coalition settings.

Since its inception, Thor’s Hammer has grown significantly, with 14 nations participating in the 2024 exercise, up from just five in 2015. The event brought together more than 200 U.S. and foreign personnel, supported by Naval Sea Systems Command (NAVSEA), the U.S. Army, NSWC Crane, the Indiana National Guard and the State of Indiana.

“Indiana has been a fantastic partner for this event. The support we’ve received from the State of Indiana, the Indiana Economic Development Corporation, the Applied Research Institute Inc., and the National Guard has been incredible to help execute,” said Alperi.

“VIP Day highlighted the importance and mutual benefit of collaboration and how to apply data from standard testing at Camp Atterbury into an urban environment. Demonstrations were provided on the importance of ECM, Counter-Unmanned Aerial System (C-UAS) and the interoperability of systems. I’m sure the Thor’s Hammer Group will want to come back to Indiana again to conduct this type of testing in the near future.”

Dr. Angela Lewis, SES, the Technical Director at NSWC Crane, emphasised the significance of hosting such a high-profile event in Indiana. “It is great to be able to host such a significant event in Indiana. We can’t do it alone, it takes the NATO partners together to counter current threats. Thor’s Hammer 2024 provided real-world testing environments, enhanced warfighter capability and enabled improvement in warfighter safety.”

As Thor’s Hammer continues to evolve, the exercise remains focused on keeping pace with emerging threats and enhancing the capabilities of coalition forces.

“Thor’s Hammer allows the participating nations to test in an environment that is not available in their home country, test against different devices and collaborate in an atmosphere that occurs when personnel understand and trust each other’s skills and abilities,” Talbert noted.

Lyndon Theodore “LT” Snider, TH24 Focal Point Lead, underscored the importance of the event in strengthening international military cooperation:

“In a time when the criticality of international military cooperation cannot be overstated, Thor’s Hammer 2024 brought participating nations together to sharpen coalition capabilities in ground electronic warfare,” said Snider. “The event exemplified the cooperative spirit of partner nations who share the common goal of ensuring success on the battlefield and the survivability of troops and equipment.”

https://cuashub.com/en/content/nswc-crane-hosts-natos-electronic-warfare-exercise/?utm_campaign=C-UAS%20Hub%20General&utm_medium=email&_hsenc=p2ANqtz–Rs5ZRWRuCYnbe-mU4JrUkpkSZ4BjC5uV1Ce9FeE2oP_OucK3wqQq1gAiV4Oe-TeaBujVis6DI_7r8cKYHJefsKk-BwcFTqnC4_N_fAhEZL1uh_OM&_hsmi=320856988&utm_content=320856988&utm_source=hs_email (Source: https://cuashub.com/)

 

17 Aug 24. US Army’s first TITAN ground station prototype delivered at JBLM. The US Army’s need for a next generation intelligence, surveillance and reconnaissance system that rapidly processes sensor data from space, high altitude, aerial and terrestrial layers to provide real-time intelligence support for targeting and situational awareness is the impetus behind Project Manager Intelligence Systems and Analytics’ delivery of the Army’s first Tactical Intelligence Targeting Access Node, or TITAN, ground station prototype to Joint Base Lewis-McChord. This milestone marks a significant advancement in the Army’s capabilities to support multi-domain operations.

“Delivering the first TITAN prototype to JBLM is a pivotal step in enhancing our warfighters’ capabilities,” said Col. Chris Anderson, PM IS&A. “TITAN provides game-changing technologies that revolutionize how we collect, process, and disseminate intelligence across the battlefield, giving us a decisive edge.”

The system which leverages cutting-edge artificial intelligence and machine learning technologies is a ground station that will significantly reduce the sensor-to-shooter timeline, enabling faster and more accurate decision-making in complex operational environments. This delivery is part of a broader effort to equip the Army with advanced intelligence, surveillance and reconnaissance capabilities that support the rapid and effective execution of multi-domain operations.(Source: Paulo Dominonni via LinkedIn)

 

16 Aug 24. Russian defense plan kicks off separate AI development push. Russian officials have unveiled a new 10-year defense plan that includes a dedicated section on artificial intelligence, signaling Moscow’s focus on fielding autonomous weapons.

The move comes as Russia’s full-scale invasion of neighbor Ukraine has triggered an AI arms race on the battlefields there, especially in aerial and land drones, that analysts believe will shape future conflicts.

Elements of artificial intelligence have long been used in the Russian military industry, which is tightly controlled by the government. For example, there is a cluster of ground robot makers for the Marker, Platforma-M, Soratnik, Uran-9 vehicles that have supplied their wares for the war against Ukraine.

The country’s missile complex, too, has a history in infusing varying degrees of autonomy into targeting algorithms, perhaps most famously under the Perimeter program, a Soviet-era algorithm sequence for orchestrating a retaliatory nuclear strike.

Now, Russian officials are outfitting equipment returning for repairs from the Ukraine war with new technology, like remotely controlled fire modules, automatic target tracking, and propulsion systems, Vasily Elistratov, who oversees AI technology at the Russian Ministry of Defence, said at the Forum Army-2024 held here this month.

According to Deputy Prime Minister Dmitry Chernyshenko, the volume of the Russian AI market in 2023 reached almost 650 bn rubles, or $7.3 bn, an amount dwarfed by spending in the collective West on various outgrowths of the technology.

The dedicated AI budget line, for which officials have yet to give a number, is meant to help facilitate the transition into defense applications. A specialized department for the development of artificial intelligence is now in place in the Russian Defense Ministry, Chernyshenko announced.

For example, an AI control capability is now in development for the S-500 air-defense system, with threat assessment and damage prediction of a possible ballistic missile attack.

“The Russian defense industry will develop artificial intelligence and automated systems for products with high speed, where errors are not so critical,” said Sergei Smyslov, an independent defense industry expert based in Russia. With that in mind, potential applications include missile defense systems, artillery shells and aerial drones, he added.

Another area of AI use will be aviation and artillery to increase their efficiency, said Pavel Luzin, senior fellow at the Center for European Policy Analysis. Autonomous attack drones will likely remain commodities for a long time. As for autonomous ground robots, most of them will be used to supply troops on the battlefield and evacuate the wounded. AI will also be used in computer modeling of military campaigns during their preparation, Luzin said.

Russia is also going to use AI to improve the production processes of military products, with automatic quality checks that will trigger a manufacturing halt if they fail.

The Ministry of Defense by itself is unlikely to be able to effectively develop weapons with AI. There is a personnel problem in the scientific institutes of the Ministry of Defense, as the best graduates tend to go elsewhere.

Government officials have been building a development track in the government-owned industries instead, for example through Rostec companies and the Era Foundation, according to Luzin.

In early 2022, Rostec State Corporation’s Roselektronika Holding created the Artificial Intelligence Technologies Research Laboratory, which is engaged in research on the use of AI in radio communication systems, development in the field of virtual-reality technologies, big data technologies, and machine learning of deep neural networks.

The Era Foundation seeks to identify new technology among private companies and universities. In August, the foundation selected eight projects – including an unmanned boat, a remote-controlled turret, various drones, and a drone-detection system – that will receive funding to enter mass production. (Source: Defense News)

 

16 Aug 24. Second World War codebreaker Alan Turing’s ‘Delilah’ project papers at risk of leaving the UK. A temporary export bar has been placed on Alan Turing’s unpublished Second World War papers relating to his ‘Delilah’ project

  • The wartime documents are valued at £397,680
  • Export bar is to allow time for a UK institution to acquire the papers

An export bar has been placed on Alan Turing’s unpublished Second World War papers relating to the ‘Delilah’ project, which developed a portable encryption system for use in military operations.

The papers are valued at £397,680 (inclusive of VAT of £16,280 which can be reclaimed by an eligible institution), and are at risk of leaving the UK unless a domestic buyer can be found to acquire them.

Following Turing’s groundbreaking work on the Enigma machines at Bletchley Park, he began work on the ‘Delilah’ project at Hanslope Park to develop a portable encryption system or voice scrambler to protect military secrets in the field.

The papers consist of two bound notebooks and six separate gatherings of loose sheets. It comprises the notes of Alan Turing (1912-54) and Donald Bayley (1921-2020) relating to the World War Two project ‘Delilah’.

Unpublished evidence of Alan Turing’s work has rarely survived. Turing himself did not usually keep research notes, working drafts, or correspondence. This collection of papers dating from 1943 to 1945 sheds light on some of Turing’s most inventive, secret, and overlooked work.

Shortly after the Second World War ended in 1945, the Delilah machine was complete and Turing was able to demonstrate the working machine successfully, which showed a recording of one of Winston Churchill’s speeches, using a system which encrypted and decrypted communications from telephone and radio devices.

Alan Turing’s work prefigured our modern digital world and his work at Bletchley Park is seen as being crucial to ending the Second World War early and saving many lives.  His post-war work formed the foundations of computer science as we know it today.  Alan Turing was later awarded an OBE for his work during the Second World War.

Arts Minister Sir Chris Bryant said: “The Delilah project papers offer unique insights into the extraordinary mind of Alan Turing, who is famed for decoding the Enigma machines, being instrumental in ending the Second World War and saving many lives.  The British mathematician was central to the development of our modern digital world. It is right that a UK buyer has the opportunity to purchase these papers to give people the opportunity to continue to study and appreciate his work as an important part of our national story.”

The Minister’s decision follows the advice of the Reviewing Committee on the Export of Works of Art and Objects of Cultural Interest. The Committee found that the papers met the first and third Waverley criteria for their outstanding connection with our history and national life and their outstanding significance for the study of the history of computing, as well as Alan Turing’s mathematical knowledge of electrical engineering.

RCEWA Chair Andrew Hochhauser KC said: “The United Kingdom owes a debt of gratitude to Alan Turing. His extraordinary work on the Enigma project at Bletchley Park played a major part in winning World War Two and saved so many lives. Turing is closely connected to our modern digital world. He is generally accepted to be the founder of computer science and is also widely considered to be the father of Artificial Intelligence.”

The regard in which he is held is illustrated by the fact that in 2019 he was voted by a BBC audience the most iconic person of the twentieth century. He appears on the current £50 note. Explaining the Bank of England’s choice, the then Governor of the Bank of England, Mark Carney, observed, ‘All around us, his legacy continues to hold. Turing is a giant on whose shoulders so many now stand.’

The decision on the export licence application for the papers will be deferred for a period ending on 15 November 2024 (inclusive). At the end of the first deferral period owners will have a consideration period of 15 Business Days to consider any offer(s) to purchase the papers at the recommended price of £397,680 (inclusive of VAT of £16,280 which can be reclaimed by an eligible institution). The second deferral period will commence following the signing of an Option Agreement and will last for four months.

  1. Organisations or individuals interested in purchasing the papers should contact the RCEWA on 02072680534 or .
  2. Details of the object are as follows: two bound notebooks and six separate gatherings of loose paper sheets. It comprises the papers of Alan Turing (1912-54) and Donald Bayley (1921-2020) relating to the World War Two project ‘Delilah’. The papers date principally from 1943 to 1945, with some later additions. The material is divided as follows: Laboratory notebook (Turing and Bayley) (70 folios; 4to; 258 x 204mm). Papers on the Bandwidth theorem (Turing) (2 folios; 4to; 289 x 220mm). ‘Red form’ notes: mathematical diagrams, calculations and explanations written on the reverse of wireless-telegraphy intercept forms (Turing and Bayley) (20 folios; frayed; 4to; 250 x 189mm). ‘Determination of cut-off volts’: mathematical calculations, written on reverse of a wireless-operator log sheet (Turing) (1 folio; frayed; 4to; 249 x 197mm). ‘Faltung’: notes on the mathematics of convolutions, with diagram of mushroom, on reverse of radio log sheet (Turing) (1 folio; frayed and creased; 4to; 262 x 195mm). Notebook of notes taken by Bayley at Turing’s lectures delivered at Hanslope Park (90 folios), followed by notes taken by Bayley at university (140 folios) (Bayley) (230 folios; 4to; 278 x 235mm). Notes on different electrical problems (Turing) (2 folios) and summary notes on topics covered in Turing’s lectures (Turing, Bayley, and unidentified) (11 folios) (13 folios; 4to; 288 x 215 mm), two foolscap folios (325 x 200mm) one folio (227 x 288mm). Notes on a mathematical problem (Turing) (2 folios; 288 x 215mm)
  3. Provenance: Donald Bayley, thence by descent; sold at Bonham’s 14 November 2023
  4. The Reviewing Committee on the Export of Works of Art and Objects of Cultural Interest is an independent body, serviced by Arts Council England (ACE), which advises the Secretary of State for Culture, Media and Sport on whether a cultural object, intended for export, is of national importance under specified criteria. (Source: https://www.gov.uk/)

—————————————————————————————————————————————————————————————————————————————————————————————————————————————–

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

 

—————————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

August 16, 2024 by

 

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————————————————————————————————————————————————————————————————————————————————————————–

15 Aug 24. The members of the research and business consortium led by Bittium Wireless Ltd, a subsidiary of Bittium Corporation, have signed a framework agreement as part of the indirect industrial cooperation program related to the procurement of F-35 fighter jets with manufacturer Lockheed Martin. In the three-year project, the members of the consortium and Lockheed Martin will jointly develop methods and capabilities for cyber situational awareness. The other members of the Bittium-led consortium are VTT Technical Research Centre of Finland Ltd and Huld Oy, which offers technological solutions for the space industry, among other things. The agreement applies to the years 2024–2026 and its total value is approximately USD 3.8 m distributed among the consortium member companies in proportion to the amount of work done.

The goal of the project is to develop cyber capabilities for constantly changing defense and security. One example of this is developing the ability to observe and identify different phenomena, which affects cyber resilience of the tactical network and the creation of situational awareness. The project will be used to develop the survivability of Bittium’s Tactical Wireless IP Network™ (TAC WIN) and Bittium Tough SDR™ radios. The Finnish Defence Forces will also benefit from the cooperation, as the performance of the products they use will be improved with the help of new functionalities.

“The new development project continues the successfully started cooperation between the consortium and Lockheed Martin. This development project focusing on cyber security of tactical networks further strengthens the cyber resilience of our tactical communications systems to meet the demanding requirements of the battlefield,” says Tommi Kangas, Senior Vice President, Defense & Security Business Segment.

Through indirect industrial cooperation projects, Lockheed Martin builds industry partnerships with indigenous companies, which offer opportunities to develop and promote global cooperation far into the future.

 

14 Aug 24. Ultra Intelligence & Communications successfully participated in the NATO-led Coalition Warrior Interoperability Exploration, Experimentation, Examination Exercise (CWIX) in Bydgoszcz, Poland. The exercise provides bilateral technical testing and testing of fielded, developmental and experimental systems in the context of a coalition scenario.

As part of the Marine Corps Forces Europe and Africa (MARFOREUR) team, Ultra I&C deployed its ADSI® system in a joint coalition environment. The deployment demonstrated key accomplishments through tactical data link compliance, Curser on Target (CoT) integration, CoT to Joint Range Extension Applications Protocol (JREAP-C) translation, JREAP-C forwarding and digital warfighting platform demonstration.

“By rapidly configuring TDL interfaces to multiple nations on the fly, ADSI demonstrated how it enables seamless forwarding and interoperability across coalition C2 systems and helps pave the way to meet CJADC2 goals for the U.S. and its partners,” said Bradford Powell, president of Ultra I&C’s C2IE division. “We remain committed to enhancing mission effectiveness and operational efficiency across multi-domain operations.”

Ultra I&C will begin incorporating feedback from the exercise as it continues to participate in future exercises with the U.S. Marine Corps and partners, furthering its commitment to continuous improvement and partnership.

“The responsiveness and partnership demonstrated by Ultra I&C were instrumental in achieving the objectives of CWIX and was imperative to achieving new milestones compared to previous exercises,” said MSgt. Larry Morales, operations and plans chief with MARFOR Europe and Africa. “The team’s ability to adapt quickly to our evolving requirements and provide real-time solutions significantly contributed to the overall success of the exercise. This collaboration exemplifies the kind of industry partnership that enhances our coalition interoperability efforts.”

As a collaborative Cooperative Research and Development Agreement (CRADA) partner with U.S. Marine Corps Tactical Systems Support Activity (MCTSSA), Ultra I&C is integral to the efforts dedicated to perfecting interoperability between NATO members and partner nations.

“Deployment of Ultra Intelligence & Communications products enabled successful demonstrations of service, joint, and mission partner capabilities,” said Thomas Johnson, senior principal engineer, USMC MCTSSA. “Their participation enabled demonstration of significant advancements in our data transfer and interoperability capabilities with NATO partners, representing a substantial improvement in our operational effectiveness.”

ADSI, the premiere Command and Control (C2) gateway, ensures seamless interoperability and enhanced mission effectiveness with best-in-class datalink translation and the largest number of datalinks and interfaces available in a single library. Integrated in over 35 countries at 2,500 sites around the globe, ADSI’s flexible design provides a common operating picture to coalition C2 systems. (Source: PR Newswire)

 

14 Aug 24. Global: China-backed actor expands operations, heightening espionage risks to global firms. On 14 August, international media sites reported that China-backed cyber actor ‘Earth Baku’ expanded its activities outside the Indo-Pacific region to include Africa, Europe, and the Middle East in 2022. In the group’s more recent operations, Earth Baku exploited vulnerable public-facing applications (such as Microsoft IIS servers) as initial attack vectors to deliver malware. The actors use new loader malware and a new backdoor, pointing to the group’s evolution and growing maturity. The group targeted Georgia, Germany, Italy, Qatar, Romania and the UAE, focusing on the education, healthcare, government, media and communications, technology and telecommunications sectors. Consequently, we assess the presence of elevated security and espionage risks. As Earth Baku is linked to the Chinese government, operations will likely continue against global targets in the long term as Beijing seeks to bolster its security and economic posture. (Source: Sibylline)

 

13 Aug 24. Soteria and Panther Enter into Strategic Partnership to Defend Clients from Cyber Threats. Soteria’s dedicated cybersecurity expertise combined with Panther’s cloud-native security platform provide organizations worldwide with 24×7 cybersecurity coverage.

Soteria, a leading cybersecurity services company, today announced a strategic partnership for its Managed Detection and Response line of business, partnering with next generation Security Information Event Management (SIEM) provider Panther.

Panther is a cloud-native SIEM that accelerates threat detection, response, and investigations to make security teams smarter and faster than adversaries. Soteria customers can now leverage the next generation capabilities of the Panther platform while offloading time and resource intensive security tasks to the cybersecurity expertise of Soteria’s Detection and Response Team.

“Soteria Defense Managed Detection and Response services protect organizations across the globe. Together, Soteria and Panther provide an easy path for customers to use their security data to take decisive action and reduce their cyber risk, 24 hours a day. Panther allows us to deliver a Managed SIEM solution in a way that aligns with our security values, and we are very excited to bring this to market,” said Paul Ihme, Co-Founder & Managing Principal at Soteria. “This partnership levels up our capabilities and in turn, our ability to deliver our mission– providing safe passage for our clients so they can remain focused on delivering their missions.”

Soteria is dedicated to improving cybersecurity outcomes, preventing cyber incidents before they happen, and providing organizations with business-critical cybersecurity services. Soteria Defense MDR is a leading cybersecurity monitoring and response service that defends clients from cyber-attack, spanning endpoints, cloud platforms, identity providers, and more.

Panther’s next-generation, cloud native SIEM platform delivers code-driven detection and response at petabyte scale without the overhead or cost of traditional SIEMs. Detections-as-code lets security teams code, test, and deploy detection rules in Python, using CI/CD for streamlined collaboration and enhanced reliability. This approach to detection engineering aligns directly with the approach and philosophy Soteria has helped pioneer.

Now businesses can prioritize the areas that matter most for their mission, using Panther as a cost-effective basis of their security program, and Soteria’s Managed Detection and Response service for 24×7 coverage with real-time response to cyberthreats.

“Panther welcomes Soteria into the strategic partnership family, where our combined efforts will help customers globally adopt our partnered solutions,” said Andrew Dooley, Head of Partnerships at Panther.

“Since day one, Soteria’s services capabilities, detection-as-code approach, and exceptional cybersecurity focus stood out as an ideal fit for our clients. We could not be happier to partner with Soteria and bring our enhanced capabilities to the wider market. The result is increased security coverage, reduced cyber risk, and clients avoiding the budget-busting that generally takes place with legacy SIEMs. Paul and the team at Soteria are champions of detection-as-code, and their approach to MDR is ideal for Panther and our customers.”

Panther’s mission is to make security monitoring fast, flexible, and scalable for all security teams. They are leading the evolution of security operations, helping security teams overcome the challenges of detection and response at scale.

Learn more about Soteria Defense Managed SIEM at its page on the Soteria website.

About Soteria

Soteria’s leadership and security professionals have held leading positions in private industries, state governments, and federal intelligence communities, having defended thousands of client environments and shaping deep expertise in cybersecurity. With this combination of technical expertise and industry-specific insight, Soteria provides tailored cybersecurity services spanning pre-breach consulting, incident response, and managed security services.

(Source: BUSINESS WIRE)

 

13 Aug 24. The MCS Group Announces RelativityOne Government Offering to Expand eDiscovery Solutions. The MCS Group, Inc., a leader in outsourcing solutions including eDiscovery, records retrieval, and management services, today announced it is expanding its offerings with the addition of Relativity’s FedRAMP-authorized, cloud-based eDiscovery solution for government agencies, RelativityOne Government. With RelativityOne Government, The MCS Group will be able to offer all the tools needed to handle FOIA requests, litigation, and investigations – from legal hold through production.

The MCS Group will leverage its existing workflows and eDiscovery expertise on RelativityOne Government to assist government entities with managing growing data volumes, sources, and types, and provide them with access to the same cutting-edge solutions available to private entities. With the release of Relativity aiR, government clients will have access to state-of-the-art generative AI tools and customizable workflows designed to empower government experts and reduce overall legal spend in discovery preparation.

Beyond traditional eDiscovery, The MCS Group excels developing customized solutions using Relativity’s existing architecture to solve complex problems for its customers. These customized solutions create new efficiencies for clients, allowing them to work confidently knowing their data is hosted entirely within a FedRAMP-certified environment.

With the secure and powerful RelativityOne Government product, The MCS Group will be able to further leverage its eDiscovery expertise to provide more value and better results for its public sector clients. RelativityOne Government is FedRAMP-authorized software secure from the ground up with proactive threat intelligence and 24/7 monitoring.

“We are excited to expand into the Government space with our eDiscovery solutions,” said Stephen Ehrlich, CIO of The MCS Group. “Our ability to assist clients at all levels with their eDiscovery workflows, data management and technology will be of great benefit to government entities, especially within the secure confines of RelativityOne Government.”

“The MCS Group continues to demonstrate their dedication to serving the varying technological needs of their clients with the addition of the RelativityOne Government solution to their vast range of offerings,” said Laurie Usewicz, Chief Partner Officer at Relativity. “We look forward to further supporting government agencies and organizations alongside MCS Group by providing tools to meet users’ growing data challenges.”

RelativityOne Government is the only cloud-native eDiscovery platform built in Microsoft Azure Government, empowering users to work confidently knowing their data will never leave the Azure cloud. With responsible AI built in directly to RelativityOne Government, The MCS Group’s customers spend less time waiting and more time doing, with automated workflows eliminating the most repetitive tasks and reducing the chance of human error. In 2023, on average, RelativityOne Government customers saved approximately over 1,200 hours across automated workflows.

For more about The MCS Group’s work within the government sector, visit https://www.relativity.com/partners/themcsgroup/. To learn more about RelativityOne Government, a FedRAMP authorized SaaS solution that tackles the diverse challenges of litigation, investigations and FOIA requests for government agencies, visit https://relativity.com/data-solutions/government-agencies/.

About The MCS Group: Founded in 1979 in Philadelphia, Pennsylvania, The MCS Group is a privately held company certified by the Women’s Business Enterprise National Council (WBENC). Our mission is to deliver custom, efficient, and cost-effective legal support solutions. With over 100TB of data under management and an average of 20+ years of experience in eDiscovery, MCS offers a suite of eDiscovery tools and services that clients can rely on to solve difficult challenges and control costs. For more information, please visit www.themcsgroup.com.

About Relativity

Relativity makes software to help users organize data, discover the truth and act on it. Its SaaS product, RelativityOne, manages large volumes of data and quickly identifies key issues during litigation and internal investigations. Relativity has more than 300,000 users in approximately 40 countries serving thousands of organizations globally primarily in legal, financial services and government sectors, including the U.S. Department of Justice and 198 of the Am Law 200. Please contact Relativity at  or visit www.relativity.com for more information. (Source: BUSINESS WIRE)

 

13 Aug 24. Pacific Defense Announces US Army CMFF Program Team. Defense, a leading provider of Modular Open Systems Approach (MOSA) products and mission solutions, announced their team to compete for the U.S. Army’s CMOSS Mounted Form Factor (CMFF) program. Led by Pacific Defense, the CMFF team includes state-of-the-art industry technology leaders Thales Defense & Security Inc., BAE, Regal Technology Partners, Palantir and STC, an Arcfield Company.

“Our company is purpose-built to drive the open-systems change the Army needs to take advantage of the commercial technology base and keep pace with the evolving threat,” said Travis Slocumb, CEO of Pacific Defense. “One hundred percent of what we do is modular, open system architecture. That, combined with this carefully curated team, will allow the Army to unlock mission systems’ technical baseline and enable rapid, recurring and affordable innovation.”

The Pacific Defense CMFF team’s layered standards will make it simpler, faster and much less expensive to rapidly introduce new capabilities and commercial technology. The standards will also reduce complex integration challenges, eliminate proprietary interfaces and enable greater competition and reuse. Pacific Defense’s CMFF team brings essential capabilities to address program requirements including ground and aviation platform design and integration, multi-waveform communications, Type 1 cryptographic implementation, model-based systems engineering (MBSE), and production at scale.

Pacific Defense is a leader in advancing integrated, open mission systems (C5ISR/EW Modular Open Suite of Standards and Sensor Open Systems Architecture) for U.S. customers and Five Eyes Alliance countries. The company has invested more than $100m in its MOSA product base – both hardware and software – and has extensive integration experience, including third-party content. (Source: BUSINESS WIRE)

 

13 Aug 24. Australia establishes Cyber Command. The Australian Defence Force (ADF) has established a new command focused on cyber within its Joint Capabilities Group (JCG).

This new command is expected to reinforce the ADF’s efforts to enhance its capabilities in cyberspace and the electromagnetic spectrum, the Australian Department of Defence (DoD) said on 9 August.

The cyber domain also plays a critical role in enabling forces to have an edge in cognitive and information warfare, the DoD added.

“Establishing a Cyber Command ensures [the DoD] meets the government’s direction to enhance our cyber capabilities and enable an integrated, focused force requirement,” Lieutenant General Susan Coyle, Chief of JCG, said.

The DoD said that with the establishment of Cyber Command, the Cyber Force Generation branch has evolved into Cyber Forces Group, a command entity. The ADF’s Joint Cyber Unit, Fleet Cyber Unit, 138 Signal Squadron, 462 Squadron, and 1st Joint Public Affairs Unit have been moved into Cyber Forces Group.

Transferring all cyber-warfare units into Cyber Command will help integrate soldiers skilled and trained in cyber warfare from all services of the ADF, along with public servants and personnel from industry partners, and enable a more centralised and co-ordinated management of this workforce, the DoD added.

The DoD said the Joint Survivability Tactics Validation Unit has also been transferred from the Royal Australian Air Force (RAAF) to the JCG’s Joint Capabilities Division to consolidate all operations associated with the cyber domain within the JCG.

The DoD also plans to create a Joint Data Network Unit in the future to support Cyber Command. (Source: Janes)

 

13 Aug 24. South Korea: Strategic military data will likely remain key target in espionage operations. On 11 August, South Korea’s government stated that North Korean threat actors had stolen critical information regarding South Korean military assets. The press release reported that cyber operations targeted technical data related to aerial reconnaissance planes. Any such operations are likely to have involved North Korean cyber actors exfiltrating sensitive data in a bid to compete with South Korea’s military arsenal. Similarly, data related to South Korea’s main battle tank was reportedly exported abroad illicitly after engineers from a South Korean parts manufacturer moved to a competing organisation, taking with them external storage drives containing sensitive information regarding the tank’s overpressure systems. Whether the reported exfiltration was the result of negligence or malicious intent, the incident highlights the security and operational risks associated with third-party vendors’ access to strategic data. As tensions in the Korean peninsula continue to fester, we assess that the military sector will remain a key target during espionage operations in the long term. (Source: Sibylline)

 

09 Aug 24. i2 increases investment in intelligence analysis software to strengthen agencies’ pursuit of ‘bad actors.’  Today, i2 Group said increasing demand for its intelligence analytics software among NATO forces and intelligence and law enforcement agencies was driving the company’s double-digit growth.

The global leader in visual data analysis today reported an annual 18% uptick in software license sales and 10% workforce growth as it launched a refreshed brand and new website to showcase its pioneering tech. The company said it was committed to supporting its customers and the wider market with continued investment in its products.

Acquired by Constellation Software subsidiary Harris Group from IBM in 2022, the UK and US-based company has since grown its client list, updating its product portfolio to meet the ever-evolving risks landscape for national and international organizations tackling the world’s ‘bad actors’.

Mission-critical tools such as the i2 Analyst’s Notebook are now helping more agencies and governments to analyze complex datasets, ‘join the dots’ and make data-driven decisions to combat terrorism, serious crime, espionage, insurgency, human trafficking and much more.

The World Economic Forum’s 2024 Global Risks Report identified interstate violence, illicit economic activity, terrorist attacks and cyber insecurity as key risks. The backdrop is behind the high demand for increasingly sophisticated software that can uncover hidden connections in disparate data ‘to stay two steps ahead’, said i2.

The company’s refreshed brand and new website reflect its unstinting commitment to delivering innovative solutions to the many global threats we now face, said i2 Executive Vice-President Jamie Caffrey.

Caffrey added: “We live in an increasingly volatile, uncertain and complicated world. Agencies need i2 solutions to make data-driven decisions about the biggest threats we now face. After a period of strong growth and development, we’re confident in our ability to deliver exactly what agencies need.”

For more information about i2, visit https://i2group.com.

About i2

i2 Group is the global leader in advanced visual analysis solutions, with a presence in more than 140 countries. Its innovations empower analysts and investigators to discover, create, and disseminate actionable intelligence to combat threats, such as serious crime, terrorism, war and fraud. These pioneering solutions are relied upon by thousands of organizations in global, international, national and local operations.

(Source: PR Newswire)

 

09 Aug 24. Global: Increased use of legitimate cloud services in cyber activity points to raised espionage risks. On 7 August, the cyber security company Symantec reported that the exploitation of legitimate cloud services in cyber operations has increased substantially since mid-July 2023. More threat actors are leveraging legitimate cloud services in attacks (including Microsoft OneDrive and Google Drive) to obfuscate malicious traffic. In July, Symantec observed three cyber espionage operations using legitimate services to host malware or actor-controlled command-and-control (C2) servers. For example, Microsoft Graph was employed by the state-backed group ‘Harvester’ to install a new backdoor against media organisations in South Asia in November 2023. Similarly, another backdoor was deployed against entities in Hong Kong, Taiwan and Vietnam in April using a C2 server hosted on Microsoft OneDrive. These incidents highlight threat actors’ growing exploitation of the trust associated with legitimate cloud service providers to feign legitimacy and obfuscate malicious activity to ensure successful operations. As such, we assess that this points to elevated espionage risks for global entities in the long term. (Source: Sibylline)

 

09 Aug 24. Cyber Update Key points.

  • A cyber operation compromised an unnamed internet service provider (ISP), elevating espionage and supply chain risks from the Chinese state-sponsored group ‘Evasive Panda’.
  • Cyber attacks on South Korea’s machinery and construction sectors have underscored the espionage risks stemming from North-Korean state-sponsored groups.
  • A ransomware attack targeted the Grand Palais in Paris (France), sustaining operational risks to the Paris 2024 Olympic Games.
  • A new worm compromising high-value targets in Russia will sustain information-theft and disruption risks for firms.
  • The increased use of legitimate cloud services to obfuscate malicious traffic points to elevated espionage risks facing global entities.

Technical analysis of weekly stories

A new worm, ‘CMoon’, has compromised high-value targets in Russia as part of an information-theft campaign since early July. The unnamed threat actors replaced legitimate document links on a gas company website with a malicious executable to distribute CMoon to targeted entities. Upon initial infection, CMoon searches for the presence of native antivirus security tools, copying itself into a new folder and emulating the legitimate service. It then changes the creation date of the new folder to 22 May 2013 to prolong obfuscation on compromised systems. Notably, the worm ensures it runs on system startup, thereby establishing persistence and allowing itself space to operate without the need for user input. Subsequently, CMoon monitors connected USB drives alongside other removable media to steal information and simultaneously propagate the infection. The worm collects files from specific locations containing saved passwords, cookies, bookmarks, browsing history and data for auto filling forms such as credit card data. Additionally, CMoon communicates with actor-controlled infrastructure to download and execute additional malicious files, as well as to take screenshots, initiate distributed denial-of-service (DDoS) attacks, collect information about available resources and send stolen files to a remote server. We assess that the malware’s numerous obfuscation techniques and varied functionality underscore the sophistication of this operation.

The Chinese state-sponsored group ‘Evasive Panda’ compromised an unnamed ISP to infiltrate organisations in a cyber espionage operation in mid-2023.  Although some details of the initial attack vector remain unknown, the threat actors reportedly conducted a domain name system (DNS) poisoning attack to intercept customers’ DNS requests. More specifically, the threat actors modified the content of requested HTTP pages to display a pop-up browser update alert. This then prompted users to update their browser, downloading malicious files onto the system. Alternatively, the threat actors exploited vulnerabilities in their victims’ automatic update mechanisms, injecting malware without requiring any user interaction (and consequently highlighting the threat actors’ sophistication). Subsequently, Evasive Panda deployed the ‘MACMA’ and ‘POCOSTICK’ payloads to steal information from targeted systems via device fingerprinting and keylogging, as well as audio and screen capture. Additionally, the group deployed a Google Chrome extension, ‘RELOADTEXT’, in some operations to exfiltrate browser cookies to an actor-controlled Google Drive account. We assess that the exploitation of a third-party vendor in the attack lifecycle further underscores the security and espionage risks presented via the software supply chain.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices, including personal devices connected to corporate networks or applications.

Our cyber word(s) of the week: Domain name system (DNS) poisoning attack

(Source: Sibylline)

——————————————————————————————————————————————————————————————————————————————————————————————————————————————

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

August 9, 2024 by

 

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

———————————————————————————————————————————————————————————————————————————————————————————————————————————————

09 Aug 24. AUKUS takes another step forward with real-time AI trials.

AUKUS nations test AI-enabled uncrewed aerial vehicles that allow a human operator to locate, disable and destroy targets on the ground.

  • AI-enabled aerial vehicles support the disabling of ground targets
  • Trials saw seamless exchange of data between AUKUS nations
  • Ground-breaking exercise highlights continued progress on Pillar 2 technology work

In a significant landmark for AUKUS, the 3 nations have trialled a futuristic integration of autonomy and artificial intelligence (AI) for the first time.

Testing saw the deployment of a series of AI-enabled uncrewed aerial vehicles that allow a human operator to locate, disable and destroy targets on the ground.

This ground-breaking exercise, which included AUKUS partners and experts from the Defence Science and Technology Laboratory (Dstl), is the first use of autonomy and AI sensing systems in a real-time military environment.

The successful trial focused collaborative AI and autonomy with our allies, to ensure we achieve the best possible outcomes. AI and autonomous systems were used to reduce the time it takes to identify enemy targets and operate with reduced risk to life. This included several drones from each nation operating together in the same airspace to achieve a common outcome, whilst being augmented by an AUKUS AI team, which retrained and deployed AI onto the platforms.

The seamless exchange of data and control between the 3 nation’s technologies demonstrated the progress that has been made by AUKUS in the trilateral adoption of AI and autonomous systems.

Commodore Rachel Singleton, Head of the Defence Artificial Intelligence Centre (DAIC), and UK lead for AUKUS AI and Autonomy Working Group, said:

“Resilient and Autonomous Artificial Intelligence Technologies provides the opportunity to develop, test and trial AI models on autonomous systems.

“The AUKUS partnership is key to ensuring that the systems designed by each nation are interoperable into the future. Service personnel from one nation will be supported by capabilities that have been developed across all 3 nations.”

The trial, which is part of a series of trials named AUKUS Resilient and Autonomous Artificial Intelligence Technologies (RAAIT), took place as part of the annual US-hosted multinational Project Convergence experimentation exercise. AUKUS continues to develop and deploy AI and autonomy technologies in a safe and responsible manner that ensures context-appropriate meaningful human control.

The trial demonstrated the significant improvements AUKUS partners have made to the application and viability of RAAIT since the first UK trial in April 2023. The technology has been developing at rapid pace and once proven, will be incorporated onto national platforms, providing the military with operational advantage through a quicker response to current and future threats.

Through AUKUS, new capabilities are being tested to protect platforms. For example,  protecting armoured vehicles from electronic warfare, laser and GPS attacks. Working across the AUKUS nations in this way means our militaries have greater interoperability and access to the most advanced AI across all 3 nations. It also opens up opportunities for sovereign industry partners.

AUKUS is a landmark defence and security partnership between Australia, the UK, and the US that supports both Euro-Atlantic and Indo-Pacific security and the rules-based international order. Under Pillar 2, AUKUS partners are deepening cooperation on a range of cutting-edge military technologies, which is enhancing military edge for the UK and our allies. This makes sure we have the capabilities needed to defend against rapidly evolving threats.

Participants of Project Convergence

Around 500 British Army personnel were deployed on Project Convergence, drawn from:

  • 1 Deep Recce Brigade Combat Team
  • 2nd Battalion the Royal Yorkshire Regiment
  • Ranger Regiment

Dstl was supported by a variety of industry partners including:

  • Deloitte
  • Cambridge Consultants
  • IQHQ
  • Blue Bear Systems Research
  • Frazer Nash Consulting

Government participants included Australia’s Defence Science and Technology Group. And from the US:

  • Air Force Research Laboratory
  • Office of the Under Secretary of Defense
  • Research and Engineering
  • Naval Air Warfare Center Aircraft Division
  • Chief Digital and Artificial Intelligence Office
  • Army Combat Capabilities Development Command Aviation & Missile Center
  • Ground Vehicles System Center
  • Army Research Laboratory (Source: https://www.gov.uk/)

 

07 Aug 24. Signal Shielding. The rollout of the GPS M-Code PNT waveform promises a major enhancement for the resilience of the constellation’s PNT signals. This is an important consideration given the high levels of GNSS jamming witnessed during the ongoing war in Ukraine.

Work continues in rolling out the resilient M-Code capability across the US Global Positioning Satellite constellation.

The United States Space Systems Command (SSC) Military Communications and Positioning, Navigation and Timing Programme Executive Office (MILCOM PNT PEO) has briefed Armada on the status of the introduction of M-Code. M-Code is a Position, Navigation and Timing (PNT) signal waveform equipping the US Global Positioning System (GPS) Global Navigation Satellite System (GNSS) constellation. A comprehensive discussion of the workings of M-Code can be found here. In a nutshell, M-Code is a secure GPS PNT signal waveform designed to be highly resilient to jamming and spoofing.

The MILCOM PNT PEO told Armada that “M-Code … was designed for military operations in electronic warfare environments.” It is separated from civilian GPS PNT signals in the same frequency bands, allowing the power of M-Code to be significantly increased without interfering with the former. M-Code also features more robust modernised cryptography to prevent spoofing. The main GPS PNT signals, known as L1 and L2, use frequencies of 1.57542 gigahertz/GHz (L1) and 1.22760GHz (L2). Other transmitted signals include L5 (1.17645GHz) and L1C (1.57542GHz), L2C is a new version of the L2 signal transmitted on the same frequency.

M-Code

The encrypted M-Code signal is reserved for use by US and allied militaries. M-Code is transmitted across the L1 and L2 frequencies. Militaries originally used the encrypted P(Y) Code signal, although employing this depended on the GPS receiver first acquiring the civilian C(A) Code transmitted using the L1 channel. Failure to acquire the C(A) Code, for example if the GPS receiver is being jammed, can prevent the acquisition of the P(Y) Code. Although P(Y) Code is encrypted, “M-Code features more robust modernised cryptography to prevent spoofing.”

M-Code is not completely invulnerable to electronic warfare: “The effectiveness of a jammer depends on its overall generating power, the direction the interference signal energy is focused and its proximity to the targeted GPS receiver,” the statement continued. “The combination of these factors means that any receiver, including an M-Code receiver, can be jammed in a specific situation. However, the goal of GPS modernisation is to maximise the availability of secure and accurate position, velocity, and timing information in challenging electronic warfare environments.”

Satellites

The first of the M-Code compatible satellites, known as Block IIRM which were built by Lockheed Martin, was launched in September 2005. The MILCOM PNT PEO says that 24 M-Code compatible satellites are now in orbit. The subsequent Block III satellites, the first of which was launched in December 2018, transmit the M-Code signal with even more power than the original M-Code spacecraft to help counter jamming. The Block III “satellites currently being launched can transmit M-Code approximately seven times stronger than the legacy military signal P(Y) Code.” The forthcoming Block IIIF constellation, which are expected to be launched in the coming years, will see a further increase in M-Code signal power: “The Regional Military Protection (feature) on future Block IIIF satellites will increase M-Code power over a region of interest by an additional factor of 20.” At the same time, military GPS receiver technology is improving through “greatly increased resistance to spoofing, improved encryption of the M-Code signal and integrity checks built into M-Code receiver technology.”

As matters stand at present, seven Block IIRM and twelve Block IIF satellites capable of transmitting M-Code are in orbit, according to the MILCOM PNT PEO. Six of the ten M-Code capable Block III satellites have been launched “with the remainder planned for launch in 2025 and 2026.” The PEO continued that the first Block IIIF satellite is expected to be launched in 2027. (Source: Armada)

 

07 Aug 24. 5G in a Box. The United States Air Force’s (USAF’s) Global Strike Command is deepening its levels of connectivity with the acquisition of transportable 5G cellular communications networks.

Fifth generation (5G) cellular communications protocols promise increases in data rates and the number of subscribers hosted on individual networks than currently possible with existing 4G standards. Details on the advantages and disadvantages of 5G can be found here. The advent of 5G comes at an opportune moment for the USAF and the US Department of Defence (DOD) in general. The latter is embracing the Multi-Domain Operations (MDO) philosophy. MDO stresses the inter- and intra-force connectivity of all military assets (personnel, platforms, weapons, sensors, bases and capabilities) at all levels of war. The goal of MDO is to facilitate simultaneous, synchronous operations. Multi-Domain Operations aim to improve the pace and quality of military decision making vis-à-vis that of the enemy. MDO places a premium on the timely and efficient movement of data between military assets. Data carriage in turn depends on robust, redundant and survivable communications. 5G is thus a welcome addition to existing US and DOD communications capabilities.

Transportable 5G network

In July news emerged that the USAF Global Strike Command is moving ahead with the acquisition of its first transportable 5G network, dubbed the T Node. The T Node has been developed and produced by SEMPRE and Instant Connect. The former provides the network while Instant Connect provides bridging software to enable disparate 5G-compatible devices to connect with the network.

According to a press release announcing the news, the transportable 5G network includes an enterprise-level data centre and Satellite Communications (SATCOM) gateway. Both these components are housed within a single enclosure to protect them from the destructive effects of the Electromagnetic Pulse (EMP). EMPs occur when a nuclear weapon is detonated. Electromagnetic pulses can have destructive effects on unshielded electronics across a large area. As well as using SATCOM for communications backhaul, the transportable 5G network can employ fibre optic and free space optics links. Handheld radios, smartphones and computers can connect to the 5G network using internet protocol standards. This connectivity is facilitated using the Instant Connect Mobile software application.

Hiding in plain sight

Rob Spalding, SEMRE’s chief executive officer, told Armada that these 5G nodes can be used as in a fixed or mobile capacity as well as being transportable. He adds that the T Node can be activated by a single person, and be operating and providing a network in around five minutes. Usefully, the network can host hybrid cloud and cloud management software. Users can thus access applications at the touch of a button. Mr. Spalding says that the 5G network, which operates in the sub-six gigahertz waveband, will soon benefit from a mesh capability to link with other networks: “This will allow customers to create larger coverage areas by linking nodes together,” he says. “The intent is to transform how infrastructure is deployed and get around the painful permitting process that goes along with large, power-hungry, expensive and complex macro towers.”

Each 5G network node provides coverage across a circa five-kilometre (three-mile) radius. Furthermore, the nodes do not require a Global Navigation Satellite System (GNSS) signal to operate. Not needing GNSS ensures “service is not lost when jamming is present.” Electronic protection has been built into the architecture and “the 5G network will operate through jamming, and in the future will be able to operate simultaneously in waveforms other than 5G.”

Another useful attribute of the T Node is that, as a 5G network, it can ‘disappear’ in the ether amidst civilian fifth-generation networks. Mr. Spalding says that this allows the T Node to “hide in plain sight by running private secure resilient networks over the top of public networks.” Two T Nodes have already been delivered to Global Strike Command. Additional deliveries are expected in the future. (Source: Armada)

 

06 Aug 24. Command Post Protection. The US Army’s Centre for Lessons Learned recent report examining command post survivability in Ukraine contains some important observations regarding electromagnetic concealment.

The US Army is digesting lessons learned from the ongoing war in Ukraine concerning command post survivability, lessons which have implications for tactical communications deployment.

Although published this February, the US Army’s Centre for Lessons Learned (CALL) publication entitled Lessons Learned from the Ukrainian Territorial Defense Forces: Command Post Survivability, only recently came to Armada’s attention. This document is based on wider observations articulated in the CALL publication entitled Battalion Command and Observation Posts: Practical Advice Based on War Experiences. It does not appear the latter publication has been made available to the public domain.

Using observations of Ukraine’s experience protecting her deployed command posts, the Lessons Learned publication stresses that “US Army leaders and soldiers should consider these CP (Command Post) survival lessons and best practices to improve their ability to survive on the modern battlefield.” The document continues that a key challenge to Ukrainian CP survivability has been Russian Electronic Warfare (EW).

According to the publication, Ukrainian command posts are routinely positioned at between two and five kilometres/km (1.2 and 3.1 miles), and ten kilometres (6.2 miles), behind the frontline. Anecdotal evidence from Ukraine suggests that Russian land forces can turn a geolocated and identified Ukrainian military communications signal into an artillery aimpoint within minutes. As a result, electromagnetic concealment for forward-deployed command posts is a must. One observation of the CALL document is that basements offer good concealment for electromagnetic emissions. Nonetheless, while wooded and forested areas provide camouflage, they can have electromagnetic drawbacks. As the document notes, thick vegetation and foliage can hamper certain communications frequencies.

Electromagnetic concealment

Other suggested electromagnetic concealment techniques include preventing the accumulation of military personnel near the command post. Having numerous personnel located nearby using radios or other electromagnetically dependent systems could generate emissions which can be exploited by the enemy. The use of wi-fi should be prohibited unless the command post’s work depends on this. No routers should be placed above the CP. Instead, routers should be located at ground level, or ideally placed underground when possible. Handheld, mobile and cellular communications should be banned in and around the CP. All antennas and associated radios should be moved a safe distance from the command post. If emissions from this equipment are detected and geolocated, there is less chance the CP will be damaged or destroyed. One technique cited by the document has been to use oval-shaped objects like a “lid form a large vessel such as a pot, bucket, etc.” to mimic a satellite communications antenna. Covering the object in white paint, chalk or white cloth gives added realism as do fake cables mimicking the antenna’s connections.

Additional electromagnetic concealment can be achieved using decoy emitters placed away from the CP, “but in a configuration that is believable and deceives the enemy.” The enemy can find the approximate location of the decoy CP by tracing its electromagnetic emissions.” Furthermore, “another method is to use a mobile team that imitates command and staff radio transmissions.” Nonetheless, the document concedes that “(i)t is difficult to hide the radio emissions of working communication devices from enemy EW means.”

HF dangers

CALL’s publication counsels against the use of command post High Frequency (HF: three megahertz/MHz to 30MHz) communications “because of their strong electromagnetic emissions and easily recognised signature.” If HF radio must be used power settings should be kept as low as possible and terrain masking employed to hide the HF antennas. Although “(m)obile internet connection is less dependent on distance and terrain … enemy EW can easily find the signature and location of routers.”

Although CALL’s publication is written from the perspectives of what has, and more importantly what has not, worked from an electromagnetic perspective, its findings have implications beyond Ukraine. North Atlantic Treaty Organisation (NATO) land forces are no doubt eagerly adopting such techniques. Should NATO find itself in a shooting war with Russia these electromagnetic lessons learned will prove invaluable. (Source: Armada)

 

05 Aug 24. August Radio Roundup.

Hurricane hunters

KenCast is supplying its Fazzt software to the US Air Force’s 53rd Weather Reconnaissance Squadron located at Keesler airbase, Mississippi. The software will improve communications for the squadron’s Lockheed Martin WC-130J turboprop freighters. These aircraft collect meteorological information, particularly regarding hurricanes. According to a company press release KenCast has partnered with R4 Integration to provide a capability to enhance these aircraft’s transmission of meteorological data. While KenCast supplies the software, R4 Integration installs this onboard the planes. The initiative forms part of a wider effort by the US National Oceanic and Atmospheric Administration to improve hurricane forecasting. Better forecasting should help enhance preparedness for such extreme weather. A written statement from KenCast revealed that all WC-130Js will receive KenCast’s software. “KenCast’s technology enables real-time reliable data transmission directly from the centre of the storm to the base, delivering information that can be crucial in saving lives, amid severe weather,” said the statement. The use of Fazzt by the WC-130Js means it is no longer necessary to wait until the conclusion of a mission before a WC-130J can share its data. Sometimes these missions can be over eleven hours’ duration.

Persistence pays off

On 9th July Persistent Systems announced it had won a $1.3 m contract from the US Navy to supply the company’s MPU5 radios and antennas to the force. A press release announcing the news said the hardware will be delivered to support “expeditionary and littoral operations.” Specifically, the radios and antennas will provide secure networking for navy Uninhabited Surface Vehicles (USVs). Personnel and USV ground control stations will also receive these systems. The radios will be outfitted with Persistent Systems’ Wave Relay mobile ad hoc networking waveform. The company’s July contract follows a similar $3.6 m contract it was awarded to integrate MPU5 radios with navy sensors. A Persistent Systems spokesperson told Armada that the contract covers the supply of a few dozen of the radios. A similar number of antennas, rugged displays and controllers will also be supplied. The spokesperson added that deliveries will begin by the end of the year and that the radios will equip Hydonalix’ Reckless, Emily and Amy USVs.

New MMW comms

Peraso has launched its new PRM2136X millimetric wave wireless platform for the provision of secure communications, according to a company press release. The company says the PRM2136X provides communications across a 57 gigahertz/GHz to 63GHz waveband. In a written statement supplied to Armada, Peraso disclosed that PRM2136X “evaluation units have been supplied to research and development groups in the US military and to companies associated with various militaries.” The statement continued that the PRM2136X “is a small 20mm x 45mm printed circuit board module containing the Peraso Baseband and RF (Radio Frequency) chipset and integrated antenna. The module communicates with the host and receives power from a USB 3.0 interface.” The PRM2136X has a useful range of circa 500 metres (1,640 feet) providing around one gigabit-per-second of data throughput. (Source: Armada)

 

07 Aug 24. Chinese Z-10 operates with new electronic warfare pod. China has developed a new, updated variant of its KG300G airborne electronic warfare (EW) pod for use by rotary-wing platforms.

The KG300G system has been previously identified with Chinese high-performance combat aircraft. However, on 1 August the state-owned China Central Television (CCTV) aired footage of a Changhe Z-10 attack helicopter equipped with a redesigned version of the pod.

Janes assesses that the new pod is shorter in length and differs in external design from the baseline KG300G pod, which is longer with a cylindrical, streamlined body designed for use with fighter aircraft.

The new KG300G is rectangular, box-like in shape, but with a semi-rounded nose and aft edges. The pod is also equipped with heat sinks on the upper frame, near the mounting pins, and an air intake to support the cooling of electronics. The design of the new pod’s square-shaped mounting lugs is also suggestive of its exclusive use by rotary-wing platforms.

The updated KG300G appears to be a product of the China Electronics Technology Group Corporation (CETC), a state-owned electronic manufacturer. CETC has previously showcased the pod at defence exhibitions. In comparison, the original KG300G, which entered service with the People’s Liberation Army (PLA) in 2007, is a product of the China National Electronics Import and Export Corporation (CEIEC). (Source: Janes)

 

07 Aug 24. Space Force Space Systems Command Praises EdgeRunner AI’s Battle Buddy: A Revolutionary Air-Gapped Military Support System. EdgeRunner AI, a new startup building Generative AI for the edge, is thrilled to announce that the U.S. Space Force Space Systems Command (SSC) has lauded EdgeRunner’s Battle Buddy, a groundbreaking offline AI platform designed to revolutionize military support. This cutting-edge system, which integrates seamlessly with any device—including laptops and smartphones—operates in fully air-gapped environments, bridging critical knowledge gaps between non-commissioned officers (NCOs) and Officers across all experience levels. The EdgeRunner Battle Buddy leverages the advanced EdgeRunner Tactical model, boasting 7 bn parameters that deliver performance on par with Meta’s Llama 3-70B model, yet with significantly lower resource requirements.

The Battle Buddy is a revolutionary tool that can encapsulate over 20 years of military wisdom into a single, interactive assistant, envisioned as an “NCO in a bottle.” It transforms legacy military data into an intelligent knowledge base, ensuring sensitive information remains secure within controlled environments without the need for cloud transfer.

The Battle Buddy features local data integration for precise, role-specific guidance based on current military practices and operates offline to ensure operational security by protecting sensitive data from cyber threats. It is customizable for various military roles, such as infantry or engineering, and includes built-in RAG capabilities for real-time, context-aware recommendations. The system uses custom adaptors (LoRAs) for task-specific enhancements and integrates advanced motion tracking and multi-language translation, among other features, to facilitate comprehensive support in diverse operational settings.

Lieutenant Devrin Chullanandana from the U.S, Air Force SSC, commented, “We took 10,000 documents and within a week, transformed it into an offline, localized ‘Jarvis’ for Space Operators to use in Mission Scheduling.”

EdgeRunner and Space Force SSC showcased the Battle Buddy prototype at Stanford University where the system ingested 10,000 PDFs—equivalent to around 300 m tokens—and demonstrated superior performance compared to GPT-4o-mini, particularly in delivering accurate Standard Operating Procedures (SOPs) for ground station satellite scheduling.

“We are incredibly proud of the EdgeRunner Battle Buddy’s ability to operate independently in secure environments while offering the kind of tailored, real-time support that military personnel need in the field,” said Tyler Xuan Saltsman, Co-Founder and CEO of EdgeRunner AI. “This recognition from the Space Force underscores the potential of our technology to make a real difference in military operations.”

The Battle Buddy is set to transform how Warfighters and Operators receive support, embodying the ultimate vision of military assistance by providing instant access to critical doctrine and procedural knowledge. It offers enhanced decision-making, increased operational security, tailored support, efficient training, and improved situational awareness through real-time insights into movement and positioning. The Battle Buddy also overcomes language barriers with its advanced translation capabilities and adapts to the unique cultures, terminologies, and training methods of various military branches, ensuring highly relevant support.

This cutting-edge technology also minimizes reliance on traditional “death by PowerPoint” presentations, streamlining Warfighter training and accelerating readiness. It serves as an advanced educational tool, providing real-time support during both preparation and active missions.

For more information about EdgeRunner AI’s groundbreaking technology and partnership opportunities, please visit www.edgerunnerai.com.

About EdgeRunner AI

EdgeRunner AI is a transformative startup on a mission to build Generative AI for the edge that is safe, secure, and transparent. EdgeRunner AI develops small, task-specific Ultra-Efficient Language Models (UELMs) that operate without needing internet access, improving data privacy, security, and compliance. By providing Generative AI solutions that run locally on any device or hardware, EdgeRunner AI enables enterprises and organizations to leverage AI technology responsibly, without compromising performance or security. EdgeRunner AI is backed by a $5.5m seed round led by Four Rivers Group with participation from Madrona Ventures and strategic angels. (Source: BUSINESS WIRE)

 

05 Aug 24. Cybersecurity Industry Leaders Launch the Cyber Threat Intelligence Capability Maturity Model. Today, Intel 471, the premier provider of cyber intelligence-driven solutions worldwide, sponsored a partnership of 28 industry leaders serving public and private organizations across the vendor and consumer community. Together, these professionals volunteered their time, effort, and experience to launch the first version of the Cyber Threat Intelligence Capability Maturity Model (CTI-CMM), designed as the first-of-its kind vendor agnostic and universally applicable resource to support organizations of all shapes and sizes across the CTI industry. In today’s evolving threat landscape, the sign of a successful Cyber Threat Intelligence (CTI) program is a mature program that seamlessly integrates with an organization’s core objectives and key outcomes.

“Unlocking the full potential of your CTI program requires alignment with the capabilities of each stakeholder it supports, and a tangible measurement of success synchronized with organizational priorities,” said Michael DeBolt, Chief Intelligence Officer at Intel 471. “The CTI Capability Maturity Model (CTI-CMM) is designed to support CTI teams in building their capabilities by aligning to defined practices for stakeholder business domains unique to each organization. The Model establishes shared values and principles across the industry to empower organizations to take a holistic approach to cyber threat intelligence with stakeholders in mind.”

“Advising numerous clients globally, I have observed a consistent need for an outcome-focused model for cyber intelligence programs. The CTI-CMM bridges the gap to help CTI programs create impactful and demonstrable value for their organization,” said Colin Connor, CTI Services Manager at IBM X-Force.

The all-volunteer team behind the CTI-CMM is comprised of professionals representing a wide range of sectors, geographic regions, backgrounds and experiences, including leaders from Intel 471, IBM, Kroger, Venation, Mandiant, IntL8, Regfast, Trellix, Autodesk, Centre for Cybersecurity Belgium (CCB), Northwave Cyber Security, Workday, Marsh McLennan, Signify, Tidal Cyber, DeepSeas, BP, Gojek, SAND and many more. These individuals created CTI-CMM to elevate cyber threat intelligence across the industry through knowledge and experiences. Together, they defined the following values and principles to support the CTI community moving forward:

Shared Values

  • Intelligence provides value through collaboration with our stakeholders and supporting their decision-making process.
  • Intelligence is never completed. Improvement is continuous. This also applies to adoption. Constant improvement is crucial for success and distinguishing from other models which failed to keep up with the time.
  • Intelligence is not proprietary, nor is it prescriptive. Therefore, the model should never be claimed by a single commercial party.

Shared Principles

  • Contextualizing threat intelligence within risk
  • Continuous self-assessment and improvement
  • Actionable intelligence based on stakeholder needs
  • Quantitative and qualitative measurement of intelligence
  • Collaborative and iterative intelligence processes

This team made the decision to design the CTI-CMM to align with industry best practices and the concepts and format of a recognized cybersecurity maturity model, the Cybersecurity Capability Maturity Model (C2M2). Similar to the C2M2, the CTI-CMM is organized into ten domains. Each domain includes a “Domain Purpose” followed by a “CTI Mission” description describing how the CTI function supports it and consists of the CTI Use Cases and CTI Data Sources.

The CTI-CMM is the blueprint for a successful and effective CTI program. It exists to support the people who make decisions and take action to protect organizations. For more information, please visit: https://cti-cmm.org/

About Intel 471

Intel 471 empowers enterprises, government agencies, and other organizations to win the cybersecurity war using the real-time insights about adversaries, their relationships, threat patterns, and imminent attacks relevant to their businesses. The company’s platform collects, interprets, structures, and validates human-led, automation-enhanced intelligence, which fuels our external attack surface and advanced behavioral threat hunting solutions. Customers utilize this operationalized intelligence to drive a proactive response to neutralize threats and mitigate risk. Organizations across the globe leverage Intel 471’s world-class intelligence, our trusted practitioner engagement and enablement and globally dispersed ground expertise as their frontline guardian against the ever-evolving landscape of cyber threats to fight the adversary — and win. Learn more at https://intel471.com/.

(Source: BUSINESS WIRE)

 

02 Aug 24. Australia speed up procurement processes with new digital strategy. The ADF’s new Digital Engineering Strategy will be modelled on the digital transformation programmes undertaken by the US Department of Defense. Australian Minister for Defence Industry, the Hon Pat Conroy MP (centre), takes questions from media during an announcement of a $500m Head Contract for Project AIR6500, Lockheed Martin Australia, Williamtown, New South Wales. Credit: Australian Defence Force.

Australia’s Defence Forces (ADF) will implement a new Digital Engineering Strategy to help the Commonwealth streamline its acquisition process and address operational gaps.

The outcome will result in increased collaboration with industry, better decision making and faster introduction of capability across the ADF.

“By working more closely with industry in this space, existing partners and small to medium enterprises will have the opportunity to contribute to the design of shared collaborative platforms, delivering speed to capability in a secure and streamlined digital environment,” outlined the Deputy Secretary for the Capability Acquisition and Sustainment Group, Chris Deeble.

So far it has yet to be seen what this strategy will look like in its details. The ADF will work in close consultation with industry and universities to develop a greater understanding of digital engineering practices for collaboration.

What will this look like?

Australia’s forthcoming digital transformation will be modelled on US DoD processes.

In mid-July 2024, the Washington-based Center for Strategic and International Studies spoke to Dr Radha Plumb, the DoD’s Chief Digital Officer, who outlined the American model, which he asserts hinges on artificial intelligence (AI).

“I think the good news for DoD AI is we have really strong technical foundations and we have proven out now over the last year-and-a-half an experimentation-based approach that allows us to rapidly accelerate technology solutions into fielded capabilities.

“I think part of this [is] what doe sthe government need to do? Like, to enable this commercial technology to… meaningfully be adopted, we need these kinds of environments that can take the data in the department, mash it up against commercial technology, and see sort of what are the tech solutions that are actually solving our capability gaps?”

Tapping into SME innovation in Australia

A longstanding problem for Western governments has been their lack of agility to derive innovation from small-to-medium size enterprises (SME). Of course, governments cannot fund every concept on the market, and they have come to rely on larger primes based on their enduring relationships.

Both have wrestled with how far either side must concede to successfully cultivate a more diverse industrial supplier ecosystem that leverages SME innovation when it emerges. This remains a potential operational gap that the ADF may need to overcome through its new Digital Strategy.

Typically, the UK and US governments have approached this dilemma with a competitive procurement process, stripping their prescriptive requirements, to enable SME competition.

At the end of April, the US DoD accepted Anduril, a non-prime, in the competitive procurement process for its future crewed-uncrewed teaming concept: the Collaborative Combat Air programme. At the time, a company spokesperson noted that the decision “signals a demand for continued expansion of the defence industrial base.”

Likewise, in July, the UK Ministry of Defence released a notice broadening the scope of suppliers in the existing uncrewed aerial system heavy-lift capability framework.

The MoD aims to accelerate numerous concepts to better understand its options on the market while also ensuring it has access to them as technology evolves. No limit has been placed on the number of concepts that may be developed, but certain factors will need to be considered first, not least funding availability. (Source: army-technology.com)

 

05 Aug 24. Global: Cyber operation elevates espionage, supply chain risks from Chinese state-sponsored group. On 2 August, the security company Volexity reported that the Chinese state-sponsored group ‘Evasive Panda’ compromised an unnamed internet service provider (ISP) to infiltrate targeted organisations in mid-2023. The group exploited insecure update mechanisms to steal sensitive information from targeted macOS and Windows machines. Evasive Panda conducted a domain name system (DNS) poisoning attack against targeted ISP providers to intercept HTTP update requests. This enabled the group to manipulate customer DNS requests to covertly install malicious payloads instead of legitimate application updates. The group subsequently deployed multiple malware strains onto customer systems, highlighting security risks stemming from the software supply chain. In July, Evasive Panda targeted organisations in Taiwan and China-based US NGOs using similar tools and techniques, suggesting that there may be a connection between this more recent campaign and the mid-2023 campaign. We assess that this incident further increases security, espionage and supply chain risks from Chinese state-sponsored groups in the long term. (Source: Sibylline)

 

02 Aug 24. Cyber Update Key points.

  • The Belarusian-nexus group ‘GhostWriter’ targeted Ukrainian organisations in a cyber operation, sustaining espionage risks.
  • Unnamed threat actors are targeting Android users with new spyware, raising information theft risks to users globally.
  • The ‘Black Basta’ ransomware group has developed several new custom malware strains, elevating financial and disruption risks to firms (see Sibylline Cyber Daily Analytical Update – 31 July 2024 and our Technical analysis below).
  • A large non-profit blood centre suffered a ransomware attack, underscoring supply chain and disruption risks facing the healthcare sector (see Sibylline Cyber Daily Analytical Update – 1 August 2024).
  • A new remote access trojan (RAT) heightens security and financial risks for Android users (see Sibylline Cyber Daily Analytical Update – 2 August 2024 and our Technical analysis below).

Technical analysis of weekly stories

Unnamed threat actors are targeting Android users with a new RAT, ‘BingoMod’, in a financially motivated operation. The malware is distributed via phishing text messages (smishing), tricking potential victims into downloading fraudulent applications disguised as legitimate security services. Upon installation, BingoMod requests permissions to activate accessibility services and execute a malicious payload. The application then establishes a line of communication with the command-and-control (C2) infrastructure, collecting sensitive data via keylogging and SMS interception. The threat actors leverage accessibility services to conduct overlay attacks and steal sensitive information such as login credentials and/or bank account balances. SMS interception also enables threat actors to monitor incoming messages from financial institutions to obtain transaction authentication numbers (TANs). Additionally, BingoMod facilitates remote access to infected devices via virtual network computing (VNC) to control and interact with victims’ screens in real time, providing threat actors with significant capabilities, such as taking regular screenshots. The threat actors use on-device fraud (ODF) techniques to hijack banking applications and initiate bank transfers of up to EUR 15,000 (USD 16,363), highlighting the highly lucrative nature of this campaign. Notably, ODF allows the threat actors to target any legitimate banking application, significantly widening their target pool. BingoMod also contains several obfuscation techniques. These include the capacity to disable editing by the user and the ability to wipe data from infected devices, further highlighting the malware’s high level of sophistication.

The ransomware group Black Basta has developed several new malware strains and pivoted to new initial attack vectors since the beginning of 2024. In early 2024, Black Basta deployed two new custom tools, ‘DawnCry’ and ‘DaveShell’, in a multi-pronged operation. This enabled the group to download a new custom tunneler (‘PortYard’) on compromised systems to establish communication with their C2 infrastructure and redirect traffic. Additionally, the group developed several other malware strains, marking a shift from using publicly available tools to developing bespoke custom malware. Some of these include a .NET reconnaissance tool (‘CogScan’), a tunneler that retrieves commands from the C2 server (‘SystemBC’), a utility that executes a BASTA ransomware payload (‘KnockTrock’), and a memory-only dropper, (‘KnowTrap’). Notably, Black Basta typically used the modular malware ‘QakBot’ (also known as ‘QBot’) to obtain initial access to corporate networks via phishing emails. The group has also exploited zero-day vulnerabilities including the VMware ESXi authentication bypass flaw (CVE-2024-37085) to gain access to targeted systems. This underscores a shift in Black Basta’s tactics, techniques and procedures (TTPs) while also highlighting the group’s sophistication.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Enforce strict patch management policies to protect against known software vulnerabilities.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices, including personal devices connected to corporate networks or applications.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: On-device fraud (ODF). (Source: Sibylline)

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

August 2, 2024 by

 

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

—————————————————————————————————————————————————————————————————————————————————————————————————————————————-

31 Jul 24. The Japanese Ministry of Defense sets its first AI policy and seven priority areas.

On July 2, the Ministry of Defense adopted its first basic policy for promoting the use of artificial intelligence (AI).

The Ministry of Defense stated that they will plan to reduce the burden on SDF’s members and manpower by utilizing AI in order to maintain the SDF’s system despite a declining population. The ministry will also plan to use AI effectively in seven fields, including the detection and identification of targets using radar and satellite images.

The basic policy, which is called the “Basic Policy for the Promotion of AI Utilization”, states that it is pointed out that AI would decide aspect of warfare in the near future considering efforts by the U.S. and Chinese militaries to utilize AI. This also stated that it is urgent to respond to a “new way of fighting” involving space, cyber, and electromagnetic waves in addition to land, sea, and air and operate personnel efficiently. It is also pointed out that we are now at a crossroads whether we are falling behind and becoming an inefficient, old-fashioned organization or not.

It also recognized that AI also carries risks of error and bias and emphasized that what AI does is support for human decisions, and human involvement should be ensured.

The seven areas in which AI will be used mostly are: (1) target detection and identification; (2) collection and analysis of information from the Internet and radio waves; (3) decision support for commanders; (4) logistics support such as supply and maintenance; (5) control of unmanned vehicles; (6) improvement of cyber security capabilities; and (7) efficiency of administration work.

On the same day, the Ministry of Defense also announced a “comprehensive strategy to recruit and train personnel specialized in cyberspace.” The ministry plans to establish a new examination category for cyber in the Ground Self-Defense Force on the premise of being assigned to Cyber Defense Command which will begin accepting applications in fiscal 2025. The ministry also plans to double the number of GSDF students enrolled in the cyber education program at the GSDF High Technical School in Yokosuka, Kanagawa Prefecture, from 30 to 60 by the same fiscal year.

“AI and cyber can be technologies to overcome challenges such as declining population.” Defense Minister Minoru Kihara stated at a press conference after the cabinet meeting.

(Source: AMR

 

01 Aug 24. Claims and Counter Claims. Apparently, the prowess of Chinese radar design and networking has successfully defeated the state-of-the-art Electronic Warfare (EW) capabilities of the US Navy’s E/A-18G Growler EW jet. The staggering news was conveyed in the Eurasian Times in mid-July. The report quoted the Chinese academic journal Radar & ECM which articulated the incident in question that took place in late 2023. The debacle was so severe that the commander of VAQ-136, the US Navy electronic attack squadron to which the aircraft was assigned, was dismissed according to the report.

People’s Liberation Army Navy (PLAN) officials claimed that the ‘Type-55’ class destroyer Nanchang used Artificial Intelligence (AI) techniques to nullify jamming by the E/A-18G. The AI approaches in question comprised cognitive radar techniques. Moreover, a ‘kill web’ networked PLAN assets deployed in the South China Sea at the time of the incident. The kill web allegedly helped the Nanchang, and other PLAN ships, avoid the Growler’s jamming. These capabilities let the destroyer move 100 nautical miles (185 kilometres) north of the PLAN task group and prevent a US Navy Carrier Strike Group (CSG) entering an area where the PLAN was exercising. The Nanchang’s radar locked onto CSG surface combatants dissuading them from entering the exercise area. So successful was the PLAN effort that members of the Nanchang’s crew were decorated.

Do the PLAN’s claims add up? Possibly not. Firstly, the Radar & ECM journal article in question is not in the public domain. Although notionally available for purchase with an English language translation, the associated website does not appear to work; your editor tried it numerous times. It is difficult to examine the claims if the journal article in question cannot be read. Secondly, the argument about the dismissal of the VAQ-136’s boss are dubious. The commander in question was relieved due to a loss of confidence in their abilities; a catch-all term covering a variety of shortcomings. Thirdly, why was the E/A-18G allegedly jamming the Chinese vessels? The US and China are not at war. Despite the two country’s geopolitical tensions, using jamming signals in peacetime would be risky. It could send the wrong message that the US Navy CSG was preparing to attack the PLAN ships. Deploying jamming waveforms in peacetime risks handing your potential adversary information about tactics you might use in wartime. Fourthly, illuminating US Navy ships using a radar’s war modes is similarly risky. If such an incident had occurred it is likely to have drawn a full-throated public condemnation from the White House.

Instead, it seems that the alleged ‘incident’ is in fact PLAN propaganda intended for international consumption. China gets to flex its electromagnetic muscles, if only in an imaginary sense, showing that its navy can stand up to Uncle Sam. Even if the incident amounts to no more than propaganda, it is no reason to dismiss the PLAN as technologically inferior. China will continue to make her investments into sophisticated defence technology to reach technological parity, or even supremacy, with the US and her allies. This is a situation the United States and her allies must not allow to happen, and this latest alleged confrontation should serve as a reminder of China’s scientific direction of travel. (Source: Armada)

 

01 Aug 24. Persistent Systems Provides MANET Connectivity for U.S. Military Field Training Exercise. Persistent’s mobile ad hoc network (MANET) enabled geographically dispersed U.S. military commanders to move small, agile operational centers across the INDOPACOM region while maintaining contact with aircraft and ground forces.

Persistent Systems communications solutions have successfully supported Valiant Shield, a biennial joint Field Training Exercise conducted by the U.S. military in Guam and across the INDOPACOM Area of Responsibility (AOR). During the 11-day exercise, Persistent Systems Wave Relay® MANET and Cloud Relay™ networking capabilities enabled U.S. commanders operating from forward-deployed and fixed operations centers to test the Air Force’s Agile Combat Employment (ACE) concept through the MANET-Cloud High Mobility Radio (MCHMR) as well as conduct a run-through of the Joint Fires Network, a prototype battle management system.

Adrien Robenhymer, Persistent’s VP of Business Development, Air Force and Intelligent Community, said; “U.S. forces in the INDOPACOM AOR are under constant alert from threats marshaled by near-peer powers in the region. The U.S. must be prepared to counter by operating in a nimble, distributed fashion with a swift kill chain.”

Utilizing MCHMR’s MPU5-based MANET and cloud services facilitated by Persistent’s Cloud Relay network, Valiant Shield commanders at both fixed and deployable operations centers, as well as individual units at the edge, were able to track bombers and fighter jets in the air, personnel on the ground, and ships at sea.

Robenhymer added; “During the exercise, airmen and Marines were using our MANET technology to demonstrate the viability of the ACE concept. Commanders were rapidly establishing operations in Hawaii, Guam, and the First Island Chain, all while maintaining communication and tracking of their forces. We also showcased our ability to reduce the Joint Fires Network response time from minutes to seconds.”

Persistent’s involvement with Valiant Shield, say company officials, is yet another example of how it is leading the way in delivering a Joint All-Domain Command and Control (JADC2) capability today.

Robenhymer said; “The network is the key to enabling JADC2. By delivering a rapidly deployable, scalable network providing both connectivity at the tactical edge and strategic reach back; decision-makers are finally united with the sensors and effectors. MCHMR has turned the JADC2 vision into a reality, and we just demonstrated it across the Pacific.” (Source: https://www.defenseadvancement.com/)

 

30 Jul 24. Taking Stock of Vostok. The Vostok-3D radar produced by KB Group of Belarus may enter service in the country by the end of 2024. Marketing video reveals that at least one Vostok-3D radar has already been occasionally active in the vicinity of Minsk.

In partnership with EW Analytics LLC, we share details of the new Belarussian Vostok-3D ground-based air surveillance radar.

Built in Belarus, the KB Group Design Bureau’s Vostok-3D S-band (3.1 gigahertz/GHz to 3.3GHz) and Very High Frequency (VHF: 170MHz to 220MHz) ground-based air surveillance radar is a new system. The company’s literature says the radar has an instrumented range of 194 nautical miles/nm (360 kilometres/km). The Vostok-3D detects and tracks targets across 360 degrees’ azimuth, and between -3 degrees’ to 45 degrees’ elevation. Marketing video reveals that at least one Vostok-3D radar has already been occasionally active near Minsk.

Target range, azimuth and velocity are measured by the radar’s VHF transmissions. Azimuth is also measured by the radar’s S-band signals which, in addition, measure range and elevation. The radar determines range to within 200 metres (656 feet), azimuth to within 5.5 degrees, elevation to within 1.2 degrees and velocity to within 19 knots (35 kilometres-per-hour). The radar rejects jamming signals equal to, or greater than, 30 decibels/dB and rejects clutter equal to, or greater than, 50dB.

The radar tracks up to 250 targets simultaneously and can detect and measure bearings of up to ten jamming signals. When transmitting in VHF and S-band, pulse-to-pulse and train-to-train frequency turning is possible in automatic and semi-automatic modes. S-band signals use chirp modulation with the VHF signals using chirp and quadrature phase shift keying modulation.

Operating modes

EW Analytics LLC’s analysis notes that four signal modes are available when the radar is performing VHF transmissions with the same number of signal modes available when the radar is transmitting in S-band. The key difference between these modes are their pulse power, duration and repetition intervals. EW Analytics LLC’s study adds that it is unclear how these modes are used: Can different modes be used on different frequencies simultaneously? Are the radar modes automatically determined, set by the operator, or both?

The analysis has determined that the operator can set radar rotation speeds to either three- or six rotations-per-minute. It is noteworthy that the Vostok-3D’s VHF and S-band antennas are mounted back-to-back. EW Analytics LLC assesses that radar echoes from the VHF and S-band signals are probably merged into single tracks. Merging tracks in this way will help to provide a richer radar picture.

Targets are automatically classified as fixed- or rotary-wing aircraft, ballistic missiles, balloons or are left unidentified. Photographs of the Vostok-3D reveal that an Identification Friend or Foe (IFF) interrogator can be integrated below the S-band antenna. It is not thought that the interrogator is supplied as standard and may need to be added by the customer. Additional investigation by EW Analytics LLC has determined that target identity can be ascertained from an Automatic Dependent Surveillance Broadcast (ADS-B) system feed. ADS-B information is available to be displayed on the operator’s screen.

Into service

EW Analytics expects the Vostok-3D to enter service with the Belarussian military by the end of this year. As of 2022, KB Group was under United States government sanctions. These sanctions were imposed in retaliation for Belarussian support for the invasion of Ukraine and assistance given to Russia therein.

A VHF transmission that displays some Vostok-3D signal attributes and that possibly originates from Belarus can currently be found in an amateur radio channel that is publicly accessible on the Internet. Assuming the Vostok-3D’s service entry occurs as planned by the end of 2024, it is possible that signals from these radars maybe detected with increasing regularity in the coming years; especially if the Vostok-3D radar is not as “stealthy” as advertised. North Atlantic Treaty Organisation airborne signals intelligence collection assets appear to take a close interest in Belarus. Therefore, these assets may have the opportunity to collect potentially lucrative intelligence on this radar.

(Source: Armada)

 

01 Aug 24. MARS Attacks. Part of the control panel for the AN/ALQ-172(V)2 system which helps protect USAF B-52H Stratofortress strategic bombers. This system is undergoing a comprehensive upgrade via the MARS initiative to improve its resilience vis-à-vis emerging threats.

The US Air Force’s venerable Boeing B-52H Stratofortress strategic bomber is receiving important enhancements to its self-protection systems.

L3Harris was awarded a ten-year $947 m contract in 2021 to implement a host of improvements to enhance the B-52H’s AN/ALQ-172(2) self-protection suite. This contract forms part of the Stratofortress’ MARS (Maintainability and Reliability System) upgrade programme. According to reports, the AN/ALQ-172 has been in service onboard the B-52 series since the early 1980s. The original version was the AN/ALQ-172(V)1 fitted to now-retired B-52G bombers with the AN/ALQ-172(V)2 equipping the B-52H.

Capabilities and improvements

Open sources state that the AN/ALQ-172(2) can protect the aircraft against radar-guided air-to-air and surface-to-air threats. The system detects and jams low band (100 megahertz to two gigahertz/GHz), mid-band (two gigahertz to six gigahertz) and high-band (six gigahertz to 18GHz) threats. These threats can include simultaneous monopulse, multiple pulse, pulse Doppler and continuous wave radars.

According to L3Harris’ literature, the MARS upgrade extends the AN/ALQ-172(V)2’s frequency coverage. This may mean coverage has been extended upwards to circa 40GHz. Extending the system in this fashion would allow the AN/ALQ-172(V)2 to detect and jam K-band (24.05GHz to 24.25GHz) and Ka-band (33.4GHz to 36GHz) threats. K-band and Ka-band radars are often employed as seekers for active radar homing air-to-air and surface-to-air missiles. Field-programmable gate array technology has been added to the AN/ALQ-172(V)2 making the system easier to reconfigure in situ. The upgrade also added digital receivers while reducing overall weight and power consumption.

Stratofortress path

“There isn’t a single MARS contract,” says Jimmy Mercado, L3 Harris’ programme director for bomber electronic warfare. “The MARS campaign started as a series of form, fit, function (and) interface LRU (Line Replacement Unit) redesigns triggered by sustainment demand.” Mr. Mercado says that the first LRU to be redesigned was the system’s LRU-10 with work commencing in 2014. The AN/ALQ-172(V)2’s LRU-14 has also been redesigned via the MARS programme. As Mr. Mercado states both LRU-10 and LRU-14 are “in production and are fieldable”. He adds that “(a)ll but two LRU redesign contracts have been completed. The remaining two will complete in 2025. Production for MARS LRU-4 is expected to begin this year.”

Writ large, MARS heralds improvements “inherent from transitioning from analogue to digital technology, the use of digital receivers and high-speed signal processing, and increased accuracy and precision measurements,” Mr. Mercado continues. An open, modular approach has been taken to ease future upgrades. During a recent test flight five of the nine LRUs being upgraded were successfully evaluated. MARS shows there is growth potential for the EW systems protecting a bomber which may remain in service until 2050. (Source: Armada)

 

01 Aug 24. New Systems for the Space Force. One of the few existing images of the US Space Force’s Remote Modular Terminal satellite communications jamming system. The RMT is expected to soon enter service as a complement to the Space Force’s existing Counter Communications System.

The United States Space Force is set to enhance its electronic warfare capabilities with the service entry of the Remote Modular Terminal.

Reports in late July said that the US Space Force’s (USSF’s) Remote Modular Terminal (RMTs) jammers will enter service at undisclosed locations by the end of this year. The reports continued that 24 jammers have been ordered with eleven expected to begin deployment by late 2024. Four of the jammers are thought to have already been delivered. Few details exist regarding the RMT’s capabilities although they are intended to jam Satellite Communications (SATCOM). This may mean they transmit jamming waveforms into ground-based, airborne or ship-based SATCOM terminals. Specifically, the jammers may cover wavebands of circa 240 megahertz/MHz up to 40GHz. By covering these wavebands, RMTs could attack a raft of frequencies routinely used for SATCOM. This April, it was confirmed that the USSF had concluded Remote Modular Terminal testing.

Complementing CCS

Once in service, the Remote Modular Terminals will complement the USSF’s Counter Communications System (CCS) SATCOM jammers. Like the RMTs, much remains unknown vis-à-vis the CCS apparatus including the SATCOM frequencies it targets. CCSs operated by the Space Force are undergoing an upgrade dubbed Meadowlands. The $219 m Meadowlands programme is reducing the quantity of equipment racks used by the CCS; a reduction which will help reduce the CCS’s maintenance burden and ease of deployment.

It is unclear why the Space Force has moved ahead with the RMT acquisition. Previous analysis by the Secure World Foundation surmised that the CCS may attack C-band (5.925GHz to 6.425GHz uplink/3.7GHz to 4.2GHz downlink), X-band (7.9GHz to 8.4GHz uplink/7.25GHz to 7.75GHz downlink) and Ku-band (14GHz uplink/10.9GHz to 12.75GHz downlink) SATCOM frequencies. The Secure World Foundation is a thinktank based in Washington DC specialising in space policy.

Is it possible that the RMT has been procured to attack other SATCOM frequencies not covered by the CCS? The Russian SATCOM sector has made investments into Ka-band capabilities in recent years. Russian military SATCOM has already been confirmed as using C-band and Ku-band frequencies. Likewise, analysis of the SATCOM market confirms that the People’s Republic of China is investing in Ka-band. It would be prudent to ensure that the USSF has SATCOM jammers targeting frequencies used by US and allied strategic rivals.

Tactical and operational deployments

In the USSF’s own words the Remote Modular Terminals are compact, portable and cost-effective, and designed for deployment in difficult environments. The terminals have a small, modular design employing off-the-shelf components. One of the few technical specifications in the public domain is the terminal’s three-metre (ten-feet) diameter dish. It is possible that the larger CCS equipment will be statically deployed for SATCOM jamming at the operational/tactical level. In contrast, the RMTs may be intended for tactical level use at the halt and be easy to redeploy as the tactical situation warrants. Although details regarding the RMT remain scant, more maybe forthcoming once the system enters service later this year. (Source: Armada)

 

01 Aug 24. August Spectrum Sitrep.

Rohde & Schwarz is providing its RCESM system to furnish the Polish Navy’s three new frigates which will help enhance the electromagnetic situational awareness of these vessels.

Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.

New naval ESMs

On 9th July, Rohde & Schwarz announced that the company had concluded a contract with PGZ Stocznia Wojenna to support the Marynarka Wojenna (Polish Navy) Miecznik frigate programme. A press release revealed that Rohde & Schwarz will supply several Electronic Warfare (EW) systems. These systems include the company’s Radar and Communications Electronic Support Measures (RCESM) for the three new frigates. Rohde & Schwarz told Armada via a written statement that the RCESM is “adaptable and scalable to specific requirements.” The system “detects, identifies and locates complex and broadband radar emissions and captures enemy communications.” Signals intelligence collected by the RCESM is combined to provide “an extended picture of the entire electromagnetic spectrum.” The statement added that “(t)he solution’s particularly high sensitivity and accuracy results in an increased range coverage and early warning capability (and it) protects navy vessels against time-critical threats.” Rohde & Schwarz declined to provide details of the contract’s value and timelines for delivery citing confidentiality.

Got your back

The US Army’s Terrestrial Layered System–Brigade Combat Team (TLS-BCT) backpack Electronic Warfare (EW) apparatus is on course for service entry by the end of 2024. The backpack will be deployed with dismounted troops at the tactical level and is being developed and produced by Mastodon Design. In early July, the army’s Intelligence, EW and Sensors Programme Executive Office (PEO IEWS) announced it had awarded the company a contract worth $99.9 m. The contract encompasses “the procurement, training, and fielding” of the TLS-BCT backpack. The news was announced via a PEO IEWS press release. The document continued that the deployment of the first TLS-BCT backpacks should occur by the end of 2024. A PEO IEWS spokesperson told Armada that the equipment “provides a small form factor full spectrum signals intelligence, EW, and cyber-enabling, non-kinetic offensive operation capabilities to BCT commanders” near the tactical edge. TLS-BCT backpacks will be “fielded to infantry, armoured, and Stryker formations operating across regionally aligned areas of responsibilities.”

AFWERX work

HawkEye 360 has been awarded a Small Business Innovation Research (SBIR) Phase-2 contract by the US Air Force’s AFWERX programme. The AFWERX initiative aims to identify and nurture the innovations of small businesses which may benefit the air force. According to US Department of Defence definitions, SBIR Phase-2 contracts run for between twelve and 18 months and are typically worth up to $2 m. The contracts are intended to help move a technology or innovation towards a prototype stage. Under the terms of the contract, a HawkEye 360 press release said that the company will deliver its RFGeo signal mapping and RFIQ emitter analysis data to AFWERX. A statement from HawkEye 360 supplied to Armada said that these data will be delivered over the next twelve months. (Source: Armada)

 

30 Jul 24. Viasat Introduces Wearable Secure Wireless Hub for Advanced Network and Edge Communications. Viasat Inc. (NASDAQ: VSAT), a global leader in satellite communications, today announced the introduction of Viasat’s Secure Wireless Hub (SWH), a wearable tactical gateway solution for dismounted soldiers that is easy to carry and simple to use. The SWH solution was developed as part of a multi-phase effort with U.S. Special Operations Command (USSOCOM) to identify and develop advanced tactical communications capabilities for mobile ground forces.

The SWH is the first wearable addition to Viasat’s portfolio of tactical gateway solutions, providing a flexible, all-in-one design to enable faster set up for warfighters to improve user experience and support situational awareness within minutes. With a base of less than one kilogram, the SWH system offers significantly reduced size, weight and power (SWaP) to seamlessly integrate with body armor without adding unnecessary weight. In addition to reducing the physical load soldiers carry, the SWH provides an 85 percent reduction in cabling compared to other wearable hub systems, further simplifying ease of use for ground operators.

Viasat’s SWH is designed to provide the capability of much larger systems to meet expanding requirements for tactical edge compute and networking in a small form factor for dismounted users. As a complete solution, the SWH will offer a body-worn tactical gateway that can provide a level of interoperability only previously seen in larger transit boxes that are too big for dismounted operations. Viasat’s mobile software defined networking platform, NetAgility, will enable the SWH to utilize various tactical transports and advanced networking capabilities to improve situational awareness and data exchange. The edge compute capability will also offer a secure VPN, allowing the use of multiple transports and waveforms across a range of devices to provide resilient connectivity and safely share critical battlefield information.

“Tactical edge operators are seeking lightweight compute and resilient connectivity solutions to advance Battle Management Command, Control, and Communications (BMC3) capabilities. The Secure Wireless Hub is our latest tactical solution created to support this by addressing interoperability, automation, and security challenges for the dismounted user,” said David Schmolke, Vice President of Mission Connections and Cybersecurity, Viasat Government. “The SWH was designed with a focus on a user experience that enables the warfighter to focus on the mission and not the equipment.”

The SWH’s modular design allows tactical operators to integrate and configure connections for their mission, including LTE and Wi-Fi/Bluetooth for additional resilience. Users can also benefit from the Secure Wireless Hub App that seamlessly integrates with military devices as a single source configuration manager. As part of the development effort, Viasat worked with USSOCOM to undergo a full customer test and user assessment of the SWH system during the Strategic Level Joint SOF Fires Exercise last fall. (Source: ASD Network)

 

30 Jul 24. Kromek (AIM: KMK), a leading developer of radiation and bio-detection technology solutions for the advanced imaging and CBRN detection segments, is pleased to announce that its D3M detector has been named as the Personal Radiation Detector (“PRD”) under the UK Government Resilience Framework (the “Framework”). The Group has received its first order under the Framework from Merseyside Fire & Rescue Service, which will use the D3M for its Detection, Identification and Monitoring (“DIM”) vehicles.   The Framework is designed to strengthen the UK’s resilience system to prevent risks manifesting or crises happening where possible, addressing all serious threats to public safety and security. It focuses on the foundational building blocks of resilience, setting out a plan to 2030 to strengthen the frameworks, systems and capabilities that underpin the UK’s resilience to all civil contingencies risks.   The D3M is the only PRD that has been pre-approved for purchase under the Framework, which is scheduled to be in place for four years. As a result, all blue light service operators in the UK, such as fire, police, ambulances and first responders, can purchase the D3M detector for projects under the Framework without going through a separate approval process.

Merseyside Fire & Rescue service is the first of many potential customers in the UK to have bought the D3M under their Detection, Identification and Monitoring (DIM) Equipment Uplift project, which involves acquiring equipment to enhance their capabilities for detection of Chemical, Biological, Radiological, and Nuclear (“CBRN”) threats. The customers are all blue light services in the UK – ambulance, fire and police. This is a sole supplier framework for this a category of products which allows any blue light organisation to buy directly without tendering. The original UK potential order before cuts was estimated to be 8000 units, the amount now is estimated at 3500 units plus any exports. This updates an earlier release of this contract showing the possible new customers.

 

30 Jul 24. New malware variant accentuates security, information theft risks to Android users. On 29 July, the cyber security firm Kaspersky reported that unnamed threat actors have targeted Android users with a new version of the ‘Mandrake’ spyware since 2022. Threat actors distributed Mandrake via five fraudulent applications available on the legitimate Google Play platform. Upon installation, Mandrake establishes communication with actor-controlled infrastructure to collect data and prompt victims to download additional malicious packages. Although the objective of this campaign is unclear, there is a realistic possibility that threat actors sell sensitive data and access to devices on the dark web for illicit profit. The spyware notably hides its malicious code in a native library to achieve prolonged obfuscation. Additionally, it checks for the presence of security tools, highlighting the increased sophistication of the spyware’s detection evasion capabilities. This incident underscores threat actors’ ongoing development of Mandrake since it was first detected in 2020, accentuating security and information theft risks to global Android users in the short-to-medium term. (Source: Sibylline)

 

26 Jul 24. Cyber Update Key points.

  • New cyber campaigns capitalise on the CrowdStrike IT outages, raising security and disruption risks (see Sibylline Cyber Daily Analytical Update – 22 July 2024).
  • A new ‘Play’ ransomware variant heightens security and financial risks from cyber criminals (see Sibylline Cyber Daily Analytical Update – 23 July 2024 and our Technical analysis below).
  • A new industrial control systems (ICS) malware disrupted heating provision in Ukraine, elevating security and disruption risks to critical infrastructure (see Sibylline Cyber Daily Analytical Update – 24 July 2024).
  • New malware strains targeting organisations in the Asia-Pacific, sustain elevated espionage risks from the Chinese state-sponsored group ‘Evasive Panda’ (see Sibylline Cyber Daily Analytical Update – 25 July 2024 and our Technical analysis below).
  • The exploitation of three new vulnerabilities underscores elevated information theft and supply chain risks from cyber criminals (see Sibylline Cyber Daily Analytical Update – 26 July 2024).

Technical analysis of weekly stories

The ‘Play’ ransomware group targeted VMware ESXi virtual machines (VMs) with a new version of their custom ransomware. Play typically uses several tools such as the ‘Coroxy’ backdoor, NetScan and WinSCP to identify attack vectors and deploy the ransomware. Upon initial infection, the ransomware conducts a series of checks to ensure it is running in an ESXi environment before executing any additional commands. Notably, it evades detection by automatically terminating and deleting itself from compromised systems if it does not detect ESXi environments. The payload then identifies and powers down all VMs on the system by executing a series of shell script commands. This enables the threat actors to encrypt all VM files, issuing a ransom demand for illicit profit. Additionally, the URL hosting the Play payload can be traced back to another cyber criminal group, ‘Prolific Puma’, highlighting potential co-operation between the two groups. Prolific Puma typically generates domain names via a random destination generator algorithm (RDGA) and provides URL shortening services to enable other cyber criminal groups to evade detection. Play’s development of new custom ESXi malware likely points to the group’s intent to widen their victim pool and bolster success rates of ransom payouts.

The Chinese state-sponsored group ‘Evasive Panda’ has targeted organisations in Taiwan as well as US NGOs operating in China, with new versions of their custom malware. The group reportedly infiltrated targeted systems via the software supply chain or adversary-in-the-middle (AITM) attacks in multiple cyber operations. One of these campaigns installed an updated version of the ‘Macma’ macOS backdoor which provided the threat actors with additional espionage capabilities. These include the ability to adjust screenshot sizes and debug logging to obtain detailed information about compromised systems, alongside its original functionalities such as device fingerprinting, keylogging, audio capture and uploading and downloading files. Evasive Panda also exploited a vulnerability in Apache HTTP during one operation to deliver their ‘MgBot’ malware, highlighting the evolution of the group’s tactics, techniques and procedures (TTPs). We assess that these operations underscore Evasive Panda’s commitment and resources to continuously develop their custom malware. Additionally, the group has used a new backdoor, ‘Nightdoor’, since at least March alongside MgBot. Notably, the backdoor loads two files to establish persistence on compromised systems and contains embedded code to detect VMs, sandboxes and malware analysis environments as well as aid detection evasion. Furthermore, Evasive Panda used trojanised Android packages (APKs) as well as text and domain name system (DNS) interception tools in some of these operations, further pointing to the group’s likely ample resources and capabilities.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Enforce strict patch management policies to protect against known software vulnerabilities.
  • Implement network segmentation to segregate critical systems and networks and limit the spread of malware.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices.

Our cyber word(s) of the week: Domain generation algorithm

(Source: Sibylline)

—————————————————————————————————————————————————————————————————————————————————————————————————————————–

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

——————————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

July 26, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

———————————————————————————————————————————————————————————————————————————————————————————————————————————

25 Jul 24. Skydio Announces Upgraded Suite of Wireless and Connectivity Capabilities for Enterprise Drones.

Skydio Connect Fusion brings city-wide connectivity for Drone as First Responder (DFR) programs while new Skydio Connect Access Points bring new capability to rural, urban and battlefield environments, further enabling beyond-visual-line-of-sight (BVLOS) operations

July 25, 2024 02:04 PM Eastern Daylight Time

SAN MATEO, Calif.–(BUSINESS WIRE)–Skydio, the leading U.S. drone manufacturer and world leader in autonomous flight, today announced Skydio Connect Fusion and Skydio Connect Access Points. Learn more about these products and overall connectivity improvements on Skydio’s blog.

The drone world’s first multi-modal connectivity solution

Historically, drone platforms relied on point-to-point, line-of-sight connectivity, which can easily lose connection against obstacles such as buildings, forests and hillsides. DFR initiatives require uninterrupted, continuous connectivity across the entire city. Skydio Connect Fusion seamlessly combines modular point-to-point radio systems with 5G and LTE cellular networks to create the first-ever city-wide drone connectivity solution built for Drone as First Responder operations, enabling uninterrupted connectivity across varied terrains and environments. Using Fusion, Skydio X10 will seamlessly transition to the best connectivity network option available at any point in the mission.

It will be implemented in phases with initial capabilities available this fall. Any Skydio customer with a 5G-enabled X10 in the U.S. who hasn’t yet purchased Skydio Connect 5G will have access to a free trial when it’s released.

New Skydio Connect Access Points bring connectivity to anywhere its needed

Oftentimes the best place to put a radio is some distance from an operator or another control device like a Dock. Providing extended connectivity to the drone on the same point-to-point radio as the controller, Skydio Connect Access Points can provide a safe distance buffer for drone operators and can also act to increase network coverage throughout a city or region. Access Points are dedicated radio units that broadcast signals connecting to the X10 and X10D. With an ethernet backhaul, Access Points can be connected to local networks, the controller over long wired connections or even Starlink for command and control as well as data streaming. Skydio Connect Access Points are already in testing and will be generally available early next year. (Source: BUSINESS WIRE)

 

25 Jul 24. Asia-Pacific: New malware strains sustain elevated espionage risks from Chinese state-sponsored groups. On 23 July, the software company Symantec reported that the Chinese state-sponsored group ‘Evasive Panda’ has targeted organisations in Taiwan and US NGOs in China with new versions of their custom malware. The group reportedly infiltrated targeted systems via the software supply chain or adversary-in-the-middle (AITM) attacks, likely to steal sensitive information. One of these campaigns installed an updated version of the ‘Macma’ backdoor which provided the threat actors with additional espionage capabilities. Evasive Panda also deployed a new backdoor, ‘Nightdoor’, and an updated version of their malware, ‘MgBot’, highlighting the group’s continuous development of its arsenal. Additionally, the group used trojanised Android packages (APKs) as well as text and domain name system (DNS) interception tools, pointing to Evasive Panda’s likely ample resources and capabilities. Chinese state-sponsored actors will likely continue routinely conducting espionage operations to bolster their economic and security posture, sustaining elevated security and espionage risks to organisations in the Asia-Pacific region. (Source: Sibylline)

 

23 Jul 24. Lockheed Martin’s Skunk Works® and KX Shaping the Future of Open Mission System Architectures. Today, at the Farnborough Air Show, Skunk Works®, the renowned Advanced Development Programs division of Lockheed Martin (NYSE: LMT), and KX, a global leader in vector-based, time-series data management, announced a new collaboration focused on the evolution of Open Mission System architectures.

KX has engaged with Skunk Works to combine kdb+, the world’s fastest analytical database for time-series data, with Lockheed Martin’s leading-edge and next-generation AI and data tooling technologies. KX has cornerstone locations in the United Kingdom and the formal collaboration will create a UK-sovereign, real-time situational awareness model that can be applied across the armed forces for combined joint all-domain command and control (CJADC2), which will allow for greater connectivity, coordination, and faster access to data for enhanced decision-making and operational agility.

The two organisations have been experimenting and showcasing innovation and competitive advantage in the provision of real-time, data-driven decision-making capabilities that allow operational users to respond more quickly to threats in theatre.

These collaborative efforts evidence Lockheed Martin’s commitment to partnering with UK industry, and all allies, to demonstrate interoperability with international sovereign systems.

“Skunk Works has a long history of innovation and incorporating cutting-edge technologies into our systems”, explained Atherton Carty, vice president of business development at Skunk Works. “Our work with KX is part of an initiative to add unique capabilities to our systems through expanded relationships with specialized industry suppliers. Skunk Works develops solutions that keep our customers ahead of ready, leveraging the expertise of in-country companies to build stronger alliances is a key enabler for us to support our domestic and international customers’ mission needs.”

“Today marks a major milestone for KX,” said Gary Connolly, vice president aerospace, defence and space at KX. “Skunk Works continuously pushes the technological boundaries of performance and innovation, while KX has a proven ability to deliver unmatched value to those who operate in the toughest data management environments. Together, we endeavour to make data more accessible, enhance operational decision-making at scale, and deliver information to the warfighter exactly when it’s needed.” (Source: BUSINESS WIRE)

 

23 Jul 24. Horizon Technologies Signs £3.7m Contract for Multiple BlackFish™ Systems.

On the first day of the Farnborough Air Show, Reading, UK-based Horizon Technologies announced a £3.7m contract for BlackFish™ airborne SIGINT systems for a Middle East government customer.

Horizon Technologies’ BlackFish™ technology (which geolocates and monitors L-band emitters such as SatPhones) is the key to Horizon’s Multi-Domain Amber™ ISR Network Products.  Horizon Technologies’ ISR technology is embedded as an ISR Node on manned aircraft (rotary and fixed wing), UAVs, ships, terrestrial ground stations (AmberPersistent™), and in space, on LEO (Low Earth Orbit) Amber™ SIGINT satellites.

Each domain offers unique advantages to government and non-government customers, and Horizon Technologies is the only commercial company which offers such a comprehensive, integrated, total ISR solution.  Aircraft and naval solutions offer the advantages of quick reaction man-in-the-loop crews, UAV payloads offer long-duration missions, the upcoming Amber™ space-based constellation offers worldwide coverage, and ground-based AmberPersistent™ offers 24/7 ISR coverage over thousands of sq/km to cover sensitive strategic regions, and is already in operation with a FiveEyes user.

Horizon Technologies’ CEO John Beckner stated, “Our business continues to expand, and we are now selling our cutting-edge products into the FiveEyes community.  Thanks to the generous support of the UK Space Agency, our Amber-2 (Phoenix Mission) satellite will be launched in early 2025, and several customers are already buying complementary AmberPersistent™ stations for persistent 24/7 SIGINT collection.”

Beckner noted that “The performance of our products in Ukraine and the Mid East has clearly shown the value of our sophisticated airborne SIGINT capabilities to provide real-time data to our NATO and Allied end-users.  In the maritime world, we are offering customers unique RF signatures of commercial vessels to track ‘dark vessels’ who no longer use AIS at all times.”  “Besides the scope and breadth of our solutions, we offer a variety of commercial options to customers:  from the sale of hardware, to include ISR space-based payloads and even complete turn-key ISR satellite constellations, to worldwide ISR data via subscription.”

 

23 Jul 24. Global: New ransomware variant heightens security, financial risks from cyber criminals. On 22 July, international news outlets reported that the ‘Play’ ransomware group is targeting VMware ESXi virtual machines (VMs) with a new version of their custom ransomware. The group typically uses tools such as the ‘Coroxy’ backdoor, NetScan and WinSCP to identify attack vectors and deploy the ransomware. This Play variant powers down all detected VMs and encrypts all files before issuing a ransom demand to garner illicit profit. Additionally, it evades detection by automatically deleting itself from compromised systems if it does not detect ESXi commands. The threat actors also incorporated URL shortening provided by the cyber criminal group ‘Prolific Puma’, highlighting possible co-operation between the groups. We assess that the development of new custom ESXi malware likely points to the threat actors’ intent to widen their victim pool. Play increased its targeting of the manufacturing and professional services sectors between January and June, heightening ongoing security and financial risks.(Source: Sibylline)

 

22 Jul 24. Ultra Intelligence and Communications (Ultra I&C) has successfully earned a continuous Authority to Operate (cATO) for ADSI®, its premier Command and Control (C2) gateway currently fielded across the US Joint Forces and over 35 coalition partners. This achievement is a historic first for Cloud Based Command and Control (CBC2) gateway system, enabling operators to rapidly field ADSI and related system upgrades onto classified networks for immediate use.

The cATO designation for ADSI also enables developers to push validated code into production on an ongoing basis, resulting in shorter development cycles, quicker feature deployment and reduced cost while providing a more secure capability for mission operations. This modernization milestone also resolves existing interoperability challenges among a large volume of data links, setting a new standard for data utilization in support of mission success.

“This achievement represents a turning point in realizing the CJADC2 vision of delivering secure, seamless interoperability between joint and coalition systems for decision advantage,” said Bradford Powell, president of Command, Control, Intelligence, and Encryption for Ultra I&C. “The ADSI continuous Authority to Operate enables the rapid deployment of new CBC2 mission modules as quickly as they’re developed for the warfighter – when and where they’re most needed.”

Accreditation was achieved following rigorous evaluation through Second Front Systems’ Game Warden product. Second Front is a public benefit, venture-backed software company that equips defense and national security professionals for long-term, continuous competition for access to emerging technologies. “This achievement underscores our joint commitment to enhancing the strategic capabilities of the DOD, while safeguarding code development and accelerating the delivery of mission-critical CBC2 solutions to the warfighter,” said Tyler Sweatt, CEO of Second Front Systems. (Source: PR Newswire)

 

22 Jul 24. BAE Systems’ (LON: BA) strategic partner Stellar Blu Solutions has completed qualification and earned supplemental type certification on the multi-orbit Sidewinder aero terminal using BAE Systems’ Ku-band electronically scanned antenna (ESA). The milestone enables the companies to begin mass production and installation of the antennas to support in-flight connectivity (IFC) on commercial aircraft, business jets, and other military and government platforms.

BAE Systems’ strategic partner Stellar Blu Solutions has completed qualification and earned supplemental type certification on the multi-orbit Sidewinder aero terminal using BAE Systems’ Ku-band electronically scanned antenna (ESA). (Credit: Stellar Blu Solutions)

In March, the ESA completed its DO-160 airborne equipment qualification. The antenna completed qualification from its original design and moved directly to production, showcasing its design maturity, product quality, and strong heritage. Upon completion of flight testing in June, the Sidewinder terminal received its first supplemental type certification (STC) from the Federal Aviation Administration, opening the door for airlines to begin integrating the system onto regional jets. The terminal will continue with global performance validation and testing with a second aircraft, including in polar areas.

With these requirements met and Sidewinder now in service, BAE Systems and Stellar Blu have ramped production and begun shipment to meet more than 1,000 existing orders, including several hundred installations scheduled over the next year. In parallel, the companies continue their collaboration on next generation terminal designs focused on Ku and Ka low-Earth orbit (LEO) optimized terminals.

“The need for quality in-flight connectivity is growing every day, as displayed by our already considerable number of orders,” said Paula Burns, vice president and general manager of Tactical Solutions for BAE Systems Space & Mission Systems. “This is a major milestone for both BAE Systems and Stellar Blu, and it will serve as a building block as we continue to advance these capabilities for our commercial and military customers.”

BAE Systems designs and produces the transmit antenna, receive antenna, and antenna control software that Stellar Blu integrates into its Sidewinder terminal. Sidewinder is a complete aero terminal, and the full kit includes all external and cabin components to support internet service providers offering multi-orbit connectivity. Integrator kits are available for government applications. Stellar Blu was responsible for the qualification and STC process for the terminal.

“Our collaboration is foundational to our success, which is reflected in our backlog and the overwhelming interest in every aero market,” said Tracy Trent, CEO of Stellar Blu Solutions. “We continue to invest in the adaption of Sidewinder with airframe original equipment manufacturers and the development of new products, utilizing proven BAE Systems technology to bring a range of solutions to our customers.”

BAE Systems’ antennas support multi-orbit satellite communications and have been extensively flight tested on LEO and geostationary orbit satellite networks. The low-profile antenna met all qualification requirements without requiring an external radome, reducing the cost and installation complexity while improving radio frequency performance.

(Source: PR Newswire)

 

22 Jul 24. oneNav’s L5-direct™ Technology Enables Defense and Location Services to Overcome GPS Jamming and Spoofing in Israel.

  • oneNav’s first-of-its-kind GPS technology proves resilient to widespread GPS interference in live conflict zone near Haifa, Israel, where leading smartphone brands failed.
  • Live field test comes as attacks on GPS systems are increasing globally, most notably Russia’s jamming of GPS systems across Europe.

GPS technology developer oneNav today announces the results of a groundbreaking real-world test proving the resilience of its first-of-its-kind technology to widespread GPS interference.

The tests took place in and around Haifa, Israel, and examined the performance of the GPS receivers in leading smartphone and smartwatch brands – the first such study to ever be conducted in an active conflict zone.

For this test, oneNav compared its L5-direct™ GPS receiver to receivers found in iPhone, Samsung Galaxy and Google Pixel smartphones and Garmin watches. While these receivers all experienced navigation failure due to GPS interference, oneNav’s L5-direct™ test solution maintained accurate location fixes despite active jamming and spoofing.

This resilience is due to L5-direct™ being able to directly acquire the most modern band of GPS signals, known as L5, and bypass the outdated L1 GPS signal which was first invented more than 50 years ago. While current commercial GPS receivers in smartphones, car navigation systems, and airplanes are able to process the L5 band, they can only do so in a hybrid system that must first acquire L1. This means that, to use the most modern GPS signal available, a device must rely on L1 signals – the very same signals that are currently being jammed in Israel and elsewhere worldwide.

Given the vital role that GPS plays – not only for smartphones, but also for aviation, emergency response services and military use – relying on the L1 signals in a hybrid GPS system is an enormous national security and public safety risk.

However, L5-band signals are 30x harder to jam and interfere with compared to L1, and they offer superior performance in difficult-to-navigate areas such as urban canyons and tree-covered regions. This new technology has the potential to revolutionize GPS in our most essential devices and across our most critical industries.

“We now have clear, indisputable evidence that L5-direct™ is resilient to widespread GPS jamming and is able to provide precision location in GPS-contested environments,” said oneNav CEO Steve Poizner. “This test is a real-world validation of our first-of-its-kind technology and shows the potential for L5-direct™ to revolutionize how we use GPS for civilian and military purposes in Israel and globally.”

While the field testing took place in Israel, GPS interference is a global security concern due to the increase in attacks on GPS systems worldwide. In Ukraine, Russia is countering American-made smart weapons on the battlefield through GPS-jamming technology and is accused of interfering with GPS navigation systems in more than 46,000 flights across Europe. An April 2024 field study by oneNav confirmed widespread Russian GPS jamming from Finland to Turkey, with the L5-band signal proving immune to Russian L1 jamming attempts.

“As our adversaries’ GPS jamming capabilities become more sophisticated, the need to modernize this crucial technology could not be clearer,” said oneNav Advisory Board Member Rear Admiral Mark Montgomery (Ret.), also a Senior Director of the Center on Cyber and Technology Innovation at the Foundation for Defense of Democracies. “Make no mistake, GPS interference can happen in any war zone and even our domestic critical infrastructures are at risk. As evidenced by oneNav’s groundbreaking field study, the United States has the technology to combat these threats, we just need to implement it.”

oneNav’s IP core is currently available for evaluation and integration by select chip developer partners and its low-SWaP (space, weight and power) chips and modules will soon be available for select partners. L5-direct™ is compatible with global navigation satellite system (GNSS) constellations including GPS, Galileo, BeiDou and more. (Source: BUSINESS WIRE)

 

23 Jul 24. ELT Group at the Farnborough International Airshow 2024. The Group will show its innovative solutions in the field of electromagnetic spectrum operations. ELT Group attended the 2024 edition of the Farnborough International Airshow, from 22 to 26 July, with its innovative solutions in the field of electromagnetic spectrum operations in all operational domains.

A constant activity in R&D is behind the technology trend that sees new solutions increasingly oriented to the needs of interoperability and integrated management of the electromagnetic spectrum across all operational domains, extending capabilities to space and cyberspace.

ELT Group continues its important role in upgrading the self-protection system of the EFA Typhoon aircraft to enable the platform to operate at its best in the years to come, in a context of continually evolving operational requirements and with technological solutions that will facilitate the transition to the future generation of fighter aircrafts. Moreover, thanks to the experience and know-how acquired, ELT Group is a partner in the Isanke & ICS domain of GCAP, the programme for the development of the sixth generation fighter aircraft.

The Group has developed advanced solutions to offer a complete defence capability, providing alarm, surveillance, intelligence and active countermeasure, in an integrated sensor layer with an embedded management capability capable of allocating operational priority between sensors and deep functional integration between them.

The company’s offer includes the integrated Virgilius system, for Alarm, Surveillance and Countermeasure functionality. It is conceived to perform emitter detection, classification, identification and to counter a large threat variety and installed on any fixed and rotary wing platform.

Other solutions can be mounted externally to the platform, such as the EDGE Escort Jamming, that provides the function of self or mutual protection of combat aircrafts, housing Alarm and Countermeasure functionalities in the same architecture.

ELT Group also offers fully digital alarm systems, such as the RWR ELT162, and the new DIRCM ELT577 that, based on Quantum Cascade Laser (QCL) technology, provides a reliable and effective protection of small and medium avionics platforms against surface to air missile threats.

The solutions offered by the company also fall within the scope of countering mini-micro and small drones. In fact, ELT Group’s offer includes the ADRIAN (Anti-Drone Interception Acquisition Neutralisation) system, a Counter-UAV solution capable of intercepting and neutralising LSS (Low-Small-Slow) UAVs in different scenarios and environments, including urban ones. Thanks to a modular architecture, the ADRIAN system can be adapted to multiple operational requirements and their continuous evolution. Moreover, with the support of Cy4gate, a company of the group specialising in the Cyber domain, ELT Group has increased the capabilities of Adrian with the ‘Cyber RF’ functionality, which makes the product capable of detecting and reacting effectively to new and more complex operational scenarios, both military and civil, threatened by new-generation malicious drones.

The Group continues to increase its involvement in the Space EW domain following the launch of SCORPIO, the payload developed by the company and put into orbit last year for electronic intelligence activities. Visitors can find out more about ELT Group’s activities in the Space domain on the company’s stand (Hall 1 Booth 1340), where the Scorpio model will be on display.

Moreover ELT Research & Innovation Team is working with the NATO Science and Technology Organization CMRE (Centre for Maritime Research and Experimentation) located in La Spezia for a joint Spectrum Monitoring data acquisition. The joint activity encompasses assets deployed at sea. ELT Group is providing data acquisition with its space systems SCORPIO to conduct a joint study exploiting the result of the fielded experiments.

 

19 Jul 24. Global: Cyber attack spike heightens security, espionage risks from Chinese state-sponsored groups. On 18 July, the cyber security firm Mandiant reported a significant increase in cyber attacks from the Chinese state-sponsored group ‘APT41’ since at least 2023. The group targets organisations in the shipping, logistics, technology and automotive sectors across Asia and Europe. APT41 typically downloads web shells on compromised servers and executes a dropper to install the ‘BEACON’ backdoor. This enables them to establish communication with their command and control (C2) infrastructure and deploy additional malware. Notably, the group often uses a Google Workspace account as their C2 infrastructure, blending in with legitimate traffic to evade detection and achieve prolonged persistence. Additionally, the group uses ‘SQLULDR2’ and ‘PINEGROVE’ to copy and exfiltrate data, highlighting the campaign’s focus on reconnaissance and espionage. Chinese state-sponsored groups routinely target competitive sectors to bolster their economic posture relative to their perceived adversaries. We assess that APT41’s activities heighten security and espionage risks to global organisations in the long term, especially those with interests that do not align with China’s own. (Source: Sibylline)

 

19 Jul 24. Cyber Update.

Key points

  • A data breach affected nearly 109 m users, sustaining elevated information theft and reputational risks via the software supply chain (see Sibylline Cyber Daily Analytical Update – 15 July 2024).
  • A new backdoor, ‘BugSleep’, points to elevated espionage and security risks from the Iranian state-sponsored group ‘MuddyWater’ (see Sibylline Cyber Daily Analytical Update – 16 July 2024 and our Technical analysis below).
  • A new campaign targeting developers points to amplified financial and information-theft risks from Iraqi cyber criminals (see Sibylline Cyber Daily Analytical Update – 17 July 2024 and our Technical analysis below).
  • A new campaign exploiting the recent assassination attempt against former US president Donald Trump underscores elevated financial and cryptocurrency-theft risks.
  • A significant spike in cyber operations heightens security and espionage risks from the Chinese state-sponsored group ‘APT41’ (see Sibylline Cyber Daily Analytical Update – 19 July 2024).Technical analysis of weekly stories

The Iranian state-sponsored group ‘MuddyWater’ is targeting organisations in India, Israel, Portugal, Saudi Arabia and Turkey with a new backdoor called ‘BugSleep’. The campaign targets a diverse range of sectors including government entities, municipalities, media outlets, travel agencies and journalists. It accessed targeted organisations via phishing emails (disguised as invitations to webinars or online courses) to trick potential victims into clicking on a malicious link. The link then redirects users to the legitimate file-sharing service Egnyte which stores the BugSleep payload. Alternatively, some phishing emails contained a custom malware loader designed to inject BugSleep into multiple apps such as Google Chrome, Microsoft Edge, Microsoft OneDrive and PowerShell. The backdoor establishes communication with the actor-controlled infrastructure, sending initial system information including computer name and username. BugSleep can then perform several additional tasks. These include creating scheduled tasks to ensure persistence, sending file content to the command and control (C2) infrastructure and writing content into files. It also enables two code flags to evade endpoint detection and response (EDR) solutions. This highlights the sophistication of the group’s tactics, techniques and procedures (TTPs). In this campaign, MuddyWater used English and less sector-specific themes to craft phishing emails, suggesting that the group has shifted to targeting a wider victim pool. The group has also reportedly created several different versions of BugSleep to address technical bugs, demonstrating their commitment to continuous malware development.

Unknown Iraqi cyber criminals are targeting developers and their affiliated companies in a new and ongoing information theft campaign. The threat actors upload malicious files to the legitimate open-source Python Package Index (PyPI) file repository to obtain access to targeted systems. Upon obtaining initial access, the malicious files establish direct communication with an actor-controlled Telegram chatbot that functions as their command and control (C2) infrastructure. The malware then follows a systematic approach, searching for files of interest in the compromised system’s root and data centre infrastructure management (DCIM) folders. Although the nature of the stolen data is unknown, we assess the group likely stole intellectual property and valuable assets to sell on the dark web for illicit profit. Notably, the Telegram bot contained over 90,000 messages dating back to at least 2022, pointing to the scale and longevity of this operation. Additionally, the bot operator maintained numerous other bots also based in Iraq, suggesting this operation forms part of a wider cyber criminal enterprise. We assess that the longevity of this operation is also evident in the evolution of its operations which initially focused on purchasing Telegram and Instagram views, followers, spam services and discounted Netflix memberships.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering attempts.
  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices.

Our cyber word(s) of the week: Root folder

(Source: Sibylline)

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

July 19, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

———————————————————————————————————————————————————————————————————————————————————————————————————————————————-

18 Jul 24. Kromek’s Radiation Detector Selected by Merseyside Fire and Rescue Service. Kromek, the designer and manufacturer of radiological and biological detectors, based in Sedgefield, Co. Durham, announced that its D3M radiation detector has been selected by the Merseyside Fire and Rescue Service under Lot 6 of the Detection, Identification and Monitoring (DIM) Equipment Uplift contract on the UK’s National Resilience  Framework. The Framework, which supports all blue light services, is scheduled to be in place for four years and an initial order has already been placed specifically for the DIMS vehicles.

The D3M is a combined gamma/neutron Personal Radiation Detector with superior sensitivity and offers unprecedented situational awareness, constantly monitoring the radiological and nuclear environment. It is able to detect even shielded fissile or Special Nuclear Material and its lightweight design and small form function means that it can be body-worn or pocket-carried by first responders, without adding to their equipment load.

The D3M displays both the current and accumulated dose rates and features an ultra-low false alarm rate – over six times better than the ANSI standard – allowing first responders to operate safely and efficiently in critical situations. Spectral data is saved on the device’s internal storage for secondary adjudication.

Additionally, the D3M can be connected to a phone and Kromek’s ID app, which allows the D3M to not only detect radioisotopes but also identify the source. The networking capability of this pairing allows the D3M to integrate into any existing system, enabling multiple detectors to be monitored from a single hub with automatic alerts and information sent instantly for comprehensive situational awareness.

Commenting on Kromek’s win, Craig Duff, Commercial Director, said: “we are delighted to have been selected by Merseyside Fire and Rescue Services, acting on behalf of the National Fire Chiefs’ Council,  to provide detectors for the DIMS contract. Our devices are designed to be particularly user-friendly and require minimal training. The D3M can ensure the safety and security of first responders and will help them to identify potential radiological threats around the United Kingdom as quickly as possible.”

 

19 Jul 24. FREQUENTIS Drone-Based CBRN Detection System Advances European Defence. In a landmark achievement to strengthen European security, CNS Solutions & Support, as a member of the Frequentis Group, has announced the completion of the CBRN Reconnaissance and Surveillance System (RSS).

In response to evolving threats, the Frequentis Group has developed an innovative data fusion cell (DFC) to integrate sensor and uncrewed systems data, through its incident crisis management (ICM) technology. The DFC serves as a centralised hub, seamlessly integrating information from various sources including sensors and drones, therefore enabling comprehensive analysis and rapid decision- making.

“Our DFC has transformed CBRN defence in Europe, empowering military personnel with real-time intelligence to respond swiftly and effectively to emerging threats,” Peter Skiczuk, Frequentis Vice President Defence.

“CNS is dedicated to enhancing CBRN defence technologies. Future phases will focus on readiness for full military deployment, ensuring continued security for European nations”

says Stefan Ringsmuth, Managing Director of CNS Solutions & Support GmbH.

The adoption of state-of-the-art technologies, including drones equipped with sensors and uncrewed robotic vehicles heralds a new era in CBRN defence. These uncrewed assets swiftly detect and assess hazardous substances, mitigating risks to human personnel. By leveraging data fusion and real-time analysis, commanders gain critical insights to make informed decisions, ensuring the safety of both military personnel and civilians.

“Normally, it would take us two hours to achieve this result. With the use of these modern technologies, we can reduce this time to 40 to 45 minutes, and we don’t have to bring soldiers directly to the source of danger, as this is taken over by robots and drones,”

says Colonel Schlechter, Commander of the CBRN Defence Center/Austria (ÖBH). (Source: UAS VISION)

 

16 Jul 24. Teal Group’s Market Overview, published in its new Military C4I & EW Systems Briefing, forecasts the 10-year market for UAV/Drone SIGINT & Electronic Countermeasures (ECM) Systems to be worth $31bn over the next decade. Signals Intelligence (SIGINT) has become not only a primary focus of electronic warfare (EW) over the past decade or two, but it now garners genuine “A-list” funding for UAVs as well as manned airborne platforms. SIGINT had a relatively low profile among manned EW programs in the Cold War, while jammers and radar and missile warning systems received most of the attention and funding. But that changed with the conflicts in Afghanistan and Iraq, and the threat continues today from non-state actors worldwide – new geographies of conflict resulted in changing needs.

Now again forecast to be a major market in the future – as it was in the past – is electronic attack (EA), including Suppression of Enemy Air Defenses (SEAD). With the 21st century iteration of the Cold War’s near-peer threats (still Russia and China), many EA systems are either planned for, already aboard (as classified programs), or will soon be shifted to UAVs – especially stealthy Unmanned Combat UAVs (UCAVs). We include current and speculative UCAV EA program forecasts, including classified programs.

By 2020, most of the biggest SIGINT programs of record for UAVs were already well-established, with production underway in most cases or with first generation system production already complete. Despite this relative maturity, Teal Group forecasts the SIGINT market (when excluding UAV and UCAV EA) to continue to grow strongly, from $1.3bn in FY23 to $3.1bn in FY32, with a solid 10.3% CAGR.

But if production of EA systems for US Navy/Marine Corps, Army, and Air Force UCAV and UAV programs – including likely classified programs – is going ahead as we forecast, we see EA funding growing even more substantially than SIGINT as production ramps up – more than tripling from $520m in FY23 to $1.7bn in FY32, with a whopping 13.9% CAGR.

Regarding market segments, treated in detail in the new Briefing, delays and program cancellations and truncations (Global Hawk) have limited production of all major planned endurance UAV SIGINT programs so far. The plans of a few years ago, for major unclassified UAV SIGINT fleets for all services, have not yet been realized. The UAV SIGINT market will continue to grow steadily over the next few years, but perhaps without dominant unclassified programs.

Instead, much as Teal Group forecasts for the future of other UAV sensor markets, classified Combat UCAV and tactical/mini/ nano-UAV markets will provide the highest-growth markets and the largest markets in the out-years of our forecast. But as is evident from a close reading of our forecast charts and graphs (see the Briefing), the SIGINT component of this growth will remain steadier and more stable, even when including speculative classified funding forecasts. Production numbers of UCAVs will likely not be large this decade, and UCAV SIGINT systems may be less expensive than systems already in service on ISR HALE/MALE UAVs. Small Tactical, Mini-, and nano-UAVs will increasingly provide close-in tactical SIGINT for the soldier, but much funding will be for basic research and miniaturization of simple capabilities.

Instead, the electronic attack (EA) market for SEAD (Suppression of Enemy Air Defenses) and strike UCAVS will see major funding; it will grow from a very small market a few years ago to a dominant market later this decade. This represents a shift back to traditional electronic warfare (EW) funding as discussed above – manned-equivalent systems and funding for more traditional air strike missions versus near-peer opponents such as Russia or China. Most of these programs will remain classified, but our funding forecasts in line with legacy manned EA programs will see the UCAV EA market grow from just $186m in FY16 to almost $1.1bn forecast in FY30 – when we forecast full-rate production will have ramped up for the classified USAF SEAD/Strike UCAV.

Market shares and access are difficult to forecast with such a large “black” share of the total market. But with Airborne Signals Intelligence Payload (ASIP) aboard some US Air Force Global Hawks, with ASIP QRC systems aboard many other non-classified USAF endurance UAVs (Reaper), and with an ASIP derivative possibly nearing or in production for future Triton SIGINT UAVs, Northrop Grumman will remain important in the contracted, unclassified UAV SIGINT market, with at least $210 m in prime contractor funding in the next 10 years.

But Teal Group forecasts the new leader in the UAV SIGINT & EA market from FY23-FY32 will be Lockheed Martin with the US Army’s Multi-Function Electronic Warfare (MFEW) system that will, “provide Maneuver Commanders with an organic airborne offensive Electronic Warfare (EW) capability.” The MFEW Air Large (MFEW-AL) system will be installed on the Army’s MQ-1 Gray Eagle MALE UAV to provide Offensive Electronic Attack (OEA) and Electronic Warfare Support (ES). This program should be worth nearly $700 m to Lockheed Martin.

However, the Top Six prime contractors for UAV SIGINT & EA discussed in Teal Group’s Military C4I & EW Systems Briefing frankly show measly funding amounts from FY23-FY32 – due to the dominance of classified programs with unknown competitors, suppliers, and primes. Despite our also speculative “Other” forecast line for already contracted but unknown prime contractors, our “Available” funding forecast will comprise between 81% and 92% of the UAV SIGINT & EA market annually from FY23 through FY32, worth between $1.5bn and $4.5bn annually – totaling $27 bn in still-available funding in our forecast period.

 

16 Jul 24. Bittium Delivers Bittium Tactical Wireless IP Network™ System Products and Bittium Tough SDR Vehicular ™ Radios to Croatian’s Navy and Land Forces. Bittium delivers Bittium Tactical Wireless IP Network™ system products and Bittium Tough SDR Vehicular ™ radios to Croatian’s Navy and Land Forces. The modernization of the tactical communications of the Croatian Navy and Land Forces is part of the renewal of the command and control system of the Croatian Armed Forces. Bittium announced on June 6, 2024, that its Bittium Tactical Wireless IP Network™ System and Bittium Tough SDR Vehicular™ Radios have been accepted as tactical communications solutions for the armament of the Croatian Armed Forces.

Bittium has received a purchase order for the products and their accessories from IntellByte INFO, Bittium’s Croatian partner, and supplier of IT solutions, who supplies and integrates the tactical communications system entity for the Croatian Armed Forces. The purchase order is part of a four-year framework agreement between IntellByte INFO and the Croatian Ministry of Defence for the supply and integration of tactical communications systems for the use of different military branches of the Croatian Armed Forces.

The goal of the renewal is to enable real time situational awareness to support commanding the deployed troops of Croatian Armed Forces. The TAC WIN system is used to build a modular and survivable backbone network and the high performance Tough SDR Vehicular radios connect the Navy’s vessels as part of the network. Bittium Tough SDR Vehicular radios will also be used in Land Forces for seamless connectivity with Navy.

Bittium Tactical Wireless IP Network™

Bittium Tactical Wireless IP Network (TAC WIN) is a software-defined radio (SDR) based wireless broadband network system intended for military and public safety use. With the system, MANET (mobile ad hoc network), link, and connection networks can be formed into one logical IP network quickly, no matter what the location is. Bittium TAC WIN is compatible with existing fixed and wireless network infrastructures. The core of the system is a tactical router that enables users to freely form both wired and wireless broadband data transfer IP connections. The tactical router also enables connections to different types of terminals and other communication systems in order to connect them into a single communication network. In addition to the router, the system comprises three types of radio heads, and each radio head covers its own frequency band area and can be used for flexible formation of optimized network topologies for different communication needs. All the products of the system are designed for harsh conditions, and thanks to the system’s automated functions, the implementation of the system can be done quickly. Due to the software-based functionality of the Bittium TAC WIN system, it can be easily updated with additional performance, which allows it to be developed and maintained cost-efficiently throughout the whole lifespan of the system.

More information: Bittium TAC WIN system

Bittium Tough SDR™ product family

Bittium Tough SDR product family of tactical radios consists of Bittium Tough SDR Handheld™, tactical handheld radio for individual soldiers, and Bittium Tough SDR Vehicular™, tactical radio for vehicle installations. The Tough SDR radios help to produce and share real time situational awareness to all levels of the organization. This improves the performance and the effectiveness of the tactical troops, and leading the troops is easier based on the up-to-date situational awareness and more reliable connections. The uniquely wide range of frequency bands in the radios improves combat survivability. Using several waveforms, even simultaneously, improves compatibility and enables operations on different levels and missions. The radios are compatible with the NATO standardized ESSOR High Data Rate Waveform that enables tactical communications between troops from different nations. Together with the software-defined radio based Bittium Tactical Wireless IP Network™ (TAC WIN) system, used for forming a broadband mobile IP backbone network, it is possible to bring broadband data and voice to all mobile troops across the battlefield.

 

16 Jul 24. Global: New backdoor points to elevated espionage, security risks from Iranian-sponsored groups. On 15 July, the cyber security company Check Point Research revealed that the Iranian state-sponsored group ‘MuddyWater’ is targeting global organisations with a new backdoor called ‘BugSleep’. The campaign has targeted specific sectors (including government organisations and media outlets) in India, Israel, Portugal, Saudi Arabia and Turkey. The group obtains access to targeted systems via phishing emails. BugSleep is then downloaded onto compromised systems via legitimate file-sharing services, subsequently collecting sensitive information and executing additional commands. Notably, the backdoor contains several endpoint detection and response (EDR) evasion techniques; it can also inject itself into applications, highlighting the sophistication of the group’s tactics, techniques and procedures (TTPs). In this campaign, MuddyWater uses more generalised phishing lures that are often written in English, pointing to a wider target pool. We assess that this underscores the elevated security and espionage risks facing global organisations stemming from Iranian state-sponsored actors, especially as geopolitical tensions involving Tehran persist. (Source: Sibylline)

 

15 Jul 24. U.S., Singapore Cooperate on Data Analytics, Artificial Intelligence. Today, the Defense Department’s chief digital and artificial intelligence officer and Singapore’s deputy secretary for technology signed a new statement of intent for data analytics and artificial intelligence cooperation, said Secretary of Defense Lloyd J. Austin III.

Austin hosted an enhanced honor cordon and meeting welcoming Singapore’s Defense Minister Ng Eng Hen to the Pentagon.

This statement of intent will strengthen interoperability and promote the responsible use of AI, Austin said.

Austin noted some key bilateral cooperation items.

Singapore is one of 29 countries currently participating in the Rim of the Pacific, or RIMPAC, exercise in Hawaii, the secretary said.

About 25,000 personnel are participating in that exercise, which started June 26 and ends Aug. 2.

Austin thanked Ng for hosting leaders and senior military officials from nations in the Indo-Pacific region in late May and early June at the annual International Institute for Strategic Studies’ Shangri-La Dialogue.

Also in May, the two nations signed an important memorandum of understanding on defense innovation, he said.

“This will help both of our countries to source cutting-edge technology quickly and effectively,” Austin said.

In December, both nations finalized a supply chain security arrangement and are taking steps to strengthen its resiliency, he said.

Both militaries continue to train together across all domains: land, sea, air, space and cyber. And both nations have a shared vision for a free and open Indo-Pacific, Austin said.

“Singapore remains one of our most valued defense partners, and I’m proud that our defense partnership keeps growing stronger,” the secretary said.

Ng thanked Austin for his leadership of DOD and for strengthening partnerships. (Source: U.S. DoD)

 

15 Jul 24. Global: Data breach sustains elevated information theft, reputational risks via software supply chain. On 12 June, international news outlets reported that cyber threat actors targeted the telecommunications provider AT&T, instigating a data breach between May and October 2022. The breach affected nearly 109 m customers, exposing information pertaining to the duration and dates of phone calls and the phone numbers of service users. The threat actors reportedly hijacked AT&T’s account for the third-party IT cloud services provider Snowflake using stolen credentials. Although no sensitive information was stolen, there is a realistic possibility that threat actors could correlate metadata to reveal customers’ identities for future fraud activities. This highlights the role of third-party software vulnerabilities in sustaining security risks. In May, the cyber criminal group ‘UNC5537’ hijacked several Snowflake customer accounts to steal sensitive information, highlighting cyber criminals’ ongoing exploitation of third-party providers as initial attack vectors. Since April, unauthorised access attempts using stolen credentials have increased, amplifying security and reputational risks via the software supply chain. (Source: Sibylline)

 

15 Jul 24. Helsing bring AI capabilities to Estonia in strategic expansion. Greater autonomy is needed to operate UAS carrying warheads posing a considerable, asymmetric threat to expensive, protected platforms.

After talks on the fringes of the Nato summit in Washington, the German defence and artificial intelligence (AI) company Helsing approached Estonia’s Prime Minister Kaja Kallas to discuss its strategic expansion to Nato’s eastern flank on 11 July 2024.

As well as the establishment of Helsing Estonia OÜ, and its plans to equip Estonian Defence with necessary AI capabilities, the company extended its commitment with a pledge to invest €70m ($76.2m) in the Baltic defence industry over the next three years.

Kallas had previously announced the development of a national defence industrial park, efforts to amend legislation for the production of arms, and the creation of a new defence industry fund with an initial size of €50m on 24 May in the lead-up to the latest strategic move.

“The changed security situation in Europe has clearly shown the need for greater defence investments and has also highlighted the current bottlenecks in the defence sector,” she stated in her May speech at Stenbok House in Tallinn. “For defence companies to be able to create new solutions, they need the money and the infrastructure to do so.”

Notably, on the same day that Helsing Estonia was announced, the German company revealed it had raised €450m in a Series C financing round. The funds will be used for product development and research and development with a particular focus on capabilities to secure European sovereignty including protecting Nato’s eastern flank.

“This new funding round allows us to further up the tempo and invest in large-scale [research and development] and capabilities across all domains,” affirmed Helsing co-CEO Dr. Gundbert Scherf.

Europe’s collective defence

Particularly, Helsing Estonia will offer the wider Baltic region locally produced AI capabilities drawing on lessons from the conflict in Ukraine.

“We are seeing how readily available technologies can prove fatal for military equipment costing ms,” she added. “Cheap drones carrying warheads can deplete the reserves of even more sophisticated defence systems.”

Autonomy is needed to operate the cheaper uncrewed aerial systems carrying warheads whirring across the south and east of the wartorn nation posing a considerable, asymmetric threat to expensive platforms such as main battle tanks and infantry fighting vehicles.

In early June, Helsing entered a framework agreement with Airbus to explore AI technologies that will be used on the European Future Combat Air System ‘Wingman’, a “fighter-type drone concept” that operates alongside a centralised crewed fighter jet.

“Europe must allocate bns of euros to strengthen its defences,” she stressed. “We continue to call on all European partners and the European Commission to find more robust and direct ways to finance defence investments.”

Kallas’ statement indicates her priorities for expanding Europe’s collective defence form the top down. At the end of June, the Estonian leader was nominated to succeed as the European Union’s (EU) High Representative for Foreign Affairs and Security Policy in the coming months.

A leading voice for defence expansion and championing Western support for Ukraine in the war against Russia, Kallas’ stance on the security climate is clear. The High Representative is a diplomatic appointment established by the Treaty of Amsterdam in 1999. It encompasses a range of roles as the title suggests; it includes heading up the European Defence Agency and maintaining European interests on an uncertain and fragile world stage. These objectives will be implemented more systematically following the inauguration of the Union’s European Defence Industry Programme.

Established in March, the organisation will mobilise $1.63bn of the EU budget throughout 2025-27 to enhance their defence market competitiveness. The idea is to end their short-term measures since the start of the war in Ukraine for a more structural, longer-term approach to strengthening Europe’s defence industrial and technology base with new objectives. (Source: army-technology.com)

 

15 Jul 24. Improving cyber resilience of frontline forces in Europe.

Enhancing allied cyber defences through multinational Exercise Baltic Mule. International participants in Exercise Baltic Mule. MOD Crown copyright

Exercise Baltic Mule was a joint UK and Poland led exercise to reduce the cyber vulnerabilities of frontline military activity and ensure we can protect against future threats. The exercise helped to improve frontline units’ ability to withstand cyberattacks and continue their missions even when facing sophisticated cyber threats.

International participants gathered in Poland for the exercise – including from Canada, Estonia, Germany, Latvia, Lithuania, Poland, the UK, and the USA – a clear demonstration of the strength of our international cyber partnerships.

Exercise Baltic Mule was the first cyber mission assurance exercise to primarily focus on vulnerabilities within the forward land forces in Eastern Europe. These multinational forces protect the Baltic nations from aggression, as well as train together to improve integration amongst NATO allies.

The exercise explored how we make sure military supply plans are secure. Military experts from all the nations involved spent three days analysing potential threats to supply lines and communication systems, resulting in a comprehensive list of solutions and advice to address these threats. Such findings will be instrumental in refining the plans of the forward land forces and providing recommendations to present at the next Cyber Commanders Forum in September.

Exercise Baltic Mule played an important role in a move towards a more cyber-resilient force. As the cyber threats we face become increasingly sophisticated and frequent, Strategic Command will continue to work ever more closely with our NATO allies to defend against these threats. Exercises like Baltic Mule make sure the UK and our allies are better equipped to protect current and future military activity from cyber threats. (Source: https://www.gov.uk/)

 

12 Jul 24. Cyber Update Key points.

  • The emergence of a new ransomware-as-a-service (RaaS) operation points to elevated security and operational risks facing global firms (see Sibylline Cyber Daily Analytical Update – 8 July 2024).
  • A new highly sophisticated cyber espionage campaign conducted by the advanced persistent threat (APT) group ‘CloudSorcerer’ points to heightened security risks facing government entities (see Sibylline Cyber Daily Analytical Update – 9 July 2024 and our Technical analysis below).
  • The takedown of a large bot farm signals elevated disinformation risks stemming from Russian-linked threat actors ahead of November’s US presidential election (see Sibylline Cyber Daily Analytical Update – 10 July 2024).
  • A large-scale financially motivated campaign points to heightened financial risks ahead of the Paris 2024 Olympic Games (see Sibylline Cyber Daily Analytical Update – 11 July 2024).
  • The development of two new highly sophisticated strains of malware underscores the elevated espionage risks stemming from the Chinese state-sponsored group ‘APT41’ (see Sibylline Cyber Daily Analytical Update – 12 July 2024 and our Technical analysis below).

Technical analysis of weekly stories

A new APT, ‘CloudSorcerer’, is targeting Russian government entities in a highly sophisticated espionage campaign. Although the campaign’s initial attack vector is unknown, the threat group manually executed a new malware, also known as ‘CloudSorcerer’, on compromised systems. The malware itself typically executes a backdoor and/or a command and control (C2) module depending on which local processes it detects, highlighting its ability to adapt dynamically to different systems. The C2 module first establishes communication with the initial C2 server, namely a GitHub page designed to appear legitimate. The GitHub repository then initiates contact with three separate public cloud services – Microsoft Graph, Yandex Cloud and Dropbox – facilitating asynchronous data exchange between the backdoor and the C2 infrastructure. Subsequently, the backdoor module collects information from the compromised system, such as the computer name, user name, Windows information and system uptime, storing it in a specially crafted structure. It then sends the stored data to actor-controlled infrastructure via two separate flows (a backdoor and an information-gathering flow). Furthermore, the backdoor module is able to receive additional commands from the C2 infrastructure, which includes collecting information about system hard drives, files and folders, as well as executing shell commands and creating, writing and reading data (and running additional advanced functionality). CloudSorcerer’s complex communication infrastructure demonstrates a well-planned approach to cyber espionage, further highlighting the malware’s significant sophistication.

The Chinese state-sponsored group ‘APT41’ is targeting organisations in Southeast Asia with two new strains of malware, ‘DodgeBox’ and ‘MoonWalk’. Although the campaign’s initial attack vector is unknown, APT41 first downloads the malware DodgeBox onto compromised systems via a legitimate executable. The malware notably shares similarities with another loader used by APT41, ‘StealthVector’, though it boasts several improvements. Namely, DodgeBox employs ‘call stack’ spoofing to remain undetected within compromised systems. More specifically, call stack spoofing obscures the origins of application programming interface (API) calls, making it more challenging for endpoint detection and response (EDR) solutions and antivirus systems to detect malicious activity. Additionally, DodgeBox loads the backdoor MoonWalk to collect information from infected systems, as well as to download new configurations and to execute commands. MoonWalk then establishes communication with actor-controlled C2 infrastructure via Google Drive. This enables APT41 to mimic legitimate traffic, thereby achieving prolonged persistence on a compromised system. The backdoor also shares similarities with DodgeBox, notably incorporating several of the same detection evasion techniques. As a newer and more advanced version of StealthVector, DodgeBox underlines the group’s ongoing commitment to develop new malware continuously. Both malware strains also contain several highly advanced anti-detection techniques, pointing to the substantial sophistication of Chinese state-sponsored actors’ TTPs.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices. (Source: Sibylline)

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

Spectra Group (UK) Ltd

 

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

July 12, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

———————————————————————————————————————————————————————————————————————————————————————————————————————————————–

12 Jul 24. Cyber Update Key monthly trends. The increased emergence of operations from Chinese state-sponsored groups underscores elevated security and espionage risks to organisations in the Asia-Pacific region

Reports revealed several long-term cyber espionage campaigns from Chinese state-sponsored groups in June. The campaigns targeted government, telecommunications, academia, technology and diplomatic organisations in the Asia-Pacific region. The state-sponsored group ‘RedJuliett’ infiltrated multiple Taiwanese organisations, likely to steal sensitive information and intellectual property. The group reportedly exploited software vulnerabilities in internet-facing network edge devices to obtain initial access. Additionally, reports indicate that several Chinese-nexus actors (including ‘Fireant group’, ‘Needleminer group’ and ‘Firefly group’) have been targeting telecommunications providers in an unnamed Asian country since at least 2021. The groups used multiple custom backdoors to steal sensitive information from compromised systems, including credentials, while also likely pre-positioning themselves for future disruptive operations. Similarly, threat actors targeted an unnamed government agency in Southeast Asia in a long-term espionage campaign known as ‘Crimson Palace’ between March and December 2023. Crimson Palace is likely centrally co-ordinated by a single entity, pointing to the likely co-operation of several state-sponsored groups including ‘BackdoorDiplomacy’, ‘REF5961’ and ‘Earth Longzhi’. The first phase focused on conducting reconnaissance; the second and third phases prioritised achieving persistence and lateral movement. Notably, Crimson Palace exploited staff shortages in targeted organisations, highlighting the group’s extensive capacity for reconnaissance and planning. The likely co-operation, of multiple state-sponsored groups in different phases of the campaign, combined with the high sophistication of the groups’ tactics, techniques and procedures (TTPs), highlights the growing significance of cyber espionage operations as the Chinese government seeks to bolster their economic and security posture. Furthermore, the focus on targets in the Asia-Pacific region highlights a risk-intensive cyber security environment amid ongoing bilateral and regional tensions.

Ongoing malware development highlights elevated financial and cryptocurrency theft risks from financially motivated actors

Financially motivated actors continued to develop malware during June to garner illicit profit. A financially motivated campaign targeted Brazilian bank users with a new banking trojan, ‘Carnaval Heist’. The TTPs used throughout this campaign emulate those of other known banking trojans in Brazil, pointing to the potential collaboration between Latin American malware developers. Additionally, cyber actors resumed use of the ‘Medusa’ banking trojan, also known as ‘TangleBot’, in June. The campaign capitalised on security vulnerabilities exacerbated by the ongoing UEFA EURO 2024 football championship. The newest version of this malware requires fewer permissions to run, achieving prolonged obfuscation on compromised systems. It also contains new capabilities to capture screenshots and perform actions remotely, underscoring the growing sophistication of Medusa’s TTPs as well as the campaign’s wider capacity to steal financial information. Several Chinese threat actors also used a new remote access trojan (RAT), ‘NoodleRAT’ to target Windows and Linux systems in cryptocurrency theft operations. NoodleRAT shares similarities with other Chinese-made malware, pointing to the likelihood that the malware is sold to other threat actors or created via co-operating with other threat groups. The cyber actors also resumed the use of RAT ‘Agent Tesla’ in a new campaign targeting Spanish speakers. This new iteration infiltrates victims’ computers to steal sensitive information, such as login credentials, and exfiltrates them via the File Transfer Protocol (FTP), underscoring security risks. Furthermore, threat actors developed a new highly sophisticated malware, ‘Snowblind’, to target banking customers in Southeast Asia. The malware uses rare techniques to bypass anti-tampering code in legitimate Android applications, enabling threat actors to modify security mechanisms and conceal malicious activities on compromised systems. The resumption of existing malware operations and the development of new strains throughout June both emphasise threat actors’ commitment to developing TTPs to counter new security measures and detection mechanisms, underscoring sustained risk.

Cyber criminals demonstrate evolving TTPs, highlighting security, phishing and financial risks to financial institutions

We reported several highly sophisticated phishing campaigns in June, displaying threat actors’ growing knowledge of modern security mechanisms and capacity to harness advanced TTPs. Criminal actors used a new phishing-as-a-service (PhaaS) kit, ‘V3B’, to target customers from over 54 Europe-based financial institutions. The kit is distributed through social engineering and contains a sophisticated JavaScript that emulates local login and authentication techniques such as QR code login and SmartID processes. The script also contains several advanced detection evasion techniques, further highlighting its sophistication. Similarly, threat actors are also using another PhaaS kit, ‘ONNX’, to target employees of global financial institutions, likely to exfiltrate sensitive data for financial profit. Actors typically distribute ONNX via phishing emails containing a malicious QR code. The victim is then prompted to enter their credentials and authenticate via a two-factor authentication (2FA) process on a fraudulent Microsoft 365 login page. The threat actors subsequently hijack the user’s account. ONNX also possesses several detection evasion techniques in a similar manner to V3B, highlighting sustained security risks. Also in June, the cyber criminal group ‘Scattered Spider’ used social engineering techniques to compromise employee accounts belonging to a range of global financial firms. The group abused account permissions to access software-as-a-service (SaaS) environments, signalling a shift in their TTPs. These operations underscore some cyber criminals’ growing knowledge and sophistication in financially motivated campaigns, elevating security, phishing and financial risks to financial institutions in the long term.

Strategic risk trends

Sibylline observed several key strategic risk trends throughout June. We reported an increase in Malware operations compared to May; state-sponsored and cyber criminal groups created new and more sophisticated strains of malware to garner illicit profit and sustain strategic geopolitical objectives. These new strains consisted of banking trojans, backdoors, RATs and phishing-as-a-service kits. Both state-sponsored and cyber criminal groups continue to exploit software vulnerabilities. Consistent with May trends, these groups continued to exploit the software supply chain in June to obtain initial access to strategic targets. Although Sibylline only reported on a few major ransomware incidents in June, we assess ransomware operations will likely continue at a steady pace. State-sponsored operations continue to form a large portion of cyber attacks, with state-sponsored groups consistently prosecuting espionage campaigns. This particular trend is likely to continue into the next few months. (Source: Sibylline)

 

11 Jul 24. Comtech (NASDAQ: CMTL) (the “Company”), a global technology leader, today announced it recently completed the full migration and deployment of a Next Generation 9-1-1 (“NG9-1-1”) system in Saskatchewan-marking a significant milestone for the Company and Canada’s NG9-1-1 infrastructure.

In October 2023, Comtech helped Strathcona County in Alberta become Canada’s first Public Safety Answering Point (“PSAP”) to transition to NG9-1-1 services. With the Saskatchewan NG9-1-1 deployment, Comtech is now the first company, in partnership with leading Emergency Services IP Network (“ESInet”) provider SaskTel, to deploy a province-wide NG9-1-1 system in Canada.

“We are honored to build on our longstanding partnership with SaskTel to complete this critical NG9-1-1 transition in Saskatchewan,” said Aaron King, General Manager of Comtech’s Solacom Technologies Division. “With a government mandate to transition to NG9-1-1 services by March 2025, Comtech is partnering with Canada’s public safety agencies to lead the way in building one of the first national transitions to a NG9-1-1 infrastructure. This province-wide NG9-1-1 deployment paves the way for other NG9-1-1 migrations across Canada that will empower PSAPs throughout the country with the ability to leverage new technologies that can significantly enhance safety, reliability, and response in a wide range of emergency situations.”

In addition to the Saskatchewan NG9-1-1 deployment, Comtech also recently completed a local NG9-1-1 PSAP migration in Ontario, Canada. With these NG9-1-1 migrations complete, Comtech is the first public safety provider in Canada to partner with all three major ESInet suppliers in the country-SaskTel, Bell, and Telus-to build out the nation’s NG9-1-1 infrastructure.

As one of the most trusted providers of public safety technologies, Comtech is continuing to expand its NG9-1-1 call routing and call handling solutions, including the Company’s Guardian Call Management platform, for governments and emergency response providers across the globe. The Company’s NG9-1-1 offerings are designed to adapt and continuously evolve over time to meet the needs of emerging use cases as well as future applications.

 

11 Jul 24. Share and Share Alike. Chairing a study day on radar technology in London in late June was an absolute pleasure for your editor, save the capricious vagaries of the English weather. Hot and humid one minute, cold and clammy the next. West London’s microclimate never fails to surprise and disappoint in equal measure. Despite the mercurial meteorology outside, the conference hall was abuzz with discussion. Radar technology is moving at breakneck pace. The use of hypersonic missiles and drones in the ongoing Ukraine war is presenting radar experts with engineering challenges they must surmount. The key priority is to enrich the recognised air picture as much as possible without causing an information deluge. The targets that need to be seen must be done so in rich clarity, false alarms must be discarded. Artificial intelligence, machine learning and edge computing all have their role to play in meeting these objectives.

This rich data needs to be shared with those who defend the skies at strategic, operational and tactical levels. Air defence assets do not work well in a vacuum, they come into their own when connected and able to share their information at the speed of light. Sharing timely information demands robust, redundant and capable communications. Bandwidths must be sufficient to exchange radar plot and track data with minimal latency. Much as the radar engineers have their work cut out as they adapt their systems to emerging threats, so communications engineers must ensure requisite networking is available. It is interesting that it is all but impossible to now have a conversation about sensors without talking about communications. This synergy will only deepen in the future as military philosophies like multi domain operations gather pace.

 

09 Jul 24. Talking Dutch. The Dutch military’s Foxtrot programme will see a major enhancement of the communications used across the country’s armed forces. The MTBB phase of the project focuses on the procurement of new tactical radio hardware and software. Discussions concerning the procurement of new tactical radios to support the Dutch military’s Foxtrot communications modernisation programme are entering their final stages. The Netherlands Ministry of Defence (MOD) is in the process of deciding which radios will fulfil the requirements of the country’s Military Transmission Building Block (MTBB) programme. MTBB forms a key part of the wider Foxtrot military digitisation programme being rolled out across the Dutch armed forces. Foxtrot will transition the Dutch military into an integrated force capable of performing Multi-Domain Operations (MDO) according to reports. MDO stresses the intra- and interconnectivity of all forces to perform rapid, synchronous operations at all levels of war. MTBB focuses on the acquisition of the communications hardware and software necessary to facilitate Foxtrot. A spokesperson for the Dutch MOD told Armada that “(Foxtrot) is responsible for the modernisation of communication equipment within a vast number of vehicles, vessels, aircraft and other operational units.”

Recent radios

L3Harris was selected in November 2023 to answer the MTBB requirement. The Dutch military already uses the company’s products. In May 2023, L3Harris won a contract to provide AN/PRC-117G and AN/PRC-163 radios to modernise the Dutch military’s ground-to-air/air-to-ground radios. The AN/PRC-117G is a 20-watt/W backpack radio covering a 30 megahertz/MHz to two gigahertz/GHz waveband. The handheld, ten-watt AN/PRC-163 radio covers wavebands of 30MHz to 2.6GHz. These radios were procured outside the MTBB framework. Meanwhile, in 2020 Elbit Systems won a contract to supply its E-Lynx tactical radios, although precisely which radios were provided was not made public.

The spokesperson declined to specify exactly what radios were being supplied by L3Harris. Sources close to the programme told Armada that discussions were ongoing regarding specific models, as of June. While the specific radio types are yet to be defined, the source said that Type-1 encryption is an MTBB pre-requisite. Type-1 is a United States National Security Agency encryption standard representing one of the highest encryption standards used by the US government and select US allies.

Likewise, no details have been supplied on which waveforms these radios will accommodate. The spokespersons did say that “Waveforms are an essential prerequisite for interoperability in the mobile tactical domain and are thus an important part of MTBB.” Through the Foxtrot programme, the MOD is “committed to acquire multiple waveforms to create maximum interoperability with (inter)national partners.” Armada’s source confirmed that elements of the radio’s specifications are also subject to ongoing discussions. The spokesperson’s reference to procuring waveforms to foster “maximum interoperability” is interesting. This maybe a tacit indication that the Dutch MOD may be considering procuring the European Secure Software Defined Radio (ESSOR) High-Data Rate Waveform (HDRWF). More information on this waveform can be found here.

Moving forward

It remains unclear exactly which of the Dutch military’s existing radios will be replaced via the MTBB undertaking: “The exact radios that will be replaced have not been made public,” said the spokesperson. They added that several of the current radios are “several years past the end of their technical and operational life. Manufacturers provide limited support and maintenance for these assets, and they are increasingly difficult to replace or repair.”

It appears likely that the E-Lynx, AN/PRC-117G and AN/PRC-163 radios will remain in service, given their recent procurement. However, the Thales PR4G radios that the Dutch MOD procured in 2008 could be one candidate for replacement. Circa 10,000 of these Very High Frequency (VHF: 30MHz to 88MHz) were supplied to the Dutch military in various configurations. The Dutch MOD declined to state when deliveries of the L3Harris MTBB radios will commence. Nonetheless, given that discussions on the exact model of radios to be supplied are in the final stages, it is reasonable to assume deliveries will begin within the next two-to-three years. (Source: Armada)

 

10 Jul 24. New Radios for Ireland. The Irish Army is overhauling its tactical communications with a large acquisition of new systems to replace scores of legacy transceivers. The Irish Defence Forces have taken an important step forward in the modernisation of their communications with a procurement of new tactical radios.

Up to 6,000 tactical radios are being supplied by Thales to the Irish military, chiefly the company’s SquadNet and Synaps transceivers. The order breakdown covers 3,500 SquadNet radios and 2,500 Synaps systems, according to a Thales press release announcing the news. The press release continued that Synaps deliveries to the Óglaigh na hÉireann (Irish Defence Forces) have already begun. The first batch of SquadNet radios will be delivered during the second half of 2024.

SquadNet is a personal role radio using wavebands of 430 megahertz/MHz to 470MHz or 865MHz to 880MHz, depending on the variant. The radio provides voice-over-internet protocol communications. The company says that SquadNet’s point-to-point range is circa 2.5 kilometres/km (1.6 miles). The Synaps radios the Irish military is receiving are derived from the Contact radios Thales has developed for the French military. Covering Very/Ultra High Frequency (V/UHF: 30MHz to three gigahertz) wavebands, the Irish military will receive Synaps-H handheld radios, Synaps-V vehicular/naval transceivers and the Synaps-A airborne radios. As well as equipping the An tArm (Irish Army), Synaps-V radios will outfit the vessels of the An tSeirbhís Chabhlaigh (Irish Navy). Synaps-A will used by the aircraft of the An tAerchór (Irish Air Corps).

ESSOR for Ireland

The Irish military’s Synaps and Squadnet radios will be outfitted with Thales’ proprietary Geomux blue force tracking waveform. The Synaps radios will also carry the pan-European ESSOR (European Secure Software Defined Radio) High Data Rate Waveform (EHDRWF). The EHDRWF is a UHF waveform using a waveband of 225MHz to 400MHz. Up to 200 nodes can be housed on a single EHDRWF network. The waveform can handle data rates of up to one megabit-per-second. It can sustain full duplex data and voice-over-internet-protocol communications. Transmission security includes fast frequency hopping. EHDRWF can work in environments where global navigation satellite signals are badly degraded or denied.

The ESSOR project is being realised via an international effort involving Finland, France, Germany, Italy, Spain and Portugal. All six countries will be introducing the EHDRWF into their tactical communications over the coming years. The a4ESSOR consortium is the industrial element of the programme involving Bittium, Indra, Leonardo, Radmor, Rohde and Schwarz, and Thales. Ireland’s acquisition of the EHDRWF represents one of the first acquisitions beyond the ESSOR partner nations. Porting the EHDRWF into Ireland’s new radios will greatly enhance the European interoperability of the Irish military.

Sources close to the programme told Armada that dismounted troops will be outfitted with Squadnet, with their commanders using both Squadnet to communicate with subordinates and Synaps-H to communicate with higher echelons. Traffic can be moved between these radios simply by connecting both transceivers to a vehicle’s intercom, for example. The Synaps radios will also carry command and control traffic shared by the Irish Army’s Systematic SitaWare battle management system.

The contract to supply the radios is worth $81 m, according to Ireland’s Department of Defence. The new Synaps and Squadnet radios replace the Irish military’s existing ITT/L3Harris Single Channel Ground and Airborne Radio System (SINCGARS) tactical radio family. These radios were supplied to the Irish military sans accompanying US encryption standards. The new radios being delivered will include communications and transmission security standards such as AES-256. AES-256 is an advanced encryption standard established by the US National Institute of Standards and Technology.

The introduction of the new radios represents an important modernisation for the Irish military. Despite the small size of the country’s armed forces, they are energetically engaged in operations around the world, in particular supporting peacekeeping efforts. Ireland’s acquisition of the EHDRWF will also help deepen interoperability with her European allies who are also adopting this new waveform. (Source: Armada)

 

11 Jul 24. Crest of a Wave. Germany is the most recent entrant to the ESSOR programme having formally joined in 2020. Rohde & Schwarz was selected three years earlier in 2017 as the initiative’s German industrial national champion.

This year’s Eurosatory exhibition, held in Paris between 17th and 21st June, was an opportunity to learn about the status and plans for the ESSOR tactical communications waveform initiative.

The European Secure Software Defined Radio (ESSOR) project is multilateral initiative developing several radio-agnostic tactical communications waveforms which can be used by a plethora of transceivers. The project is being realised via an international effort involving Finland, France, Germany, Italy, Poland and Spain. The a4ESSOR consortium is the programme’s industrial element involving Bittium, Indra, Leonardo, Radmor, Rohde and Schwarz, and Thales. ESSOR is managed by OCCAR (Organisation Conjointe de Coopération en Matière d’Armement/Joint Organisation for Armaments Cooperation). OCCAR is a pan-European body tasked with managing European multilateral defence equipment programmes.

One of the key deliverables is the ESSOR High Data Rate Waveform (EHDRWF). The EHDRWF is an Ultra-High Frequency (UHF) waveform using a waveband of 225 megahertz/MHz to 400MHz. Up to 200 nodes can be housed on a single EHDRWF network. The waveform can handle data rates of up to one megabit-per-second. It sustains full duplex data and voice-over-internet-protocol communications. Transmission security includes fast frequency hopping. It can work in environments where Global Navigation Satellite System (GNSS) Position, Navigation and Timing (PNT) signals are badly degraded or denied.

All six countries will be introducing the EHDRWF into their tactical communications over the coming years. Two of the ESSOR nations, Finland and France, have already introduced the waveform into service with their land forces tactical radios. However, the EHDRWF is not the programme’s only deliverable. Narrowband and airborne waveforms are in the offing.

E3DWF

The ESSOR Three-Dimensional Waveform (E3DWF) is optimised for air-ground-air communications, a4ESSOR representatives told Armada. Covering similar UHF wavebands to those used by the EHDRWF the frequency-hopping E3DWF performs simultaneous voice and data transmission. Data rates are dynamic adopting to prevailing electromagnetic conditions. E3DWF uses Multi-hop Ad Noc Networking (MANET) with network synchronisation provided by GNSS PNT signals. The A4ESSOR representatives continued that up to 32 nodes can be accommodated on each E3DWF network.

ENBWF

The ESSOR Narrowband Waveform (ENBWF) complements the wideband EHDRWF for land tactical communications. The a4ESSOR officials said that ENBWF is optimised to support communications in urban, rural, littoral, undulating and mountainous terrain using a MANET architecture. Providing dynamic kilobits-per-second data rates, the ENBWF handles NATO (North Atlantic Treaty Organisation) Restricted voice and data traffic. The waveform can use frequencies of 30MHz to 88MHz, or 225MHz to 400MHz. Like the E3DWF, the ENBWF uses frequency hopping to help resist electronic attack. Network synchronisation is possible with or without a GNSS PNT signal. Up to 60 nodes can be accommodated on each ENBWF network.

Over the longer term, the ESSOR initiative plans to develop a Tactical UHF Satellite Communications Waveform (ESATWF). In the near term, the a4ESSOR officials said that development of the E3DWF could conclude by the end of 2024. Work on the ENBWF is ongoing and could be completed in 2025. Specifications for the EHDRWF have already been enshrined in a draft version NATO’s Standardisation Agreement 5651 (STANAG-5651). ENBWF specifications could be included in the second edition of NATO’s draft STANAG-5630, with E3DWF particulars enshrined in edition four of STANAG-4372.

Enshrining the specifications in the STANAGs would mean that waveforms designed to these stipulations would be compatible with the ESSOR waveforms discussed above. Standardising waveform design will help deepen European and NATO interoperability. Disparate radios used by different NATO forces but with wideband, narrowband and air-ground-air waveforms designed to meet the STANAGs will communicate directly with ease.

The ESSOR programme was launched in 2008 and its efforts are now bearing fruit. Increased adoption of the EHDRWF among and beyond the a4ESSOR nations will be seen in the future. Croatia and the Republic of Ireland are two nations outside the a4ESSOR membership adopting the EHDRWF in their tactical radios. Other militaries will follow suit in the coming years, with the E3DWF and ENBWF set for adoption by the ESSOR member nations and their allies. At a time when Europe faces an ever-growing threat from a resurgent Russia, these efforts to deepen tactical communications interoperability are highly relevant. (Source: Armada)

 

11 Jul 24. July Radio Roundup.

Kongsberg’s Thor multiband vehicular radio is equipping the Norwegian Army as part of the country’s overarching Mime communications modernisation programme.

Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.

Thor radios for Norway

Officials from Kongsberg have told Armada that the company will begin deliveries of its Thor tactical radio in the 2025 to 2026 timeframe. The officials were speaking during the Eurosatory defence exhibition held in Paris between 17th and 21st June. Thor has been selected by the Norwegian armed forces as part of the country’s overarching military communications modernisation initiative known as Mime. The Kongsberg officials said they expect to begin shipping Thor radios to the Norwegian military in the same timeframe. Thor is expected to be installed in Hæren (Norwegian Army) vehicles. The dual channel, multiband radio covers frequencies of three megahertz to three gigahertz. The 20-watt transceiver has embedded AES-256 encryption and handles data at between 600 bits-per-second to 2.5 megabits-per-second, according to company literature. Kongsberg officials added that the Norwegian military is expected to furnish their radios with standard waveforms such as the North Atlantic Treaty Organisation’s HAVEQUICK air-to-surface/surface-to-air protocol. As Jane’s reported in May, the Thor contract is valued at $22.9 m.

Bittium’s TAC WIN system is providing a new tactical communications backbone for the Croatian Navy. TAC WIN is complemented with the company’s Tough SDR radios which will provide fleet-wide communications.

TAC WINs

Bittium announced in early June that the company’s Tactical Wireless Internet Protocol Network (TAC WIN) and Tough SDR tactical radios had been accepted by the Croatian Ministry of Defence (MOD). A company press release announcing the news stated that the acceptance followed an implementation process performed by the Hrvatska Ratna Mornarica (Croatian Navy). Speaking during the Eurosatory exhibition, held in Paris between 17th and 21st June, Bittium sources said that TAC WIN will form the navy’s communications backbone. TAC WIN provides a deployable, secure, wireless internet protocol network with achievable data rates of circa 50 megabits-per-second. Tough SDR radios are deployed on Croatian Navy vessels to provide fleet-wide communications. These radios cover a waveband of 30 megahertz to 5.2 gigahertz. Bittium sources continued that the navy’s radios will include the European Secure Software-Defined Radio (ESSOR) waveform. This represents one of the first publicly declared provisions of ESSOR beyond the militaries of the ESSOR partner nations. The sources added that the Croatian MOD is expected to explore the modernisation of the tactical communications used by the Karlovac (Croatian Army) in the near future. (Source: Armada)

 

12 Jul 24. Asia-Pacific: New sophisticated malware points to raised espionage risks from China-backed groups. On 10 July, the cyber security company Zscaler reported that the Chinese state-sponsored group ‘APT41’ is targeting organisations in Southeast Asia with two new strains of malware, ‘DodgeBox’ and ‘MoonWalk’. APT41 first downloads DodgeBox onto compromised systems via a legitimate executable. Notably, the loader is able to conceal malicious activity from endpoint detection and response (EDR) security mechanisms, thereby achieving prolonged presence on the system. DodgeBox subsequently loads the backdoor MoonWalk to collect information from infected systems, as well as to download new configurations and to execute commands. MoonWalk then establishes communication with actor-controlled infrastructure via GoogleDrive to blend in with legitimate traffic and evade detection. Both malware strains contain several highly advanced anti-detection techniques, pointing to the extremely high sophistication of Chinese state-sponsored actors’ tactics, techniques and procedures (TTPs). APT41 routinely targets organisations in Southeast Asia in cyber espionage campaigns. As such, we assess that entities operating in the region will face elevated security and espionage risks in the long term.  (Source: Sibylline)

 

10 Jul 24. Global: Bot farm takedown signals elevated security, disinformation risks from Russian-linked actors. On 9 July, global news outlets reported that a joint international law enforcement operation with the US Department of Justice (DOJ) seized a large bot farm that was spreading Russian disinformation. The bot farm had primarily targeted users of the platform X (formerly Twitter) in multiple countries (including Germany, Israel, the Netherlands, Poland, Spain, Ukraine and the US) since at least 2022. It used artificial intelligence (AI)-enabled software to create authentic-looking social media accounts posing as real people from various countries. The bot farm then used these profiles to spread Russian propaganda and to influence narratives favourable to the Russian government. Notably, the incident underscores the wider adoption of AI tools by Russian actors to amplify the impact of disinformation campaigns. Additionally, Russian-linked groups have recently ramped up disinformation campaigns targeting November’s US presidential election and the Paris 2024 Olympic Games. We assess that security and disinformation risks stemming from Russian-linked threat actors will be elevated in the short-to-medium term. (Source: Sibylline)

 

10 Jul 24. L3Harris milestone in B-52 Stratofortress modernisation.

Advanced self-protection system sets a new benchmark in B-52 modernisation efforts.

L3Harris has tested an upgrade to the B-52 Stratofortress’ electronic warfare capabilities, marking a moment in the aircraft’s modernisation journey.

A 5.3-hour test flight, conducted over Texas, validated the performance of five newly enhanced Line Replaceable Units (LRUs) within the AN/ALQ-172 electronic warfare (EW) self-protection system. This breakthrough emphasises the aircraft’s continued evolution in response to increasingly sophisticated electronic threats.

Through its modernisation project, L3Harris is fronting efforts to keep the US Air Force’s (USAF) B-52 relevant. The recent test, a component of a $947m, 10-year contract awarded in 2021, demonstrated enhancements in maintainability and reliability, setting the stage for future advancements.

Acquired from Boeing in 1961-1962, the US Air Force has 76 B-52 Stratofortress bomber aircraft in its fleet, as highlighted by GlobalData’s intelligence on the US defence market.

Jimmy Mercado, L3Harris Programme Director, explained, “The electronic threat landscape grows more complex and contested every day, underscoring the importance of our continued EW enhancements to the B-52.

The flight test showed that we’re providing the advanced capabilities needed to ensure the aircraft and its crews remain mission-ready and effective well into the 2050s.”

So far in 2024, the US has invested $5bn in electronic warfare technology. This expenditure reveals America’s leveraging of electromagnetic spectrum capabilities to enhance its military operations. As nations like Russia and China expand their electronic warfare capabilities, competition in this arena is intense.

The road ahead

The MARS upgrade, central to this project, has already seen the redesign of seven out of nine LRUs, with the final two nearing completion. These upgrades are poised to enhance the USAF’s Global Strike Mission, bolstering the B-52’s role in modern warfare. Notably, the improvements also aim to simplify and reduce the cost of future updates.

L3Harris’ approach to enhancing the B-52 Stratofortress reveals the importance of solutions in maintaining aerial presence. The test flight demonstrates the legacy and future potential of one of the USAF’s most storied aircraft.

The US Air Force (USAF) faces dual challenges with its B-52 Stratofortress fleet. Recent audits revealed shortcomings in spare parts management amidst ongoing modernisation efforts. A Department of Defense’s Office of Inspector General report highlights deficiencies in addressing material shortages crucial to sustaining the ageing fleet.

(Source: airforce-technology.com)

 

10 Jul 24. U.S. Navy Funds Mercury to Advance Chip-Scale Technologies Needed to Reduce Electronic Warfare Design Timelines. Mercury Systems, Inc. (NASDAQ: MRCY, www.mrcy.com), a technology company that delivers mission-critical processing power to the edge, today announced an agreement with the U.S. Navy to advance sensor processing technologies that will allow radar and electronic warfare (EW) capabilities to be designed on much shorter timelines.

For decades, increasing system and software complexity has extended the timelines for developing and fielding military platforms. The Office of Naval Research’s Open Rapid Chipletized Approach (ORCA) program aims to reduce the time needed to design edge processing solutions by increasing the modularity of components at the chip level. Under a $13.2 m contract, Mercury will develop a next-generation RF System-in-Package (SiP) that integrates the latest commercial chips from major semiconductor providers within a smaller and lighter footprint.

This work will build on Mercury’s RFS1140 SiP, which integrates an AMD Versal FPGA, Jariet Electra-MA high-speed data converters, and Micron memory for a truly advanced solution to support sensor processing.

“ORCA represents a significant evolution of the Mercury Processing Platform that will drive down radar and EW system development timelines, allowing next-generation capabilities to be fielded much faster,” said Tony Trinh, Mercury’s Senior Director of Advanced Packaging. “The ORCA approach opens up incredible opportunities to integrate mission-specific pre-processing chiplets to rapidly upgrade systems on a wide variety of existing platforms and stay ahead of evolving threats.”

“Mercury is pioneering the way for on-shore advanced secure microelectronics integration and packaging capability with DMEA-certified full product lifecycle support, including concept, design, assembly, and test, to rapidly deliver application-tailored system solutions to the warfighter,” said Adam Miller, Office of Naval Research Program Officer.

 

09 Jul 24. State-sponsored and hacktivist groups will likely exploit the increased convergence of information technology (IT) and operational technology (OT) to target critical national infrastructure (CNI) amid ongoing conflicts and geopolitical tensions.

  • State-sponsored actors will likely increase espionage actions targeting global CNI to bolster the economic position of their sponsors. Bilateral tensions and ongoing conflicts will also foment pre-positioning and disruptive operations.
  • Escalations in regional tensions will likely result in a wave of disruptive attacks from state-aligned hacktivist groups.

Context

On 30 May, the technology company Microsoft reported an increase in attacks targeting internet-exposed and vulnerable operational technology (OT) environments since late 2023. The onset of the Israel-Hamas war in October 2023 engendered a wave of hacktivist attacks against US OT environments, many of which successfully infiltrated critical national infrastructure (CNI). In early Q1, pro-Russia hacktivists altered the normal parameters of water pumps and blower equipment, compromising the systems of several US water and wastewater providers and causing water tanks to overflow. This recent increase in OT cyber attacks is a symptom of the inadequate and outdated nature of OT security systems, which will likely continue to incentivise attacks against this sector.

Forecast

State-sponsored and hacktivist groups will likely seek to compromise OT equipment within critical national infrastructure amid ongoing conflicts and geopolitical tensions

Cyber attacks against critical national infrastructure rose by 140% in 2022, according to a 2023 report by Waterfall Security. OT is often responsible for critical functions within CNI, making it an attractive target for cyber threat actors. More specifically, OT professionals are increasingly adopting smart industrial devices or Industrial Internet-of-Things (IIoT) devices to automate the maintenance of national infrastructure. Despite reducing costs and increasing efficiency, IIoT devices expose OT environments to potential cyber attacks by transmitting data from industrial equipment to assets connected to the internet. The White House and Environmental Protection Agency (EPA) released an advisory in March, warning that water and wastewater utilities in the US are being routinely targeted by adversarial state-sponsored groups. The advisory specifically mentioned threats to OT environments with the potential to affect the safety and supply of drinking water, highlighting significant infrastructure risks. The continued convergence of IT and OT systems provides threat actors with unprecedented opportunities to achieve their strategic objectives by amplifying their ability to gather intelligence, disrupt adversarial infrastructure and hinder defences. As such, cyber attacks against CNI by state-sponsored and hacktivist groups will likely increase in the long term as ongoing regional conflicts and bilateral tensions persist and OT environments become increasingly exposed to threats from the internet.

Cyber actors undertaking espionage operations will highly likely intensify their targeting of OT environments within CNI systems

In February 2024, the Federal Bureau of Investigations (FBI) stated that the Chinese state-sponsored group ‘Volt Typhoon’ infiltrated hundreds of small office/home office (SOHO) routers since at least 2019. The group executed espionage operations against US critical infrastructure including telecommunications organisations, transportation hubs and US military bases in Guam. Additionally, unnamed North Korean state-sponsored actors targeted at least two South Korea-based semiconductor companies in March, stealing highly sensitive data (such as product design drawings and facility site photos) possibly to spur North Korea’s own efforts to produce semiconductors. Relations between China and the US remain strained as the two countries continue to compete for military, economic and technological dominance. On 21 June, the Biden administration announced measures to curb US investment in Chinese tech firms developing semiconductors, quantum computers and artificial intelligence (AI). The announcements signal rising trade tensions between the two countries and likely precede additional measures aimed at slowing China’s economic and technological development. Similarly, North Korea continues to face economic sanctions which reduce the country’s ability to advance its weapons and missile programmes. As such, both Chinese and North Korean state-sponsored groups routinely target OT environments within CNI systems to bolster their economic and technological posture. We assess that the competitive nature of these relations, combined with talks of further economic decoupling and ongoing sanctions, will likely elevate espionage risks to global OT providers in the long term.

State-sponsored actors will likely seek to disrupt OT environments within CNI systems amid regional tensions and ongoing military conflict

The tactics, techniques and procedures (TTPs) used by Volt Typhoon signal an intent to pre-position itself for future disruptive operations. The group infiltrated IT environments within CNI, likely to migrate to OT systems for potentially disruptive operations at a later stage. Another Chinese state-sponsored group, ‘ChamelGang’, has disrupted national infrastructure in a series of ransomware operations conducted since at least 2019. As geopolitical tensions persist, we assess state-sponsored groups will likely continue to infiltrate and pre-position themselves within IT and OT environments. This will elevate disruption risks in the long term.

In October 2023, the Russian state-sponsored group ‘Sandworm’ caused a power outage after deploying OT malware in one of Ukraine’s power plants. The group reportedly executed malicious code against the plant’s supervisory control and data acquisition (SCADA) instance which included commands to turn off substations. The attack notably coincided with a series of missile strikes on Ukraine’s electrical grid, indicating that Sandworm likely worked with the Russian army to aid kinetic operations and disrupt Ukraine’s ability to defend against the hybrid attack. In April, Sandworm disrupted information and communication systems for 20 Ukrainian energy, heating and water organisations. The group deployed two new backdoors in this campaign, indicating its focus on developing new and more sophisticated cyber capabilities to target. This attack is likely indicative of Russia’s long-term objectives for the war in Ukraine, which include weakening Ukraine’s defence capabilities by undermining its energy resilience. The war in Ukraine represents the first conflict to involve significant levels of cyber operations to support military action. This trend elevates security and disruption risks to OT providers in the long term. The escalation of regional tensions and military conflicts will likely engender a wave of disruptive cyber attacks from state-aligned hacktivist groups

Security agencies in Canada, the UK and the US have warned of a rise in pro-Russian hacktivist attacks against OT environments in North America and Europe in May following an increase in hacktivist attacks against CNI in these regions. Affirming these warnings, the Iranian-aligned hacktivist group ‘Cyber Av3ngers’ compromised an Israeli-made programmable logic controller (PLC) at the Municipal Water Authority in Aliquippa (Pennsylvania, US) in November 2023. Although the attack did not cause any operational disruption, the group displayed an anti-Israel message and vowed to continue targeting Israeli-made equipment. Similarly, the hacktivist group ‘SiegedSec’ claimed responsibility for a series of attacks against Israeli infrastructure and industrial control systems (ICS) in October 2023. The group primarily compromised human machine interfaces (HMIs) within the water and wastewater sectors, altering normal equipment parameters and causing minor tank overflows. Although none of these attacks resulted in major disruption, they display hacktivists’ capabilities and intent to target OT following the escalation of regional tensions and military conflicts. The continuation of the Israel-Hamas war and the war in Ukraine will sustain elevated disruption risks to OT providers within adversarial nations in the medium-to-long term. There is also a possibility that any escalation in combat or rhetoric will further prompt a rise in hacktivist cyber attacks targeting this sector. (Source: Sibylline)

 

08 Jul 24. $2bn AUD deal for top secret Aussie cloud with AWS.

The new cloud deal “will enhance Defence’s resilience, improve the ADF’s warfighting capacity, (and) strengthen interoperability with key international partners,” Australian Defense Minister Richard Marles said. The Australian Signals Directorate plans to spend more than $2bn AUD ($1.3bn USD) over the next decade buying a highly classified and custom-built cloud to serve its intelligence and defense needs.

The plan, announced on July 4 by both the Australian government and Amazon Web Services (AWS), “will provide a state-of-the-art collaborative space for our intelligence and defense community to store and access top-secret data,” Rachel Noble, director general of the ASD. said in a statement. “This will transform how we work together as agencies and partners.”

Australia, one of the Five Eye countries who share the most highly classified intelligence with each other, has been beset by a regular onslaught from Chinese and Russian cyber attacks, and is searching for secure ways to share intelligence and targeting data with the United States, Britain, Canada and New Zealand, the other members of the elect group. While the group has traditionally shared intelligence signals data with each other, the advent of artificial intelligence and the proliferation of targeting data means the need for highly secure and transferable data has only grown.

The deal with AWS was important enough to generate a statement by Prime Minister Anthony Albanese, emphasized the importance of the contract for domestic job creation.“My Government is bolstering our defense and national intelligence community to ensure they can deliver world leading protection for our nation,” he said in the statement. “This important investment today will help enhance our national security capabilities while creating up to 2,000 local jobs.”

Defense Minister Richard Marles spoke of capabilities more important to defense, noting that the new cloud deal “will enhance Defence’s resilience, improve the ADF’s warfighting capacity, (and) strengthen interoperability with key international partners.”

It’s important to note that this contract is not entirely new business. It is, as Noble noted in her statement, part of Project REDSPICE, which was announced by the last government.

“For ASD, this capability is a vital part of our REDSPICE program which is lifting our intelligence and offensive and defensive cyber capabilities,” she said in the statement.

REDSPICE stands for for Resilience, Effects, Defence, Space, Intelligence, Cyber, and Enablers. When it was first announced by the Australian government, it was cast as the “largest ever investment” in the capabilities of the ASD, the Aussie version of the National Security Agency. When Scott Morrison, then prime minister, announced the program in March 2022, he said it would “substantially increase ASD’s offensive cyber capabilities, its ability to detect and respond to cyber-attacks, and introduce new intelligence capabilities. It will also create over 1,900 new jobs, almost doubling the ASD’s size.”

AWS already supplies a similar capability to the CIA and the US Intelligence Community. which presumably helped the company win this contract.

Secure clouds are considered by most experts to offer greater protection, operational flexibility and the ability to upgrade the system more seamlessly. (Source: Defense News Early Bird/Breaking Defense.com)

 

05 Jul 24. Global: New ransomware-as-a-service operation elevates security, operational risks to firms. On 5 July, international news outlets reported on the emergence of a new ransomware-as-a-service (RaaS), ‘Eldorado’. Cyber criminals primarily use this new RaaS to target the real estate, education, healthcare and manufacturing sectors. Eldorado contains several customisation features to target Linux, Windows and VMware ESXi hypervisors, underscoring its highly tailored nature. The new RaaS also deletes backup copies on compromised machines to maximise impact and prevent recovery. Additionally, Eldorado automatically self-deletes from infected systems to evade detection, further highlighting its high level of sophistication. The ransomware has been active since March and has compromised 16 organisations in Croatia, Italy and the US, underscoring the growing scale of this operation. The emergence of Eldorado highlights the continued adaptability and growing development of RaaS operations despite recent law enforcement takedowns of large ransomware groups including ‘LockBit’ and ‘BlackCat’/’ALPHV’. The proliferation of Eldorado also indicates elevated security, financial and operational risks to global organisations in the long term. (Source: Sibylline)

 

02 Jul 24. BATM Advanced Communications Limited (“BATM” or “the Group”). Commercial Markets Cybersecurity Partnership.

Major milestone achieved with signing of strategic partnership agreement to sell BATM’s advanced cybersecurity solution to commercial markets globally

BATM (LSE: BVC; TASE: BVC), a leading provider of real-time technologies for networking solutions and medical laboratory systems, has signed a strategic partnership and cooperation agreement with a significant global technology, engineering and defence group (the “Partner”) to deliver the Group’s advanced cybersecurity solution to commercial markets. The Partner generated revenue of over $10bn in 2023 and serves customers in more than 100 countries, with operations spanning Asia, Europe, the Middle East and the U.S.

With this agreement, the Group will customise its advanced encryption platform to meet the requirements of its Partner, with the development work being funded by the Partner. The customised platform will be distributed globally by the Partner, with exclusivity in certain territories, to a variety of commercial markets and for critical national infrastructure. This agreement, and the corresponding launch of a cyber solution for the commercial markets, represents a significant increase in the Group’s addressable market, which the Group’s cyber solution is well-positioned to target thanks to the Partner’s substantial network and commercial reach.

BATM’s encryption platform is a hardware and software solution that secures data-in-transit at high speeds across a network. It incorporates the Group’s hardware security module, which provides enhanced hardware-based protection of encryption keys, which is becoming increasingly important due to the growing number of attacks targeting weak links in the supply chain, such as the equipment vendors. It offers seamless integration with Quantum Key Distribution systems to provide customers with protection against the emerging quantum computing threats. In addition, the Group expects it to be the only commercially-available encryption platform to offer a mix of speeds, enabling customers to grow their network without replacing the platform.

Over the next two years, the Group will receive a minimum of $2.1m from the Partner for the product customisation phase and the provision of an initial quantity of units, which will be delivered in three phases over the two years. The Group is due to commence delivering the units to the Partner by the end of the first half of 2025.

Moti Nagar, Chief Executive Officer of BATM, said: “To be partnering with such a large, well-established and global organisation to deliver our cutting-edge encryption platform to the commercial markets is transformational for BATM Cyber and is a fantastic endorsement of our solution. The introduction of a cybersecurity offering for non-governmental customers has long been an important objective for BATM, and this collaboration significantly boosts our commercial market entry by providing worldwide distribution networks and a partner with the resources to engage in considerable sales & marketing activities. We look forward to working closely with our strategic partner in the fulfillment of this agreement, which we expect to serve as a prominent catalyst for the growth of our cyber business in the near future.”

 

05 Jul 24. Cuba’s Upgraded Surveillance Site Enhances Chinese Intelligence Capabilities. A recent analysis by the Center for Strategic and International Studies (CSIS) reveals that a newly upgraded radar site in Cuba represents a significant enhancement in the country’s surveillance capabilities, potentially bolstering China’s ability to monitor U.S. military activities. Satellite imagery analyzed by CSIS indicates that the site, located east of Santiago de Cuba, could become a powerful tool for intelligence gathering once operational.

The CSIS report highlights that China has access to multiple spy facilities in Cuba, pinpointing four specific sites across the island. This latest development is believed to be part of an effort by Beijing to enhance its intelligence collection capabilities in the region, leveraging Cuba’s proximity to U.S. military installations.

The new facility features a circularly disposed antenna array, with a diameter between 130 to 200 meters, capable of tracking signals from 3,000 to 8,000 nautical miles away. This technology could enable China to intercept sensitive communications from U.S. military bases, monitor rocket launches from Cape Canaveral, and gather data on other strategic activities across the southern United States.

The Cuban government, however, has denied these allegations. Vice Foreign Minister Carlos Fernandez de Cossio dismissed the claims as part of an intimidation campaign, stating that there is no verifiable evidence of Chinese military bases on the island. Similarly, China’s embassy in Washington described the accusations as unfounded slander.

Despite these denials, the CSIS report highlights advantages such a surveillance site would provide. It would allow China to develop a sophisticated understanding of U.S. military operations, potentially enhancing its strategic posture. The site’s capabilities include monitoring radio traffic and intercepting data from U.S. satellites, further expanding China’s intelligence reach.

The U.S. government has expressed concerns about China’s presence in Cuba. State Department spokesperson Vedant Patel noted that the U.S. is closely monitoring the situation, acknowledging China’s ongoing efforts to strengthen its intelligence foothold in Cuba.

The radar site in Cuba follows a pattern of increased Chinese intelligence activities globally, with similar facilities being constructed on reef outposts in the South China Sea.

The location of Cuba, just 90 miles south of Florida, makes it an ideal spot for gathering signals intelligence (SIGINT). This proximity allows for effective monitoring of U.S. military activities, including those at critical installations like the Guantanamo Bay naval base and various space-launch complexes in Florida.

Historically, Cuba has hosted foreign espionage operations, such as the Soviet Union’s largest overseas intelligence site during the Cold War. The new developments suggest a continuation of this legacy, with modern technological advancements enabling more sophisticated surveillance capabilities. (Source: https://www.sofx.com/)

 

05 Jul 24. Cyber Update Key points.

  • A security breach by the Russian state-sponsored group ‘APT29’ points to sustained security risks via the software supply chain.
  • Exploitation of a new zero-day vulnerability sustains security risks by the Chinese state-sponsored group ‘Velvet Ant’ (see Sibylline Cyber Daily Analytical Update – 2 July 2024).
  • Critical vulnerabilities in an iOS and macOS software dependency manager highlight elevated security risks facing the software supply chain (see Sibylline Cyber Daily Analytical Update – 3 July 2024 and our Technical analysis below).
  • A new cyber espionage campaign targeting an unnamed South Korean defence company underscores the bilateral tensions and supply chain risks posed by North Korean cyber actors (see Sibylline Cyber Daily Analytical Update – 4 July 2024).
  • The resurgence of a Latin American banking trojan, ‘Mekotio’, underscores the elevated security and financial risks facing firms and customers in the region.

Technical analysis of weekly stories

There is a realistic possibility that three critical vulnerabilities (CVE-2024-38368, CVE-2024-38366 and CVE-2024-38367) have compromised ms of iOS and macOS users for over a decade. The vulnerabilities reside in CocoaPods, a software dependency manager that hosts code libraries for developing applications. CocoaPods stores software dependency pods for major companies including Amazon, Dropbox and Google. The first vulnerability (CVE-2024-38368) emerged in 2014 after CocoaPods asked its customers to reclaim ownership of dependency pods via a public application programming interface (API) following a server migration. However, several pods were never reclaimed by their legitimate owners. Threat actors could thus exploit CVE-2024-38368 to claim ownership of those unclaimed dependencies, injecting malicious code into the pods and compromising ms of iOS mobile applications and users. This first vulnerability is compounded by a second vulnerability (CVE-2024-38366) which enables threat actors to bypass authentication methods when claiming a dependency pod. More specifically, the new server only validates the domain of a claimant’s email address, effectively allowing threat actors to hijack customer accounts. These two vulnerabilities are supplemented by a third (CVE-2024-38367) which enables a zero-click account takeover by allowing threat actors to validate their ownership of the account via a spoofed URL. CocoaPods has since released patches for these vulnerabilities, underscoring mitigated security risks while emphasising the importance of strict patch management policies to prevent compromises.

Threat actors have resumed using the banking trojan ‘Mekotio’, targeting banking users in Latin America (LATAM). The malware is typically distributed via phishing emails, wherein threat actors impersonate tax agencies alleging that the user has unpaid tax obligations. The phishing email contains a ZIP file that executes Mekotio and establishes communication with actor-controlled servers. The malware then collects information from the compromised system including screenshots, keystrokes and banking credentials. Notably, Mekotio steals banking information by displaying a fake pop-up mimicking legitimate banking sites’ login pages. Additionally, Mekotio contains several persistence methods, such as adding itself to startup programs and creating scheduled tasks, highlighting the high sophistication of this malware. The stolen banking information is then sent to the actor-controlled infrastructure where it can be used for further malicious activities, granting actors unauthorised access to bank accounts to garner illicit profit. There have been numerous iterations of this malware since 2015, with this latest resurgence following the law enforcement takedown of ‘Grandoreiro’, another LATAM banking trojan. This highlights the dynamic, fluid and broad nature of financially motivated malware operations in the region.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering attempts.
  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Enforce strict patch management policies prioritising high-risk and remote code execution (RCE) vulnerabilities.
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices.

Our cyber word(s) of the week: Application programming interface (API) .

(Source: Sibylline)

————————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

July 5, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

———————————————————————————————————————————————————————————————————————————————————————————————————————————————

04 Jul 24. Glimmer and Taxable. Moving scenes graced the beaches of Normandy in early June as the 80th anniversary of the Operation Overlord D-Day landings was commemorated. Veterans remembered fallen comrades and the horrors which greeted them as they took this decisive action in the battle to free the continent from fascism.

Electronic Warfare (EW) was instrumental to the success of Overlord. Operations Taxable and Glimmer played key parts in fooling the Germans as to where the allied invasion would land. Both efforts involved Royal Air Force aircraft dropping large clouds of chaff which moved progressively closer to the Pas de Calais and Cap d’Antifer on the French coast. These two locations were north of the actual D-Day objectives in Normandy. The chaff clouds were dispersed in such a way as to create an image on German radars replicating an armada of vessels approaching at a steady speed of several knots. At the same time, a flotilla of small ships and boats headed towards the Pas de Calais and Cap d’Antifer. The boats were equipped with radar-reflecting balloons and could simulate naval communications traffic.

This combination of aircraft, boats and their adornments looked on radar screens like two incoming fleets of ships headed for northern France. As history shows, the ruse paid off and the German military took the bait. Both operations greatly contributed to the success of Overlord and showed the transformative power of EW, a legacy that continues today and into the future. (Source: Armada)

 

04 Jul 24. To Kill a Pantsir.

The wreckage of a Russian 96K6 Pantsir short-range air defence system lies smouldering in Ukraine. Electronic warfare has played an instrumental role in helping hunt down and engage these short-range air defence systems.

Armada has been briefed on some of the tactics used to engage and defeat the 96K6 Pantsir-S1 series SHORAD system.

The 96K6 Pantsir-S1 (NATO reporting name SA-22 Greyhound) series Short-Range Air Defence (SHORAD) system is deployed extensively with the Russian armed forces and has been exported to twelve nations. The 96K6 has been used operationally supporting Russia’s ongoing deployment in Syria to bolster the regime of President Bashir al-Assad, the country’s leader. 96K6s have also been supplied to Syria’s armed forces. The system has been deployed to Libya where it has served with Libyan National Army (LNA) forces loyal to warlord Field Marshal Khalifa Haftar. Recently, Russian forces have deployed 96K6 systems to support their ongoing occupation of Ukrainian territory.

In Russian military service, the Russian Aerospace Forces typically deploy three 96K6s with each S-400 (SA-21 Growler) high-altitude/long-range Surface-to-Air Missile (SAM) battalion. Two S-400 battalions form an anti-aircraft missile regiment with between two and five regiments forming an air defence division. The 96K6’s role is to provide SHORAD for the S-400 batteries. This is to protect the batteries against aircraft, Uninhabited Aerial Vehicles (UAVs) and anti-radiation missiles seeking to exploit blind spots in the low-altitude coverage of the S-400’s 91N6A/E (Big Bird) S-band (2.3 gigahertz/GHz to 2.5GHz/2.7GHz to 3.7GHz) and 96L6E (Cheese Board) C-band (5.25GHz to 5.925GHz) ground-based air surveillance radars.

Capabilities

The 96K6 uses a combination of 57E6 semi-active radar homing/optically guided SAMs with a range of 9.7 nautical miles/nm (18 kilometres) and a maximum altitude of 49,000 feet/ft (14,935 metres/m). The missiles are joined by two 2A38M 30mm autocannons with a maximum altitude of 9,842ft (3,000m) and range of 2.2nm (four kilometres). Target detection is provided by the system’s 2RL80 S-band radar with a range of circa 27nm (50km). Once a target is detected, engagement is managed using the system’s 1RS2-1 X-band (8.5GHz to 10.68GHz)/Ku-band (13.4GHz to 14GHz/15.7GHz to 17.7GHz) radar. The 1RS2-1 has a 15nm (28km) range.

Sources familiar with Pantsir’s deployment to Ukraine shared with Armada that the system’s presence in previous warzones such as Libya and Syria have proved useful. Significant Electronic Intelligence (ELINT) pertaining to the Pantsir’s radars has been gathered by key North Atlantic Treaty Organisation (NATO) nations during these deployments. This bedrock of ELINT has been used to programme Electronic Support Measures (ESM) to recognise and exploit Pantsir radar signals. The ELINT has proved similarly useful for programming electronic attack systems so that the 96K6’s radars can be jammed.

Pantsir in Ukraine

Ukrainian forces claim to have captured several 96K6s, one of which has been used to develop and test ESM and electronic attack system performance against the Pantsir’s radars. One tactic pioneered by the Türk Silahlı Kuvvetleri (Turkish Armed Forces) has been to use Aselsan’s Koral electronic warfare system against the Pantsir’s radars. Koral is a ground-based ESM used by the Türk Kara Kuvvetleri (TKK/Turkish Land Forces). Koral is thought capable of detecting, locating, identifying and jamming radio frequency signals across a waveband of two gigahertz to 18GHz. Recent enhancements to the system are believed to have increased this waveband to 40GHz.

Koral was used by the TKK to provide a ‘lane’ of jamming directed against the Pantsir’s radars. With the radars blinded, the system was unable to detect and track incoming Baykar Bayraktar TB-2 UAVs which would then attack the 96K6 kinetically. Although Russian radar engineers did work to adapt the Pantsir’s radar waveforms to outflank the jamming, this has often proved unsuccessful. The continued collection of ELINT regarding the Pantsir threat in the Ukrainian, Syrian and Libyan theatres means that the adaptation of jamming waveforms for use against the 96K6’s radars has been quick. In some cases, it is possible to develop a new jamming waveform for employment against a new Pantsir radar waveform within hours. In addition to using systems like Koral, UAVs have been incorporated in the fight. Some UAVs are outfitted with ESMs to find the Pantsir. Once located, other UAVs begin jamming the radars before the 96K6 is attacked kinetically.

One measure taken by Russian air defenders has been to ring fence Pantsir deployments with 1L122 Garmon L-band (1.2GHz – 1.8GHz/1.67GHz – 1.71GHz) ground-based air surveillance radars. The radars are deployed to provide early warning of incoming hostile UAVs. Nonetheless, emissions from these radars are relatively easy to detect and jam. Moreover, detection of a Garmon radar may indicate that a lucrative Pantsir target is nearby.

The 96K6 had a fearsome reputation when it entered Russian military service in 2012 although successive conflicts in Syria, Libya and Ukraine have betrayed its vulnerabilities. The open source oryxspioenkop website which documents equipment losses in the ongoing Ukraine war has said that Russia may have lost up to 19 96K6s as of September 2023. It is all but inevitable that electronic warfare will have played a prominent part in the destruction of these, and other, 96K6 platforms. (Source: Armada)

 

04 Jul 24. July Spectrum SitRep.

Northrop Grumman’s CIRCM system equips all US Army rotorcraft including Boeing CH-47 Chinook series heavylift helicopters shown here. It will also equip the army’s Future Vertical Lift rotorcraft.

Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.

Captain CIRCM

In early June Northrop Grumman announced that the company had delivered its 500th Common Infrared Countermeasures (CIRCM) system to the US Army. Reports stated that a further 336 CIRCMs remain on order with the total number of systems to be delivered to exceed 800. CIRCM reached an initial operational capability with the US Army in 2023 following the first field installation which occurred in 2021. Since then, the system has been installed across the US Army’s helicopter fleet. CIRCM is also expected to be installed onboard the army’s Future Vertical Lift rotorcraft platform. Bob Cough, Northrop Grumman’s vice president of aircraft survivability, told Armada that he expects CIRCM production to continue into the 2030s. CIRCM units currently under contract are expected to complete delivery by 2026.

Bad News for Jammers

Project BadB, led by Krattworks, has been awarded funding worth $6.4 m to develop technology to outflank Global Navigation Satellite System (GNSS) Position, Navigation and Timing (PNT) signal jamming. A press release announcing the news said the technology will be realised by employing satellite imagery data and machine vision algorithms. A key goal of the project is to ensure that platforms like Uninhabited Aerial Vehicles (UAVS) can navigate reliably without needing external radio sources such as PNT signals.

The funding has been awarded by the European Defence Fund (EDF). The EDF is a European Union (EU) initiative which, in its own words works to foster cooperation between companies and organisations in the defence sector, boost defence capability development, and help EU companies develop cutting edge and interoperable defence capabilities. Technologies to be developed include “a machine vision module, an image recognition system and development of a path planning system, based on sensor data, cross-platform data sharing and swarming,” said the press release.

Alongside Krattworks, GIM Robotics, Kappazeta and Rigr AI are involved in Project BadB. Edward Dixon, Rigr AI’s chief executive officer, told Armada that the project is currently between Technology Readiness Levels (TRL) Two and Four. According to European Union definitions TRL-2 means the technology concept has been formulated. TRL-3 denotes that an experimental proof of concept has been realised. TRL-4 shows that the technology has been demonstrated in a laboratory. Mr. Dixon says that the aim of the project is to reach TRL-8 with a complete system being qualified. This is the penultimate level before the technology is proven operationally, and ready for deployment. The technology could be fielded on UAVs before the two-year project closes in circa 2026. (Source: Armada)

04 Jul 24. South Korea: New cyber espionage operation underscores bilateral tensions, supply chain risks. On 1 July, the security company AhnLab Security Intelligence Center (ASEC) reported that a North Korean threat group compromised a third-party enterprise resource planning (ERP) server to target a South Korean defence organisation in May. We assess that this report is likely accurate. The report suspects that ‘Andariel’, a subgroup of the North Korean state-sponsored group ‘Lazarus’, is behind the campaign. Andariel reportedly deployed the malicious file ‘Xctdoor’ on the compromised system to execute commands and steal sensitive information including keystrokes and screenshots. The group likely installed ‘XcLoader’ to inject Xctdoor into legitimate processes. North Korea routinely targets South Korean companies in espionage operations to steal intellectual property and to bolster its own economic and security posture. This highlights elevated security and espionage risks from North Korean state-sponsored groups amid ongoing bilateral tensions. Andariel’s likely exploitation of the ERP management software system to infiltrate a third-party organisation also points to elevated security risks via the software supply chain. (Source: Sibylline)

 

04 Jul 24. New Line of NATO Flange Vehicle Antennas Released.

Southwest Antennas’ latest line of ruggedized NATO flange vehicle-mount omni antennas are IP67 rated, can withstand significant impacts, and have been rigorously collision-tested. A new line of rugged vehicle-mount omni antennas has been released by Southwest Antennas.

The product line offers a range of antennas supporting L, S, and C frequency bands, along with a versatile dual-band option that combines L and S bands.

Each antenna is engineered for robust mounting, compatible with both 6-hole NATO and standard 4-hole USA vehicle mounting brackets. This ensures easy and secure installation on various military platforms, providing flexible and reliable communication solutions for defense operations.

The omni antenna range includes:

  • 1073-003 – L-band antenna (1.35-1.45 GHz) with 5.2 dBi max gain
  • 1073-001 – S-band antenna (2.2 – 2.5 GHz) with 5.6 dBi max gain
  • 1073-002 – C-band antenna (4.4 – 5.0 GHz) with 5.9 dBi max gain
  • 1073-004 – L & S-band antenna (1.35-2.5 GHz) with 2.6 dBi max gain

Engineered for compatibility with most leading tactical radio systems, the vehicle-mount antennas deliver 360-degree azimuth coverage for comprehensive communication capabilities and feature high-quality element designs that ensure optimal peak gain, enhancing signal strength and clarity. Equipped with a Type-N (female) RF connector they are designed to operate without the need for a ground plane, simplifying installation and improving operational flexibility.

Southwest Antennas’ rugged vehicle-mounted omni antennas are specifically engineered for the intense demands of military and law enforcement operations. Boasting an IP67 rating for exceptional ingress protection, they are built to endure harsh environments and challenging conditions.

Featuring heavy-duty spring bases, these antennas are resilient against snags and significant impacts. They have undergone rigorous collision testing at speeds of up to 30 mph, ensuring they maintain peak performance and durability even under extreme circumstances. (Source: https://www.defenseadvancement.com/)

 

03 Jul 24. Global: Critical vulnerabilities highlight elevated security risks via software supply chain. On 2 July, international news outlets reported that three vulnerabilities (CVE-2024-38368, CVE-2024-38366 and CVE-2024-38367) have potentially impacted millions of iOS and macOS users for over a decade. The vulnerabilities reside in CocoaPods, a software dependency manager that hosts code libraries for developing applications. CVE-2024-38368 enables threat actors to claim ownership of code libraries, allowing them to inject malicious code while CVE-2024-38367 can be used to bypass authentication processes, granting threat actors the capacity to hijack customer accounts. Additionally, CVE-2024-38366 allows for remote code execution, facilitating data theft and the installation of malware. CocoaPods is used by over three m applications across the Apple ecosystem as well as other organisations including Amazon, Meta, Microsoft and TikTok. These vulnerabilities highlight the widespread consequences of third-party security compromises and the resultant security risks to firms via the software supply chain. CocoaPods has since released patches for these vulnerabilities, emphasising the importance of strict patch management policies to prevent compromises and mitigate risk vectors. (Source: Sibylline)

 

02 Jul 24. Global: New zero-day vulnerability sustains security risks from Chinese state-sponsored actors. On 1 July, the technology company Cisco revealed that the Chinese state-sponsored group ‘Velvet Ant’ has been exploiting a zero-day vulnerability in its NX-OS software (CVE-2024-20399) since April. The vulnerability enabled threat actors with administrator-level credentials to execute arbitrary code against the targeted operating system. Velvet Ant exploited this vulnerability to deploy unnamed custom malware, allowing the group to remotely connect to compromised systems and upload additional malicious files. Notably, CVE-2024-20399 does not generate any data log messages upon executing commands, thereby allowing threat actors to remain undetected. In April, the Chinese state-sponsored group ‘UAT4356’ exploited multiple zero-day vulnerabilities in an espionage campaign targeting several government organisations worldwide. This incident highlights the ongoing exploitation of zero-day vulnerabilities by Chinese state-sponsored actors, illustrating sustained security and third-party risks to firms. Cisco has since patched this vulnerability, underscoring the importance of strict patch management policies in mitigating exploitation risks. (Source: Sibylline)

 

27 Jun 24. Pentagon to issue guidance on open radio access networks to support 5G.

As Department Defense looks to find the right mix of bespoke and openly available technologies to support 5G adoption and FutureG. initiatives, officials put an emphasis on open architecture Thursday.

At the TechNet Cyber conference presented by the Armed Forces Communications & Electronics Association International in Baltimore, leaders from the Pentagon discussed capabilities for public, private and hybrid networks. Officials acknowledged there’s a natural appetite for the most exclusive, secure networks in the national security space. And sometimes there is no wireless network infrastructure available in remote warfighting locations far from population centers.

So as the services determine appetite for private networks that offer more control over information sharing, the DoD is guiding them to use open radio access networks, or ORAN, said Juan Ramírez, the director of the 5G Cross-Functional Team at DoD.

“I think what industry wants to hear is there’s actually going to be requirements that come out that … necessitate an open RAN architecture,” he said at the conference. “So you’ll start to see those come out in the next couple of years, pending budgets.”

Certainly, private networks aren’t the only way to go. In fact, sometimes that’s not the best solution, said Lt. Col. Benjamin Pimentel, who leads the Camp Pendleton 5G experiment for Expeditionary Advanced Base Operations.

“Think about when we deploy in a theater,” he said. “A lot of countries that we go to or locations that we go to already have roads and bridges, and it’d be silly to then go and build my own private roads and my own private bridges separate and apart from that to get where I need to go. If those roads and bridges meet my transportation requirement, and they’re not going to fall under the weight of a ‘seven ton,’ we’re going to drive over it.”

But, somewhere like the first island chain, for example, may not have adequate coverage to put up sensors for long-range precision fires. In cases like those, he said, it would make more sense for units to bring private capabilities.

Given China’s rising aggression and U.S. efforts to deter it in the Taiwan Strait, what Pimentel described is the type of environment where current threats seem to colocate.

Regardless, to ensure there is connectivity wherever the need is, Ramirez said the department is looking at ORANs, which allow multiple vendors to operate as one network and provide more flexibility to scale.

ORAN is something the DoD has been pushing aggressively to explore as it simultaneously journeys toward more standard 5G adoption on military installations and “smart bases.”

Ramirez said the department is hopeful it will get additional support from Congress via future defense spending bills that will backup forthcoming requirements with dollars.

The Pentagon’s 2024 budget requested $143 bn in research, developing and testing of emerging technologies including 5G, but also artificial intelligence. Much of the spending in recent years has been for prototyping, and though the Office of the Secretary of Defense has the lion’s share, Ramirez said his office is offering direction to the services for them to budget for 5G.

“We think that pursuing ideas like [ORAN] advanced by the ORAN Alliance all the way to fully open-source code … provides the feature velocity the DoD needs and the ability to innovate quickly,” said Pimentel.

(Source: C4ISR & Networks)

 

28 Jun 24.  Cyber Update Key points.

  • A new campaign targeting Taiwanese organisations points to sustained espionage risks from Chinese state-sponsored groups (see Sibylline Cyber Daily Analytical Update – 24 June 2024 and our Technical analysis below).
  • The increased targeting of the 2024 US presidential election elevates disinformation risks posed by Russian actor, ‘CopyCop’ (see Sibylline Cyber Daily Analytical Update – 25 June 2024).
  • A new iteration of the banking trojan ‘Medusa’ is being used to target banking app users, elevating security and financial risks (see Sibylline Cyber Daily Analytical Update – 26 June 2024).
  • Financially motivated threat actors are using highly sophisticated malware to target Southeast Asian banking app users, raising security and financial risks (see Sibylline Cyber Daily Analytical Update – 27 June 2024 and our Technical analysis below).
  • Threat actors are exploiting legitimate third-party software as a malware delivery vector; this underscores sustained security, financial and reputational risks (see Sibylline Cyber Daily Analytical Update – 28 June 2024).

Technical analysis of weekly stories

The suspected Chinese state-sponsored group ‘RedJuliett’ is targeting Taiwanese government, academic, technology and diplomatic organisations in a new espionage campaign. The group reportedly exploits software vulnerabilities in internet-facing network edge devices such as firewalls, virtual private networks (VPNs) and load balancers to obtain initial access to targeted networks. Upon initial access, the threat actors deploy a SoftEther VPN service to establish persistent communication with actor-controlled infrastructure and perform reconnaissance. RedJuliett then used the ‘China Chopper’ web shell to establish persistence and to remotely execute code on the compromised system. Subsequently, the threat actors conducted structured query language (SQL) injections as well as directory traversal attacks to access sensitive files and escalate privileges. Additionally, RedJuliett also used ‘living off the land’ techniques upon infiltrating the system, and exploited a known Linux vulnerability to escalate privileges. This operation further underscores the continued focus on the exploitation of software vulnerabilities to gather sensitive data on China’s strategic targets, underscoring widespread security risks.

Threat actors are using new, highly sophisticated mobile malware (known as ‘Snowblind’) to target banking customers in Southeast Asia. The malware exploits a mobile sandbox mechanism known as secure computing, ‘seccomp’, and an application’s accessibility features to steal sensitive information and garner illicit profit. Snowblind is first injected into targeted applications before the anti-tampering code in the backend, thereby allowing threat actors to load additional malicious files. The malware then downloads a malicious seccomp filter to prevent any malicious activity from being detected by triggering a system error. Notably, the targeted nature of this filter allows for minimal performance impact and operational footprint, enabling the threat actors to achieve prolonged obfuscation. Subsequently, the threat actors can then exploit an application’s accessibility features to view the victim’s screen and input text. They also perform other malicious activities including stealing login credentials, hijacking a user’s banking session, disabling security features and exfiltrating personal information. Additionally, Snowblind can disable several other app security features such as two-factor authentication (2FA), further enabling the threat actors to remain undetected. The malware’s ability to bypass anti-tampering code, combined with its advanced anti-detection mechanisms, underscores the growing sophistication of cyber criminals’ tactics, techniques and procedures (TTPs) and highlights cyber security risks, especially for customers using banking software in Southeast Asia.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Introduce adequate network segmentation to isolate internet-facing services in a demilitarised zone (DMZ).
  • Monitor devices and networks for suspicious activity, including the presence of follow-on activities such as the use of web shells, backdoors and lateral movement.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Enforce strict patch management policies prioritising high-risk and remote code execution (RCE) vulnerabilities.
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.

Our cyber word(s) of the week: WebSocket.  (Source: Sibylline)

————————————————————————————————————————————————————————————————————————————————————————————————————————————–

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

———————————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

June 28, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

——————————————————————————————————————————————————————————————————————————————————————————————————————————————–

27 Jun 24. General Atomics Aeronautical Systems, Inc. (GA-ASI) and Lockheed Martin (NYSE: LMT) are collaborating to provide Net-Enabled Weapons (NEW) capability for GA-ASI’s MQ-9B SeaGuardian® Unmanned Aircraft System (UAS). The addition of NEW capability for SeaGuardian will bolster the Intelligence, Surveillance, Reconnaissance and Targeting (ISR&T) capability for the aircraft.

The NEW technology provides expanded sensor targeting applications for the precision targeting of long-range weapons. SeaGuardian’s demonstrated persistence coupled with its vast array of precision targeting sensors enables more efficient kill chains, especially in contested environments. GA-ASI’s MQ-9B SeaGuardian® UAS, and SeaVue multi-role radar from Raytheon, an RTX business, will effectively leverage Lockheed Martin’s extensive NEW expertise to further refine targeting capabilities for future theater deployments. Initial testing was completed on June 5, 2024, with F/A-18s on the U.S. Navy’s W-289 test range in Southern California.

GA-ASI and Lockheed Martin have been developing Link 16 messages to communicate with weapons inflight using the SeaGuardian Systems Integration Lab (SIL) in preparation for overwater range test flight.

“This is a very important system attribute for SeaGuardian to enable naval long-range targeting CONOPS against high-end threats at much less risk to manned platforms,” said GA-ASI President David R. Alexander. “We appreciate Lockheed Martin’s support in helping us prove out the NEW technology, which is an important component of our ISR&T capability.”

MQ-9B SeaGuardian is a medium-altitude, long-endurance UAS. Its multi-domain capabilities allow it to flex from mission to mission. SeaGuardian has been used by the U.S. in several recent demonstrations, including Northern Edge, Integrated Battle Problem, and Group Sail.

 

27 Jun 24. Comtech (NASDAQ: CMTL) (“the Company”), a global technology leader, today announced the launch of SmartAssist™, an artificial intelligence (“AI”)-backed solution developed to answer low-priority non-emergency calls without engaging a telecommunicator.

SmartAssist is designed to help Emergency Communications Centers (“ECCs”) and Public Safety Answering Points (“PSAPs”) manage call and Internet of Things device volumes by using AI chatbots to answer and triage non-emergency calls. The first of many applications in SmartAssist relies on AI bots programmed using conversational design to understand the natural language of the caller and resolve the caller’s request without the need for human intervention for non-emergency calls.

“One of the most critical challenges ECCs face today is staffing shortages, which can cause delays in 9-1-1 call answering times,” said Jeff Robertson, President of Comtech’s Terrestrial & Wireless Networks Segment. “Our SmartAssist solution solves call volume challenges and staffing shortages by streamlining 9-1-1 workflows with new AI-backed capabilities that can effectively handle most non-emergency administrative calls without telecommunicator assistance. Built on Comtech’s industry-leading public safety solutions, SmartAssist further demonstrates our ability to deliver innovative first-to-market solutions that solve today’s most pressing public safety challenges.”

The SmartAssist solution provides robust AI-backed voice and chatbot capabilities that enable public safety customers to leverage customized response solutions for a broad spectrum of low-priority non-emergency caller inquiries, ranging from text messages and form creation to foreign language capacities and performance metrics.

 

26 Jun 24. DOD, Partners Find Data Sharing Challenging. The mission of the Chief Digital and Artificial Intelligence Office is to accelerate the adoption of artificial intelligence, data and analytics across the Defense Department in an effort to modernize the force.

Bill Streilein, its chief technology officer, spoke today at the virtual Defense One event, “Genius Machines: Understanding the AI Threatscape.”

A major challenge is data sharing among industry and foreign partners who might have a lot to contribute. However, classification of data remains a barrier to sharing, he said.

“It’s not so much a technical challenge, because the ability to share data has been around for a while. It’s more of a policy challenge, to be honest. But getting there requires a lot of conversation, a lot of mutual understanding of what the data is that needs to be shared,” he said.

There are recent discussions about allowing DOD to streamline sharing from a whole data set and which portions need to be specially protected and which ones can be shared as they are, he said.

The crises in Ukraine and Israel have ramped up those discussions since information sharing has been critical to those battlespaces, he said.

Streilein also touched on the importance of talent management and training candidates for AI and other digital technology positions within the department.

There are a number of courses recently launched, including at Massachusetts Institute of Technology, Johns Hopkins University and at the Naval Postgraduate School, where senior leaders can immerse themselves in data analytics and AI, he said.

These courses help to dispel the mystery around it and help them to understand the rationale for why these capabilities are important, he said, adding that “the more the leaders know about it … the better decisions they can make about how to bring the capability to the department.” (Source: U.S. DoD)

 

25 Jun 24. Pentagon unveils IT modernization plan to tackle talent, tech hurdles. The Pentagon unveiled a new IT modernization strategy dubbed “Fulcrum” on Tuesday that lays out tangible steps for leaders to address workforce shortages, make its networks faster and streamline policies for more efficient procurement and governance.

On June 20, Deputy Defense Secretary Kathleen Hicks approved the strategy, and the department announced it on June 25, coinciding with the 2024 TechNet Cyber conference presented by the Armed Forces Communications & Electronics Association International in Baltimore.

“Fulcrum describes ‘what’ the DoD must achieve with respect to advancing IT for the warfighter and ‘why’ it matters,” according to a department statement.

The strategy offers specifics on broad, sweeping goals by the Pentagon to communicate faster and more securely with warfighters and allies. To date, the government has issued a number of strategic plans and frameworks to double down on cybersecurity and accelerate the military’s development of tools like AI, but this plan takes that a step further by prioritizing user experience and scalable, agile investments.

“It’s called ‘fulcrum’ because it sits at the nexus between our national security strategy, our strategic management plans — our really ‘big thinking’ strategies,” said Leslie Beavers, principal deputy chief information officer, on Tuesday.

With so many tools coming to market from different vendors and small businesses also hoping to break in, the strategy gives leaders guideposts for how to assess what tools and internal resources are needed.

Critically, it also devotes a category to developing the workforce, specifically by broadening the DoD Cyber Workforce Framework to focus more intently on roles for data, AI and software engineering.

The DoD has long said this is an established need.

“There is a recognized shortage of skilled cyber personnel that could potentially impact operational readiness across the Department and put national security at risk,” according to the department’s 2023 Cyber Workforce Strategy. “Despite the vast expansion of cyber educational and experiential opportunities, the nation’s cyber talent pipeline remains limited.”

As in the private sector, government, too, is struggling with too few tech practitioners that make new cybersecurity practices difficult to implement. At the same time, much of the technical guidance handed down by experts in tech shops is written for the actual programmists, not senior executives, so there needs to be an available reserve of workers, DoD officials said at the conference.

“Leadership is a force multiplier and to outpace [adversaries] we have to maximize the talent from our broad array of partners, and recruit and retain our own talent,” said Gen. Timothy D. Haugh, commander of U.S. Cyber Command and director of the National Security Agency, at the conference.

Finally, the new strategy also seeks to streamline governance and enhance use of data to backup decision-making and identify cost savings to deliver joint warfighting capabilities faster amid high-tempo, multi-domain operations.

“We must challenge legacy approaches and move move toward rapid innovation for them,” said Haugh. “We cannot succeed when our existing processes move slower than the rate of innovation change.”

(Source: C4ISR & Networks)

 

26 Jun 24. Lufthansa Technik Selects Thales For The Pegasus Programme.

Thales will supply its last generation of secured audio/radio management system capable of managing the communications of the flight deck and operators both internally and externally to the aircraft.

This system features full compliance with German military requirements, the highest level of security, and significant weight savings, as well as enhanced reliability compared to traditional technologies.

“Lufthansa Technik’s and Thales Aerospace Communications’ engineering teams have worked very closely to develop the most adapted audio/radio management system for this program. Together we have come up with a highly efficient system that enables the aircraft to fulfill very demanding missions. This new contract confirms our market leadership in terms of audio/radio management systems for missionized single intelligence platforms.” Nicolas Bonleux, Executive Vice-President, Thales Aerospace Communications

 

25 Jun 24. L3Harris Technologies is expected to unveil new wideband waveforms in September 2024, intended initially for Central and Eastern European (CEE) militaries, Janes learnt.

Speaking to Janes at the Eurosatory 2024 defence exhibition in Paris, held from 17 to 21 June, a company spokesperson disclosed that CEE militaries would be the first international customers for the ‘Vapor’ and ‘Vanguard’ waveforms, designed to increase security and resilience in contested areas of operation.

The spokesperson was unable to disclose which specific armed forces were interested in purchasing the new waveforms, although, L3Harris business development executive Michael Wolfe confirmed to Janes that the new waveforms were being designed to support the Falcon III RF-7850 family of software-defined radios (SDRs).

L3Harris Technologies has been supplying non-Type 1 SDRs to Ukraine’s Ministry of Defence (MoD) and Special Operations Forces since 2012, where they are used to co-ordinate operations in highly contested, electromagnetic operating environments.

The new waveforms, which operate between 225 MHz and 2.5 GHz and will be made available as a pair, have been designed to support anti-jamming and anti-detection requirements, Wolfe said.

The Vanguard waveform is designed to enable ground-to-ground communications, embedded into RF-7850D vehicular and RF-7850S handheld SDRs. Meanwhile, the Vapor waveform will support video datalink communications from unmanned air and ground vehicles equipped with the RF-7850A-ER Embeddable Modular Radio (EMR).

Wolfe confirmed that the new waveforms are developments from legacy Soldier- and Video-TDMA Networking Waveforms, but will also include frequency-hopping technologies. (Source: Janes)

 

25 Jun 24. Armed with quantum sensors, France eyes leaps in electronic warfare. The French Navy took delivery of its first serial-produced, quantum-technology sensor this year, a quantum gravimeter used for mapping the seabed, the head of the country’s defense innovation agency AID said. Future uses of such sensors could be for navigation or detecting enemy submarines.

The agency is also working with Thales on quantum sensors for electronic warfare that will allow monitoring of a broad swath of the electromagnetic spectrum, Patrick Aufort, the head of the agency, told Defense News at last week’s Eurosatory defense show in Paris. Those sensors will be available within the next five years, he said.

France in 2022 earmarked €1.8 bn, or U.S. $1.93 bn, to develop quantum technologies, a rapidly evolving field that exploits the laws of quantum physics to create new forms of computing, communication and sensing. Quantum gravimeters measure falling, laser-cooled atoms to detect tiny variations in gravitational pull, which could be used to detect the mass of an adversary submarine. There are no methods for submarines to shield themselves from such sensors, according to a 2020 policy brief from the European Leadership Network.

The gravimeter “is particularly useful for the first applications we’re doing here, mapping the seabed,” Aufort said. “But afterward, we can imagine other uses for the gravimeter, notably for positioning, notably for detecting the existence of a cavity on the seabed.”

French defense-procurement agency DGA has been funding work by the French national aerospace research office Onera on quantum gravimeters since 2006, with a first demonstrator in 2016. The office has worked with France’s Muquans, now part of the technology firm Exail, to industrialize the production of the gravimeter.

The second development France is working on is quantum-based, electronic-warfare sensors, which will allow for a higher probability of intercepting emissions in the electromagnetic spectrum, including radar and communications, according to Aufort.

“Quantum technologies allow you to have both a much better resolution on what you’re going to detect and, above all, to have instant detection over a very wide bandwidth,” Aufort said. “You have access to much greater bandwidths, and so a higher probability of interception, because emissions are in fact fleeting.”

Quantum-based electronic warfare sensors can use laser-cooled quantum bits that interact with any incoming electromagnetic waves, measuring tiny changes in a qubit’s quantum state. Today’s analysis relies on rotating through different bands to monitor the entire spectrum.

France is working in particular with Thales on such quantum sensors, which are “a question of, I’m not going to say months, but years, in the next five years,” Aufort said.

The head of the defense innovation agency said quantum computers are also a “question of years,” and they may be a mix of traditional high-performance computing with a quantum part. The DGA in March awarded contracts to five domestic computer research startups to develop technology that will allow France to have two universal quantum computer prototypes by 2032. (Source: Defense News)

 

26 Jun 24. Goldilock, the British cybersecurity company behind a unique physical network isolation solution, today announces a series of strategic channel partnerships with distributors and value-added resellers (VARs) to fuel global expansion and empower organisations worldwide with its mission-critical technology.

The increasingly complex cyber threat landscape necessitates a layered security strategy to effectively protect assets from attacks. Goldilock’s innovative “kill-switch” solution fits into this strategy as a powerful yet simple hardware-based approach that uses Dynamic Physical Network Segmentation (DPNS) technology, enabling users to physically isolate their digital assets and systems at the touch of a button.

Goldilock has now forged alliances with a select group of diverse channel partners, renowned for their established customer relationships and deep industry knowledge, to swiftly provide as many industries as possible with access to its physical isolation solution, including to high-risk industries such as defence and healthcare. These partners, listed below, will play a central role in broadening Goldilock’s footprint across new territories and market segments.

  • Distributors: Cyber Distribution (UK), Naperto (Mainland Europe), and CreaPlus (Mainland Europe).
  • Resellers: Brookcourt Solutions (UK, Enterprise), Sterling (UK & US, Defence and Security), NCS (Singapore, Enterprise), and BKJ Works (US, Enterprise).

These initial and carefully chosen partnerships grant Goldilock access to proven expertise in deployment, integration, and ongoing support, and unlock a vast network of potential customers. While Sterling brings unparalleled knowledge in the specific needs of the defence sector, NCS, Brookcourt, and BKJ Works cater to enterprise customers, with a deep understanding of their regional threat landscapes and requirements. This combined force ensures customers receive not just the technology, but also the expert guidance and industry-specific knowledge needed to maximise its effectiveness and achieve a truly holistic cybersecurity posture.

“Traditional security measures, like reactively patching vulnerabilities, are proving increasingly ineffective” said CEO and Founder Tony Hasek at Goldilock, “Our solution seamlessly integrates with existing technologies like firewalls, routers, and switches, allowing it to easily slot into any multi-layered security approach. We’re looking forward to working together with our new partners to make sure customers have access to tailored and ongoing support, helping them establish a cybersecurity setup that truly works for them.”

“Our commitment to a channel-first approach takes a major leap forward with these partnerships” said Steven Brodie, Head of Channel at Goldilock. “We’ve already established strong relationships with our new partners, and we’re actively seeking more to join our growing ecosystem.” He added “Ultimately, this is about meeting the demand for such a critical cybersecurity solution as quickly as possible.”

Luke Flanagan, Business Development Manager for EMEA at Sterling said “Sterling is thrilled to embark on this journey with Goldilock. Goldilock’s robust portfolio enhances cybersecurity, addressing a top concern for our customers. With Goldilock’s offerings, Sterling can provide even more secure solutions to our clients.”

Rob Leggett, CEO and Founder of Cyber Distribution said “Cyber Distribution is always on the lookout for game changing products which can make a real difference in the crowded cybersecurity market, and Goldilock fits the bill. Goldilock’s ability to physically isolate critical network infrastructure, OT and IT systems, ensures that assets remain secure, invisible, and inaccessible to adversaries, connecting to the internet only when necessary or being truly physically isolated in an instant. Our partners can now offer another level of security to their customers that was previously unavailable.”

 

26 Jun 26. Mattermost, Inc., a leader in secure collaboration for mission-critical work in complex environments, today announced that it has completed its $1.25m Small Business Innovation Research (SBIR) Phase II contract, delivering mission-critical ChatOps capabilities for the Air Force Research Laboratory’s (AFRL) Tactical Assault Kit (TAK) and ATAK operating systems.

Built in collaboration with the development team at BrainGu, a leader in mission software solutions, the Mattermost integration for TAK improves distributed collaboration and enhances warfighter efficiency, safety and accuracy. Developed to improve TAK’s tactical chat function by providing secure, enterprise-grade ChatOps capabilities, the plugin also leverages the Mattermost open-source secure collaboration platform’s self-hosting capabilities, enabling teams to retain full data ownership and meet communications security (COMSEC) requirements. Additionally, with support from BrainGu, the Mattermost integration creates an extension for TAK capabilities, laying the foundation for future capabilities such as AI-enabled decision support tools.

“We’re pleased to address a demonstrated capability gap with the delivery of the Mattermost integration for TAK, enabling our operators to leverage streamlined ChatOps functionality that facilitates the mission-critical transmission of intelligence,” said Corey Hulen, co-founder and CTO of Mattermost. “In partnership with BrainGu and goTenna, we’ve developed this integration to satisfy the Department of Defense’s need for primary, alternate, contingent and emergency communications protocol.”

In addition to the secure ChatOps plugin, Mattermost and BrainGu also worked closely with goTenna, the world’s leading mobile mesh networking platform, to develop and deliver transmission-layer integrations for TAK on goTenna’s mesh radios, addressing challenges associated with low-bandwidth communications and providing resilient, decentralized connectivity. The goTenna plugin also offers support for ATAK systems, enabling seamless connectivity with TAK servers and ensuring scalability and reliability in diverse operational environments.

With new collaboration features now available, 350,000 civilian, DoD and partner TAK users can leverage the secure chat integration and low-bandwidth capabilities to effectively communicate mission-critical information between operational teams at the tactical edge and their forward operating bases (FOB) in near-real-time. The completion of this contract marks Mattermost’s second completed SBIR Phase II this year, just three months after the company announced the completion of its first contract with delivery of its message acknowledgment and urgency capabilities for the 618th AOC.

To learn more about how Mattermost enables mission-critical collaboration for government customers, visit https://mattermost.com/solutions/industries/government/.

Supporting Quotes:

“Resilient communication is key to mission success,” said Tim Gast, Vice President, Labs, at BrainGu. “We’re proud to join Mattermost and goTenna in putting innovative software in the hands of warfighters to enhance decision quality and drive positive outcomes, and we’re looking forward to continuing our pursuit of what’s next.”

“We’re pleased to support tactical ChatOps and aid in the transmission of mission-critical intelligence across distributed environments, enabling support to operators working in low-bandwidth conditions via goTenna’s mesh capabilities,” said goTenna CEO Ari Schuler. “The goTenna and Mattermost partnership brings together two operator-focused companies seeking to support hundreds of thousands of airmen and TAK users with the secure communication they need to be successful in their mission.”

About Mattermost:

Mattermost is the leading collaboration platform for mission-critical work. We serve government, defense, aerospace and critical infrastructure in their support of the national security strategy. We accelerate decision advantage through self-sovereign collaboration, critical incident management and DevSecOps workflows to bolster the focus, adaptability and resilience of the world’s most important organizations.

Our enterprise software and single-tenant SaaS platforms are built to meet the custom needs of rigorous and complex environments while offering a secure and unrivaled collaboration experience across web, desktop and mobile with channel-based messaging, file sharing, audio calling and screen share, with integrated tooling, workflow automation and AI assistance.

Mattermost is developed on an open core platform vetted by the world’s leading security organizations and co-built with over 4,000 open source project contributors who’ve provided over 30,000 code improvements towards our shared vision of accelerating the world’s mission critical work.

For more information visit mattermost.com.

About AFRL

The Air Force Research Laboratory (AFRL) is the primary scientific research and development center for the Department of the Air Force. AFRL plays an integral role in leading the discovery, development and integration of affordable warfighting technologies for our air, space and cyberspace force. With a workforce of more than 12,500 across nine technology areas and 40 other operations across the globe, AFRL provides a diverse portfolio of science and technology ranging from fundamental to advanced research and technology development. For more information, visit www.afresearchlab.com.

About BrainGu

BrainGu is a leading technology provider specializing in mission software solutions for highly-regulated industries including defense, finance, and critical infrastructure. Our mission is to help our customers build higher quality software that is not only scalable and reliable but also secure from the start.

Our flagship developer experience platform, SmoothGlue, accelerates secure software development and deployment in environments with the strictest regulatory requirements, enhancing operational capabilities and ensuring compliance. Our solutions are tailored to meet the unique demands of these rigorous settings, providing a seamless, secure, and superior developer experience across cloud-native, on-prem, and edge deployments.

For more information visit braingu.com.

About goTenna:

goTenna is advancing universal access to connectivity by building the world’s most intelligent and scalable mobile mesh networks. goTenna is the world’s leading mobile mesh networking company, providing off-grid connectivity solutions for smartphones and other devices, as well as augmenting traditional communications networks. This technology enables mobile, long-range connectivity without cell, wifi, or satellite connectivity. goTenna’s drive to create resilient connectivity began during Hurricane Sandy in 2012 when approximately a third of cell towers and power stations in affected areas failed. goTenna’s products are currently used by over 300 law enforcement, military, and public safety agencies worldwide. Based in Brooklyn, goTenna is backed by investors including Founders Fund, Union Square Ventures, Comcast Ventures, Collaborative Fund, and Bloomberg Beta.

 

24 Jun 24. Taiwan: New campaign points to sustained espionage risks from Chinese state-sponsored groups. On 24 June, the cyber security company Recorded Future revealed that the likely Chinese state-sponsored group ‘RedJuliett’ is targeting Taiwanese government, academic, technology and diplomatic organisations in an espionage campaign. The group reportedly exploited software vulnerabilities in internet-facing network edge devices such as firewalls and virtual private networks (VPNs) to obtain initial access. They then used an open-source VPN to establish a persistent connection with actor-controlled infrastructure. Additionally, RedJuliett used structured query language (SQL) and directory traversal attacks to access confidential data. They also exploited additional vulnerabilities to escalate privileges within systems. The exploitation of vulnerabilities in network edge devices remains an effective initial access vector, highlighting the importance of network segmentation and strict patch management policies. Chinese state-sponsored actors often target Taiwanese organisations to steal sensitive information. This aims to bolster China’s economic and security posture amid tensions in the South China Sea, pointing to sustained espionage risks to Taiwanese firms. (Source: Sibylline)

———————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————————————————————————————————————————————————————————————————————————————————————————————

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

June 22, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

——————————————————————————————————————————————————————————————————————————————————————————————————————————————

20 Jun 24. China Crisis. Formally, it was called the Washington-Moscow Direct Communications Link. Informally, everyone called it the ‘hotline’. Established in 1963, this direct connection between the politico-military leaderships of the United States and Soviet Union took the form of a teletype link. By 1986 it had been upgraded to use fax machines (remember them?) and, since 2008, the hotline has been a computer link. Just one year after its establishment, the hotline was lampooned in the 1964 black comedy Dr. Strangelove or: How I Learned to Stop Worrying and Love the Bomb. The fictional US President Merkin Muffley is seen on the phone to his Soviet counterpart Dimitri Kissov asking him to “turn the music down”. Mr. Muffley delivers the news that a US Air Force general has gone mad and unilaterally launched a nuclear strike against numerous Soviet targets. A drunk, partying Mr. Kissov presumably sobers up rather quickly.

The hotline was established in the wake of the 1962 Cuban Missile Crisis to provide both the American and Soviet leaderships a mechanism by which they can urgently and directly discuss growing tensions in a bid to avoid Armageddon. Today, the US finds herself in a similarly tense relationship with the People’s Republic of China (PRC). A miscalculation or misunderstanding risks plunging both nations, and much of east and southeast Asia, into war; possibly even a nuclear one.

Therefore, the news should be welcomed, as articulated in an article published on 27th May in Foreign Policy, that both the US Indo-Pacific Command (INDOPACOM) and the People’s Liberation Army (PLA), are to double-down on efforts to establish a direct communications link between these two entities. The past three decades have been littered with examples of situations where US-PLA tensions could have boiled over; near misses between US and Chinese military aircraft are but one example. Ensuring direct, secure communications between rivals cannot unilaterally prevent a war, but they can help to cool tensions when tempers flare, enabling two nuclear-armed heavyweights to discuss how to step back from the abyss. (Source: Armada)

 

20 Jun 24. Enhancing CESMO. The CESMO tactical datalink protocol helps aircraft geolocate the position of hostile ground-based air surveillance and fire control/ground-controlled interception radars to help improve survivability. The uptake of NATO’s CESMO tactical datalink protocol is proceeding apace with ongoing enhancements to deepen its abilities to share electronic intelligence to support air operations.

This year’s Association of Old Crows’ Electronic Warfare Europe exhibition and conference was held on 14th and 15th May in the town of Lillestrøm, southeast Norway. Delegates were updated on the progress of the North Atlantic Treaty Organisation’s (NATO’s) Cooperative Electronic Support Measure Operations (CESMO) Tactical Datalink (TDL) protocol.

CESMO helps aircraft share hostile emitter location information so the latter can be avoided or engaged. The SEWWG (NATO SIGINT and Electronic Warfare Working Group) is CESMO’s custodian. Military aircraft are routinely equipped with Radar Warning Receivers (RWRs) and Electronic Support Measures (ESMs). ESMs and RWRs protect aircraft by detecting, identifying and locating hostile ground-based air surveillance and fire control/ground-controlled interception radars. An RWR tends to give aircrew a relatively simple warning with details of a radar’s bearing relative to the aircraft. An ESM supplies more detailed information on the radar’s identity and location. The electronic support measure will also furnish specifics on the waveforms the radar is using although, to an extent, RWR and ESM functions overlap.

How CESMO works

RWRs and ESMs can use two mechanisms to detect and locate red force radars, chiefly Angle-Of-Arrival (AOA) and Time of Arrival (TOA). AOA determines the Line-of-Bearing (LOB) from one point to another, in this case between an aircraft and a hostile radar. Consider three aircraft flying in the vicinity of a ground-based air surveillance radar. One aircraft is flying towards the radar on a north-south bearing, the second is flying on an east-west radial away from it and the third is flying on a south-north bearing towards it. Each plane is equipped with an RWR which determines the radar’s line-of-bearing relative to the aircraft. All three planes detect the same radar transmission. The RWR on the first aircraft determines a southern LOB to the radar. The RWR on the second determines a westerly LOB while the third aircraft’s RWR determines a northerly line-of-bearing. By using this information, the radar’s position is determined as the point where all three bearings cross.

TOA works slightly differently. We will stick with our three aircraft, all of which are continuing to fly the same courses in the vicinity of the hostile radar. One aircraft is 100 nautical miles/nm (185.2 kilometres/km) from the radar flying on north-south bearing. The second is 150nm (277.8km) from the radar flying away on an east-west radial. The third is 50nm (92.6km) away flying on a south-north bearing. Triangulation relies on the fact that radar transmissions move at light speed (161,595 nautical miles-per-second/299,274 kilometres-per-second).

Radar transmissions will take different times to reach each aircraft’s RWR. For the first plane it will take the transmissions 0.6 milliseconds to get there. For the second it will take 0.9 milliseconds and for the third 0.1 milliseconds. Calculating the time difference taken by the radar transmissions to reach each aircraft relative to their position computes the radar’s location. This data is fused with the aircraft’s position as derived from its navigation equipment and sent from each aircraft via their standard communications links. The data reaches a central computer housing the CESMO software. Once the data arrives, the software computes the point where the lines-of-bearing from each RWR meet.

Once the CESMO software ascertains the radar’s location it retransmits this to other friendly aircraft at risk of detection. The radar can then be avoided or engaged with kinetic, electronic and/or cyberattack. CESMO information is sent back out across the same communications links. Data is carried on standard very/ultra-high frequency (30 megahertz to three gigahertz) links and tactical datalinks like NATO’s Link-16. Traffic is carried in IP (Internet Protocol) format messages absorbing under 16 kilobits-per-second of bandwidth. Furthermore, CESMO is a node-less network as there is no single, central point of network control. Should one platform sharing its information be lost this will not cause the collapse of the CESMO network.

Updating CESMO

As Armada reported in June 2023, new messaging standards are being introduced into the CESMO architecture. The new standards widen the remit of the data shared across a CESMO network and cover electronic attack and Emission Control (EMCON) information. Tactical messaging can now be moved across CESMO links with information on how an emitter is to be engaged. EMCON messages enable the distribution of frequencies off limits for electronic attack.

Delegates were told by representatives from the Bundeswehr (German armed forces) that recent exercises involving CESMO and the German armed forces had seen traffic carried across Link-16 and Satellite Communications (SATCOM) links. Other conduits employed include tactical radio TDLs, local area networks and SINA (Secure Inter Network Architecture) wide area networks. The representatives added that CESMO is “designed to work with limited bandwidth radios with long latencies when the reception of messages cannot always be ensured.”

CESMO will experience further capability enhancements, according to the Bundeswehr representatives. These enhancements include the handling of CESMO across NATO’s Link-22 TDL (2MHz to 29.9MHz, 225MHz to 399.975MHz). Link-22 is mainly used to support naval operations. Other protocols that will handle CESMO traffic including NATO’s JREAP (Joint Range Extension Application Protocol) and Systematic’s SitaWare Command and Control (C2) software. SitaWare is used extensively to support C2 in all domains across NATO and allied nations. JREAP allows TDL traffic to be moved across beyond line-of-sight links like SATCOM.

The Bundeswehr representatives said that two CESMO enhancements covering track classification and messaging have already been performed. The SEWWG is planning to make at least two updates per year. These updates will cover airborne electronic attack coordination, emitter association and disassociation messaging, time difference of arrival coordination and platform activity messaging. Nonetheless, the representatives emphasised that the more nations join the CESMO initiative, the more updates and enhancements can be made. (Source: Armada)

 

20 Jun 24. Avancez Mes Radios! France’s Contact programme sees a host of new radios entering service across the French Army, and the rest of the country’s military, including the NCT-T vehicular transceiver shown here. Thales is moving ahead with the development of a backpack radio as part of the programme which will have commonality with the NCT-T.

New versions of the Contact tactical radio are in the offing for the French military, while the country’s Ministry of Defence is expected to soon launch a procurement programme for a new HF transceiver.

Thales is the prime contractor for the French armed forces’ Contact tactical communications system which rolls out a raft of new transceivers and capabilities, most of which are for the Armée de Terre (French Army). The army is to retire its legacy Thales PR4G Very/Ultra High Frequency (V/UHF: 30 megahertz/MHz to three gigahertz/GHz) radios which entered service from 1990. These transceivers will be replaced with new dual band 30MHz to 108MHz, and 225MHz to 512MHz handheld and vehicular radios.

The five watt/W handheld Contact radio is known officially as the ESR-P (Equipement Radio Standard-Portatif/Handheld Radio Terminal). The Contact vehicular radio is officially designated the NCT-T (Node de Communications Tactique–Terrestre/Land Tactical Communications Node). An airborne radio (ERS-A) is in the offing and will be rolled out across France’s fleet of military aircraft. Thales officials recently shared with Armada that the company is developing a backpack Contact radio. This new transceiver is expected to enter service in 2027, the officials continued. The 20W system will have a similar configuration to the NCT-T and will carry similar waveforms.

France’s Direction Générale de l’Armement (DGA/General Armaments Directorate) procurement agency awarded a contract to Thales to fulfil the Contact requirement in 2012 with production commencing in 2019. Open sources state that circa 25,000 radios across all types could eventually be manufactured and delivered. Thales says that it will produce an average of 100 radios per month at its site in Cholet, western France.

Waveforms

Contact radios will carry several waveforms. Importantly, from an interoperability perspective, they will have the pan-European ESSOR (European Secure Software Defined Radio) wideband networking waveform. French army sources have told Armada that the ESR-P and NCT-T will carry the French version of the waveform. This latter version of ESSOR is known as ESSOR-VF. While ESSOR-VF will support multinational and coalition operations, the radio’s new CONVERT waveform is for exclusive French use. Like ESSOR-VF, CONVERT carries voice and data traffic. North Atlantic Treaty Organisation waveforms like SATURN (Second Generation Anti-Jam Tactical UHF Radio For NATO) will be included in the Contact radios. SATURN primarily carries air-to-surface/surface-to-air traffic. Furthermore, the Contact transceivers are outfitted with a Blue Force Tracking waveform.

Export variants of the Contact transceivers sans French national encryption and government waveforms, known as Synaps, are in production. Synaps is equipping the Belgian armed forces. Spain will also receive Synaps with Indra and Thales collaborating on the acquisition. Having these armed forces use a similar radio system to Contact will help further enhance pan-European interoperability.

New HF Radio

Field testing of the Contact radios has been successfully completed. The first examples were delivered to the army in September 2020. Deliveries have been continuing since then with Contact undergoing, and passing, operational evaluation in December 2023. The PR4G is being phased out while Contact deliveries continue with the former expected to leave service by the end of 2025, according to army officials.

Contact forms part of a wider overhaul of French military radio communications. Beyond this programme, French troops are receiving new Personal Role Radios (PRRs). These will replace Safran’s RIF-NG PRRs equipping the force’s Fantassin à Équipement et Liaisons Intégrés (Integrated Infantryman Equipment and Communications) ensemble. Meanwhile, plans are afoot to equip the French Army with a new High Frequency (HF: three megahertz to 30MHz) radio based on Thales’ HF XL. HF XL is already in service with the Marine Nationale (French Navy). Two variants are under development for the army, namely 400W and one kilowatt transceivers. Thales sources shared with Armada that a contract to procure a new French Army HF radio is expected from the DGA in 2025. (Source: Armada)

 

20 Jun 24. June Radio Roundup. Spectra Group is finalising the development and testing of its GENSS tactical communications system which the company expects to be available for procurement by the end of this year.

GENSS makes sense

Spectra Group showcased its GENSS tactical communications system at this year’s SOF Week special forces exhibition held in Tampa, Florida between 6th and 10th May. GENSS is a development of the company’s Slingshot tactical communications apparatus.

A company press release said that GENSS uses high frequency (three megahertz/MHz to 30MHz) and Very/Ultra High Frequency (30MHz to three gigahertz/GHz) wavebands. GENSS can also use Satellite Communications (SATCOM) frequencies including Inmarsat’s LTAC L-band (1.2GHz – 1.8GHz/1.67GHz – 1.71GHz) SATCOM service. GENSS supports data rates of up to 90 kilobits-per-second across LTAC’s 25 kilohertz channels.

The company press release continued that GENSS uses “adaptive modulation waveforms.” These waveforms “automatically adjust through network sensing techniques, to meet the tactical situation.” Tactical situations could include the user being mobile, in combat or stationary. In addition, “novel engineering techniques, voice and low data rate solutions can be applied in the contested communications space to minimise detection.”

Spectra Group told Armada, via a written statement, that GENSS is in fact “a suite of solutions based around a core radio module.” This module comprises of a Software Defined Radio (SDR) circuit board designed and manufactured in-house by the company using a “state-of-the-art chipset”.  The SDR board provides GENSS with frequency agility from 29MHz to six gigahertz, with a 40MHz operating window. The statement continued that “the first product delivery will include a Radio Frequency (RF) front end module” optimised for LTAC. GENSS operates seamlessly with Slingshot, the statement added.

Work on GENSS is wrapping up “with final development and testing” ongoing. These efforts are focusing on finalising the L-band capability. However, Spectra Group says that GENSS can be continually modified and enhanced during its lifetime. Production is scheduled for the final quarter of 2024. (Source: Armada)

 

21 Jun 24. Cyber Update Key points.

  • The cyber criminal group ‘Scattered Spider’ is evolving its tactics; this will exacerbate security and financial risks facing firms in the long term (see Sibylline Cyber Daily Analytical Update – 17 June 2024).
  • A newly discovered long-term espionage campaign by the Chinese nexus group ‘Velvet Ant’ will sustain security and espionage risks via outdated software (see Sibylline Cyber Daily Analytical Update – 18 June 2024).
  • A new phishing-as-a-service (PhaaS) kit underscores the heightened security risks facing financial institutions (see Sibylline Cyber Daily Analytical Update – 19 June 2024 and our Technical analysis below).
  • A new highly sophisticated malware will elevate the security risks facing Chinese-speaking firms (see Sibylline Cyber Daily Analytical Update – 20 June 2024 and our Technical analysis below).
  • Chinese nexus threat actors are reportedly targeting an unnamed Asian country’s telecommunications sector as part of a long-term espionage operation, prolonging security risks (see Sibylline Cyber Daily Analytical Update – 21 June 2024).

Technical analysis of weekly stories

A new Phishing-as-a-Service (PhaaS) kit, ‘ONNX’, is targeting employees of global financial institutions. ONNX operations impersonate an organisation’s HR department to trick potential victims into scanning a malicious QR code. The user is then redirected to a fraudulent Microsoft 365 login page where they are prompted to enter their credentials and pass a two-factor authentication (2FA) process. The threat actors capture this information in real time via WebSocket, which enables them to hijack the victim’s account. Notably, QR codes are almost always scanned on mobile phones, which often lack the same organisational security protections as other devices, enabling threat actors to bypass initial detection mechanisms. ONNX simultaneously downloads an encrypted JavaScript, which adds a layer of protection against anti-phishing mechanisms. Additionally, it obfuscates actor-controlled infrastructure by abusing the security company Cloudflare’s legitimate anti-bot CAPTCHA features. The kit is a new and more sophisticated version of the ‘Caffeine’ phishing kit created in 2022 by the threat actor ‘MRxC0DER’ to target Russian and Chinese platforms. We assess this highlights the kit’s ongoing development and the growing sophistication of the threat actors’ tactics, techniques and procedures (TTPs) as they refine anti-detection and obfuscation techniques. ONNX can be purchased and managed via the messaging platform Telegram, thus highlighting the accessibility of the kit and the possibility of its use in future attacks.

Since late April, unknown threat actors have targeted Chinese-speaking organisations with a new sophisticated loader malware, ‘SquidLoader’. The loader is distributed via phishing emails containing malicious payloads masked as legitimate Microsoft Word documents. The malicious file executes and duplicates SquidLoader in a secondary location, thus bypassing initial detection mechanisms. The loader also contains arbitrary code and references to popular software products such as ‘WeChat’ to evade detection. Additionally, SquidLoader automatically deletes itself from victims’ systems if it is detected; it also obfuscates the location of the actor-controlled infrastructure. Notably, the malware’s highly advanced anti-detection and anti-analysis techniques highlight the ongoing development and maturity of the threat actors’ TTPs. SquidLoader has primarily been used to deploy Cobalt Strike (an open-source post-exploitation tool) to gather information from targeted systems. Cobalt Strike can create services and modify registry keys, thus enabling prolonged persistence. The combination of highly advanced persistence and obfuscation techniques suggests that the threat actors behind this campaign possibly belong to an advanced persistent threat (APT) group.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing and other types of social engineering attempts.
  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Enforce strict security policies including regular software and password updates to mitigate and prevent infections via leaked or stolen password credentials.
  • Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise. (Source: Sibylline)

 

21 Jun 24. Safran Electronics & Defense is developing a new solution for transmitting and receiving optical communications by laser. This innovation will enable armed forces to share information at very high speed with no risk of jamming or interception. It is the result of the company’s expertise in inertial navigation, optronics and communications.

Laser optical communication technology will be based on terminals that can transmit and receive optical communications: one terminal to send data encoded in a laser beam, the other to receive it and convert it into digital information. Users will be able to share messages, pictures and video at ranges of tens of kilometers, or even further with the aid of relay satellites.

Laser optical links offer several advantages over traditional radio communication, including discretion and resistance to interference. But also throughput, with speeds of 5 Gb/s to 50 Gb/s, which is a major benefit as data volumes continue to increase and data-hungry AI becomes more widely deployed.

One of the main challenges with an optical communication system is to establish a direct line of sight between two terminals, and then ensure its stability during data transfer, whatever the conditions (for example, heavy swell for naval applications). Safran Electronics & Defense has addressed this challenge, drawing on its technological expertise in the development of mobile platform-mounted optronic sights and satellite communication solutions.

“We’re one of the only companies in the world today capable of developing this technology at scale for use by the armed forces,” says Alexandre Ziegler, Executive VP, Defense Gobal Business Unit of Safran Electronics & Defense. “We already have sovereign control over all the necessary technological components. And our teams have a deep understanding of military requirements and related technical issues on land, at sea, in the air and in space.”

 

20 Jun 24. Bittium Tough Mobile™ 2 C Approved as an Information Security Solution for NATO Restricted Level Use. Bittium Tough Mobile™ 2 C Approved as an Information Security Solution for NATO Restricted Level Use

Bittium Corporation press release on June 20, 2024, at 6.00 p.m. (CEST +1)

NATO Communications and Information Agency (NCIA) has approved Bittium Tough Mobile 2 C solution as NATO Information Assurance Product for NATO Restricted level use. The solution has been listed on the NATO Information Assurance Product Catalogue (NIAPC).

Bittium’s secure mobile communication solution meets the very high security requirements of governmental organizations. The solution consists of Bittium Tough Mobile™ 2 C smartphone, Bittium Secure Suite™ encryption and device management software, and Bittium Secure Call™ application for end-to-end encrypted communication. Tough Mobile 2 C has a unique dual-boot functionality that makes it a device with two separate operating modes, Personal and Confidential. Hardened Android™ operating system in the Personal mode is for personal use where for example social media applications are available. Operating system in the Confidential mode is completely separated and hardened for secure use. Secure Suite device management and encryption software product enables efficient utilization of the information security features of the Tough Mobile smartphones, reliable mobile device management, remote attestation, and secure data transmission of the device.

“We are very excited that our products are now approved for NATO Restricted communications. Governmental organizations in NATO countries can now benefit from an excellent and proven solution that offers end-to-end encrypted mobile communications for their requirements”, says Mr. Tommi Kangas, Senior Vice President, Defense & Security at Bittium.

Bittium Tough Mobile™ 2 C smartphone with Bittium Secure Suite device management system is targeted for ultra secure government-level mobile communications. The smartphone is a combination of unparalleled hardware- and software -based information security features and usability, and two separate and hardened operating systems. Tamper-proof information security platform, privacy switch, and the supervised and secure supply chain ensure reliable and secure communication and handling of data especially in use by professionals and authorities. More information: Bittium Tough Mobile 2 C smartphone.

Bittium Secure Suite™ device management and encryption software product complements Bittium Tough Mobile smartphones with a scalable set of software services for remote management, remote attestation and securing the network connections of the device. Bittium Tough Mobile 2 C smartphone and Bittium Secure Suite together form a unique and reliable system for processing and transferring encrypted and classified material and securing critical communications. More information: Bittium Secure Suite device management and encryption software.

Bittium Secure Call™ is a secure voice, video and messaging application with end-to-end encryption. The communication application is designed for enterprise, government, and other professional users with stringent information security needs. The application supports deployment in commercial and private networks with no dependency on public Internet or cloud services. It can be deployed and fully managed by the user organization.  More information: Bittium Secure Call application.

 

20 Jun 24. Software-Defined Radio with Widest Tuning Range Released.

Calamine from Per Vices Corporation offers an impressive tuning range from near DC to 40 GHz with four independent receive radio chains each offering 300 MSPS sampling bandwidth

Per Vices Corporation, a provider of software defined radios (SDRs), has released Calamine, the company’s latest and widest tuning range SDR.

Calamine builds on the Per Vices existing IP to offer an impressive tuning range from near DC to 40 GHz with four independent receive radio chains each offering 300 MSPS sampling bandwidth.

The latest release will offer capabilities extending other SDR systems for use by government, defense/intelligence communities and civil customers with direct applications for radar systems, signals intelligence, spectrum monitoring, and satellite communications systems.

Per Vices products aim to provide hardware and software solutions to address the growing need for high channel count, wide tuning range, and high bandwidth SDRs. According to Per Vices, Calamine sets a new standard for tuning range demanded by the market.

Victor Wollesen, CEO of Per Vices, said; “There has been a growing need in RF for operating at higher frequency ranges within sacrificing the ability to tune to lower frequencies as well. Our latest release of Calamine offers a perfect solution to address this need with multiple channels and high sampling bandwidths all within a compact 19” 2U form factor.

“We’re very excited to be offering this product to our customers as we know it is critical for many different applications.”

Per Vices Corporation is a Canadian company based in Toronto, Ontario designing and producing high-performance commercial-off-the-shelf (COTS), modified-off-the-shelf (MOTS) and fully customized SDRs that can be tailored to fit the most challenging and mission critical customer applications. (Source: https://www.defenseadvancement.com/)

 

20 Jun 24. Safran and Wojskowe Zakłady Elektroniczne join forces to support Polish Defense. During the Eurosatory exhibition, Safran Electronics & Defense and the Polish company Wojskowe Zakłady Elektroniczne (WZE S.A.) signed for the first time a contract for the supply of Safran’s Geonyx inertial navigation and pointing systems to the Polish Armed Forces. The total cumulative quantity is in the range of 200 pieces of equipment. The Geonyx were selected for both the PILICA+ and NAREW air-defense programs for Poland. They will provide precise and reliable positions to anti-aircraft platforms, even if satellite navigation signals are unavailable or inaccessible, and heading references to the various radars.

The signing of this contract will also include the transfer of production of these inertial units to WZE S.A.: Safran will produce the main elements; WZE S.A. will carry out their assembly and the necessary checks before delivering the Geonyx to Poland. The main goal is to reduce delivery times and, ultimately, ensure the local maintenance of the Geonyx of the Polish army in order to optimize the availability rate of their systems. In a similar context, the company Young Poong Electronics (YPE), which adapted Geonyx technology to the Korean K2 assault tanks of the Polish Army, will also transfer the production of its inertial units to WZE S.A.

“We are proud to participate in the Defense of a European country such as Poland alongside WZE S.A. in these two strategic segments: anti-aircraft defense and armored vehicles,” Alexandre Ziegler, Executive VP, Defense Gobal Business Unit of Safran Electronics & Defense, said. “Thanks to our partners, we will be able to provide this inertial navigation technology resilient to jamming and spoofing of satellite navigation signals to Polish Armed Forces. Resilient Positioning, Navigation and Timing (PNT) services are at the heart of the battlefield changes we are witnessing.”

“I am honoured to be able to participate in the conclusion of this agreement with Safran Electronics & Defense on behalf of Wojskowe Zakłady Elektroniczne S.A. The establishment of extensive cooperation between WZE S.A. and Safran is not only the delivery of modern INS systems for the needs of the Polish Armed Forces, but also the planned transfer of knowledge and technology,” said Damian Gorzelany, acting President of WZE S.A. He added: “I am proud to be able to enter into cooperation with YPE, which has developed the OUROS navigation system, which WZE S.A. wants to offer for products from Polish-Korean cooperation. The Koreans impressed us with their commitment and openness and they demonstrated the excellent quality of work and products.”

Geonyx’s hemispherical resonator gyroscope navigation technology, HRG Crystal, offers the best reliability on the market, with an average time between failures of more than a m hours, as well as robustness in the most demanding environments. The HRG Crystal is also independent of any external signal and very compact. This allows the Geonyx to maintain positioning and pointing accuracy, even when satellite navigation signals are jammed or spoofed, while providing the best balance of size, mass and power. (Source: Defense Arabia)

 

20 Jun 24. EDGE and Thales Announce a Strategic Partnership for Radio Communications Development and Manufacturing in the UAE. KATIM, an EDGE Group entity and leader in the development of ultra-secure communication solutions, and Thales, will start discussing the co-development of Software Defined Radio technologies in the United Arab Emirates (UAE). A declaration of intent was signed at the international defence and security show, Eurosatory, by Didier Pagnoux, CEO of KATIM, Abdelhafid Mordi, CEO of Thales in the UAE and Christophe Groshenry, Vice President, Radio of Thales, and in the presence of Hamad Al Marar, Managing Director and CEO of EDGE Group, Waleid Al Mesmari, President, Space & Cyber Technologies of EDGE Group, Pascale Sourisse, President & CEO of Thales International, and Christophe Dumas, CEO of Thales Secure Communications & Information Systems in France.

To meet the demands of the UAE’s large-scale high-tech programmes and its exportation needs, KATIM and Thales will work jointly on the full cycle development, production and maintenance of airborne and long range HF (high frequency) radio communication solutions. Both companies will bring their expertise to the partnership and will promote and export the co-developed solutions-based portfolio to the international market.

Didier Pagnoux, CEO of KATIM, said: “Partnering with Thales represents a significant milestone for EDGE, underscoring the global confidence in our leadership in advanced communications technology. By combining our expertise, we will develop sophisticated Software Defined Radio solutions that meet the rigorous demands of both domestic and international markets. This collaboration aligns with our goal of driving innovative secure communication solutions and fully supports the UAE’s ambitious global exports roadmap. We eagerly anticipate the transformative outcomes of our joint efforts.”

Christophe Salomon, Executive Vice-President, Thales Secure Communications & Information Systems, said “As a worldwide leader for tactical radios and on-board communication solutions for land, air and naval forces, Thales is proud to partner with EDGE in radio communications solutions. The partnership is fully aligned with the Group’s development strategy in the UAE.” (Source: Defense Arabia)

 

19 Jun 24. Revolutionizing team connectivity – Savox launches new, game-changing wireless team communication system, Savox Pack-COM.

Designed for the demanding needs of tactical environments, the Savox Pack-COM provides seamless, secure, and reliable communication, enabling teams to perform optimally

  • The Savox Pack-COM enhances team coordination and situational awareness in tactical environments with secure, reliable communication.
  • It features a portable base station with AES-256 encryption, ensuring secure communications within a 400-meter range.
  • The system includes the Savox TRICS series for advanced team communication, integrating with existing radios for versatility and interoperability.
  • Providing crystal-clear sound quality, the Pack-COM reduces misunderstandings and boosts operational efficiency in challenging conditions.

The full press release article is included below. If you are interested in covering the story, you can also find high resolution images on our newsroom from the link below. All content is freely available to you to publish as you wish:

https://ins-news.com.

Thank you for your time in considering this article. If you have any questions about the product, comments or feedback on the content, or decide to cover the news, I would be delighted to hear from you.

 

19 Jun 24. Bittium Wireless Ltd, a subsidiary of Bittium Corporation and BAE Systems Signed a Framework Agreement on Bittium’s Tactical Communications Offering.

Bittium Wireless Ltd, a subsidiary of Bittium Corporation has signed a Framework Agreement with BAE Systems (Operations) Ltd (acting through BAE Systems Digital Intelligence) for BAE Systems to offer Bittium’s tactical communications products, services, and systems for the use by its customers both in the UK and abroad. The agreement does not contain a minimum purchase commitment, nor an exclusive right to sell. BAE Systems is one of the world’s largest defense operators providing some of the world’s most advanced, technology-led defense, aerospace, and security solutions.

The framework runs from 2024 to 2027. As part of this framework, BAE Systems and Bittium intend to participate in selected future tenders for tactical communications requirements. Together, BAE Systems and Bittium can offer the ESSOR High Data Rate Waveform that is a NATO standard and the preferred waveform for radio interoperability across NATO partners. ESSOR waveform is supported by Bittium Tough SDR™ radios. Under this Framework Agreement the first call for tenders applicable to tactical communications products is estimated to start during the latter half of 2024.

“The cooperation with BAE Systems is a significant step in Bittium’s internationalization strategy. We are proud that Europe’s leading defense company has chosen our products as part of their offering. This is an indication of reliability, quality, and technological pioneering of our products. Our opportunity to grow in international markets improves significantly alongside a major operator and we look forward to possible future joint customers projects”, says Johan Westermarck, CEO of Bittium Corporation.

“This framework agreement demonstrates our commitment to ensure we are always able to deliver the most impactful technology solutions for our customers – no matter what operational challenge they face. Partnering with organisations like Bittium help our customers navigate today’s complex and dynamic defence landscape and ultimately achieve their missions. Finland is known across the world for its innovative technology companies and BAE Systems has a strong partnership with Finnish industry that we are pleased to continue to build on with Bittium,” says Mark Todd, Head of Products – C5ISR, BAE Systems Digital Intelligence.

 

19 Jun 24. At Eurosatory 2024, Safran Electronics & Defense is launching its Advanced Cognitive Engine (ACE) artificial intelligence system. Its purpose is to integrate AI capabilities into all Safran Electronics & Defense products to deliver enhanced situational awareness, decision support and reduced cognitive load for forces in the field.

ACE will improve target detection, classification and identification capabilities by correcting for environmental effects such as atmospheric turbulence and low light conditions. Other functions such as advanced tracking and automatic target detection will help users perform missions by reducing their cognitive burden. Each capability can be adapted to specific environments — flat open landscape, desert, jungle, etc. — for optimum performance.

These combined capabilities, called “ACE on board”, will be integrated into all equipment, including land vehicle, aircraft and naval sights, as well as portable optronics products. ACE will also integrate on Safran Electronics & Defense drones and robotic systems, enabling operators to manage and operate their fleets more efficiently.

ACE responds to the ethical challenges posed by the use of AI: all of its capabilities keep the user at the heart of the decision and action loop.

“It’s important but also quite natural for us to be talking about AI at this year’s event,” said Alexandre Ziegler, EVP Defense Division, Safran Electronics & Defense. “By capitalizing on our expertise in this field, coupled with our high-tech imaging systems, we’re offering significant advances in performance for our customers.”

Initially available on an external processor, these new capabilities will be built into equipment via dedicated electronics. The ACE solution will benefit from twice yearly updates to keep pace with evolving operational realities. Safran is an international high-technology group, operating in the aviation (propulsion, equipment and interiors), defense and space markets.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————–

 

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————————————————————————————————————————————————————————————————————————————————————————————

UNMANNED SYSTEMS UPDATE

June 19, 2024 by

Sponsored by The British Robotics Seed Fund

 

Sponsored by BCB INTERNATIONAL

 

http: https://www.bcbin.com/

 

———————————————————————————————————————————————————————————————————————————————————————————————————————————————–

18 Jun 24. Thales Unveils OpenDRobotics to Support a New Era of Extended Collaborative Combat Enabled by AI.

  • Thales is launching OpenDRobotics, a revolutionary new solution that combines robotics technologies with unmanned air and ground vehicles to provide the armed forces with an integrated, human-in-the-loop mission system capability.
  • Artificial intelligence transforms collaborative combat by integrating multiple drones and robotic systems, increasing their ability to operate autonomously and reducing the cognitive burden on warfighters.
  • OpenDRobotics was developed in close cooperation with the armed forces and leverages the expertise of an ecosystem of innovation partners to meet the challenges of high-intensity combat.

With OpenDRobotics, Thales is taking collaborative combat to the next level through the development of a revolutionary integrated system that ties together robotics technologies and different types of drones to provide an automated mission system capability.

Recent conflicts have demonstrated the operational value of drones and robotic systems in terms of battlefield transparency and speed of action to enhance mission effectiveness while keeping human operators out of harm’s way. These systems can also saturate enemy defences without requiring larger numbers of human operators or increasing the cognitive burden on the forces already deployed.

Thales is a pivotal player in the field of collaborative combat, providing AI modules, connectivity solutions, mission systems that enable engaged units to operate as a network and a unique ability to integrate with conventional assets already in service with land forces.

Building on the success of CohoMa II1, the OpenDRobotics initiative creates operational value by coordinating the capabilities of a wide range of drones and robotic systems, providing command-and-control and extended collaborative combat functions by capitalising on the Group’s long-standing experience with tactical mission systems, in particular for the Scorpion programme.

OpenDRobotics has a central role to play in a broad spectrum of armed forces missions: reconnaissance, intelligence, CBRN2, Special Forces operations, cavalry, artillery, etc.).

OpenDRobotics builds on the open-source ROS (Robot Operating System) and STANAG 4586 standards, which are widely used by NATO and were developed as collaborative initiatives to promote easier integration of drones and robotic systems developed by partners and third parties.

“We are proud to present OpenDRobotics, a comprehensive offering that will accelerate the process of integrating drones and robotic systems in land combat operations. Building on our experience on the Scorpion programme and the lessons learned from collaborative combat deployments, Thales is enabling the forces to conduct their missions more quickly and in greater safety by coordinating large numbers of autonomous systems on the battlefield,” said Arnaud Lacaze, Vice President Defence Business Segment, Thales. (Source: ASD Network)

 

19 Jun 24. TEKEVER, the European market leader in unmanned aerial systems (UAS), today announced it has signed a memorandum of understanding (MOU) with BTI Defence, a defence procurement specialist, headquartered in Indonesia, to be the exclusive provider of UAS technology for the Indonesian defence ministry for two years.

The partnership, signed at the Eurosatory 2024, will see TEKEVER provide first and second-line support, deploying its UAS for immediate assistance and monitoring for potential threats and risks. Under the MOU, BTI defence will have access to the full suite of TEKEVER’s systems including the AR3, AR4, AR5, and from 2025, the ARX as well as ATLAS, the interface that presents intelligence and data insights. The UAS systems feature cutting-edge AI, machine learning, edge computing and high-precision sensors, revolutionizing intelligence gathering and surveillance with unparalleled accuracy and efficiency.

This latest collaboration with BTI Defence marks TEKEVER’s expansion into Indonesia where it will drive the development of the country’s UAV market, among the armed and security forces,  as well as private and state-owned entities. It highlights TEKEVER’s growing global footprint with the company also retaining contracts in Europe, Africa, and North America.

TEKEVER’s CEO, Ricardo Mendes, said, “We are delighted to partner with BTI Defence who share our commitment to promoting stability and security. Our cutting-edge technology, agile operating model and relentless innovation will prove critical in enhancing security in the region. This partnership is further evidence of our reputation as a trusted partner for governments and security agencies across the globe.”

Director of BTI Defence, Mr Peter Tjahjono, said, “This agreement between BTI Defence and TEKEVER comes at a time when Indonesia is expanding its investment in tactical and strategic UAVs as part of its national surveillance and border control operations. TEKVER’s market leading performance and reliability is the perfect match to Indonesia’s operational requirements.”

 

18 Jun 24.  Arkeocean, the Cyprus Marine and Maritime Institute (CMMI), Lanego and SignalGeneriX Ltd have signed a research and development agreement to co-develop a solution called ‘EONIOS’, a micro-AUV swarm system with AUV docking stations integrated in nature-based artificial reefs. The EONIOS system will explore and protect designated underwater areas including marine ecosystems and biodiversity.

The agreement was signed at Eurosatory, the global defence exhibition in Paris, during a ceremony at the Cyprus Pavilion, in the presence of government officials representing both France and Cyprus This agreement follows the recent signature of a two-year Memorandum of Understanding (MoU) between the same parties to establish cooperation in marine and maritime research and innovation and to cultivate proficiency and knowledge in the marine and maritime sectors.

The signature of ‘EONIOS’ showcases the commitment of Arkeocean, CMMI, Lanego and SignalGeneriX to contribute to the advancement of the marine and maritime industry in the Mediterranean and beyond, while strengthening the bilateral relations between France and Cyprus in areas of paramount importance such as research and innovation in marine and maritime science and technology.

 

18 Jun 24. Red Cat Introduces New Family of Low-Cost, Portable Unmanned Reconnaissance and Precision Lethal Strike Systems.

Red Cat Holdings, Inc. , a drone technology company integrating robotic hardware and software for military, government, and commercial operations, has introduced its new family of unmanned Intelligence, Surveillance, and Reconnaissance (ISR) and precision lethal strike systems.

The announcement, made on the first day of Eurosatory in Paris, comes on the heels of Red Cat’s LOI to acquire FlightWave Aerospace Systems Corporation.

Red Cat’s family of ISR and precision strike drones will provide the industry with an alternative to conventional ISR/strike systems on the market that are high cost and non-retrievable. Red Cat’s sensor-to-shooter (S2S) system for identifying targets with optional precision strike capabilities is differentiated from other systems with its low cost portable drones. The objective of this new family of systems is to meet the increasingly urgent need of the Pentagon’s Replicator Initiative for swarms of low-cost “attritable” ISR and surgical strike drones deployable in air, land, sea, and sub-sea environments.

Red Cat’s mission is to redefine the role of sUAS for defense applications by combining the capabilities of ISR drones with precision strike payloads. The company is an established leader in the sUAS (Group 1) space with its flagship Teal 2 aircraft. As part of the new family of systems, Red Cat is introducing FANG, a new First-Person View (FPV) drone with precision strike payload capabilities. The FPV drone is currently undergoing Blue UAS certification. The acquisition of FlightWave’s Edge 130 rounds out the family of systems, which will include all current and future Teal models.

“The entire nature of warfare and use of drone technology is undergoing a fundamental shift, and this new family of systems will completely disrupt the traditional ISR and loitering munition systems market,” said Jeff Thompson, Red Cat CEO. “Warfighters will be able to choose the right combination of drones and payloads for their specific missions and have access to an ecosystem of tactical AI, computer vision, and machine learning software that can positively identify threats and then have the option to engage and eliminate those targets.”

Red Cat’s new family of low-cost and portable unmanned ISR and precision lethal strike systems includes three aircraft with complementary capabilities and a common Ground Control System (GCS) such as the Android Tactical Assault Kit (ATAK) for multi-vehicle command and control:

  • The Edge 130 Blue, a Hybrid VTOL system, can be assembled and ground or hand-launched in just one minute by a single user to capture high-accuracy aerial imagery with long-range autonomy. Weighing only 1200g, the Edge can fly for over 2 hours in forward flight mode, an industry-leading endurance among all other Blue UAS approved drones available.
  • Teal 2 and future variants are cost-effective, man-portable sUAS designed to “Dominate the Night™” that has best-in-class night vision, multi-vehicle control, and a fully modular design. Teal 2 has a flight time of 30 minutes and it is both Blue UAS Certified and FAA Remote ID approved. Used together with FPV strike drones, Teal drones can be used to provide battle damage assessment once a target has been engaged.
  • FANG, an FPV drone with a flight time of 10 minutes (under development and undergoing Blue UAS certification), will add surgical strike capabilities. Warfighters can combine and deploy these FPV drones with lethal payloads and ISR drones based on the mission profile for seek and destroy capabilities.

“We are at the forefront of a new innovation cycle for the drone industry,” said George Matus, Red Cat CTO. “Technology integrations and partnerships that connect and optimize this new family of systems will play a significant role in its success. Open architecture and established relationships with some of the leading hardware and software companies in autonomy, AI, machine learning and computer vision will enable us to expand our capabilities over time.”

The new family of systems will require ongoing industry collaboration, underpinned by the Red Cat Futures Initiative. Both through Red Cat’s agile internal research and development, as well as partnerships, there is significant opportunity to optimize the family of systems with higher capacity batteries, C2 links, dedicated Electro-Optical (EO) and thermal payloads, and other accessories and decision support software. Additionally, Red Cat has the ability to manufacture these systems at a high production rate with repeatability to meet the demands of customers globally. (Source: UAS VISION)

 

17 Jun 24. Latvia-led drone coalition for Ukraine gains more funding, members. The international coalition to supply drones to Ukraine has received almost $600 m in commitments from Western allies, with Italy and France being the latest countries to join the alliance, the Latvian minister of defense said.

The four-month old initiative, which was born in mid-February and now counts 14 participating nations, outlined an ambition to deliver at least one m unmanned aerial vehicle systems to the embattled country.

“The caveat in this goal is to specify that while, yes, quantity is important, so is providing quality systems – so with this number we aren’t only talking about providing one type of drone but the full spectrum of them, including electronic warfare and counter capabilities,” Latvian Defense Minister Andris Spruds said during a panel at the Eurosatory trade show here.

According to the official, the drone alliance has received over €500 m euros ($590 m) in international pledges, which he expects will increase further in the future.

Spruds added that the coalition, which is spearheaded by his home country and the U.K., recently gained two new members – Italy and France – following a meeting of NATO defense ministers in Brussels.

On a national level, Baltic states have accelerated their drone procurement and training programs, with a special focus on first-person-view types, which have come to dominate the battlefield in Ukraine.

“FPV drones are a game-changer for the current and future battlefield – the most expensive pieces of equipment will be destroyed by these cheaper drones,” Linas Idzelis, Commander of Lithuania’s Riflemen’s Union, a paramilitary non-profit organization supported by the Lithuanian government, told the audience.

The officer said that the country is currently training roughly 6,000 cadets on how to use these cost-effective weapons, with a teaching course taking about 60 hours to complete.

According to Arunas Kumpis, a volunteer soldier in Ukraine who also operates FPV drones, one team typically launches between 30 and 35 of these systems daily to hit assigned targets.

The soldier detailed the usual setup of three-person FPV teams in Ukraine, which hide in concealed and entrenched locations such as bunkers and can operate up to 100 meters away from antennas.

These platforms have proven to be a headache for armored vehicles near the frontlines in recent weeks, with reports that the threat even led U.S. officials to request that donated Abrams main battle tanks no longer be deployed to these areas.

“If armored vehicles are 10-15 kilometers from the frontlines many of these drones can generally hit them – you need to move fast as FPVs have a fast reaction time, around one minute to start, and ten minutes to fly to a target,” Kumpis said. (Source: Defense News)

 

17 Jun 24. Anduril to build factory to increase Dive-LD unmanned systems capacity. Defense tech company Anduril Industries said it will build a new production facility in Rhode Island capable of churning out as many as 200 of its Dive-LD autonomous underwater vehicles annually.

The company will use its own money, plus some support from the state of Rhode Island, to establish the factory in Quonset Point.

The factory is set to open in late 2025, being operations in early 2026, and then reach full capacity by the end of that year: 50 hulls a year, with the ability to scale up to 200 a year if customer demand calls for that.

Until the facility opens, the company will continue to build Dive-LD hulls in its Quincy, Massachusetts, maritime engineering center. Anduril in February received a contract to provide the Defense Department with Dive-LD vehicles through Defense Innovation Unit’s Commercial Solutions Opening process. The U.S. Navy subsequently awarded the company an $18.6 m award using that contract vehicle.

Anduril’s chief strategy officer, Chris Brose, told reporters June 11 the company proved the maturity and utility of its Dive-LD vehicle during a swim-off event last year that led to the DIU contract. But a remaining and recurring question from the government has been, “can Anduril ramp production to really hit high-rate manufacturing numbers?”

He said the Quonset Point factory will “show the U.S. government that we are ready to and able to deliver on large contracts, if those contracts are forthcoming.”

The standup of the 100,000-150,000 square foot production facility will create more than 100 jobs in the next five years.

It will also allow Anduril to try to realize its vision to build a massive fleet of AUVs. A company statement notes the Dive-LD family of vehicles is “designed from the ground-up for production at scale, with a heavy emphasis on commercial-off-the-shelf components with robust supply chains, a modular design, and advanced, scalable manufacturing techniques that enable rapid iterations based on customer needs.”

The company can build 12 Dive-LD vehicles at the Quincy facility today, or could scale up to 24 a year if needed by adding extra shifts.

“We’re out of space in terms of our ability in the Quincy facility to meet the demand that we’re seeing from the Navy at present, let alone where we believe that’s going in the future,” Brose said.

“This is the challenge that I think all defense companies have in terms of, how much to facilitize in order to meet a demand that is not always crystal clear,” Brose continued. “Our approach to that is, we’re going to lean forward. We’re going to invest in ourselves; we’re going to invest in our ability to produce these kinds of systems in a totally different way. And we’re going to put the facilities in place to meet a demand that that we expect to grow,” rather than wait for the government to award a contract and have to play catch-up in building a larger factory.

As for the location in Quonset Point, Brose said the region is a “phenomenal center of undersea expertise and production.”

“Nav[al] Undersea Warfare Center, other major contractors that are performing on significant undersea programs, access to the water — you just have an enormously rich environment of undersea expertise, talented workforce, and it’s phenomenal for Anduril to be a part of that and plug into that,” Brose said. (Source: C4ISR & Networks)

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

BCB certainly has a rich history (1854) and an impressive portfolio of products designed to enhance the safety and effectiveness of NATO defence personnel in various environments.

The core competency of protecting lives in hostile environments, includes:

LAND:

BCB`s camouflage creams and camouflage nets have been standard issue to conceal generations of British and NATO forces.

Our newly developed MultiSpectral Cam technology, the MK8 Phantom, camouflages and protects people/vehicles/assets in the visual, IR and thermal (SWIR/MWIR/LWIR) spectrums.

FireDragon, our eco field cooking fuel, burns cleanly so can also be used in the confined space of a foxhole or tent. It is waterproof, easy to light, non-toxic and smokeless.

SEA;

Our patented Floating Body Armour is unique, versatile and sensibly protects both you and your life jacket, under the soft and hard armour. Designed to be low bulk, it`s massive 275 newtons of buoyancy is self-righting. We say it will “save your life twice”.

Our range of Boat Stopping Systems, provided a layered non-lethal stopping capability against all sizes of vessels, including unmanned threats. So you can stop and search, defeat pirates from boarding, prevent terrorists from getting near your vessel or close off quickly a waterway, port or maritime borders.

AIR;

BCB`s sister company UAVE have been manufacturing since 2013, the Dragon MK3, large, long range (1,000km) long endurance (12hours), versatile and mission-ready UAV. It is proven and operational from the polar regions to 45deg C heat in the Middle East and Asia. The larger of the 3 models, carries 25 kilos payload.

 

———————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

June 19, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

———————————————————————————————————————————————————————————————————————————————————————————————————————————

18 Jun 24. ELT Group participates at Eurosatory 2024, which takes place in Paris from 17 to 21 June, an international event for Defence and Security, with a particular focus on applications in the terrestrial domain. The event will be an opportunity to present ELT Group’s latest technological and capacitive developments for applications in the terrestrial domain. Visitors can find out more at the ELT Group’s stand Hall6 C160.

Thanks to its 70 years of experience in the dominance of electromagnetic spectrum in all operational domains (air, naval, land, cyber and space), ELT Group proposes the latest generation of capabilities in the land domain that can guarantee tactical superiority, strategic autonomy and interoperability to the operator, basing these capabilities on new digital processes, artificial intelligence and cybersecurity.

For example, the multi-domain, multi-layer Cyber Electro-Magnetic Activities (CEMA) capability protects networks and operational assets from cyber attacks through coordinated monitoring, early warning and immediate resolution, through high synergy between radio frequency and cyber capabilities.

In the area of countering mini-micro and small drones, the ADRIAN (Anti-Drone Interception Acquisition Neutralisation) system is a counter-UAV solution capable of intercepting and neutralising LSS (Low-Small-Slow) UAVs in different scenarios and environments, including urban ones. ADRIAN is based on multi-spectral sensors (radar, EO/IR, acoustic and radio link interceptors) that perform data fusion for threat detection and identification. The ‘Cyber RF’ functionality, a complement to the ‘jamming’, ‘radar’ and ‘visual’ modules, has been implemented, making the product capable of effectively detecting and reacting to new and more complex operational scenarios, both military and civil, threatened by new-generation malicious drones.

ADRIAN’s architecture is modular so that it can be adapted to multiple operational requirements and their continuous evolution. The family includes versions for fixed and transportable use, moving configurations and ship integration. A modern and intuitive command and control, powered by artificial intelligence-based algorithms for data fusion and image analysis, functionally integrates multi-spectral sensors/effectors.

TEWS (Tactical EW Solution) is a capability enabled by both Electronic Warfare and Signal Intelligence (SIGINT) capabilities composed of networked integrated mobile tactical platforms to simultaneously achieve total protection of the infrastructure and the acquisition of intelligence data to increase the Situational Awareness.

 

18 Jun 24. Global: New campaign reveals sustained security, espionage risks stemming from outdated software. On 17 June, the cyber security company Sygnia reported that the Chinese-linked group ‘Velvet Ant’ targeted a large unnamed organisation in a long-term espionage campaign. Although the initial attack vector is unknown, the threat group first accessed the victim’s network in 2021. The targeted organisation reportedly operated two F5 BIG-IP appliances that were running outdated software. These were likely exploited by Velvet Ant to deploy a known remote access trojan (RAT), ‘PlugX’. This enabled the group to evade traditional monitoring solutions and to achieve prolonged persistence, highlighting the sophistication of the group’s tactics, techniques and procedures (TTPs). Notably, the group has shifted its tactics to use an internal server as part of its command and control (C2) infrastructure after it is initially detected. We assess this demonstrates the threat actors’ extensive knowledge of their victims’ systems, as well as their ability to adapt quickly. Additionally, the incident underscores the security and espionage risks stemming from outdated software, further underscoring the importance o(Source: Sibylline)

 

17 Jun 24. Thales’s first resilient high-data-rate High Frequency (HF) radio sets for land theatre command posts are on display on the company’s stand at Eurosatory.

  • They provide a resilient long-distance communications capability and, with data rates 10 times higher than earlier generations of HF radios
  • The new HF radios use patented technology that has already been proven in naval operations aboard several types of warships including FDI-class defence and intervention frigates and France’s Charles de Gaulle aircraft carrier.

At Eurosatory 2024, Thales is unveiling the first two radios in its new HF XL range of resilient high-data-rate wideband HF radios for command posts deployed by land forces in the theatre of operations. They are ideally suited to high-intensity conflict scenarios.

High frequency (HF) transmissions, fully secure and with low operating costs, are still essential for armed forces, particularly in areas with poor satellite coverage (polar regions, for example, or in constrained environments) or where there is a high risk of jamming. However, HF is limited in terms of bandwidth, and can no longer meet the growing needs of armed forces for data exchange.

By developing high-frequency broadband communication capabilities (HF XL), Thales is offering a 10-fold increase in bandwidth and a significant improvement in quality of service, while still benefiting from HF’s advantages of long range and operation in constrained environments.

This technological feat is made possible by a cognitive engine that automatically selects frequencies throughout the communication. Jammed frequencies are automatically rejected and replaced by free frequencies, ensuring link stability and optimized data rates. This makes the radios easy-to-use.

The 1 kW and 400 W radios, fully interoperable with all wideband HF radios, enable deployed command posts to communicate with command headquarters or with other units in remote areas of the theatre of operations, over distances of up to 10,000 km.

To the two stations currently available, 1kW and 400W, new radios for vehicles and soldiers will be added in 2025 to complete the tactical range. In addition to land and naval environments, it is planned tp extend HF XL technology into the aero and infrastructure domains.

“These new radios are the culmination of several years of consistent innovation and design efforts to provide our customers with a mature solution that represents the state of the art in wideband HF technology”, said Christophe Groshenry, Vice-President Radiocommunication Products, Thales

 

17 Jun 24. Rohde & Schwarz introduces sensor fusion – the ultimate solution for powerful and reliable data analysis.

Rohde & Schwarz showcases the TARAN Suite, the tool of choice for coping with massive amounts of data that require powerful and reliable analysis, obtaining a comprehensive situational picture is crucial for mission success in multi-domain operations.

Rohde & Schwarz, a leading provider of innovative communications and information security solutions, is proud to showcase a cutting-edge analytical solution that revolutionizes the decision-making process in various domains.

In today’s complex and rapidly evolving world with multiple intelligence domains, obtaining a comprehensive situational picture is crucial for mission success in multi-domain operations. To address this need, this powerful sensor fusion and analysis tool combines fragmented and contradictory sensor data into a full situational picture. By leveraging cloud-based technology, sensor fusion from Rohde & Schwarz processes massive amounts of data and enriches it with open source information and intelligence, providing users with a detailed overview of their environment in real time.

The advanced capabilities of sensor fusion from Rohde & Schwarz go beyond data aggregation and enrichment. With intelligent filters and advanced screening models, it tracks and identifies significant information from various sources. This enables users to make informed decisions and improve supervision, examination, and investigation in any intelligence domain.

“Our sophisticated analytical solution, the TARAN Suite, has become the tool of choice for coping with massive amounts of data that require powerful and reliable analysis,” said Frank Schrudde, CEO of Schönhofer Sales & Engineering, a Rohde & Schwarz subsidiary. “Sensor fusion from Rohde & Schwarz offers an end-to-end intelligence solution, empowering our customers with comprehensive operational insights and unrivalled efficiency.”

One of the key strengths of sensor fusion from Rohde & Schwarz is its scalability and security. It provides a secure information exchange platform and offers special connectivity options for heterogeneous or decentralized analytics scenarios. With configurable data replication and synchronization over secure network links, extensive offline processing capabilities for mobile teams, and adaptable resilience for low-bandwidth or high-latency data links, sensor fusion from Rohde & Schwarz ensures seamless and reliable data analysis in any situation.

Rohde & Schwarz is showcasing its solutions and capabilities supporting multi-domain operations by ensuring spectrum dominance in all domains and along the complete signal chain at Eurosatory 2024 on booth 6-K279.

 

17 Jun 24. Thales and CEA Partner on Trusted Generative AI for Defence and Security.

  • Thales and the French Alternative Energies and Atomic Energy Commission (CEA) have signed a new partnership agreement in the field of generative artificial intelligence (AI).
  • The Thales AI research teams at cortAIx, the Group’s AI accelerator for mission-critical systems, will work with the CEA teams to deliver sovereign trusted AI solutions.
  • Through this three-year renewable partnership, Thales will provide its AI expertise and deep knowledge of the defence and security sectors, while the CEA will contribute its know-how in multimodal generative AI (based on text, images, audio, electromagnetic signals, structured data and other inputs) to accelerate the integration of AI into solutions for Thales customers with critical mission requirements.

To create trusted generative AI solutions, Thales’s cortAIx Lab, the most powerful integrated laboratory for critical AI in Europe, and the CEA, which is one of the world’s most innovative research organisations and is listed alongside Thales in the Clarivate Analytics Top 100 Global Innovators,1 have joined forces to focus on a range of generative AI use cases, in particular for intelligence and command applications.

Bertrand Tavernier, Chief Technical Officer for Thales’s Secure Communications and Information Systems business: “This partnership with the CEA’s AI teams will combine the power of their research with our work at cortAIx, Thales’s AI accelerator, which brings together the Group’s technological expertise and deep knowledge of the defence and security sectors. Our customers — governments, armed forces, critical infrastructure operators — need trusted, sovereign generative AI solutions for their critical missions.”

Alexandre Bounouh, Director of the CEA’s List Institute, specialising in smart digital systems: “This partnership builds on the long-standing collaboration between the CEA and Thales and extends it to the sensitive issue of generative AI, combining the expertise and excellence of the CEA’s research teams in AI safety and security with cortAIx’s strengths in the strategic domain of defence and security. It will support the CEA’s mission in safety, security and artificial intelligence with our partners and all institutional and industry stakeholders in this field.”

Generative AI can be developed to accelerate OODA command loops (observe, orient, decide, act) and implemented across the entire critical decision chain: sensing and data gathering, data transmission and storage, data processing and decision support.

Generative AI will serve as a trusted smart assistant for users, enabling them to dialogue easily and efficiently with complex systems with the aim of facilitating and accelerating human decision-making and the tempo of operations. For intelligence gathering, for example, multimodal generative AI will make it possible to simultaneously extract, process, correlate and interpret different types of information from multiple sources — such as the web, social media and sensors in a theatre of operations — to generate summaries and accelerate the production of reliable reports.

Thales’s cortAIx Lab and the CEA will also focus on interoperability within coalitions. To simplify communication between member states in the context of a joint operation, trusted generative AI will facilitate interaction between operators and complex systems by translating their intentions into a sequence of actions and translating technical terms into the languages of the various nations involved. (Source: ASD Network)

 

17 Jun 24.  Eviden, the Atos Group business leading in digital, cloud, big data and security, today announces that the French Defense Procurement Agency (DGA), via the Defense Digital Agency (AND), has entrusted it with the development and deployment of SICS[1] ALAT[2]. This system onboard the ALAT (French Army Light Aviation) aircraft is part of the French army’s ramp-up of its collaborative combat capabilities. This new information system will replace the existing systems by 2026.

SICS ALAT enables ALAT aircraft to be networked with land-based tactical information systems in an interoperable, coherent, and unified way, thus creating the SCORPION air-land tactical bubble.

SICS ALAT is a complete and unique digitalization solution for army helicopters, ensuring the continuity of the digitized command chain of air-land combat, capable of providing patrol leaders and helicopter crews with knowledge of the tactical situation in their area of interest and the rapid exchange of information in data transmission. A major technical achievement, this advanced version of SICS is designed to be fully interoperable with the original system, while adapting to the constraints specific to aeronautics: three dimensions, movement, speed, ergonomics adapted to cockpits, and security. Eviden is drawing on its experience of the SICS program and its close collaboration with the DGA, the French Army and operational crews, to meet the challenges of intuitiveness and ease of use to optimize operational acceptance of the system.

As a defense manufacturer, Eviden, through its Mission-Critical Systems (MCS) business line, designs and develops both the information system and the on-board computers that will be integrated into the aircraft to meet the challenges of the ALAT. Drawing on its experience in the design and manufacture of onboard electronics for the military aerospace industry, and its range of MLS Gateway solutions, Eviden is able to offer a computer adapted to the sizing and connectivity constraints of currently operational aircraft (2005-2010 generation), while providing tenfold increase in computing power. This design meets the challenges of availability and operational scalability for armed forces since it does not require current aircraft to be re-qualified.

SICS ALAT demonstrates Eviden MCS’s ability to meet the needs of collaborative combat and digital defense with an end-to-end on-board operational solution for sharing and maintaining the tactical situation, able to communicate with its ecosystem thanks to on-board computing power.

Fabrice Laclef, Director of Mission-Critical Systems (MCS) for France, Eviden, Atos Group said: ” This unique project, which embodies the know-how of Eviden’s Mission-Critical Systems business line, once again proves our expertise in defense, and demonstrates the trust placed in us by the French Army. This project is the fruit of the expertise and collaboration of various teams, to deliver a complete and innovative solution to the Army.”

 

17 Jun 24. Northrop Grumman Corporation (NYSE: NOC) delivered the first production Integrated Battle Command System (IBCS) Engagement Operations Center (EOC) and Integrated Fire Control Network (IFCN) Relay to the U.S. Army. The delivery of this equipment, coupled with the Integrated Collaborative Environment (ICE) delivered in December 2023, completes the first full set of IBCS delivered under the low-rate initial production (LRIP) award.

  • A complete IBCS set allows the Army to conduct the necessary training to deploy IBCS’ ready now, cutting-edge command and control system powering unprecedented multi-domain integration.
  • The EOC hosts the battle management software, communications and computing power enabling IBCS operators to plan and fight the battle.
  • The IFCN Relay forms the IBCS communications network and serves as the interface for sensors and weapons integrated into IBCS.
  • The U.S. Army awarded Northrop Grumman a Full Rate Production (FRP) contract for IBCS in May. The fiscal year 2024 FRP award of $145 m will support production and deployment of IBCS’ revolutionary command and control capabilities to support U.S. warfighters.

Expert:

Rebecca Torzone, vice president and general manager, combat systems and mission readiness, Northrop Grumman: “IBCS is ready now to provide our warfighters more decision time in the battlespace to outpace tomorrow’s threats. Northrop Grumman is committed to putting IBCS in the hands of our warfighters at an accelerated delivery rate so they can lead the way in modernized air and missile defense.”

Details on IBCS:

The EOC and IFCN Relay deliveries follow the initial December 2023 delivery of the ICE to the Army, of which the Army has accepted 13. This first full set of equipment will support initial activities leading to IBCS Full Operational Test and Evaluation in 2025.

The recently issued Full Rate Production  contract award for IBCS is a critical milestone, reflective of successful IBCS performance at numerous air and missile defense test events, integrating Patriot, Lower Tier Air and Missile Defense , Indirect Fire Protection Capability  and other sensors and effectors. It also reflects Northrop Grumman’s successful delivery of LRIP systems to the U.S. Army.

IBCS is a revolutionary command and control system unifying current and future assets in the battlespace, regardless of source, service or domain. Through its modular, open and scalable architecture, IBCS gives warfighters capabilities not previously available by fusing sensor data for a single actionable picture of the full battlespace, enabling rapid, informed decisions to optimize shooters. This capability gives warfighters more time to make decisions on how best to defeat threats. IBCS is the centerpiece of the U.S. Army’s modernization strategy for air and missile defense, and it is currently fielded in Poland. IBCS is a foundational element for the multi-domain, multi-national future.

Northrop Grumman is a leading global aerospace and defense technology company. Our pioneering solutions equip our customers with the capabilities they need to connect and protect the world, and push the boundaries of human exploration across the universe. Driven by a shared purpose to solve our customers’ toughest problems, our employees define possible every day.

 

14 Jun 24. India: Long-term espionage operation points to heightened risks facing government, tech sectors. On 13 June, the cyber security company Cisco Talos reported that a malware operation (‘Operation Celestial Force’) has been targeting Indian entities since 2018. The campaign uses phishing and other social engineering techniques to coerce victims into downloading malicious links and documents. The operation focuses on espionage and surveillance activities, and primarily targets entities and users in the defence, government and technology sectors. The operation uses two types of malware to target Android and Windows devices, underscoring the threat actors’ sophisticated ability to prolong their campaign. Researchers attribute the operation to a Pakistan-aligned group, ‘Cosmic Leopard’, which employs similar tactics, techniques and procedures (TTPs) to the Pakistani state-sponsored group ‘Transparent Tribe’. However, there is not enough technical evidence to link the two groups directly. As such, we assess that the groups possibly operate separately. We also assess that the aim of both groups is to help bolster Pakistan’s geopolitical ambitions amid strained regional tensions. This will sustain the security risks facing the aforementioned sectors in India.  (Source: Sibylline)

 

14 Jun 24. Rohde & Schwarz showcased its solutions and capabilities supporting multi-domain operations by ensuring spectrum dominance in all domains and along the complete signal chain at Eurosatory 2024.  Rohde & Schwarz, a leading provider of cutting-edge communications and security solutions, is proud to announce its participation at Eurosatory 2024, the global land and air defense and security benchmark event June 17 to 21, 2024. The company is a trusted partner for armed forces, law enforcement, regulatory authorities, and governmental organizations.

At Eurosatory 2024 on booth 6K279, Rohde & Schwarz presents solutions and capabilities that support multi-domain operations by ensuring spectrum dominance in all domains and along the complete signal chain:

  • Measure and monitor the complete spectrum – explore the electromagnetic spectrum with military spectrum monitoring solutions;
  • Information superiority – high-performance SIGINT/EW sensor systems detect, locate and counter all RF signals including RF-controlled drones in military operations;
  • Connect battlefields – secure, reliable and interoperable communications with SOVERON; the software defined radio family that delivers advanced voice and data connectivity for all branches of the armed forces;
  • Get the full situational picture – sensor fusion and signal analysis through AI enriched data.

Visitors to the Rohde & Schwarz booth will have the opportunity to explore a wide range of innovative products and systems. Among the highlights are the company’s latest technologies, equipment and systems for armed forces.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————–

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

June 13, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

———————————————————————————————————————————————————————————————————————————————————————————————————————————————-

13 Jun 24. Spectra Group announces pre-production trials success of their next generation tactical radio system GENSS at Eurosatory 2024. Following the initial concept launch in January 2024, Spectra Group, a specialist provider of secure voice, data and satellite communications systems introduces their next generation tactical radio GENSS to European markets by announcing pre-production trials success.  Spectra Group will be discussing their new tactical radio system GENSS (pronounced genesis /jĕn′ĭ-sĭs), their award winning satcom SlingShot and the highly popular Troposcatter Family of Systems at Eurosatory in Paris from 17-21 June 2024 (Hall 5a Stand B156).

GENSS builds on the foundations created by their award-winning SlingShot system, embodying Spectra Group’s vision of producing ultimate radio systems that capitalize on technological advances, adapt to the evolving demands of military operations and simplify the user experience.  It has been designed and developed through a collaborative effort of tactical communication experts, seasoned military specialists and top-tier U.K. scientists and engineers.  GENSS is a significant advancement in the field of tactical radio communications, due to its modular core framework and software-defined flexibility, heralding a new era in communication technology.

Since January, Spectra Group have continued development of the GENSS platform at pace using initial working prototypes to prove key concepts.  At Eurosatory, Spectra Group are announcing the success of key concept capability prototype trials.  This month they have completed ‘over the air’ Beyond Line of Sight (BLOS) testing which has proved critical initial operating concept capabilities for the key planned modes of operation.  GENSS to SlingShot – standard UHF line of sight radios were connected to both SlingShot and GENSS devices and worked perfectly together, proving backward compatibility to maintain ultimate flexibility and interoperability.  LTAC TACSAT communications were achieved for GENSS as a stand-alone radio, transmitting simultaneous voice and data traffic over the same net.  Finally, Data Rebroadcast/Backhaul was proved, successfully establishing two ATAK Data MANET networks using a GENSS Bridge, connected through the Inmarsat L-TAC (satellite) BLOS service, thus delivering high data rate transmissions over strategic distances.

These trials validate the GENSS concept of delivering a single tactical radio capable of meeting the extensive secure data, voice, and application demands of modern military users.  GENSS is a modular, hardware-agnostic radio system designed and now proven to be exceptionally agile, providing ultimate interoperability through straightforward software reprogramming.  This allows it to adapt quickly and easily to diverse user needs.  Capable of operating across HF, VHF, UHF and satellite bands from 29Mhz to 6 GHz, GENSS overcomes BLOS barriers and supports Communications on the Move (COTM). It delivers a robust and agile solution for voice and high-bandwidth data transmission across all domains and platforms, whether on land, sea, or in the air.

Simon Davies, Chief Executive at Spectra Group, states, “GENSS represents the pinnacle of our development efforts, transforming complex communication needs into simple, effective solutions.  My vision has been to craft the ultimate radio system — user-friendly, light, modular and supremely flexible to adapt to the evolving demands of military operations and technological advances and GENSS is proving to deliver exactly that.  We are thrilled to introduce such a transformative tool to the European market at Eurosatory.”

 

14 Jun 24.  Thales and Google Cloud have signed a new partnership to deploy a global SOC (Security Operation Centre) platform and provide Thales customers with advanced cybersecurity incident detection and response capabilities.

  • These new-generation services combine Thales’s expertise in cyber detection and response with Google Cloud’s widely acclaimed intel-driven, AI-powered SecOps capabilities.
  • Under the new agreement, Thales and Google Cloud are combining their knowledge of the cyberthreat environment to offer a single platform, which is already operational in France, and will be available to international customers later this year, to round out Thales’s existing SOC offering.

Thales has teamed up with Google Cloud to expand its capacity to detect and respond to cyberattacks on the information systems of businesses and organisations.

Under the terms of this new partnership, Thales is developing a global SOC (Security Operation Centre) platform based on Google Cloud cybersecurity technologies and expertise, including Google Security Operations,VirusTotal and Mandiant Threat Intelligence, all powered by generative AI. It will leverage the existing network of eleven Thales SOCs, which are based on cloud or hybrid technologies and can be connected to on-premise environments. The agreement will benefit Thales’ customers by combining both partners’ expertise in cyberthreat analysis and drawing on the latest developments in AI technologies.

The new-generation SOC will provide organisations with enhanced protection against the most sophisticated cyberthreats:

  • Uncompromising system supervision: cost-effective data processing at Google cCloud speed and scale via an open platform to expand the scope of security monitoring;
  • Accurate, reliable cyberattack detection: advanced multi-source data analytics backed by the cyberthreat intelligence capabilities of two market leaders (Thales Cyber Threat Intelligence in Europe and Asia Pacific and Google’s Mandiant and VirusTotal threat intelligence resources);
  • Fast, efficient incident response: use of AI to quickly determine the impact of an attack and reduce incident response time to enable business continuity;
  • Permanent surveillance: 24/7 surveillance of IT and OT systems to guarantee immediate breach detection.

Pierre-Yves Jolivet, Vice President, Cyber Digital Solutions, Thales: “Thales is delighted to announce this partnership with Google Cloud, which will combine the latest cyber technologies and threat intelligence capabilities to provide customers with one of the most advanced suites of SOC services available in the market. In a world that is increasingly exposed to cyberattacks, this partnership will take Thales’s cyberthreat detection capabilities to the next level and provide faster, more efficient incident response solutions to ensure the resilience of its customers’ information systems.”

Sunil Potti, Vice President Cloud Security, Google Cloud: “This new extensive partnership with Thales is a confirmation of the relevance of our cloud security offering, combining our SecOps technology and threat analysis capacities, all supercharged with generative AI. Cybersecurity is not an individual sport and we are pleased to team up with Thales to further empower organisations around the world to better detect, investigate and respond to persistent threats.”

Thales and cybersecurity

As a global leader in cybersecurity, Thales is involved at every level of the cyber value chain: identification, protection, detection, response and recovery. Thales’s offering is focused on three families of cybersecurity products and services:

  1. Global security products around the CipherTrust data security platform, the SafeNet trusted Identity and Access Management (IAM) as-a-service solution, and the Group’s broader cloud protection and licensing offerings. Imperva’s products are part of this family.
  2. Sovereign protection products including encryptors and sensors to protect governmental and institutional critical information systems.
  3. A complete suite of cybersecurity services including threat and risk evaluation, training and simulation, detection and response, and integration projects. The Group’s 11 SOCs around the world provide 24/7 availability and include a number of SOCs with PRIS and PDIS certification by the French cybersecurity agency (ANSSI).

Thales has significantly increased its strategic focus on cybersecurity in recent years, expanding its geographic footprint and portfolio of products and capabilities through organic as well as external growth, including the acquisition of Imperva in 2023.

 

12 Jun 24. Global: Chinese-led operations will raise security risks facing Western government, defence entities. On 10 June, the Dutch authorities reported that an existing Chinese-led cyber espionage operation that was discovered in February was more extensive than they initially reported. In February, the Dutch authorities disclosed that Chinese threat actors exploited a vulnerability in Fortinet appliances (CVE-2022-42475) to install a backdoor, ‘COATHANGER’, onto Dutch Ministry of Defence systems. The backdoor is able to establish permanent persistence even when rebooted or given firmware updates. The report stated that Chinese threat actors gained access to over 20,000 vulnerable FortiGate systems in Western government and defence organisations between 2022 and 2023. They reportedly exploited the vulnerability for at least two months prior to Fortinet disclosing the zero-day, infecting 14,000 devices in that time. As a result, it is likely that the threat actors still have access to several systems due to COATHANGER’s ability to evade detection. As such, we assess that long-term espionage and security risks stemming from Chinese-backed operations will persist for Western government and defence entities in the long term. (Source: Sibylline)

 

11 Jun 24. Asia-Pacific: New backdoor points to elevated security, financial risks facing firms across region. Earlier on 11 June, the cyber security company Trend Micro reported that several Chinese threat actors are using a new remote access trojan (RAT), ‘NoodleRAT’, in cyber espionage and criminal operations. NoodleRAT is suspected to have been active since at least 2018; it also reportedly has Windows and Linux versions. This indicates the malware’s versatility and the threat actors’ ability to target multiple operating systems (which ultimately enlarges their potential victim pool). The malware shares similarities with other Chinese-made malware, including ‘Gh0stRAT’, which points to the likelihood that NoodleRAT is shared or offered for sale among Chinese-speaking threat groups. It exploits vulnerable public-facing applications for initial access, underscoring the security risks that misconfigured internet-facing applications can pose to firms. The RAT has been used as part of espionage operations in India, Japan, Malaysia, Taiwan and Thailand. NoodleRAT has also been employed in cryptocurrency theft operations, elevating the security and financial risks facing firms across the Asia-Pacific region. (Source: Sibylline)

 

10 Jun 24. Zambia-region: Cyber fraud convictions highlight organised cyber crime activity, exposure risks. On 7 June, a Zambian court convicted 22 Chinese nationals of operating an online fraud and money laundering syndicate. The syndicate was dismantled in April and operated call centres and numerous social media channels to defraud victims and make unauthorised withdrawals from thousands of SIM and bank accounts throughout Sub-Saharan Africa. Although petty cyber crime is extremely common in Zambia, the arrests highlight increasingly sophisticated cyber security threats from organised criminal groups with links to foreign entities. Although authorities will likely continue efforts to prosecute organised cyber criminal activity, low telecommunications infrastructure resilience throughout the region will likely undermine broader efforts to improve cyber security protections. As such, firms will continue to face elevated exposure to criminal activity, particularly entities relying on online banking and mobile money transfer services. Increasing organised cyber criminal activity will also increase threats of exposure to money laundering, elevating compliance concerns for firms in the financial sector. (Source: Sibylline)

 

07 Jun 24. NIST seeks innovators for UAS wireless data challenge. The United States National Institute of Standards and Technology (NIST) is seeking innovators for its First Responder Uncrewed Aerial Systems (UAS) Wireless Data Gatherer Challenge, also known as UAS 6.0.

As a first responder, the need to investigate accidents, as well as prepare for and adapt during a rescue, requires collecting various types of data about the potentially dangerous environment. In radio-complex outdoor environments, where communications infrastructure may be non-existent, UAS’ ability to collect information, via visual inspection and radio communication, from devices in the field, could be imperative to gaining situational awareness and deploying critical resources.

NIST is looking for applicable expertise across and beyond the UAS ecosystem who can contribute invaluable knowledge and ingenuity in artificial intelligence (AI), radio communications and mapping, Internet of Things (IoT), cybersecurity, and more.

Interested parties are invited to complete a research paper on relevant component technologies by July 26. A panel of SMEs and judges will review all eligible papers from which judges will select winners to receive prize awards. Prizes for this stage include cash prizes and those selected are encouraged to enter the second stage where capabilities will be measured with a view to progressing to scenario testing.

NIST says the challenge results will support the public safety community and its partners to improve real-time situational awareness and save lives while operating in potentially dangerous radio-complex outdoor environments without fixed communications infrastructure or satellite communications. (Source: www.unmannedairspace.info)

 

07 Jun 24. Global: Exploitation of existing vulnerabilities underscores security risks facing businesses. On 5 June, the security company Akamai reported that Chinese threat actors have been exploiting two patched vulnerabilities (CVE-2018-20062 and CVE-2019-9082) in the open-source application ‘ThinkPHP’ since April. The threat actors have exploited CVE-2018-20062 and CVE-2019-9082 to perform remote code execution on targeted systems. They have deployed the web shell ‘Dama’, which allows the actors to continue accessing infected systems remotely. Subsequently, they can perform port scanning, access existing databases and escalate privileges. This suggests that the operation is possibly an espionage-focused campaign. Patches for both vulnerabilities were released in late 2018 and early 2019, highlighting the long-term security risks emerging from lax patch-management policies. Additionally, we assess that this operation further emphasises the growing adoption of web shells to allow threat actors advanced control over victims’ systems. The threat actors reportedly deployed Dama against a wide range of targets, underscoring the ongoing security risks facing global organisations in the short-to-medium term. (Source: Sibylline)

 

07 Jun 24. Cyber Update Key points.

  • New malware targeting Brazilian bank users has underscored the elevated security and reputational risks facing financial institutions (see Sibylline Cyber Daily Analytical Update – 3 June 2024).
  • A new multi-pronged disinformation campaign has elevated the security, disinformation, disruption and reputational risks stemming from Russian state-sponsored actors ahead of the Paris 2024 Olympic Games (see Sibylline Cyber Daily Analytical Update – 4 June 2024).
  • A new phishing kit targeting customers from over 54 Europe-based financial institutions has heightened the security and reputational risks facing business operations (see Sibylline Cyber Daily Analytical Update – 5 June 2024 and our Technical analysis below).
  • A long-term multi-pronged campaign has underscored the espionage risks stemming from Chinese state-sponsored actors (see Sibylline Cyber Daily Analytical Update – 6 June 2024 and our Technical analysis below).
  • The exploitation by Chinese threat actors of existing vulnerabilities has underscored the security risks facing global businesses.

Technical analysis of weekly stories

A new phishing kit, ‘V3B’, is being sold to cyber criminals on the messaging platform Telegram as a phishing-as-service (PhaaS) model. V3B contains a sophisticated JavaScript that is typically distributed via social engineering techniques. The script distinguishes itself through its advanced features, including its ability to emulate local login and authentication techniques. The threat actors were able to create fraudulent QR codes, enabling them to access a victim’s account automatically in a QR code login jacking (QRLJacking) attack. Additionally, they demonstrated their knowledge of modern authentication methods by using a live chat function to interact with victims in real time and steal one-time passwords (OTPs) and other information to bypass authentication on local platforms such as PhotoTAN and SmartID. The kit also includes professionally translated pages in several European languages, highlighting its highly tailored nature. Notably, the kit also comprises multiple code obfuscation techniques and an advanced anti-bot system to prevent detection by security tools and to achieve prolonged persistence. V3B’s ability to emulate modern technologies combined with its various obfuscation and persistence techniques further underscores cyber criminal groups’ developing tactics, techniques and procedures (TTPs).

Several Chinese state-sponsored groups targeted an unnamed government agency in Southeast Asia in a long-term espionage campaign known as ‘Crimson Palace’. The campaign comprises three clusters of activity: ‘Cluster Alpha’, ‘Cluster Bravo’ and ‘Cluster Charlie’. The operations were primarily active between March and December 2023, though it is likely that the groups first obtained access in early 2022. Cluster Alpha focused on reconnaissance activities, including mapping server subnets and enumerating administrator accounts. The TTPs used in this phase of the operation also resemble those used by known Chinese-sponsored threat groups such as ‘BackdoorDiplomacy’, ‘REF5961’, ‘Worok’ and ‘TA428’. Cluster Bravo used legitimate accounts for lateral movement and deployed the malware ‘EthernalGh0st’ to maintain communication with actor-controlled servers and to exfiltrate credentials. Cluster Charlie notably attempted to collect and exfiltrate large volumes of sensitive information including documents concerning military, cyber security and economic interests in the South China Sea. It then deployed ‘PocoProxy’ to establish persistence and ‘HUI Loader’ to maintain control over the compromised system. While Cluster Bravo was likely associated with the group ‘Unfading Sea Haze’, Cluster Charlie is likely attributable to ‘APT41’.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing and other types of social engineering attempts.
  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Enforce strict security policies including regular software and password updates to mitigate and prevent infections via leaked or stolen password credentials.
  • Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.

Our cyber word(s) of the week: QR code login jacking (QRLJacking) attack

(Source: Sibylline)

———————————————————————————————————————————————————————————————————————————————————————————————————————————————

Spectra Group (UK) Ltd

 

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————————————————————————————————————————————————————————————————————————————————————————————-

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

June 7, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

——————————————————————————————————————————————————————————————————————————————————————————————————————————————

05 Jun 24. There be Dragons!

Reports on social media emerged in April that Royal Air Force General Atomics MQ-9A Reaper uninhabited aerial vehicles are flying equipped with the Outdragon signals intelligence system.

Open sources have stated that Outdragon is primarily a podded airborne Communications Intelligence (COMINT) system. Outdragon’s role appears to be the detection, location and tracking of persons of interest via their electromagnetic signals. The analysis continued that these signals could include cellphone and wireless router transmissions, among others. Cellphones tend to use Ultra High Frequency (300 megahertz/MHz to three gigahertz/GHz) wavebands while wireless routers use frequencies of 2.4GHz, five gigahertz and six gigahertz. Taking these wavebands into account, it is reasonable to assume that Outdragon covers frequencies of circa 30MHz to six gigahertz. Extending frequencies into the Very High Frequency (30MHz to 300MHz) part of the spectrum would let the capability also detect, locate and track individuals using VHF communications systems. Outdragon equips the Royal Air Force’s (RAF’s) General Atomics MQ-9A Reaper Uninhabited Aerial Vehicles (UAVs)

The MQ-9A has an operational altitude of 25,000 feet/ft (7,500 metres/m). Outdragon could detect and process communications signals at a range of circa 192 nautical miles/nm (356 kilometres/km) at this altitude. The pod is likely to have impressive sensitivity. Assume there is a cellphone transmitting a 300MHz signal with 0.6 watts/W of transmission power from an antenna with a gain of 12 decibels/db across a 300km (162nm) range. The cellphone transmission will have a strength of circa -201dB by the time it reaches the pod. Generally speaking, the closer a negative decibel signal strength is to zero the stronger that signal will be.

Outdragon procurement

A Freedom of Information (FOI) request made to the British government did shed some light on the Outdragon capability. The UK government procured Outdragon from General Atomics in April 2018 for $5m as a Foreign Military Sale (FMS) from the United States. Additional information regarding Outdragon was not forthcoming with the FOI response citing national security interests. A further procurement was made in April 2019 worth $2.2m for the modification and integration of Outdragon onboard the RAF’s MQ-9As.

Mission set

UK Ministry of Defence (MOD) documents in the public domain provide some additional information: Outdragon can be fitted on the MQ-9A’s number 8 underwing hardpoint. The documents continue that Outdragon supports combat ISR (Intelligence Surveillance and Reconnaissance) missions. When performing combat ISR, Outdragon is carried alongside MBDA Brimstone-3 air-to-surface missiles, and Raytheon Paveway-IV GNSS (Global Navigation Satellite System) and laser-guided bombs. When flying non-combat ISR missions, the aircraft exclusively deploys the Outdragon pod. The combat ISR configuration enables persons-of-interest to be detected, located, identified and attacked should this be required by the mission. Amalgamating the COMINT capability with kinetics gives the RAF a highly responsive reconnaissance and strike asset. Such capabilities are particularly useful for Counter-Insurgency (COIN) operations. Reports have stated that RAF MQ-9As are routinely based at Ali Al Salem airbase in central Kuwait. This location is well-placed for supporting RAF operations, particularly COIN efforts, around the Middle East. Although the aircraft can be flown from the base in Kuwait, their flying operations may be controlled from RAF Waddington airbase, eastern England.

Off-the-shelf?

Much remains unknown vis-à-vis Outdragon. For example, it appears that Outdragon is not a product name per se but instead maybe a British codename for a US-supplied system. Given that the procurement was made directly from General Atomics this suggests the capability is one that the company directly produces. General Atomics’ Scalable Open Architecture Reconnaissance pod (SOAR) can be configured for electronic intelligence and COMINT gathering. SOAR has been developed in partnership with L3Harris. General Atomics also provides a podded electronic warfare system called Sledgehammer. Sledgehammer is a communications jamming system and there is no indication that Outdragon has such attributes. Certainly, Outdragon’s relatively inexpensive procurement price of circa $7.7 m seems to indicate it was an off-the-shelf purchase. The fact that it had been purchased as an FMS also points to an off-the-shelf procurement. Much remains unknown regarding Outdragon, but recent social media interest is helping cast some light on this intriguing capability.

(Source: Armada)

 

05 Jun 24. Difficult Decisions. Armada has been told that the United Kingdom Ministry of Defence (MOD) had considered supplying examples of the ALARM missile to Ukraine.

A senior Royal Air Force (RAF) source shared with Armada that consideration had been given to supplying the Ukrainian Air Force (UAF) with British Aerospace/MBDA ALARM (Air-Launched Anti-Radar Missile) examples left over from the type’s decommissioning. Armada understands that plans to supply the missile, and integrate it onto Ukraine’s combat aircraft, stopped amid concerns regarding the missile’s seeker head. It was uncertain if the missile’s Radio Frequency (RF) seeker would have been effective in detecting, and homing in on emissions from Russian radars.

Should it have been deployed, ALARM would have been used to engage Russian ground-based air surveillance and fire control/ground-controlled interception radars.  It was thought that ALARM had been formally retired from RAF service in 2013. The source added that examples of the missile had been retained until 2018. An undisclosed number of missiles were in the possession of the UK Ministry of Defence (MOD) at the time of Russia’s second invasion of Ukraine in February 2022. UAF jets tasked with deploying ALARM would have needed to be upgraded with the necessary software.

Into combat

The Royal Saudi Air Force (RSAF) is believed to be the last ALARM operator and was the missile’s only export customer. Armada has been told in the past that the RSAF deployed ALARM during the country’s intervention in Yemen’s civil war. The RSAF did not specifically deploy ALARM as an anti-radar missile, instead the weapon was used against general surface targets. The source cast doubt on whether the RAF had deployed ALARM during Operation Odyssey Dawn/Unified Protector. This was the codename for the US/North Atlantic Treaty Organisation operation mounted in 2011 to protect Libyan civilians from forces loyal to the country’s late dictator Colonel Muammar Gaddafi.

Tactical modes

ALARM could be deployed in several ways: After launch, the weapon could climb to 40,000 feet (12,192 metres) which gave the missile’s seeker the elevation to detect emissions over a wide area. When used in a direct mode, the missile would look for specific emitters from altitude. Once detected, ALARM would home towards the radar, using the radar signals as guidance. Alternatively, ALARM could be used in a loiter mode. The firing sequence would be similar to direct mode. Once at altitude, the missile would deploy a parachute and slowly descend to Earth while listening for radar emissions. If a hostile radar was detected the parachute would detach, the missile’s motor reignite and it would zoom towards its target. Alternatively, the missile could be programmed to listen out for hostile emissions in a specific area, such as around an airfield. It would be possible for the crew to fire two ALARMs with one set to direct mode and the other to loiter.

Other tactics were available to ALARM users: The missile could be fired on a specific bearing along which it would fly while the seeker would listen out for radar targets of opportunity. This tactic could be particularly effective when there was a need to sanitise an ingress or egress corridor of threats. ALARM could also be programmed before a sortie to strike specific, known targets using latitude and longitude. Coordinates could be changed in the cockpit should a new target emerge during the mission.

Ultimately, the decision not to supply ALARM to the UAF has probably not adversely affected Ukraine’s offensive counter-air and subsequent air defence suppression posture. Given the concerns over the missile’s RF seeker head, it is remains open to question how effective the weapon would have been. To be fair the missile, which was initially selected by the MOD for development in 1983, was built for another age. This late Cold War period was characterised by different radar threats used by Soviet and Warsaw Pact forces. Ironically, the RAF would meet many of these threats in the post-Cold War world in the skies above Iraq and Kuwait in 1991, and later above the Balkans in 1995 and 1999.

By all accounts, ALARM acquitted itself well during these conflicts. Fortunately, the United States has supplied the UAF with Texas Instruments/Raytheon AGM-88B/C High Speed Anti-Radiation Missiles (HARMs). These weapons continue their important work of making life miserable for Russian radar operators in Ukraine. (Source: Armada)

 

06 Jun 24. June Spectrum SitRep. MASS’ THURBON CEMA electronic warfare and intelligence mission data management system can hold and manage a mind-bending array of data related to electromagnetic emitters and their users. The software offers clear benefits not only for the military, but also for the intelligence and law enforcement communities.

Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.

THURBON enhancements

MASS has unveiled further enhancements to the company’s THURBON electronic warfare and intelligence mission data management system. The company revealed it has developed a new iteration of the software known as THURBON CEMA (Cyber and Electromagnetic Activities).

THURBON CEMA significantly increases the system’s capabilities regarding blue and red force electromagnetic emitters across sea, land and air domains. THURBON presents the battlespace in a cartographic form covering the area of operations. Blue and red force assets such as bases, sensors, weapons systems, platforms and even individuals can be populated with an array of electromagnetic information. This data includes everything from the radars used by a surface-to-air missile battery to the cell phone of an individual. In fact, all the communications systems used by an individual can be matched to the person and depicted. As with the legacy THURBON architecture, THURBON CEMA users can easily see all the electromagnetic information associated with a blue or red force asset by clicking onto the asset and extracting the information you want to see. Alternatively, assets in the operational area can be filtered.

For example, a user may want to see all white force (neutral) assets in the operational area using satellite phones. This information can be easily retrieved and presented. As relevant intelligence is collected it can be entered into THURBON CEMA to populate the relevant assets. The CEMA enhancements to the THURBON software allows the user to not only see the red force Electronic Order-of-Battle (EOB), the blue force EOB can also be presented. The latter is invaluable during blue force electromagnetic planning and command and control, ensuring that a convoy’s communications coverage is uninterrupted, for example. Interruptions could arise from red force jamming, but also be due to natural causes like rugged terrain interrupting communications lines of sight.

Additional useful information like taboo frequencies can be loaded into THURBON CEMA and presented. Likewise, intelligence concerning Remote-Controlled Improvised Explosive Devices (RCIED) can be processed and presented. RCIED intelligence can include the types of radio system used to detonate roadside bombs. Alongside THURBON CEMA’s applicability to the military domain, the software can be employed to support intelligence gathering and law enforcement.

PLATH’s NEMO COMINT system is shown here equipping a Heer (German Army) General Dynamics/MOWAG Duro wheeled vehicle. The Heer acquired three NEMO systems as technology demonstrators in 2014. PLATH ‘s SDI Core is being developed to provide additional COMINT processing to networked NEMO systems.

Core business

This year’s PLATH Intelligence Workshop took place on 13th May in the town of Lillestrøm, southeast Norway. The company presented its SDI (Software Defined Intelligence) Core which is designed to provide a remotely accessible software core that can support Communications Intelligence (COMINT) analysis. The SDI Core is designed to work with the company’s NEMO COMINT systems family.

Company representatives said that some COMINT can often be unclear or corrupted. Such signals may eclipse the processing capabilities of NEMO. NEMO users can send ambiguous or unclear signals to the SDI Core which performs additional signals analysis. The SDI Core accommodates a host of software applications which can execute this additional analysis in near real time. The results of this additional analysis can then be shared with the NEMO users, or with third parties.

Company representatives said that the SDI Core is at the experimental stage and currently at between Technology Readiness Levels Three and Four (TRL-3/4). According to European Union definitions, TRL-3 denotes the demonstration of a technology’s experimental proof of concept. TRL-4 denotes that the technology has been demonstrated in a laboratory environment. PLATH representatives continued that the SDI should reach TRL-5, when the technology is demonstrated in a relevant environment over the next year.

BAE Systems’ new Dual Band Decoy is being developed to outfit the US Navy’s F/A-18E/F Super Hornet fleet. It is expected to enter service in circa 2027.

Dual is cool

On 15th May BAE Systems announced its selection by the US Navy to develop a new Dual Band Decoy (DBD) to equip the service’s combat aircraft. A press release announcing the news said the decoy will be used to help protect aircraft from radar-guided threats. The release continued that the DBD will build on the work the company has already performed vis-à-vis its AN/ALE-55 fibre-optic towed decoy. Like the AN/ALE-55, the DBD will outfit the US Navy’s Boeing F/A-18E/F Super Hornet planes. Don Davidson, BAE Systems’ advanced compact electronic warfare solutions director, told Armada that the company cannot specify what wavelengths and frequencies the DBD will be effective against. However, Mr. Davidson did state that the initial operational capability for the DBD is expected to be declared in circa 2027. (Source: Armada)

 

06 Jun 24. USAF on verge of rapid electronic warfare updates.

The Air Force is “very close” to being able to rapidly update electronic warfare systems with fresh battlefield data in a matter of hours, one of the service’s commanders said Wednesday.

Col. Josh Koslov, commander of the 350th Spectrum Warfare Wing, has set an ambitious goal of updating EW systems within three hours, instead of days.

In a webcast hosted by C4ISRNET, Koslov said that three-hour goal — which he once referred to as a “moonshot” — is now within reach.

“We’re very close to that, if not exceeding, in most of the systems that we cover in the spectrum warfare wing,” Koslov said. He went on to say that more than half of the 70 EW systems his organization touches across the Air Force are either at or below the three-hour mark for updating.

But many of those systems have unique elements, he said, and the Air Force’s EW systems need to make more use of interoperability and open architecture standards to simplify the process for rapid data updates.

And Koslov said his wing will need enough resources to develop these data production methods that will allow the military to process this data on a large enough scale to work in war, and then transport the data back to the field.

Koslov and Brig. Gen. Ed Barker, the Army’s program executive officer for intelligence, electronic warfare and sensors, said in the webcast that in a future war against an advanced adversary, conditions on the battlefield, threats and targets will likely change so quickly that rapid updates to EW systems will be critical.

‘Data is the weapon’

“We have to be able to continue to add pressure to the adversary in a war in order to seize the advantage and achieve our objectives,” Koslov said. “Data is the weapon that will allow this to happen, and data processing is the way to do that.”

This will include combining data from all sources in the joint force, such as Army units on land, naval ships in the Pacific, or airborne platforms, he said, and then combing through that information to find new threats. The military must then use that data to develop a way to counter that new threat, and then get that new capability back to the field.

To achieve these kind of rapid data updates, Koslov said, the Air Force has revamped its tactics, techniques and procedures to have more of a “warfighting” focus.

When asked whether data updates could be made to systems remotely, or whether they would require something to be physically plugged in, Koslov said that would depend on the EW system. He said information would be transported to Eglin Air Force Base in Florida, where the 350th is located, or other reprogramming centers where more people can process the data.

That will be especially useful during a major conflict against a nation such as China or North Korea, he said, in which joint forces would be spread out across the Pacific region.

“When you come out with a new capability, it’s not good if you just get it into one pocket,” Koslov said. “You have to be able to get it across the force. And so centralizing that is going to be the right way to do that as we move forward.”

The Air Force activated the 350th in 2021, and has since been building up its capabilities by adding more units. Earlier this year, the wing stood up two new electronic warfare squadrons — the 388th at Eglin and the 563rd at Joint Base San Antonio-Lackland in Texas.

The 563rd is focused on building new EW software for operational units to respond to the threats they encounter in the field. And the 388th is focused on studying adversaries such as China to find ways to breach and thwart their digital capabilities.

Koslov said his wing is next focused on building out the 950th Spectrum Warfare Group at Robins, which is expected to be fully activated in 2027. The 950th will be in charge of assessing the EW systems in Air Force’s combat aircraft and improving EW capabilities.

“Everything has to be assessed from a platform perspective — does the platform do what we’ve asked it to do?” Koslov said. “But also our [tactics, techniques and procedures] have to be assessed. … How good are we at fighting and training in the [EW] spectrum?” (Source: Defense News)

 

06 Jun 24. Bittium Tactical Wireless IP Network™ System and Bittium Tough SDR Vehicular™ Radio Accepted as Tactical Communications Solutions for the Armament of the Croatian Armed Forces.

Bittium Tactical Wireless IP Network™ System and Bittium Tough SDR Vehicular™ Radio Accepted as Tactical Communications Solutions for the Armament of the Croatian Armed Forces

The Ministry of Defence of the Republic of Croatia has accepted the software-defined radio based Bittium Tactical Wireless IP Network™ (TAC WIN) system and Bittium Tough SDR Vehicular™ radio as tactical communications solutions for the armament of the Croatian Armed Forces. The acceptance follows an implementation phase of few years of the products by the Croatian Navy. The implementation phase was carried out in cooperation with Bittium’s Croatian partner IntellByte INFO, a supplier of IT solutions that acts as the integrator of the Croatian Navy’s tactical communications system entity as well as the contracting party with the Navy. The orders related to this cooperation, received during the implementation phase as well as the ones expected in the future, do not have significant impact on Bittium’s financial guidance for the year 2024, nor in achieving its long-term targets.

During the implementation phase, part of the Croatian Navy’s backbone network for communications was built with the modular and broadband TAC WIN system and Tough SDR Vehicular radios were used to connect the Navy’s vessels as part of the survivable tactical backbone network.

Based on the successful implementation, the Ministry of Defence of the Republic of Croatia has accepted Bittium’s TAC WIN system and Tough SDR Vehicular radios for the armament of the Croatian Armed Forces. In addition to the Navy, the products can be offered also to other branches of the Croatian Armed Forces. The implementation of the tactical communications network for the Croatian Armed Forces will take place gradually and the Armed Forces will issue possible separate purchase orders for Bittium’s products and solutions as the implementation progresses.

“The successful implementation of the TAC WIN system and Tough SDR Vehicular radios by the Navy and acceptance for the armament of the Croatian Armed Forces is an excellent demonstration of our products’ and systems’ performance and applicability for different use cases. The modular software-defined radio-based TAC WIN system works seamlessly with other systems in use. We are proud to offer our products and systems to all the branches of the Croatian Armed Forces together with our local partner IntellByte INFO. Together we can take the Croatian Armed Forces’ tactical communications into a new era,” says Tommi Kangas, Senior Vice President of Bittium’s Defense & Security business segment.

“Situational awareness, fast movement, and the ability to make quick decisions are the key elements of a modern warfare doctrine. In order to achieve these goals, the modernization of tactical communications is set as a development imperative for the Croatian Armed Forces. By implementing Bittium’s solutions we significantly raised performance and brought a new and advanced work experience to the Croatian Armed Forces. This was a visible ICT technological leap, both for us who implemented Bittium solutions, and for the Croatian Armed Forces who gained the possibility of using broadband technologies locally, but also globally by implementing intercommunication services that enable communication between military coalition troops,” says Jasmin Hodzic, IntellByte INFO’s CTO.

 

03 Jun 24. Eight new companies to bolster cyber defences of critical UK sectors. Digital Catapult, the UK authority on advanced digital technology, has announced that a new cohort of companies will join Digital Security by Design’s (DSbD) Technology Access Programme (TAP) to trial necessary new cyber security solutions. Building on the programme’s success to date, eight companies will have access to an Arm Morello board, a prototype evaluation hardware kit based on Capability Hardware Enhanced RISC Instructions (CHERI), to consider its application across critical UK sectors.

DSbD is an initiative supported by the UK Government that is set to revolutionise cyber security in modern-day computing. In partnership with the University of Cambridge and Arm, DSbD’s Technology Access Programme works towards creating a more secure digital environment, in which only planned access to data and operations is permitted. The CHERI Instruction Set Architecture (ISA) will open up new markets for cyber secure-by-design products, providing a competitive advantage to companies that understand its strategic value and identify new use cases, such as protecting device users.

The new cohort’s efforts come as the UK Government stated that cyber security issues are now on an equal footing with other threats such as financial and legal pitfalls to UK businesses, and as the programme’s technology recently received recognition from the UK Government and the White House for its cyber security value. If the hardware and software features are implemented correctly, evidence has established that they can prevent two thirds of hacks, cyber attacks and data breaches, demonstrating the strategic importance of the programme on a global scale.

Bolstering the security of the UK’s device and gaming sector will be critical to maintaining levels of inward investment in the industry, as HaC Arcade will use the Morello board and CHERI architecture to secure a networked gaming rig system that virtually connects players across the UK. Since vulnerabilities can occur on both the network and hardware, additional memory security is highly valuable. ExactTrak aims to improve the security of laptop devices by developing a platform that can securely manage employee devices while complying with government protocols for products used by security and intelligence services, and make this solution available across all enterprises.

The cohort will also look to enhance the safety and security of drivers and those that have fallen victim to cyber-attacks. Coventry-based Secure Elements will develop a solution that uses the Morello Board to identify new vulnerabilities in vehicles’ security systems, allowing for vulnerabilities to be flagged immediately to its cyber security application. Cyntegra, a company that offers solutions to fix systems after they have been attacked by malware, will integrate their own system into Morello and CHERI, to restore an entire system’s functionality back to normal after an attack.

Defence will also be a focus for the new cohort, as Kaze Consulting and Cyber Defence Service Ltd will experiment with and test the Morello board and CHERI architecture to uncover security vulnerabilities in their own products. Kaze Consulting will consider how cyber security can be improved by deploying CHERI devices to new environments, with a view to deploying CHERI to a specialist domain such as the satellite ecosystem, while Cyber Defence Service Ltd will explore how CHERI architecture could monitor and protect critical national infrastructure in the near future.

The remit of the cohort’s solutions extends beyond the UK, with Vividgrd aiming to transform commercial sites into microgrids globally, while OpenLX SP Ltd will deploy its hardware solutions worldwide, collecting data and controlling systems across various sectors. During the programme, Open LX will look to explore how Morello can bring more security to its ultra lightweight “Function-as-a-Service” that blurs the boundaries between on-premise servers, cloud, edge and devices for internet of things (IoT), while the latter will consider how to make digital security an integral part of its distributed internet of things IoT system.

Digital Catapult hopes that the new cohort’s participation on the programme will encourage the development of new security solutions in the long term, as several leading alumni of DSbD, including ScienceScope, have since planned additional development phases to enhance their security measures and solutions.

Jessica Rushworth, Chief Strategy and Policy Officer, Digital Catapult said: “Cyber security remains front of mind for businesses across almost every sector in the UK, and the success of the Digital Security by Design programme is testament to the strategic value and importance of the ongoing collaboration between Digital Catapult, the University of Cambridge, Arm and participating companies, both past and present. Security issues continue to inhibit business growth, so the development of new solutions to tackle real-world cyber security challenges is critical to achieving long-term commercial success. This fifth cohort will build on the groundwork laid by their predecessors, moving us closer to a safer cyber landscape.”

Prof. John Goodacre, Challenge Director, Digital Security by Design, UK Research and Innovation, said:  “With the announcement of this Fifth Cohort of the Digital Security by Design Technology Access Programme, we are delighted to offer further businesses across the UK the opportunity to engage with the DSbD Technology and provide applicants with the funding and support to understand how their products and services can benefit, blocking vulnerabilities so that their operations and customers can be better protected against the growing costs and harm of a cyber attack.”

Companies interested in taking part in Digital Security by Design’s Technology Access Programme can register their interest on the DSbD website and be notified when applications open again.

 

03 Jun 24. UK General Election will face increased cyber threats. On 23 May, UK Prime Minister Rishi Sunak announced that a general election will be held on 4 July.

SIGNIFICANCE

  • In the run-up to and during the election, state-sponsored actors are likely to conduct cyber attacks against the UK. These attacks will likely aim to influence the election’s outcome, to disrupt election infrastructure and to undermine trust in the electoral process. However, the impact of any such cyber activity on the formation of the government is unlikely to be significant.
  • Cyber criminals will also likely exploit the election during financially motivated operations, elevating phishing and information-theft risks for UK voters.
  • If the Conservative Party loses to the Labour Party, we assess that the consequent transfer of power would create further opportunities for cyber actors. This would possibly disrupt the creation of the new government and delay policy making.

FORECAST

We assess there is a realistic possibility that Chinese- and Russian-backed threat actors will target election infrastructure and conduct influence operations. Both countries have an interest in influencing or deterring the next government’s policies pertaining to London’s relations with Beijing as well as its ongoing military support for Ukraine. As such, Chinese and Russian actors will possibly target the electorate in influence operations to sway the voting population, as demonstrated by their interference in prior elections. The upcoming European Parliament (EP) elections also face similar risks (see Sibylline Special Report – 3 May 2024). Any such operations will likely take the form of artificial intelligence (AI)-generated content, including deepfakes; bots on social media platforms are also likely to spread dis/misinformation at increased levels.

We assess that Chinese and Russian state-sponsored actors will possibly target election infrastructure in disruption operations to inhibit the voting process. The UK Electoral Commission suffered a cyber attack in 2021 that was conducted by suspected Chinese state-sponsored actors. The attack granted the actors undetected access to electoral registers, employee emails and the commission’s computer systems for over a year. Consequently, state-backed actors will possibly target similar information sources. However, while the UK general election will face possible disruption and influence risks stemming from state-backed actors, it is likely that these actors will focus more on operations targeting November’s US presidential election.

We assess that cyber criminals are likely to exploit the general election to garner illicit profit via phishing and watering hole campaigns. UK residents will likely face an increase in election-themed phishing emails from actors who aim to steal information to sell on the dark web. It is also likely that more ‘typosquatting’ and ‘watering hole’ attacks will take place. ‘Typosquatting’ occurs when a user unwittingly types an infected URL in which there is a subtle typo into their web browser, while a ‘watering hole’ attack takes place when cyber actors infect a website they know their target(s) will visit. These domains will likely pretend to be related to particular candidates or other election themes in an aim to steal personal and financial information from users (again to sell on the dark web for profit). Ransomware will also pose moderate disruption risks for the electoral system. Consequently, there will be elevated phishing, fraud and identity-theft risks facing UK residents and voters in the run-up to the election.

We assess there is a realistic possibility that threat actors will exploit the potential transfer of power following the election via disruptive espionage operations. The instability that typically occurs during these transition periods will possibly exacerbate operational continuity risks for the UK government. In particular, state actors will possibly attempt to delay or influence the establishment of certain policies and/or legislation for their own country’s strategic benefit. State-sponsored actors and cyber criminals will possibly target government entities during the transition period after the election if the Conservative Party loses the majority vote. Attackers will possibly use ransomware to disrupt operations, while also conducting phishing operations to install backdoors on strategic networks for future long-term espionage campaigns.(Source: Sibylline)

 

31 May 24. Open DAGIR: DoD plans July industry day, experiments for new CJADC2 command apps. The Chief Digital & AI Office wants to bring in a wide range of software developers to rapidly create new applications for Combatant Commands worldwide, with the new apps plugging into Palantir’s open-architecture Maven Smart System.

Instead of a single megaprogram run by a single contractor, the Pentagon wants its nascent global battle network, called CJADC2, to evolve into a rapidly adaptive ecosystem, where dozens of different applications bloom and die as military needs arise and change.

So, just after awarding almost a half-bn dollars to Palantir Technologies to expand its Maven Smart System tenfold, the Chief Digital & AI Office (CDAO) announced a new initiative, Open DAGIR, to open the doors to other software developers.

While Palantir’s Maven will act as the de facto backbone for the global system, its “open architecture” design is meant to allow other companies’ code to plug in, quickly, with a minimum of integration work. That plug-and-play approach, in turn, should allow the operational Combatant Commands (COCOMs) around the globe to commission custom apps as needed from any vendor.

“We want America’s best talent solving DoD’s hardest problems,” said the new Chief Digital & AI Officer, Radha Plumb, in a published statement Thursday.

The first of those hard problems is CJADC2: Combined Joint All-Domain Command & Control — that is, linking all the US armed services (“joint”) and their coalition partners (“combined”) across the five “domains” of land, sea, air, space, and cyberspace. Last year, CDAO and the COCOMs used quarterly Global Information Dominance Experiments (GIDE) to speed-run development of a “Minimum Viable Capability” for CJADC2. Now, as the GIDE experiments continue, CDAO is looking to build beyond that “minimum,” a senior defense official told reporters Thursday.

“What we learned is, it’s not one company or one thing that makes advanced C2 capabilities,” the official said. “It’s making sure we have the data in a way that’s accessible to a broad range of talented software developers, across a range of companies….What we’ve done here is created a scalable way to do that.”

The push for “third-party capabilities” will kick off June 1 with “a six week sprint” by Pentagon experts in intellectual property, contracting, and software development, the official said. Their mission: to figure out a competitive process that will meet military commanders’ needs, build on Palantir’s technology, but also protect other contractors’ IP.

Then, in July, CDAO will hold an industry day for interested companies and run an initial round of experiments to try out software, as part of the same quarterly GIDEs the Pentagon has been using to thrash out CJADC2.

Triple DAGIR

Overall, Open DAGIR — short for “Open Data & Applications Government-owned Interoperable Repositories” — involves three interdependent but distinct layers, the official explained:

  1. Data Infrastructure: Data is the foundation for any functioning analytics or artificial intelligence, as Radha’s predecessor, founding CDAO Craig Martell, was fond of saying. That means the data is not only accessible but properly tagged, labeled, and structured so a variety of different systems can read it. The government will retain ownership and control of the data, but Palantir will build and operate the software “stack” required to manage it day-to-day. (This is a model known as Government Owned, Contractor Operated, or GOCO). However, third-party contractors will be able to access the Palantir-managed data as needed to make their software work, the official emphasized.
  2. Mature Applications: This layer is for software that has proven stable, functional, and cybersecure, and which the government decides to use on a large scale for a long time. Such apps will be purchased on an “enterprise license” basis, meaning CDAO will buy the rights for them to be used by an entire organization, like a COCOM or even the whole Department of Defense. Palantir’s Indefinite-Quantity, Indefinite-Delivery (IDIQ) contract for the Maven Smart System is the leading example here, and the only one the official mentioned by name, but others will presumably be added in the future.
  3. Competitive Environment: Even the most mature and regularly updated software program can’t meet all needs, however. That’s why the final layer of CDAO’s new approach is a “competitive environment” where COCOMs can issue new requirements, interested software developers of all sizes can compete to meet them, and the winning products can be fielded rapidly, using Other Transaction (OT) contracts. (All these developers will have access to the Palantir-managed but government-owned data). Successful software may eventually graduate to the “mature” layer and earn a long term contract, or it may simply meet an immediate need and fade away.

“They can be applications that are fit for a particular urgent or emergent need that we want to build and deploy rapidly, but we may not want to sustain for years or decades,” the official explained. “Those can be funded through the OT [Other Transaction Authority], delivered, fielded very quickly, and then…we can deprecate [them] as we no longer need them. The second class is the set of applications that are mature [and which] we want to be enduringly available, and those can be transitioned into the IDIQ itself, integrated with the Palantir stack.”

By using different types of contracts, and switching a given piece of software from one type to another as needed, CDAO should be able to exploit competition among companies to rapidly add new capabilities at the top layer — without having to change its foundation-layer contractor and laboriously rebuild everything from the bottom-up for every update. (That ordeal historically happened all too often with traditional systems where a single “lead systems integrator” built everything on a single contract using proprietary technology that was incompatible with other contractors’). In fact, although the official didn’t say so aloud, in theory it should even be possible to replace Palantir as the contract for the data infrastructure, for Maven, or both.

“Open DAGIR ensures the Department can leverage the innovative solutions from the world-class software developers in both the traditional and nontraditional industrial base,” Plumb said in her statement. “It allows us to ensure enduring access to government-owned, contractor-operated technology stacks and infrastructure and retain data rights while also maximizing the ability of other companies to develop applications with government data.” (Source: Defense News Early Bird/Breaking Defense.com)

 

31 May 24. Cyber Update.

Key points

  • A new highly sophisticated gift card scam underscores the elevated security and financial risks facing US retailers (see Sibylline Cyber Daily Analytical Update – 28 May 2024 and our Technical analysis below).
  • The adoption of new custom ransomware by the North Korean state-sponsored group ‘Moonstone Sleet’ will sustain elevated security and financial risks for the technology sector (see Sibylline Cyber Daily Analytical Update – 29 May 2024 and our Technical analysis below).
  • A new vulnerability affecting virtual private network (VPN) services has accentuated security and reputational risks via the software supply chain (see Sibylline Cyber Daily Analytical Update – 30 May 2024).
  • A new phishing campaign attributed to the Russian-aligned group ‘FlyingYeti’ highlights the sustained security and espionage threats facing Ukrainian civilians (see Sibylline Cyber Daily Analytical Update – 31 May 2024). Technical analysis of weekly stories. The cyber criminal group ‘Storm-0539’ is targeting US-based employees of retailers, luxury brands and popular fast-food chains in a new and highly sophisticated gift card scam. The campaign starts with phishing emails and text messages (smishing), which the group crafts after extensive reconnaissance to steal user credentials and session tokens through adversary-in-the-middle (AitM) phishing pages. It then uses these stolen credentials to access a targeted organisation’s cloud environment, registering its own devices on the victim’s system to  bypass authentication, achieve persistence and escalate privileges. This enables Storm-0539 to create fraudulent gift cards and sell credentials on the dark web to garner illicit profit. Notably, this campaign marks a shift in the group’s capabilities due to the sophisticated exploitation of cloud environments. Additionally, the group occasionally impersonates non-profit organisations to obtain discounted or free cloud infrastructure. This significantly bolsters the group’s success rates by enhancing its legitimacy. In one instance, an unnamed organisation detected Storm-0539’s activity on its system, implementing changes to prevent the creation of additional fraudulent gift cards; however, the group was able to adapt its tactics quickly, regaining access to corporate systems and demonstrating its ability to persist within targeted infrastructure.

The North Korean state-sponsored group ‘Moonstone Sleet’ (formerly tracked as ‘Storm-17’) has started deploying ransomware against software development companies and the defence sector. The group’s tactics, techniques and procedures (TTPs) typically align with known techniques associated with other North Korean groups, particularly ‘Diamond Sleet’, such as using social media to deliver trojanised software, malicious npm packages and tank games. However, Moonstone Sleet’s infrastructure now includes ransomware, highlighting the expansion of the group’s operations as well as its resources. The group has notably created several fake technology and software development companies to solicit co-operation with targeted individuals, while also seeking employment within targeted companies. This primarily aims to foster rapport with potential victims to trick them into downloading the group’s custom malware, ‘FakePenny’. Additionally, Moonstone Sleet’s pivot to conduct IT work within its campaigns possibly signals that it is starting to carry out financially motivated operations.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing and other types of social engineering attempts.
  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Enforce strict security policies including regular software and password updates to mitigate and prevent infections via leaked or stolen password credentials.
  • Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.

Our cyber word(s) of the week: adversary-in-the-middle (AitM) attack

(Source: Sibylline)

 

—————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Spectra Group (UK) Ltd

 

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

May 31, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

———————————————————————————————————————————————————————————————————————————————————————————————————————————-

30 May 24. SAIC Employees Embrace Generative AI with the Launch of Tenjin GPT. Science Applications International Corp. (NASDAQ: SAIC) today announced the launch of Tenjin GPT, a new internal, generative Artificial Intelligence (AI) resource available to employees that harnesses cutting-edge AI capabilities to automate and optimize business processes.

“Tenjin GPT is just one example of how SAIC is pushing the limits of technological innovation to provide employees with real-time insights and data analysis, as well as enhancing creativity and collaboration across our enterprise,” said Nathan Rogers, senior vice president and chief information officer at SAIC. “SAIC is accelerating the adoption and use of AI while also adhering to ethical AI governance values enforced by SAIC’s AI Council.”

Tenjin GPT, the latest feature of SAIC’s data science platform Tenjin, leverages the power of OpenAI’s GPT, which is the latest advancement in natural language processing. This state-of-the-art AI model enables users to develop highly sophisticated applications, automate repetitive tasks, streamline processes and gain valuable insights from vast amounts of data.

“By embracing generative AI technologies, SAIC is empowering our employees to upskill and improve productivity, while also reducing mundane tasks,” said Andy Henson, senior vice president of Digital Innovation at SAIC. “We help our customers harness data and AI to meet their mission needs every day, so it’s only natural for our employees to embrace this technology.”

Currently Tenjin GPT is being used internally at SAIC for summarizations of information, code generation, translation, research, content generation, and more, but it can also be integrated into customers’ existing infrastructure. Powered through Microsoft’s Azure AI, the robust framework ensures seamless integration and scalability. Additionally, Tenjin GPT aligns with SAIC’s and Microsoft Azure’s strong commitment to securing sensitive data, which is especially crucial for government teams. (Source: BUSINESS WIRE)

28 May 24. New Rapidly Deployable Hand Carried Internet Solutions.

Tekniam’s Remote Universal Communication System (RUCS) is a fast deploying, easy to hand carry device weighing 5lbs that throws a powerful broadband internet signal 3 miles.

Tekniam’s new Remote Universal Communication System (RUCS) is a fast deploying, easy to hand carry device weighing only 5lbs (2.27kgs) that throws a powerful broadband internet signal 3 miles (4.8km) with very low power draw.

The signal can be relayed between units up to 35 miles (56.3km) with up to a gig of throughput at a time.

This technology delivers what has become one of the single most important strategic advantages of modern warfare. Bandwidth.

The world is at a major inflection point in history where new network technology is dramatically shifting the balance of military power from offense to defense.

According to Tekniam, fighting this type of modern warfare requires bandwidth that the company’s RUCS delivers for the full spectrum of military capabilities.

RUCS is being used for military applications talking to drone swarms. The video feeds or sensory data the drones send back is then processed for analysis for target selection connecting unmanned reconnaissance with the shooters.

For special operations communications, the RUCS was designed to be lightweight and have high throughput up to a gig at a time. The RUCS is able to deliver a large amount of power with a low power draw.

Tekniam’s RUCS delivers bandwidth to the battlefield in a way that is dramatically shifting the balance of military power from offense to defense. A low cost, easily hand carried device that formerly required heavy equipment towed on a trailer with a generator and gasoline to achieve only a fraction of the network power of Tekniam’s new RUCS. (Source: https://www.defenseadvancement.com/)

 

30 May 24. Mobile Battlefield Capabilities Demonstrated for Canadian Armed Forces. The field exercise, HERMES FORGE, showcased the speed, resilience, and reliability of Ultra Intelligence & Communications (Ultra I&C) mobile command post solutions. Ultra Intelligence & Communications (Ultra I&C) has demonstrated its capabilities across multiple tactical bearers during a field exercise with the Canadian Armed Forces.

The exercise, HERMES FORGE, is designed to assess the modernization progress of its tactical network architecture.

As the proliferation of UAVs and the prevalence of long-range precision fires threaten traditional command post operations, the Canadian military has engaged select industry partners, including Ultra I&C, to develop resilient communications solutions that will meet new mobility requirements. After two years of collaboration with the Canadian Armed Forces, this culminating exercise showcased the speed, resilience, and reliability of Ultra I&C’s mobile command post solutions.

Faith Rhodes, Vice President of programs for Ultra I&C’s Communications division, said; “Ultra I&C’s participation in HERMES FORGE allowed us to showcase our technologies currently deployed within NATO countries.

“By validating these technologies during the exercise, we underscored our role as the proven partner to provide interoperable capabilities in the field in Europe and truly enable expeditionary missions with our coalition partners.”

Keith Blanchet, vice president of business development for Ultra I&Cs’ Communications division, added; “Ultra I&C has a unique expertise and advantage fielding SATCOM, LOS, and troposcatter communication bearers in an integrated fashion that provides the diversity of communications options our soldiers need to be successful.

“This enables network resilience and eases the burden of having to understand and operate disparate systems and tools, making it easy to set up and operate.”

Central to the successful demonstration was Ultra I&C’s latest generation of quick deploy vehicular-mast-mounted line-of-sight systems, critical for on-the-move-missions. In Dispersed Command Posts (DCPs), Ultra I&C’s small SWaP Orion X510 was shown to be interoperable with the existing X500 Upper Tactical Network backhaul waveforms as well as with the existing Trellisware waveform (TSM). The new Orion X630 radio was deployed on a Vertical Height Antenna system to allow highly mobile DCPs to reach back to a rear headquartered Orion X500 radio, while simultaneously extending the range of the Brigade TSM network. The deployment of Ultra I&C’s extra-light VSAT SATCOM terminal was also evaluated as an alternative bearer to Orion LOS for maintaining robust communications between rear HQ and DCPs at the tactical edge.

The initial soldier touchpoints and user engagement that took place during the HERMES FORGE exercise will inform the Canadian Armed Forces’ consideration to leverage Ultra I&C’s solutions for deployment into Latvia to enhance on-the-move mission tactical

(Source: https://www.defenseadvancement.com/)

 

29 May 24. FCAS AI-Backbone is operational. The Future Combat Air System AI Backbone has become operational, with 50 pilots and ten organisations using the system. The AI-backbone of the Future Combat Air System (FCAS) has been made operational, with more than 50 pilots from ten organisations now using the cross-sectional platform, according to a release from Rohde-Scwarzh, one half of the HIS consortium developing the technology, on 29 May 2024.

The AI-backbone was provided by Helsing and Schönhofer Sales and Engineering (a subsidiary of Rohde & Schwarz) just nine months after the contract start in 2023.

According to the release from Rohde-Schwartz, the AI-Backbone offers improvements over the current standards, by introducing standardised procedures across organisations in the military sector and reducing fragmented processes with numerous interfaces.

This centralised platform is also intended to ensure data security and sovereignty for every user and increase flexibility and efficiency across the MiLOps workflow.

“The use of AI will be critical to FCAS air superiority. AI accelerates the evaluation of sensor data, the planning of missions and the use of effectors,” explains Frank Schrudde, managing director of Schönhofer Sales and Engineering. “As an innovative, long-standing partner of the Bundeswehr, we bring vigour to the research landscape. We are proud to have brought the agility of a medium-sized company to the project in collaboration with our partners. We were able to deploy the first demonstrator in an extremely short time of nine months.”

“With the first release, an important milestone in the implementation of the AI-backbone has been reached,” says Stephanie Lingemann, program director and head of the air domain at Helsing. “We are proud to have advanced the AI-backbone from the initial idea to implementation. The development of AI is now being supported in the ongoing phase of the national R&T projects and a decisive cross-sectional contribution is being made to enabling the NGWS.”

The next stage of development will be part of the second release, expected in November 2024. Rhode-Schwarz intend this update to enable standardised, collaborative AI workflows in highly sensitive environments, and to add additional capability components. (Source: airforce-technology.com)

 

29 May 24. Global: Custom ransomware will sustain elevated security, financial risks from North Korean actors. On 28 May, the technology company Microsoft revealed that the North Korean group ‘Moonstone Sleet’ (formerly tracked as ‘Storm-17’) has started deploying ransomware against software development companies and the defence sector. The group typically uses known tactics associated with North Korean actors and has been deploying new custom ransomware (‘FakePenny’) since April. This points to the group’s involvement in financially motivated operations alongside espionage campaigns. Additionally, the group has created several fake technology companies to trick victims into downloading malicious payloads, highlighting a shift in its tactics, techniques and procedures (TTPs) and the expansion of its operations. North Korean groups often conduct financially motivated attacks alongside espionage operations to finance Pyongyang’s missile and weapons programmes amid international economic sanctions. As such, we assess that the evolution of Moonstone Sleet’s TTPs will sustain elevated security and financial risks for the technology and defence sectors. (Source: Sibylline)

 

23 May 24. Cyber Update Key points.

  • The resumption of the ‘Grandoreiro’ malware operation points to elevated financial and reputational risks facing the financial sector (see Sibylline Cyber Daily Analytical Update – 20 May 2024).
  • Destructive operations conducted by Iranian state-sponsored actors have elevated the operational and security risks facing Israel-based organisations (see Sibylline Cyber Daily Analytical Update – 21 May 2024 and our Technical analysis below).
  • A sophisticated crypto-mining campaign is disabling security protections, elevating cryptocurrency-theft and security risks for firms (see Sibylline Cyber Daily Analytical Update – 22 May 2024 and our Technical analysis below).
  • A new suspected Chinese-affiliated group, ‘Unfading Sea Haze’, is targeting countries in the South China Sea region, underscoring elevated security and espionage risks therein (see Sibylline Cyber Daily Analytical Update – 23 May 2024).
  • The recent surge in hacktivist attacks targeting the upcoming Indian general election has elevated information-theft, disruption and disinformation risks (see Sibylline Cyber Daily Analytical Update – 24 May 2024).

Technical analysis of weekly stories

The Iranian state-sponsored group ‘Void Manticore’ has targeted Israel-based organisations in several destructive attacks since October 2023. The group notably co-operates with another Iranian-sponsored threat group, ‘Scarred Manticore’, which provides Void Manticore with initial access to targeted systems. Void Manticore’s arsenal includes a highly sophisticated version of the ‘BiBi’ wiper, which has the ability to delete key functions from a system’s partition memory. This allows the group to inhibit data restoration, thereby amplifying the impact of its attacks. Additionally, the group often manually deletes data via legitimate utilities such as Windows Explorer, further highlighting its focus on quick and highly impactful and destructive attacks. The co-operation between Void Manticore and Scarred Manticore has also revealed a high degree of co-ordination, which points to the operation’s longevity ( as well as a consistent level of planning). Void Manticore has claimed attacks on over 40 Israeli organisations under the guise of the online hacktivist group ‘Karma’; its use of online personas underscores the multi-pronged nature of this campaign, which weaponises political tensions while also wiping data and causing operational disruption.

A new highly sophisticated crypto-mining campaign, ‘REF4578’, has compromised servers in China, Germany, Hong Kong, Japan, the Netherlands, South Africa, Sweden and the US to garner illicit profit. Although the initial attack vector remains unclear, the campaign starts with the deployment of a PowerShell script hidden in a PNG image; this establishes communication with actor-controlled servers and retrieves additional executables, including the malware ‘GhostEngine’. Notably, this payload has the ability to deactivate security processes, such as Microsoft Defender Antivirus and endpoint detection and response (EDR) tools, to achieve prolonged detection evasion. Additionally, the initial script downloads a dynamic link library (DLL) service to create system persistence; it also downloads any updates from the actor-controlled infrastructure. GhostEngine finally deploys the ‘XMRig’ crypto-mining malware, potentially allowing threat actors to garner illicit profit. This campaign contains highly complex anti-detection and persistence mechanisms, highlighting the high sophistication and continuous development of actors’ tactics, techniques and procedures (TTPs).

Some non-exhaustive recommendations to mitigate against these threats include:

  • Apply patches to software vulnerabilities as soon as they are released to prevent exploitation.
  • Enforce strict and timely patch management policies and ensure adequate software configuration.
  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.

(Source: Sibylline)

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

May 24, 2024 by

Sponsored by Spectra Group

Spectra Group (UK) Ltd Home Page


———————————————————————————————————————————————————————————————————————————————————————————————————————————————
23 May 24. South China Sea: New suspected Chinese group underscores elevated security, espionage risks. On 22 May, the cyber security company Bitdefender Labs announced the discovery of a new threat group, ‘Unfading Sea Haze’, which is reportedly targeting countries in the South China Sea. The group mainly targets high-level military and government entities in espionage operations. Unfading Sea Haze’s tactics, techniques and procedures (TTPs) comprise spear-phishing emails containing malicious payloads as initial attack vectors, as well as an extensive malware arsenal for data extraction, including the remote access trojan (RAT) ‘Ghost RAT’ and other custom tools. The longevity and stealth of the group’s operations combined with its malware arsenal and chosen target set indicate that Unfading Sea Haze is likely to be a Chinese-backed state-sponsored group. China routinely leverages cyber espionage operations to bolster its security and military posture in the face of perceived adversaries. As such, we assess that Chinese-affiliated cyber actors will highly likely sustain elevated security and espionage risks for organisations operating in the South China Sea region in the long term. (Source: Sibylline)

 

22 May 24. The US has spent $5bn on electronic warfare in 2024 alone. China, Russia and India are projected to eat into the US’ outsized share of global electronic warfare spending in the coming years.
The US is the world’s largest investor and developer of electronic warfare, spending an estimated $5bn on the signal technology in 2024 so far alone, according to a new report.
GlobalData’s Electronic Warfare report details that, between 2021 and 2023, the US military accounted for the largest share of electronic warfare spending by a significant margin – 45% of global expenditure compared to Russia’s 14% and China’s 13%.
Washington’s stranglehold on the electronic warfare market looks set to be challenged, however.
The report predicts that Russia, China and India’s share of the electronic warfare market will only increase over the next decade.
Total expenditure by the world’s nine main electronic warfare militaries will surpass $16bn by 2033, the report adds, up from more than $11bn this year. (Source: naval-technology.com)

 

21 May 24. Netherlands acquiring new radios and C4I system under Foxtrot. The Netherlands Ministry of Defence (MoD) is equipping its armed forces with the AN/PRC-160 HF manpack radio from L3Harris Technologies in a bid to upgrade its tactical communications as part of the Foxtrot communications programme.
The authority is also planning to acquire a new tactical command, control, communications, computers, and intelligence (C4I) network for its special operations forces (SOF).
Both are new requirements stipulated in the Defence Projects Overview (DPO) 2024, published on 15 May, which provides an outline of all the planned materiel, IT, and real estate projects valued over EUR25 m (USD27.2 m).
With regard to the radio requirement, the MoD is undertaking a new, comprehensive programme to replace its ageing high-frequency (HF) communication equipment across the armed forces. Radios such as the HF7000 long-range radio, which has reached the end of its technical service life, will be replaced with L3Harris Technologies’ AN/PRC-160 radio. (Source: Janes)

 

17 May 24. France turns to AI for signals analysis in underwater acoustics war. The French Navy is turning to artificial intelligence to help its submariners detect enemy vessels in a growing sea of underwater sounds.
The Navy’s acoustic recognition and interpretation center CIRA in Toulon is working with French startup Preligens on AI-powered analysis of underwater acoustic signals, the center’s head, Vincent Magnan, said in a presentation here Thursday. France expects to test the technology onboard its submarines by the end of the year, with operational deployment scheduled for 2025.
As France equips more and more vessels with increasingly powerful passive acoustic sensors, the amount of data collected for analysis is growing exponentially. The Navy is counting on AI to help its acoustics analysts, nicknamed “golden ears,” cut through the noise, both at the Toulon center and on board its submarines.
More sensors and greater detection ranges will result in “a massive flow of data,” Magnan said. “To be able to analyze all this data, and especially to be able to isolate from it the useful and decisive information for the conduct of our combat operations, we need to resort to technological innovations, including artificial intelligence.”
In addition to submarines, frigates and aircraft fitted with passive sensors, the near future will bring drones and underwater gliders that capture acoustic data, according to Magnan. The amount of such data gathered by CIRA has increased to around 10 terabytes in 2024 from 1 terabyte in 2020, and is expected to approach 100 terabytes or more by 2030.
Interest in “passive acoustic warfare” is growing because it allows surface vessels and submarines to detect underwater sounds during operations at sea and derive tactical elements in “all discretion,” without an adversary knowing about it, Magnan said. A particular propulsion pattern might allow the Navy to define a target’s speed, which can then in turn determine a tactical maneuver.
The Toulon center is using AI to filter out those acoustic signals of interest, after which humans can carry out high-value added analysis. The goal will be broadly similar at sea, with AI allowing human operators to focus on the useful signals.
“So we use technology to discard or filter the standard part of the signal, the almost useless part, and we rely on humans to exploit the useful part,” Magnan said.
Sifting through 12 days of acoustic data recorded in the waters off Toulon takes two “golden ears” more than 40 working days, Magnan said. With the AI demonstrator from Preligens, extracting useful signals from those same recordings can be done in 4 to 5 hours, with an additional five to six days of human analysis. “So you can already see that the gain is enormous”
Whereas in the 1990s and 2000s CIRA analyzed acoustic recordings of around 5 minutes targeted at a particular threat, the center now deals with data stretching over forty-day periods that requires “a great deal of human capacity” to process, according to the head of the center.
In the early 2000s, a sonar operator could see around 20 kilometers and would monitor 10 simultaneous acoustic contacts, by 2020 that had increased to more than 200 kilometers and a hundred tracks, Magnan said. France’s third-generation ballistic missile submarines will have even greater sensor capabilities, creating a real need to ease the detection task, the commander said.
France currently operates four Le Triomphant-class nuclear-powered ballistic missile submarines and is in the process of replacing its Rubis-class nuclear-powered attack submarines with six Suffren-class vessels.
The AI model has shown “very encouraging results,” able to distinguish hobbyist boats from commercial vessels, and identify propeller speed, propulsion systems and even the number of propeller blades, according to Magnan. A future step will be combining the AI models applied to acoustics with other sources of information, including satellite, radar, visual and electromagnetic.
The team working on acoustics detection has created a tool to automatically detect and identify various acoustic sources and sound emissions that will be demonstrated at the Viva Technology show in Paris next week, said Julian Le Deunf, an expert at the Armed Forces Ministry’s newly created agency for AI in defense.
“The promising results over these last few months also encourage us to test all these capabilities in real-life conditions, so to take the jump onboard the submarine and test these models directly at sea,” Le Deunf said. “The goal for the end of the year is really to succeed in plugging the model directly behind an audio stream, behind a sensor.”
The AI project has been running at CIRA since 2021, after Magnan met with Preligens executives in October of that year. French military intelligence was already using the company’s AI products to analyze satellite imagery, and Magnan said his discussions with Preligens led to the idea that the model could be replicated to make sense of underwater signals.
Eventually, the AI algorithms will be able to identify ambient noises such as a pump starting up or a wrench falling in a hold, according to Magnan.
“The idea in the long run is obviously to find models that are effective and efficient over the whole acoustic spectrum of the sources we encounter at sea,” he said. (Source: Defense News)

 

17 May 24. Cyber Update Key points.
• A new malware campaign has underscored the elevated cryptocurrency-theft risks facing financial firms (see Sibylline Cyber Daily Analytical Update – 13 May 2024).
• The ransomware group ‘Black Basta’ targeted US critical national infrastructure (CNI), highlighting elevated security and disruption risks (see Sibylline Cyber Daily Analytical Update – 14 May 2024).
• Cyber criminal groups exploited a new vulnerability to deploy the ‘QakBot’ malware, underscoring increased security and financial risks facing global firms (see Sibylline Cyber Daily Analytical Update – 15 May 2024 and our Technical analysis below).
• The emergence of new backdoors highlights security and espionage risks stemming from the Russian state-sponsored group ‘Turla’ (see Sibylline Cyber Daily Analytical Update – 16 May 2024 and our Technical analysis below).
• A new campaign targeting artificial intelligence (AI) experts has accentuated the information-theft risks facing technology firms (see Sibylline Cyber Daily Analytical Update – 17 May 2024).
Technical analysis of weekly stories
The Russian state-sponsored group ‘Turla’ is using two new backdoors, ‘LunarMail’ and ‘LunarWeb’, in an espionage campaign targeting an unnamed European ministry of foreign affairs and its diplomatic missions in the Middle East. It is likely that the threat actors exploited misconfigured networks and used spear phishing techniques to install the malware on the victims’ systems. In order to distribute LunarMail, Turla masked a DOCX file as a DOC file to hide malicious content and used native tools to decrypt the malicious payload. Additionally, the malware is installed as an Outlook add-in to communicate with (and exfiltrate information to) actor-controlled servers while disguised as an email. Conversely, LunarWeb conducts several security checks when first downloaded onto a victim’s system, self-deleting itself if any of these checks fail. Furthermore, the malware impersonates legitimate traffic to communicate with the threat actor’s command and control (C2) infrastructure. These methods underscore threat actors’ continuous development of sophisticated evasion techniques to achieve prolonged obfuscation and persistence within targeted networks. Both backdoors collect system information in different stages, starting with the collection of environment variables and email recipients.
A newly disclosed zero-day vulnerability (CVE-2024-30051) is being exploited in a new financially motivated campaign to deliver the ‘QakBot’ malware. The vulnerability affects the Desktop Windows Manager (DWM) service and can only be exploited after initial compromise. Threat actors can exploit this vulnerability in a heap-based buffer overflow attack, whereby they corrupt and overwrite portions of a system’s memory. This enables them to escalate their privileges, offering them the ability to move laterally within the compromised system, to execute malicious code and to access sensitive information. In their most recent campaign in April, threat actors deployed the Qakbot malware to steal credentials, website cookies and credit card details so as to garner illicit profit. The rapid integration of the vulnerability into QakBot’s arsenal points to the importance of timely updates and vigilance as actors quickly advance their tactics, techniques and procedures (TTPs).
Some non-exhaustive recommendations to mitigate against these threats include:.
• Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing and other types of social engineering attempts.
• Apply patches to software vulnerabilities as soon as they are released to prevent exploitation.
• Enforce strict and timely patch-management policies and ensure adequate software configuration.
• Monitor devices and networks for suspicious activity.
• Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
• Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions.
Our cyber word(s) of the week: X-as-a-service (XaaS) (Source: Sibylline)

 

17 May 24. US: New campaign points to accentuated information-theft risks facing technology firms. On 16 May, the cyber security company Proofpoint released a report on a new information-theft campaign targeting ten US-based artificial intelligence (AI) experts. The campaign starts with an AI-themed phishing email that tricks potential victims into downloading a remote access trojan (RAT) called ‘SugarGh0st’. The malware is reportedly a custom version of ‘Gh0st RAT’. It is therefore likely that a Chinese threat actor is behind the campaign. SugarGh0st notably contains new functionalities for reconnaissance, data exfiltration, lateral movement and code execution, highlighting the continuous development and sophistication of threat actors’ tactics, techniques, and procedures (TTPs). Conversely, the similarities between SugarGh0st and Gh0st RAT, such as offline keylogging, suggest that the campaign likely aims to steal secretive data on generative AI. As the theft of intellectual property is a prominent way for Chinese-affiliated actors to bolster China’s economic posture and technological advancements, we assess that this campaign underscores the accentuated information-theft risks facing technology firms in the long term. (Source: Sibylline)
——————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Spectra Group (UK) Ltd
Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.
With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.
Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.
In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.
Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.
Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.
———————————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

May 17, 2024 by

 

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

——————————————————————————————————————————————————————————————————————————————————————————————————————————————-

16 May 24. USSOCOM seeks new mounted, dismounted EW capabilities. US Special Operations Command’s (USSOCOM’s) electronic warfare (EW) Family of Systems (FoS) is the “newest” programme in the Program Executive Office (PEO) – SOF Warrior portfolio and was initially approved in November 2023 to focus on the “ground domain” operations, the command announced on 7 May.

SOF Warrior documents stated the EW FoS will include “dismounted/body-worn; mounted; unattended sensor; and small unmanned payloads to enable electromagnetic surveillance (ES), electromagnetic attack (EA), and electromagnetic protection (EP) capabilities”. The documents were presented at Special Operations Forces (SOF) Week 2024 in Tampa, Florida.

Officials suggested aspects of EP would be “pertinent” to countering unmanned aircraft systems as well as electromagnetic countermeasures (ECM). Other areas of interest include jamming-resilient radar capabilities. (Source: Janes)

 

16 May 24. Strong Connections. In the early 2000s a certain Japanese car manufacturer made a very memorable commercial. The advert featured a myriad of components from the vehicle the company was promoting. Like a line of dominos, one part collided into the next in a beautifully choreographed ballet of automotive components. The whole three-minute commercial was akin to an art installation; effortless, elegant and intelligent. Bizarrely, your editor was reminded of the advert in the wake of Iran’s 13th April missile and Uninhabited Aerial Vehicle (UAV) attack on Israel.

The Islamic Republic unleashed 170 UAVs, 30 cruise missiles and 120 ballistic missiles from sites in Iran, Iraq, Lebanon and Yemen. Despite the formidable number of projectiles, Iran’s attack faced formidable opposition. The Israelis are no strangers to shooting bad stuff out of the skies, with their David’s Sling and Arrow-3 surface-to-air missiles doing their thing with aplomb. Meanwhile, Israel’s American, British, French and Jordanian allies got stuck in providing radar coverage and added kinetics. The result was a resounding defeat for Tehran with the vast majority of incoming missiles and UAVs neutralised. Mercifully, casualties were relatively light with one person critically hurt, some slight damage to an Israeli airbase and others treated for minor injuries.

The success of Israel and her allies would have been impossible without the robust and capable communications which knitted together the sensors and effectors engaging the Iranian attack. The response underscored just how vital survivable and secure links are to countering such strikes. After all, as the strap line to the car commercial said: “Isn’t it nice when things just work?” (Source: Armada)

 

14 May 24. Talking to the Banshee. A new British Army capability is providing cellular connectivity on the battlefield for voice and data traffic, along with conventional communications backhaul, all via a single system. Armada has learned more details about the British Army’s Fenix Banshee BTR backpack tactical communications system. According to the radio’s manufacturers the Banshee BTR provides a bubble of Long Term Evolution (LTE) cellular communications coverage across a specific area. The radio provides LTE frequencies across a waveband of 700 megahertz/MHz to 3.7 gigahertz/GHz. Mobile Ad Hoc Networking (MANET) backhaul frequencies from one to six gigahertz are also provided. Armada was told that the Banshee BTR can host up to 120 subscribers at any one time. The backpack weighs 9.4 kilograms (20.8 pounds) including the radio’s batteries.

The company’s own literature says that the Banshee BTR offers download speeds of 300 megabits-per-second/mbps and 100mbps upload speeds. The system has AES 128 level encryption and can use encryptors meeting the US National Security Agency’s Type-1 standard. Coverage of circa one kilometre (0.6 miles) is provided by the Banshee BTR. Ranges can be extended to seven kilometres (4.4 miles) when using the vehicle-mounted Banshee BMR. The Banshee BMR hosts up to 800 subscribers and has 20 watts of transmission power, compared to the one-watt output of the Banshee BTR.

Armada was told by British Army sources that the Banshee BTR’s range can extend to five kilometres (3.1 miles) if the radio is elevated on a vantage point. The system can be made ready for use in under eight minutes. Troops can bring their own end user devices like smartphones or tablets which can send and receive traffic across the Banshee BTR’s LTE network. All that is required is for these devices to have an appropriate Subscriber Identity Module (SIM) card.

Preserving discretion

The Banshee BTR brings several key benefits vis-a-vis battlefield communications: By using a secure cellular service voice and data traffic with lower, or zero, levels of classification can be moved off conventional tactical networks. This frees up addition space on these latter networks. Conventional tactical links tend to always be in demand and are invariably operating at, or close to, their limits.

The Banshee BTR also helps shield traffic from electronic attack. The LTE network established by the radio can be given an innocuous name to make it sound like a standard, generic civilian cellphone service. Thus, this network’s purpose might not be immediately obvious to red force communications intelligence cadres. As the Banshee BTR provides MANET backhaul, traffic needing to be shared with recipients beyond the radio’s range can be easily moved onto conventional ultra-high frequency trunk links.

The British Army trialled the Banshee BTR at the force’s 2022-2023 Urban Series Warfighting Experiment that was hosted by the Royal Navy in Portsmouth on the south coast of England. Army tactical communications modernisation initiatives have had their share of difficulties. Nonetheless, the Banshee BTR is a capable system and a good example of the force procuring useful capabilities to enhance connectivity. Moreover, the embrace of cellular technology makes the Banshee BTR’s networks easy to access and use while helping to safeguard battlefield communications integrity. (Source: Armada)

 

15 May 24. Cleansing the Skies. A new report details the communications challenges faced by the British Army as the force looks to enhance and overhaul its ground-based air defence capabilities.

Mid-April saw the publication of a report by the Royal United Services Institute (RUSI) entitled Requirements for the Command and Control of the UK’s Ground-Based Air Defence. RUSI is a thinktank based in London and the report was authored by researchers Dr. Jack Watling and Dr. Sidharth Kaushal. The publication examined Command and Control (C2) requirements for the British Army’s Ground-Based Air Defences (GBAD): “The future threat environment is … characterised by diversifying and converging threat systems,” warned the authors. These diversifying and converging threats include everything from ballistic missiles to uninhabited aerial vehicles. This multiplicity of dangers means that “future air defences must be designed to maximise their efficiency as a system, allocating appropriate interceptors against simultaneous, multiple threats.” The authors assert that “(t)he challenge is how to establish a robust, layered air defence capability that can identify, classify and assign the most appropriate defeat mechanism to complex salvos.”

Data centrality

It is axiomatic that agile, robust and configurable communications underpin GBAD C2 system. These links carry track data from a multiplicity of sensors including radars and acoustic devices. Sensors could also include civilian capabilities like air traffic control radar. Track data in turn helps develop rich Recognised Air Pictures (RAPs) to assist air defenders. The Army will need links which can share its RAP outwards with allies when fighting in a coalition context and vice versa. The authors continue that the Army’s GBAD C2 architecture might need to share relevant data with UK authorities involved in civil defence such as the emergency services. This requirement is particularly relevant when Army GBAD is deployed to help protect targets in the United Kingdom.

Drs. Watling and Kaushal sound a note of caution regarding data sharing: “Whether … track data can be passed from the forward sensor and refined sufficiently to provide a guidance solution is dependent upon latency and on the compatibility of data between systems.” In a nutshell, it is good to have data, but if those data cannot be easily shared for reasons of compatibility or available links, then its utility diminishes.

Capabilities

Looking towards the design of any future British Army GBAD C2 architecture, the authors recommend communications links which can translate disparate data arriving from within and beyond the force. Likewise, this data must be moved at pace within and beyond GBAD formations. One potential solution mooted by the authors include middleware equipped with layered link translators that effectors and sensors can easily plug into. Moreover, the need to move data is directly dependent on overcoming differing national classification levels. The authors warn that “(a)ny system will also need mechanisms for moving data across classifications within the joint force.”

Solutions proposed by Drs. Watling and Kaushal include “a software-defined system that can incorporate multiple waveform cards at a central node.” Equally, data could be “routed to a common node via third-party platforms that receive and retransmit waveforms.” Conversely, other potential solutions include “(s)oftware-defined signal processing” which could allow “a system to receive data across multiple waveforms without a requirement for an unmanageable number of waveform cards.”

Securing the C2

Ultimately, “(t)o achieve the requisite efficiency, the C2 architecture for British GBAD must be able to distribute track-quality data to a diverse array of organic/inorganic systems and joint/combined assets.” The British Army is currently overhauling its ground-based air defence posture via the Land GBAD initiative. Almost $2 billion has been allocated to this programme. Nonetheless, the authors warn that “realising the programme’s goals will depend on having an open-architecture C2 capability that can integrate the increasing numbers and types of sensors that are proliferating across the battlefield.” (Source: Armada)

 

15 May 24. Band on the Run. The introduction of in-band full duplex techniques could help to reduce the spectrum congestion caused by tactical radios on the battlefield, while potentially enabling transceivers to perform addition, simultaneous missions such as electronic attack and electronic support.

In-band full duplex radio communications is a potentially game-changing technology enabling simultaneous voice and data transmission and reception, and electronic warfare applications, using the same frequency and transceiver.

PLATH’s annual intelligence workshop is always a useful opportunity to explore interesting innovations in the military communications and Electronic Warfare (EW) domains. This year’s event was held on 13th May in the town of Lillestrøm, southeast Norway. The workshop included a presentation by Professor Taneli Riihonen from Tampere University, southwest Finland. Prof. Riihonen’s presentation explained In-Band Full Duplex (IBFD) radio to delegates; an area of expertise for him and his colleagues.

IBFD Defined

Most tactical radios are half-duplex meaning that one person can transmit (Tx) but occupies a specific frequency, waveband or channel while they do so which means that the traffic can only move in one direction at a time. The receiver (Rx) must wait to obtain the traffic, be that voice or data, before they can transmit a response. Full duplex communications can move traffic in both directions simultaneously. Full duplex communications use one channel or frequency for Radio A to transmit to Radio B, and a different channel or frequency for Radio B to transmit to Radio A, for example. This approach means that a certain amount of radio bandwidth is needed to facilitate full duplex communications. Spectrum is an increasingly precious and finite commodity on and off the battlefield. Anything that can be done to reduce radio spectrum occupancy can only be beneficial.

Prof. Riihonen says that IBFD takes a different approach: The same frequency or channel can be used for the simultaneous transmission and reception of traffic. How is this achieved? The main challenge, Prof. Riihonen notes, is avoiding self-interference within the radio, primarily by preventing the Tx signal from leaking into the receiver. The problem is that the comparatively high power of the outgoing Tx signal risks ‘washing out’ the lower power incoming Rx signal. This phenomenon is akin to “trying to listen to someone whispering while someone is shouting at you.” Prof. Riihonen said that self-interference levels can reach up to 150 decibels in signal strength. The approach taken by Prof. Riihonen and his colleagues is hardware-specific, chiefly to isolate the Tx and Rx chains from one another using analogue and digital cancellers as one part of this approach. Resonators on the radio’s antennas also help reduce self-interference.

As well as offering benefits from a communications perspective, Prof. Riihonen highlighted that IBFD could be employed for EW. An Rx channel could receive traffic while a Tx channel transmits a jamming signal. Likewise, the Rx function could assist Signals Intelligence (SIGINT) gathering while the Tx function is sending traffic. This approach could put a combined EW and communications system using a single architecture and hardware into the hands of the operator. Several other capabilities were touted by Prof. Riihonen exploiting the IBFD approach including “two-way tactical radio links moving simultaneously between two or more networks, self-organising radio networks, real-time spectrum sensing, network jamming detection and uninhabited aerial vehicle swarm detection.”

Demonstrations

Prof. Riihonen said the IBFD technology has already been demonstrated to the North Atlantic Treaty Organisation’s Science and Technology Organisation. The demonstration saw IBFD radio architectures being used for simultaneous electronic support and electronic attack. The radios used frequencies of 225 megahertz/MHz to 400MHz and transmitted 100 watts of spot jamming power. Although the hardware in this demonstration was used to demonstrate EW acumen, Prof. Riihonen said that the same architectures can be employed for two-way communications.

Into the hands of the operator

Prof. Riihonen asserts that IBFD is now mature enough for civilian and commercial applications and expects the adoption of the technology from the early 2030s onwards. He anticipates that IBFD will be supporting the 3rd Generation Partnership Project (3GPP). 3GPP initiative brings together several standards organisations involved in cellular communications protocol development. Other applications include IBFD incorporation into the long-term evolution of fifth-generation (5G) cellular protocols, and IBFD’s inclusion as standard in future 6G cellular communications.

The technology could be made available to the military in a similar 2030 timeframe but will require the creation of a new generation of software-defined radios. Prof. Riihonen added that IBFD protocols can work comfortably with frequency hopping techniques. Nonetheless, tactical radios are increasingly adopting MIMO (Multiple-In/Multiple-Out) techniques. MIMO transmits traffic simultaneously across several different frequencies and wavebands. The goal of MIMO is to avoid signal disruption through phenomenon like multipath interference. Multipath interference can corrupt signals and the traffic they carry as signals collide with solid surfaces; a notable problem in built-up urban environments. Prof. Riihonen said that, while it can be difficult to get IBFD to work with MIMO protocols, it is not impossible. He also expects in-band full duplex techniques to be used as standard in future cognitive radio architectures. IBFD looks destined to equip both the civilian and military worlds in the coming years. “The academic research has been completed,” Prof. Riihonen says, “it is now time to transition the technology to a commercial environment in partnership with industry.” (Source: Armada)

 

16 May 24. May Radio Roundup. Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.

FMC300 helps SDR Upgradability

Abaco Systems has shared details regarding their FMC300 wideband, low latency FMC (Field Programmable Gate Array Mezzanine Card) module. “The FMC300 brings Analog Devices’ AD9084 multi-channel wideband radio frequency analogue-to-digital converters and digital-to-analogue converters into a FMC module designed to VITA 57.4 open standards,” Dinesh Jain, a senior product manager at Abaco Systems, tells Armada. “Most military radio hardware is designed for modularity to allow for future SDR (Software Defined Radio) upgradeability,” says Mr. Jain. One of the most common methods to achieve this SDR upgradeability “is through the industry-standard FMC connector.” The company’s FMC300 module can be installed into existing radio hardware. The module can also be installed into new systems using low-latency processing carriers such as Abaco’s SOSA (Sensor Open Systems Architecture) aligned 3U VPX VP891 Xilinx FPGA (Field Programmable Gate Array) board. Mr. Jain says that the FMC300’s seven gigahertz “wideband characteristics” mean that a single multi-band radio based on the FMC300 can replace multiple single-band transceivers. This helps reduce system complexity, footprint, maintenance, power consumption and weight. “Rather than having to support multiple, different RF modules operators can select the FMC300 and load the appropriate software and firmware to support a particular mission.” This approach reduces overall support and training costs, and allows for design reuse. “The FMC300 is available now and it is currently being designed into several different programmes including SDR and other applications,” says Mr. Jain.

Herrick Technology Laboratories provide a range of signals intelligence, electronic warfare and military communications systems to US government and allied customers.

Herrick Moves Forward

On 10th April Herrick Technology Laboratories (HTL) announced it had received an investment of $25 million from Blue Delta Capital Partners. A press release announcing the news said HTL “designs and manufactures integrated hardware and software products and systems implemented through a core Software Defined Radio (SDR) platform. The SDR platform incorporates high performance, multi-channel radio frequency and microwave receive and transmit functionality along with mission-specific firmware/software applications.” The $25 million investment “allows us to accelerate fielding the cutting-edge signals intelligence and electronic warfare products and solutions that we provide to US government defence and intelligence customers, as well as our nation’s allies.” Acie Vickers, HTL’s chief executive and co-founder, told Armada that the funding will also assist the development of “our next generation of high performance, low SWAPC (Size, Weight and Power Consumption) software defined radios along with processing improvements against sophisticated signals.” These capabilities will be made available from this year onward, Mr. Vickers continued.

DOCK StreamCaster Debuts

Silvus Technologies has joined forces with Kägwerks to develop the DOCK StreamCaster family of tactical networking systems Silvus Technologies announced in a press release published on 16th April. The DOCK StreamCaster is a soldier-worn tactical networking system. DOCK stands for Dismounted Operator’s Combat Kit. The press release continued that the DOCK StreamCaster combines Silvus Technologies’ StreamCaster MANET (Mobile Ad Hoc Networking) handheld radio with a Samsung S23TE militarised smartphone. The phone includes the ATAK (Android Team Awareness Kit) tactical situational awareness software application. ATAK was developed by the US Air Force’s research laboratory. The press release says that the DOCK StreamCaster combines the radio with Kägwerks’ DOCK dismounted soldier equipment. Silvus Technologies told Armada in statement that the first three DOCK StreamCaster models are now complete. Orders are being received. The two companies worked closely with a pilot customer in the US federal law enforcement community “to develop and refine the design of the DOCK StreamCaster.” The statement added that this pilot customer “has been operating a fleet of DOCKs in a hybrid network along with their existing StreamCaster radios, supporting tactical teams with both air and ground assets.” The ensemble has been tested in a range of environments from jungle to desert. Silvus Technologies is seeing a lot of customer interest in the product family, particularly “as a turnkey ground station” for uninhabited aerial vehicles using Silvus Technologies’ systems. (Source: Armada)

 

15 May 24. SANDF’s 22-year journey to modernise combat net radios. It’s taken 22 years for an upgrade of the SA National Defence Force’s (SANDF’s) combat net radio (CNR) systems, with SA Army brigade, division and formation commanding officers hearing upgraded radio communications have been tested by South African force elements in Democratic Republic of Congo (DRC).

The taking into service of improved and technologically updated combat net radios – as per Project Radiate – was imparted during a project outcome briefing with a view to force-wide implementation and utilisation in KwaZulu-Natal’s New Germany, where contractor Reutech Communications is headquartered.

The project started in 2002 with Reutech Communications and the SANDF Command and Management Information Systems (CMIS) Division jointly at the helm.

Christened a “work session” by Captain Lehutso Phahlamohlaka and starting on 7 May, the gathering concentrated on transitioning and implementing project outcomes as well as deployment and integration strategies. The five-day KwaZulu-Natal session followed baseline manufacturing targets being met, developmental operational testing and evaluation (OTE) successfully concluded, along with final OTE and ongoing training for operators and maintenance personnel.

Reporting on the briefing, Phahlamohlaka wrote it was a success paving the way for roll-out with the extra of active service evaluation by South African soldiers deployed to the United Nations (UN) mission in the DRC. Apart from being one of three troop contributing countries (TCCs) to the MONUSCO Force intervention Brigade (FIB), the SANDF contribution to the UN force consists of a quick reaction force (QRF), a tactical intelligence unit – all drawn from SA Army formations – and SA Air Force (SAAF) and SA Military Health Service (SAMHS) elements.

The first CNR units to be sent to the DRC formed part of extensive OTE with reports from the central African country indicating the radios performed well under “wet and nasty conditions”.

The new tactical radios allow for inter-service and division operability as specified in project documentation. The CNRs operate in HF, VHF and UHF frequencies with secure voice and data network links for ground to air, ground-based and naval applications. The new radios are reverse compatible with older still in service units.

Reutech’s landward radios are Link-ZA compatible and feature encryption, frequency hopping and fitted GPS receivers for situational awareness. The radios Reutech is supplying to the SANDF under Project Radiate were designed as a family from the outset for ease of use across all systems for logistics and human-machine interface functionality. Around 4 000 vehicle radios were ordered, with similar numbers of man portable radios. (Source: https://www.defenceweb.co.za/)

 

16 May 24. USSOCOM seeks new mounted, dismounted EW capabilities. US Special Operations Command’s (USSOCOM’s) electronic warfare (EW) Family of Systems (FoS) is the “newest” programme in the Program Executive Office (PEO) – SOF Warrior portfolio and was initially approved in November 2023 to focus on the “ground domain” operations, the command announced on 7 May. SOF Warrior documents stated the EW FoS will include “dismounted/body-worn; mounted; unattended sensor; and small unmanned payloads to enable electromagnetic surveillance (ES), electromagnetic attack (EA), and electromagnetic protection (EP) capabilities”. The documents were presented at Special Operations Forces (SOF) Week 2024 in Tampa, Florida. Officials suggested aspects of EP would be “pertinent” to countering unmanned aircraft systems as well as electromagnetic countermeasures (ECM). Other areas of interest include jamming-resilient radar capabilities. (Source: Janes)

 

15 May 24. CSignum Launches EM-2 Wireless Underwater Communications for Maritime Security, Water Quality Monitoring & Energy Applications.

CSignum, a leader in underwater and underground data networking, is proud to announce the launch of its latest innovation, the EM-2 wireless platform for IoT sensor data and control from above the surface to below. The EM-2 interfaces to many common underwater sensors to wirelessly communicate data from under the water to above the surface or directly on land.

EM-2 represents a breakthrough in wireless communication technology employing electromagnetic fields to pass data through water, ice, concrete, and rock to overcome the limitations of traditional wireless technologies. By harnessing electromagnetic field signaling (EMFS), data can be transmitted from below the water’s surface or underground to above-surface devices with unparalleled reliability.

EM-2 is a vital asset for the reliable transmission and retrieval of sensor data essential to monitor and protect resources and critical infrastructure across a variety of key sectors including:

  • Maritime Security & Defense: EM-2 offers a robust solution for enhancing maritime security by providing real-time data transmission from below the water’s surface to above-surface devices. This enables continuous monitoring of critical infrastructure such as ports and offshore structures, ensuring early detection and response to security threats.
  • Water Quality Monitoring: EM-2 revolutionizes water quality monitoring by facilitating wireless communication across the air-water boundary in both fresh and saltwater scenarios. It ensures reliable transmission of data from underwater sensors to above-surface devices, enabling timely assessment and management of environmental conditions in inland and coastal waterways, around offshore structures and aquaculture installations.
  • Offshore Wind & Energy Applications: EM-2 presents a game-changing solution for offshore energy applications by enabling seamless communication between subsea infrastructure and topside facilities. This enhances operational efficiency and safety in offshore energy operations, including wind farms and oil and gas platforms as well as inshore hydropower facilities.
  • Underground Applications: EM-2 extends its capabilities to underground applications, providing reliable data transmission through various layers, including buried structures. This makes it invaluable for monitoring and controlling underground infrastructure such as tunnels, storm drains, and underground utilities.

“EM-2 represents a quantum leap in underwater and underground communications technology,” said Jonathan Reeves, CEO at CSignum. “With its ability to transcend the barriers of traditional methods, EM-2 empowers industries to explore, monitor, and protect our waterways and subsea environments with unprecedented efficiency and reliability.”

EM-2 establishes a wireless communication link that transcends the limitations of acoustic, optical, and cabled underwater communications. It enables real-time data transmission from beneath the surface to shorelines or riverbanks, and even through ice or underground locations.

With bidirectional data transfers of up to 200 meters, EM-2 ensures successful deployment in both saltwater and freshwater environments. Its unique electromagnetic field-based communication method enables effective data transmission through mixed media scenarios.

Benefits of the EM-2 include:

  • Resilience: Unaffected by biofouling, turbidity, or environmental noise, ensuring consistent performance.
  • Flexibility: Easily integrated with various sensor packs and compatible with industry-standard data interfaces.
  • Environmental Compatibility: No adverse effects on aquatic life, making it ideal for sustainable monitoring solutions.
  • Diverse Environments: Operates through water, ice, rock and soil.

The versatility of EM-2 lends itself to diverse applications including Internet of Underwater Things, ship monitoring, offshore structural monitoring, inland and coastal environmental monitoring, underground data monitoring, and defense and security operations.

Monitoring and assessing ecological health are essential components in combating and mitigating problems in critical inland and coastal waterways. Remote sensing observations utilizing EM-2 provides rapid, accurate data to assess and act on ecosystem changes.

Traditional methods of underwater communication face numerous challenges, from cable entanglement and unreliable communications to signal degradation. EM-2 offers a reliable, cable-less alternative, providing flexibility in deployment and superior performance across various environmental conditions.

CSignum remains committed to advancing underwater and underground data transmission. Future plans include enhancing range, data rate, and battery life, while providing cellular/satellite backhaul and CSignum Cloud data analytical services.

For inquiries and further information, please visit www.csignum.com.

 

14 May 24. Global: New vulnerability underscores increased security, financial risks from cyber criminal groups. On 14 May, the cyber security company Kapersky reported that a zero-day vulnerability (CVE-2024-30051) in the Desktop Windows Manager (DWM) service was exploited during attacks delivering the ‘QakBot’ malware. The campaign has been ongoing since mid-April. The vulnerability allows threat actors to corrupt and overwrite portions of a system’s memory. This subsequently enables them to escalate their privileges to execute malicious code and to access sensitive information. Although QakBot’s infrastructure was dismantled by the FBI in August 2023, the malware resurfaced in December 2023 to target the hospitality sector, healthcare providers and government agencies. This underscores the threat actor’s ability to redevelop Qakbot and resume operations at speed. Several ransomware groups, including ‘Conti’ and ‘Black Basta’, have used QakBot as dropper malware in financially motivated operations, underscoring the increased security and financial risks facing global firms. Microsoft has released a patch for the vulnerability, pointing to the need for strict patch-management policies to prevent compromises in the long term. (Source: Sibylline)

 

10 May 24. Thales doubles down on radio production as US Army rethinks its network. “It’s not explosive, so don’t worry about it.”

Michael Sheehan was talking about fuzes embedded in the tube-launched, optically tracked, wireless-guided, or TOW, missile used for decades to blow up armor and fortifications.

“We build that here,” he said of the components resembling electronic rounds. “In the room over there.”

Sheehan is the chief executive of Thales Defense and Security Inc., a U.S. offshoot of the French Thales Group. The stateside company’s work spans air, land, and sea, including cockpit technologies, handheld communications gear, and sonar systems.

Its headquarters here in Maryland, some 40 minutes north by car of Washington, has long maintained a manufacturing capability to fulfill orders. Under the same roof where TOW fuzes are crafted are helmet displays for F-16, A-10 and helicopter pilots and the radios lugged around by troops.

A little less than half of the business TD&SI does is in the area of “tactical comms,” according to Sheehan. Standouts are Army leader and combat net radios, the latter of which the company is betting big on.

Where there was once only a single line for a mix of products there are now two, with one dedicated to the CNR endeavor. And portions of the facility are being rearranged or reworked for efficiency. The Army in 2022 tapped Thales and competitor L3Harris Technologies to furnish the radios to help phase out older gear and overhaul battlefield connectivity.

An initial order placed with Thales was valued at $18.2 m. The overarching indefinite delivery, indefinite quantity contract is worth billions more.

“They’re big numbers, and we were sort of at capacity,” Sheehan told C4ISRNET during an April visit. “We basically doubled our throughput, and we’re making more investments for that line.”

Order up

There was a thrum to the production floor. Pick-and-place machines chewed through reams of tiny components and, nearby, workers tinkered with larger pieces and parts. Headsets, battery packs, radios and more stood at varying levels of assembly. Some were moving through quality checks.

The additional line at the Clarksburg facility was established in late 2023 and has since undergone preparations for a large volume of orders. Combat net radios are slated to replace the older Single Channel Ground and Airborne Radio System, or SINCGARS, which Sheehan described as the “backbone for three, four decades of Army communications.”

Thales recently delivered a preliminary batch to the Army for inspection and testing, and the company is working with labs at Aberdeen Proving Ground to make sure “we are meeting the future needs of this program,” according to Gary Kidwell, the vice president of communications systems at TD&SI.

Aberdeen Proving Ground is home to both the Program Executive Office for Command, Control and Communications-Tactical and the Network Cross-Functional Team. PEO C3T described the CNR effort as supporting cryptographic modernization and the service’s unified network, where the tactical links of frontline troops meld with the larger, less-mobile systems used at headquarters.

“It’s not the SINCGARS radio of yesterday,” Kidwell told C4ISRNET. The new radios are software-defined, meaning updates can be quickly patched in and hardware poses fewer constraints on performance.

Thales has so far received orders for thousands of radios and expects demand for many thousands more in the coming years.

“You have a significant number of radios that, potentially, have to be replaced,” Kidwell said. “Knowing what those annual quantities look like, and even in a split, competitive market between us and L3Harris delivering capabilities, we stood up the second line.”

(An L3Harris executive, Samir Mehta, separately told C4ISRNET the company was moving in-step with the Army. Mehta described their effort as “on track,” “bullish” and considerate of lessons learned from the Russia-Ukraine war.)

Radio check

Updated connectivity has for years been a priority for the Army, alongside desires to overhaul long-range precision fires, air and missile defense, and aviation.

Army Chief of Staff Gen. Randy George last year declared the network his top priority, publicly elevating what has long been considered the backbone of the service’s modernization goals. Without the ability to talk, few other things work as promised.

“Soldiers need to shoot, move and communicate,” George said at the Association of the U.S. Army convention in October. “Technology should facilitate those fundamentals, not encumber them.”

“Antenna farms and endless server stacks are conspicuous and generate too much electromagnetic signature,” he added. “If we slog around the battlefield with massive operation centers, which are difficult to set up, and often contractor-supported, we will get pounded.”

Radios play a key role in the equation. The gear can range in size and weight and complexity, and demands among different formations can vary dramatically.

Portions of the 25th Infantry Division in Hawaii and the 82nd Airborne Division in North Carolina last year received tailored packages of radios, variable height antennas and the like known as the integrated tactical network.

Through in-the-field experiments, the goal was to see what worked and what didn’t, and how fighting styles influenced the answers. Island hopping and watercraft look vastly different than joint forcible entry and seized airfields. And Thales is preparing to satisfy soldiers’ asks, according to Kidwell.

“How can we merge commercial technologies with others to listen to the end user and give them what they’re asking for?” Kidwell said. “As you’ve heard the Army say, not every unit is going to fight the same way.”

(Source: Defense News Early Bird/Defense News)

 

13 May 24: MASS has launched THURBON CEMA, a new centralised cyber electromagnetic activity (CEMA) database management system that brings CEMA data together in one place to improve battlespace spectrum management.

THURBON CEMA is the first system of its kind, enabling users to manage CEMA data in land, air and maritime domains operating in multi-threat environments. This force multiplier will support the synchronisation and co-ordination of offensive, defensive, inform and enabling activities, across the electromagnetic environment and cyberspace.

Michael Swift, Business Development Director at MASS, said: “The EMS is constantly evolving, thanks to technological advances and the continued efforts of adversary forces. In this context, simplicity for operators is key and by reducing the reliance on multiple data sources and bringing all CEMA activity into one database, THURBON CEMA will enable quicker decision-making. Through our work with the UK Ministry of Defence (MoD) and other partners, MASS has led the way in electronic warfare (EW) and CEMA management and we’re delighted that THURBON CEMA is the next step in improving battlespace spectrum management.”

The upgraded database management system allows users to achieve information dominance with a single source of accurate, near real-time intelligence across the full EMS. THURBON CEMA takes advantage of new, richer multi-threat data to feed its common operating picture.

Designed and programmed by MASS EW and CEMA software development experts, THURBON CEMA includes a modern user interface to provide clear, accurate spectrum visualisation to inform and improve battlespace management.

THURBON CEMA is an upgraded version of MASS’ world-leading EW database management system, THURBON, which has been used and trusted by the UK MoD for over 10 years. To find about more about THURBON CEMA, visit https://mass.co.uk/.

 

10 May 24. Cyber Update key points.

  • A new campaign exploiting weak email security configurations highlights security and information-theft risks stemming from the North Korean group ‘Kimsuky’ (see Sibylline Cyber Daily Analytical Update – 7 May 2024 and our Technical analysis below).
  • The discovery of a major online shopping fraud network underscores the elevated reputational and financial risks facing businesses (see Sibylline Cyber Daily Analytical Update – 8 May 2024).
  • Influence operations targeting Israeli citizens point to the disinformation risks stemming from Iranian state-sponsored actors and our Technical analysis below).
  • A new phishing campaign targeting Polish government organisations underscores the sustained security and information-theft risks stemming from the Russian state-sponsored actor ‘APT28’ (see Sibylline Cyber Daily Analytical Update – 10 May 2024).

Technical analysis of weekly stories

Iranian state-sponsored groups are targeting Israeli citizens in a multi-pronged influence campaign called ‘Emerald Divide’. The campaign seeks to manipulate Israeli citizens so as to exacerbate existing ideological and political divisions. For instance, it aims to amplify divisions between Israel’s ultra-Orthodox religious groups and the LGBTQI+ community, as well as the far-left and -right ends of the political spectrum. We also assess that it strives to sow discontent regarding the Israeli government’s response to Hamas’ 7 October 2023 attack. The threat actors use several social media platforms and fake online personas to incite debate and to propagate content. Notably, they have increased their use of artificial intelligence (AI)-generated deepfakes to drive engagement and to boost the effectiveness of the campaign; they often impersonate figures on both sides of the debate, engaging in fraudulent conversations online to galvanise audiences. In some cases, the campaign has been successful in prompting citizens to participate in anti-government protests, underscoring the real-life consequences of influence operations. The Israel-Hamas war-focused iteration of the campaign has also managed to harvest personally identifiable informa(Source: Google/

tion (PII) to dox Israeli officials. Emerald Divide has demonstrated how state-sponsored influence operations can dynamically shift objectives to reflect the changing political landscape; this highlights the ongoing disinformation threats influence operations pose to governments.

The North-Korean threat group ‘Kimsuky’ is exploiting weak domain-based message authentication, reporting and conformance (DMARC) configurations as part of a new spear phishing campaign. In this campaign, Kimsuky has exploited organisations’ misconfigured DMARC settings; this has enabled the group to reach targets with tailored phishing messages. The group specifically spoofs email domains to impersonate journalists and trusted individuals from think tanks, academia and government organisations; this has enabled Kimsuky to build rapports with their victims, thereby effectively infiltrating targeted organisations. Subsequently, Kimsuky has taken advantage of being able to access these organisations to send additional spear phishing emails from the organisations’ legitimate domains. The highly tailored and detailed nature of the emails sent by the group further highlight the growing sophistication and adaptability of the group’s tactics, techniques and procedures (TTPs).

Some non-exhaustive recommendations to mitigate against these threats include:

  • Ensure organisational DMARC policies are configured to quarantine unauthenticated messages.
  • Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing and other types of social engineering attempts.
  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions.

Our cyber word(s) of the week: Domain-based message authentication, reporting and conformance (DMARC)

(Source: Sibylline)

 

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Spectra Group (UK) Ltd

 

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

——————————————————————————————————————————————————————————————————————————————————————————————————————————————–

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

May 10, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

——————————————————————————————————————————————————————————————————————————————————————————————————————————————

09 May 24. General Atomics Aeronautical Systems, Inc. (GA-ASI) is working with the U.S. Special Operations Command (USSOCOM) to develop a new Airborne Battlespace Awareness and Defense (ABAD) capability. The new ABAD pod is being developed for the GA-ASI-supplied MQ-9A Block 5 Medium-Altitude, Long-Endurance Tactical (MALET) Extended Range Remotely Piloted Aircraft (RPA) being operated by the U.S. Air Force Special Operations Command (AFSOC). ABAD will provide detection and protection against Radio Frequency (RF) and Infrared (IR) threats.

“Threat awareness and survivability are critical for MQ-9A to operate in contested environments,” said GA-ASI President David R. Alexander. “ABAD will enable the tracking of RF and IR missile threats, enable defensive measures, and real-time threat awareness for MQ-9A.”

The first phase of contract work evaluated suitable RF Electronic Warfare (EW) and IR countermeasures systems. This led to the down selection of a next-generation software-defined radio-based EW system from BAE Systems and the AN/AAQ-45 Distributed Aperture Infrared Countermeasure System (DAIRCM) from Leonardo DRS.

“BAE Systems’ advancements in small form factor EW technologies will provide affordable multifunction capabilities for the MQ-9A, enabling it to operate in previously inaccessible airspace,” said Joshua Niedzwiecki, vice president and general manager of Electronic Combat Solutions at BAE Systems.

“Leonardo DRS is delighted to team with GA-ASI to provide our industry-leading and proven AN/AAQ-45 DAIRCM aircraft protection system to enhance MQ-9A survivability in support of this mission for USSOCOM,” said DRS Vice President of the DAIRCM Program, David Snodgrass.

Work is underway on an engineering and test effort to mature the capability as a podded payload capable of operation on the MQ-9A aircraft in 2025.

 

09 May 24. Kromek, the designer and manufacturer of radiological and biological detectors, based in Sedgefield Co. Durham, today launches its new generation RayMon detector. This is a high-performance handheld spectrometer with a set of interchangeable probes: CZT, NaI and Alpha Beta. It is ideal for protecting critical national infrastructure such as nuclear power stations or military installations and for security screening, civil defence, homeland security or peace keeping/peace support operations. It is portable, easy to deploy and can undertake previously-lab-based spectral analysis directly in the field with speed and precision.

The new generation RayMon has a built-in library of 94 radionuclides, to which custom nuclides can be added. Key information such as dose rate and counts per second can be viewed on the Dose Screen in real-time. In Search Mode, the clear visual graphs indicate when count rate is increasing or decreasing, directing the user to the location of the source. All reports and data files on the RayMon can either be exported onto a USB or shared via email.

Enhancing the RayMon’s capabilities are three additional probes: a high resolution CZT probe, a high sensitivity NaI (sodium iodide) smart probe and an Alpha Beta smart probe.

The CZT probe provides precise identification of radionuclides, even when faced with mixed or shielded sources.  With its small form factor, operation at room temperature without the need for cooling, and direct conversion, the CZT Probe is a cost-effective and user-friendly alternative to HPGe detectors. Its small form factor alleviates the difficulty of taking measurements in hard-to-reach areas.

The NaI probe is designed for collecting count data in low-dose environments. The high sensitivity and efficiency of the 2” x 2” Sodium Iodide (NaI) crystal ensures even the weakest sources can be detected. Taking measurements in narrow areas is facilitated by the incorporation of silicon photomultiplier technology into Probe, giving the device its small form factor. The probe also includes a high dose sensor to ensure that measurements continue to be taken when the NaI probe becomes saturated with counts.

The Alpha Beta probe transfers Alpha or Beta count data onto the RayMon screen but can also store detector and calibration information itself. Its small size and lightweight build means the device can be used comfortably in one hand, with the RayMon in the other, for extended amounts of time.

Ahead of the launch of the new generation RayMon,  Craig Duff, Kromek’s Commercial Director of Radiation and Nuclear Products, said: “The new generation RayMon is the most advanced detector designed specifically for the protection of critical national infrastructure. It is a product of the innovation of our in-house scientists and engineers who are able to respond quickly to meet new customer requirements.”

The new generation RayMon will make its public debut next week, alongside the full suite of Kromek’s handheld detectors, at the Society for Radiological Protection’s annual conference in Eastbourne between 14-16 May.

 

09 May 24. Iran’s Avtobazas. Last month, Armada published an article about what maybe an Iranian version of Russia’s 1RL257E Krasukha-4 ground-based Electronic Warfare (EW) system.

Information has since surfaced on social media disclosing that Tehran recently deployed Russian-supplied IL222M Avtobaza-M ground-based signals intelligence systems. Reports state that Iran may have received its first 1L222M examples in 2011. The kit was rumoured to have been involved in the Islamic Republic’s downing of a Lockheed Martin RQ-170 Sentinel Uninhabited Aerial Vehicle (UAV). The Central Intelligence Agency UAV was brought down in Iranian territory on 4th December 2011.

Avtobaza-M is designed to collect signals intelligence to support air defence by detecting, locating and identifying air threats via their electromagnetic emissions. Russian military documents seen by Armada say the IL222M detects and processes emissions on a 200 megahertz/MHz to 18 gigahertz/GHz waveband. Avtobaza-M will detect and process signals from Identification Friend or Foe (IFF) transponders equipping aircraft. These transponders usually squawk across wavebands of between one gigahertz/GHz to 1.21GHz. Aircraft Tactical Air Navigation (TACAN) emissions from 962MHz to 1.213MHz can be detected and processed by Avtobaza-M. Other key targets include emissions from Airborne Early Warning (AEW) aircraft. Specific targets include the Northrop Grumman AN/APY-1/2 S-band (2.3GHz to 2.5GHz/2.7GHz to 3.7GHz) and Lockheed Martin AN/APS-139 and AN/APS-145 very high frequency (400MHz to 450MHz) AEW radars equipping Boeing E-3 Sentry and Northrop Grumman E-2 Hawkeye series aircraft respectively.

The 1L222M detects signals with a minimum strength of -88 decibels-per-watt. Direction-finding of emitters of interest are determined with between 0.4- and one-degree of accuracy. The documents continue that targets can be determined at ranges of 81 nautical miles/nm (150 kilometres/km) to 108nm (200km). Avtobaza-M shares data on target azimuth and elevation angle, radar type (pulse-Doppler and/or continuous wave) and emission waveform. Up to 60 targets can be detected and processed by the system at any one time. Target detection is done using a rotating antenna making either six or twelve revolutions-per-minute. The IL222M consumes twelve kilowatts of electricity.

Architecture

The system’s architecture includes one information processing station, and four detection and direction-finding stations. The entire system is deployed on two vehicles, networking is facilitated with a two-way fibre optic link carrying data at a rate of 1.2 kilobits-per-second. Target information (target angle, azimuth and elevation) is displayed on the operator’s console. Other parameters like signal carrier frequency and pulse duration are also displayed. Avtobaza-M’s human-machine interface is highly customisable by the operator with particulars regarding taboo frequencies, and specific search sectors and/or off-limits areas easy to arrange. The system has a crew of four.

Concepts of operations

Air targets can be detected and processed via their emissions providing at bearing information relative to the system’s location. Once this information is determined, it can be shared with ground-based air defences to advice the latter on a target’s possible ingress vectors. Likewise, this data can be shared with fighter controllers to direct combat aircraft to perform interceptions. Given the IL222M’s range, one should consider it an ostensibly tactical and/or operational asset which supports battlefield air defence.

It is likely the Iranian military deploys the Avtobaza-M not only to support battlefield air defence but also to help protect strategic point targets. One key tactical consideration is that emissions control could hamper the system’s utility. Combat aircraft routinely go ‘electromagnetically dark’ when flying in contested airspace, although the 1L222M could help prosecute targets exhibiting lax radio discipline. Similarly, target coordinates derived by the equipment could assist the direction of electronic attack by systems like the Krasukha-4. The documents add that Avtobaza-M supports littoral operations by detecting line-of-sight emissions from naval surveillance radars.

On 13th April Iran mounted a large-scale attack on Israel involving circa 300 surface-to-surface ballistic and cruise missiles, and UAVs. According to the Israeli Ministry of Defence, 99 percent of these threats were engaged and destroyed by American, British, French, Israeli and Jordanian electronic and kinetic effects. This engagement was assisted with sensor and communications provision from these, and other unnamed, allied nations.

Systems like the 1L222M are important capabilities for Iran. As a force protection asset, they provide a means by which the Islamic Republic can protect key strategic targets from air-to-surface attack. Avtobaza-M can also be a useful force protection asset on the battlefield. Allied nations need to be cognisant of such capabilities and ensure that systems like 1L222M are high priority targets during any future showdown with the Islamic Republic. (Source: Armada)

 

09 May 24. May Spectrum SitRep.

Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.

New COMINT Consulting Capabilities

COMINT Consulting has shared with Armada what the company says is a first for the communications and signals intelligence market, specifically precision Linear Feedback Shift Register (LFSR) classification. LFSR is a complex mathematical procedure which in the communications and signals intelligence context allows the extraction of one or more polynomials. The company told Armada that these polynomials can be used to identify the encryption hardware and/or software maybe using. This process can be performed in real time. COMINT Consulting added that LFSR precision classification will be available with its Krypto500 analysis, classification and decoding software by the end of April. The Krypto500 software performs these tasks across wavebands of three kilohertz up to 30 megahertz.

Impressive Integrity

Shift5 announced the release of its new GPS Integrity Module on 23rd April. A company press release described the product as a “platform-agnostic solution applicable for military, aviation, rail, maritime, and space industries.” The module determines changes to navigational position “through multi-faceted anomaly detection methods.” The module helps alert users to GNSS (Global Navigation Satellite System) spoofing attacks as they occur. The GPS Integrity Module works by performing algorithmic position analysis to determine significant position deviations and “GPS (Global Positioning System) data validation to verify GPS information accuracy.” Should GNSS spoofing be determined, users are notified immediately. Egon Rinderer, Shift5’s chief technology officer, told Armada that GNSS jamming can be identified through advanced signal analysis, anomaly detection, cross-validation with alternative navigation sources, and geolocation analysis and timing verification. The GPS Integrity Module “utilises raw data generated by sensors and systems onboard platforms.” Mr. Rinderer added that Shift5 is currently deploying the GPS Integrity Module with an unnamed customer. (Source: Armada)

 

08 May 24. DSA 2024: Aselsan unveils radio relay system. Turkish company Aselsan has unveiled its latest radio relay system at the Defence Services Asia (DSA) 2024 exhibition held in Kuala Lumpur from 6 to 9 May.

The system, known as URAL, is an airborne software-defined radio relay operating in the very/ultra-high frequency (V/UHF) band.

URAL is designed for unmanned aerial vehicles (UAVs) and other airborne platforms for surveillance, reconnaissance, and mapping applications.

It utilises Aselsan’s advanced network waveform features to achieve the high throughput data rate.

The VHF and UHF bands are incorporated in a single unit to reduce the system’s size and weight to meet the low size, weight, and power (SWaP) requirement of UAVs. The company told Janes that older radio relays are available in single band only, either VHF or UHF frequency.

Aselsan’s representative did not disclose the modulation type, data rate, and the waveforms incorporated in the system at the time of publication.

(Source: Janes)

 

08 May 24. Today, General Atomics Aeronautical Systems, Inc. (GA-ASI) announced its partnership with Shift5 to integrate the company’s onboard cyber anomaly detection and predictive maintenance capabilities into the MQ-9A Reaper for the United States Special Operations Command (USSOCOM) and Air Force Special Operations Command (AFSOC). The GA-ASI and Shift5 partnership will assure AFSOC and SOCOM mission readiness and cyber survivability.

“GA-ASI has long maintained a focused commitment to unmanned combat operations and unmatched unmanned aircraft system (UAS) experience, exemplified through our MQ-9A Reaper,” said GA-ASI President David R. Alexander. “The next logical and immediate extension of our work in enabling the U.S. Air Force is empowering AFSOC and SOCOM with additional resiliency and survivability of the MQ-9A on the battlefield. Shift5 represents a new class of dual-use defense tech business that can successfully operate at speed and scale with us to make an immediate impact for the warfighter.”

The Shift5 Platform reveals critical operational and cybersecurity insights that enable operators to move from data to decisions quickly and confidently. The Shift5 Platform deploys on premises or in the cloud and supports streaming and air-gapped modes for offline and online capability.

“The battlefield of the future will include more remotely piloted, autonomous, and unmanned systems. Central to maintaining advantage in this operating environment is access to real-time data,” said Josh Lospinoso, CEO and co-founder of Shift5. “Our work with GA-ASI represents one of the most efficient and effective ways that AFSOC and SOCOM can gain access to critical operational and cybersecurity insights, democratize that data, and maintain decision dominance.”

Shift5 achieved its first cross-platform Authority to Operate (ATO) Certification from the U.S. Department of Defense (DoD) in April 2023, validating the resilience and security of the Shift5 Platform. Most recently, the company announced its contract with the U.S. Army to secure the High Mobility Artillery Rocket System (HIMARS) against cyber threats and provide readiness assessments to enable predictive maintenance. It also introduced the GPS Integrity Module, the first known cross-platform solution to automate detection and alerts to combat GPS spoofing risks.

 

08 May 24. US Army Successfully Demos GD’s Impact Mission Planning System.

  • Software designed to reduce pilot workload, improve situational awareness and sensor-to-shooter timelines, and reduce fratricide

The U.S. Army recently evaluated the Integrated Mission Planning and Airspace Control Tools (IMPACT) from General Dynamics Mission Systems at the National Training Center at Ft. Irwin and Camp Pendleton, Calif. as part of Project Convergence-Capstone 4, which is an annual Joint and Coalition large-scale experiment where the military tests its cutting-edge technologies under field-like conditions. Elements of the III Corps and XVIII Airborne Corps employed IMPACT for integrated mission planning and airspace control.

The focus of the evaluation was the collection of feedback from hands-on soldier usage of the IMPACT software at the flight company level for mission planning. Soldiers successfully used IMPACT, along with its ATAK plugin for the PEO-Soldier Air Warrior Tablet, to plan and evaluate a rotary wing mission, load that mission data onto a data transfer device, and use the device to load the mission onto a UH-60M helicopter.

“This pilot effort was the result of years of teamwork between the Army and its industry partners,” said Rachel Oberc, General Dynamics Mission Systems vice president for RF Systems. “To see the payoff of this trailblazing technology tested under real-world scenarios is extraordinary.”

The team also gathered critical feedback on the software and plan to use it for improving the software prior to its scheduled fielding date in two years. Soldiers also used IMPACT in several PEO Aviation experiments to provide command post data to the aircraft in flight, enabling emergent airspace usage (Artillery, EW, and UAS re-tasking) to be pushed to the aircraft, thus enabling dynamic replanning of the mission route.

“IMPACT is a key enabling tool to facilitate Joint All Domain Command and Control for Army aviation in Multi Domain Operations,” said Col. Burr H. Miller, Product Manager, Aviation Mission Systems and Architecture in PEO Aviation. “It provides capabilities for both the command post and mobile/handheld computing environments and converges the current mission planning capabilities of AMPS with the airspace control capabilities of TAIS into one role-based solution.”

Additionally, IMPACT was used to manage the airspace control picture for the event, disseminating such information digitally to the command post (including CPCE, AFATDS, and DARPA’s experimental ASTARTE software), and coordinating all airspace control requests for the Army and coalition partners from France and the United Kingdom. IMPACT was used to inform ASTARTE’s microservices to accelerate weapon/target pairing by predictive analysis of airspace and aircraft in flight. IMPACT also demonstrated a prototype integration of ASTARTE microservices into a standalone capability enhancement for aviation commander mission planning.

By utilizing a browser-based, fully 3-D web application, IMPACT ensured that all participants on the network could access and use the airspace control and mission planning functions. IMPACT’s role-based access ensured that individuals could login from any computer using their credentials and access their mission functions, maintaining established user preferences like bookmarks, units of measurement, and display states of layers. IMPACT’s focus on services and data made sure that external systems could leverage the detailed information maintained by its operators.

“As we continue to add and mature IMPACT capabilities, the result will be an integrated enterprise solution for both the enduring and future Army aviation fleets,” said Miller. “We are excited with what IMPACT is bringing to the fight and judging by the great feedback and acceptance from the Soldier-operators, so are they.” (Source: ASD Network)

 

07 May 24. DOD Support to National Security Memorandum 22. On April 30, the White House released National Security Memorandum (NSM)-22 on Critical Infrastructure, to secure and enhance the resilience of the 16 critical infrastructure sectors that provide essential services to the American people, to include the energy, communications, transportation, water, and Defense Industrial Base (DIB) services that DoD relies on to operate.

We know that the People’s Republic of China and Russia are actively targeting U.S. critical infrastructure to be poised to disrupt our society and interfere with DoD’s operations in a crisis. Extreme weather also increasingly poses a risk to our mission. Proactive steps by government and industry partners, as outlined in this NSM, are essential to ensure that our critical infrastructure can withstand and operate through disruption, no matter the cause.

DoD will continue to invest in capabilities like the Critical Infrastructure Defense Analytic Center and in civilian-military collaboration with federal, state, local, tribal, and territorial levels of government to manage risk to the critical infrastructure that support DoD missions. As the Sector Risk Management Agency for the DIB, DoD will leverage major Secretary of Defense-level initiatives like the DOD DIB Cyber Strategy and the National Defense Industrial Base Strategy. DoD will continue to support robust information exchanges and collaboration with industry, and we will continue to assess and manage risk to the DIB. We will develop a sector-wide risk management program, leveraging and aligning DoD wide efforts. Finally, we will support and leverage Cybersecurity and Infrastructure Security Agency (CISA) led cross-sector risk management, in coordination with other federal agencies, to address challenges in areas where DoD cannot effectively act alone.

DoD thanks industry partners in the National Defense Information Sharing and Analysis Center (ND-ISAC), and in the Sector Coordinating Council (SCC) who are key partners for this NSM’s implementation, and all of the components across DoD who are coming together to support and enable this NSM’s success.

DoD encourages all DIB companies to join the ND-ISAC, the SCC, and the DoD DIB Cybersecurity programs to receive assistance and support, and to be a part of this important effort. (Source: U.S. DoD)

 

07 May 24. Red Hat Announces Podman AI Lab. Red Hat, Inc., the world’s leading provider of open source solutions, today announced Podman AI Lab, an extension for Podman Desktop that gives developers the ability to build, test and run generative artificial intelligence (GenAI)-powered applications in containers using an intuitive, graphical interface on their local workstation. This contributes to the democratization of GenAI, and gives developers the benefits of convenience, simplicity and cost efficiency of their local developer experience while maintaining ownership and control over sensitive data.

The recent surge of GenAI and open source large language models (LLMs) has ushered in a new era of computing that relies heavily on the use of AI-enabled applications, and organizations are moving quickly to establish expertise, processes and tools to remain relevant. Industry analyst firm IDC notes this shift, predicting “By 2026, 40% of net-new applications will be intelligent apps, where developers incorporate AI to enhance existing experiences and form new use cases.”1

As AI and data science move into mainstream application development, tools like Podman AI Lab can help fuel developer adoption of GenAI for building intelligent applications or enhancing their workflow using AI-augmented development capabilities. AI Lab features a recipe catalog with sample applications that give developers a jump start on some of the more common use cases for LLMs, including:

– Chatbots that simulate human conversation, using AI to comprehend user inquiries and offer suitable responses. These capabilities are often used to augment applications that provide self-service customer support or virtual personal assistance.

– Text summarizers, which provide versatile capabilities across many applications and industries, where they can deliver effective and efficient information management. Using this recipe, developers can build applications to assist with things like content creation and curation, research, news aggregation, social media monitoring, and language learning.

– Code generators, which empower developers to concentrate on higher-level design and problem-solving by automating repetitive tasks like project setup and API integration, or to produce code templates.

– Object detection helps identify and locate objects within digital images or video frames. It is a fundamental component in various applications, including autonomous vehicles, retail inventory management, precision agriculture, and sports broadcasting.

– Audio-to-text transcription involves the process of automatically transcribing spoken language into written text, facilitating documentation, accessibility, and analysis of audio content.

These examples provide an entry point for developers where they can review the source code to see how the application is built and learn best practices for integrating their code with an AI model.

For developers, containers have traditionally provided a flexible, efficient and consistent environment for building and testing applications on their desktops without worrying about conflicts or compatibility issues. Today, they are looking for the same simplicity and ease of use for AI models. Podman AI Lab helps meet this need by giving them the ability to provision local inference servers, making it easier to run a model locally, get an endpoint, and start writing code to wrap new capabilities around the model.

In addition, Podman AI Lab includes a playground environment that allows users to interact with models and observe their behavior. This can be used to test, experiment and develop prototypes and applications with the models. An intuitive user prompt helps in exploring the capabilities and accuracy of various models and aids in finding the best model and the best settings for the use case in the application.

As AI becomes more ubiquitous in the enterprise, Red Hat is leading the way in unlocking the potential for AI to drive innovation, efficiency and value through its portfolio of consistent, trusted and comprehensive AI platforms for the hybrid cloud.

Podman AI Lab builds on the strength of Podman Desktop, an open source project founded at Red Hat which now has more than one m downloads. It also offers tight integration with image mode for Red Hat Enterprise Linux, a new deployment method for the world’s leading enterprise Linux platform that delivers the operating system as a container image. This integration enables developers to more easily go from prototyping and working with models on their laptop to turning the new AI-infused application into a portable, bootable container that can easily be run anywhere across the hybrid cloud, from bare metal to a cloud instance, using Red Hat OpenShift.

The cloud is hybrid. So is AI.

For more than 30 years, open source technologies have paired rapid innovation with greatly reduced IT costs and lowered barriers to innovation. Red Hat has been leading this charge for nearly as long, from delivering open enterprise Linux platforms with RHEL in the early 2000s to driving containers and Kubernetes as the foundation for open hybrid cloud and cloud-native computing with Red Hat OpenShift.

This drive continues with Red Hat powering AI/ML strategies across the open hybrid cloud, enabling AI workloads to run where data lives, whether in the datacenter, multiple public clouds or at the edge. More than just the workloads, Red Hat’s vision for AI brings model training and tuning down this same path to better address limitations around data sovereignty, compliance and operational integrity. The consistency delivered by Red Hat’s platforms across these environments, no matter where they run, is crucial in keeping AI innovation flowing. (Source: BUSINESS WIRE)

 

07 May 24. MITRE to Establish New AI Experimentation and Prototyping Capability for U.S. Government Agencies/ MITRE is building a new capability intended to give its artificial intelligence (AI) researchers and developers access to a massive increase in computing power. The new capability, MITRE Federal AI Sandbox, will provide better experimentation of next generation AI-enabled applications for the federal government. The Federal AI Sandbox is expected to be operational by year’s end and will be powered by an NVIDIA DGX SuperPOD™ that enables accelerated infrastructure scale and performance for AI enterprise work and machine learning.

As U.S. government agencies seek to apply AI across their operations, few have adequate access to supercomputers and the deep expertise required to operate the technology and test potential applications on secure infrastructure.

“The recent executive order on AI encourages federal agencies to reduce barriers for AI adoptions, but agencies often lack the computing environment necessary for experimentation and prototyping,” says Charles Clancy, MITRE, senior vice president and chief technology officer. “Our new Federal AI Sandbox will help level the playing field, making the high-quality compute power needed to train and test custom AI solutions available to any agency.”

MITRE will apply the Federal AI Sandbox to its work for federal agencies in areas including national security, healthcare, transportation, and climate. Agencies can gain access to the benefits of the Federal AI Sandbox through existing contracts with any of the six federally funded research and development centers MITRE operates.

Sandbox capabilities offer computing power to train cutting edge AI applications for government use including large language models (LLMs) and other generative AI tools. It can also be used to train multimodal perception systems that can understand and process information from multiple types of data at once such as images, audio, text, radar, and environmental or medical sensors, and reinforcement learning decision aids that learn by trial and error to help humans make better decisions.

“MITRE’s purchase of a DGX SuperPOD to assist the federal government in its development of AI initiatives will turbocharge the U.S. federal government’s efforts to leverage the power of AI,” says Anthony Robbins, vice president of public sector, NVIDIA. “AI has enormous potential to improve government services for citizens and solve big challenges, like transportation and cyber security.”

The NVIDIA DGX SuperPOD powering the sandbox is capable of an exaFLOP of performance to train and deploy custom LLMs and other AI solutions at scale. (Source: BUSINESS WIRE)

 

07 May 24. Global: New campaign highlights security, information theft risks from North Korean groups. On 2 May, several US government agencies revealed that the North Korean state-sponsored group ‘Kimsuky’ is exploiting weak email domain-based message authentication (DMARC) settings in a new, likely ongoing spear phishing campaign. The campaign starts with tailored phishing emails designed to trick high-value targets into opening malicious links or attachments. The group conducts extensive research on potential targets, impersonating individuals from trusted organisations, such as higher education institutions and think tanks, to bolster success rates. Kimsuky specifically targets organisations with unsuitable DMARC configurations to bypass anti-spoofing protections and successfully reach victims’ inboxes. Kimsuky’s capacity for substantial pre-campaign reconnaissance demonstrates the sustained security, information theft and phishing risks facing global organisations. North Korea continues to rely on cyber operations to gather strategic intelligence from perceived adversarial countries as it seeks to bolster its military and economic posture. As such, we assess further campaigns are likely in the long term. (Source: Sibylline)

 

07 May 24. Roke, a leading UK-based prime contractor and innovator in science and engineering, has today launched Roke Intelligence – a new business unit dedicated to redefining global standards in commercially outsourced professional intelligence. By integrating the expertise and tradecraft of intelligence professionals with cutting-edge technology – including AI, machine learning, advanced sensor technology, and data analytics – Roke Intelligence will empower clients with actionable insights, more informed decision-making, and a vital competitive advantage in a dynamic global risk environment.  Roke Intelligence provides clients with tailored and customised intelligence solutions, meeting their unique requirements and providing them with access to a comprehensive suite of open-source intelligence capabilities. This gives these organisations the most robust and market-leading toolkit for faster and more accurate decision-making.  At the head of the Roke Intelligence suite of capabilities is Geollect, a geospatial intelligence solution that is at the forefront of the outsourced professional intelligence revolution.  Combining human expertise with advanced AI, machine learning and sensor technology, Geollect uncovers hidden patterns of activity and provides clients with the intelligence advantage they need to make informed decisions.

By blending multiple layers of data into one place and visualising the results, Geollect transforms the way organisations think, communicate, and strategise. With instant access to accurate real-time information and pinpoint location certainty, Geollect users know where, know first and know more.

Geollect joined the Roke family in January 2023, when it was acquired by Chemring Group PLC as part of Roke’s strategy to facilitate IP-led growth.

Paul MacGregor, Managing Director at Roke, said: “Roke has played a key role in supporting UK Defence and Security for over 65 years. Our clients face increasing levels of risk and uncertainty in today’s world, and we are delighted to be able to offer them this new capability; combining the best of our technology and tradecraft with the deep insights derived from our acquisition of Geollect.

“Roke Intelligence provides our clients with instant access to an evergreen, cutting edge capability that would traditionally only have been available to global intelligence agencies.”

Roke Intelligence offers four core capabilities:

o Geollect, Roke’s transformational solution providing state-of-the-art geospatial analytics and situational awareness.

o Centri, which leads the way in visualising and transforming geospatial data into action, providing a full data-to-intelligence solution.

o Infosight, our information operations platform that provides detailed knowledge and situational awareness about events in a defined environment.

o Intelligence Services, harnessing industry-leading intelligence tradecraft expertise, fused with cutting-edge technology, to deliver simple answers to the most complex questions.

 

07 May 24. USAF solicits AI-enabled battlefield C2 capabilities. The US Air Force’s (USAF’s) main research and development (R&D) directorate is soliciting industry solutions to accelerate the air service’s integration of artificial intelligence (AI) capabilities into its command-and-control (C2) and battle management systems. Officials from the Air Force Research Laboratory (AFRL) issued a broad agency announcement (BAA) in March, seeking industry input on “development and application of AI to C2, new concepts and techniques for the battle management, and orchestration of AI at pace and scale”. AFRL officials at the organisation’s Rome Research Site in Rome, New York, are seeking proposals to also explore “how the use of AI by adversaries can be considered in the C2 planning and execution process and distributed and collaborative C2 to enable C2 anywhere and anyplace”, the 24 March BAA noted. (Source: Janes)

 

06 May 24. Airborne Technologies announced the successful implementation of the Smith Myers ARTEMIS Mobile Phone Detection, Location & Communication system, in partnership with their local partner LIMA Aviation LLC in the UAE. This cutting-edge project involved the installation of the system into nine AW139 search and rescue helicopters belonging to a UAE government customer, with the first installation already completed. This project represents the collaboration between the teams of Airborne Technologies, LIMA Aviation and Smith Myers aimed at delivering innovative and reliable airborne surveillance solutions to UAE government customer.

Olga Martyshchenko, CEO of Lima Aviation, said: “We are thrilled to partner with Airborne Technologies on this exciting project to bring the Smith Myers ARTEMIS system to our esteemed UAE government customer. This strategic partnership marks a significant milestone in our commitment to excellence and innovation, as we continue to deliver state-of-the-art solutions that redefine industry highest standards of quality, reliability, and performance. The successful integration of the ARTEMIS system, renowned for its unparalleled capabilities in mobile phone detection, location, and communication, underscores our collective dedication to delivering innovative and advanced aviation solutions and technologies tailored to meet the evolving needs of our customers. Together, we are leveraging the power of ARTEMIS to optimize and elevate the search and rescue operational performance and efficiency for our UAE government customer.”

 

06 May 24. Military Academy launches centre for artificial intelligence excellence.

The South African Military Academy overlooking Saldanha Bay in the Western Cape has formally launched the Defence Artificial Intelligence Research Unit (DAIRU) as a centre of Artificial Intelligence (AI) excellence.

Artificial Intelligence is viewed as a critical component of the Fourth Industrial Revolution, capable of fundamentally shaping geopolitics and the conduct of warfare. Nations need to adopt AI technologies swiftly and effectively, as integration determines success in future conflicts.

In his keynote address at the ceremony held on Friday 3 May, Mondli Gungubele, Minister of Communications and Digital Technologies, remarked that the initiative is not just symbolic; it represents a strategic move towards leveraging AI for national development and security. He emphasised the transformative power of AI and its potential to revolutionise various sectors.

Gungubele said that AI is being rapidly adopted globally and has the potential to surpass human abilities. Artificial Intelligence crosses a broad spectrum, from Narrow AI, which excels in specific tasks, to General AI, which can outperform humans in intellectual tasks, and the theoretical realm of Artificial Super Intelligence (ASI).

The integration of AI into defence and military operations was emphasised, acknowledging the global trend towards AI-powered military applications and the need for proactive governance in this sphere. The establishment of the DAIRU positions the country as a leader in harnessing emerging technologies for global competitiveness and safeguarding national interests, guests at the ceremony heard.

“AI, akin to electricity or fossil fuels, has the potential to redefine modern militaries and reshape the global balance of power,” the Minister said.

Lieutenant General Michael Ramantswana, South African National Defence Force (SANDF) Chief of Staff, noted that the inauguration of the DAIRU marked a significant milestone for South Africa, reflecting the nation’s commitment to leveraging AI for military advancement and broader socio-economic growth.

The initiative is not only about bolstering military prowess but also about positioning South Africa as a leader in AI innovation on the continent and globally, attendees at the launch were told.

From radar development in World War II to the advent of GPS and the internet, the military has consistently embraced emerging technologies to gain a strategic advantage. The South African National Defence Force’s investment in AI research and development through DAIRU reflects a proactive approach to staying abreast of technological advancements.

“We do not just want to be consumers of the technology,” Ramantswana said. “The SANDF should also strive to innovate new artificial intelligence solutions.”

Collaboration with industry and academia is deemed essential for the success of the DAIRU, Ramantswana emphasised, enabling the SANDF to leverage expertise, share resources and accelerate progress in AI implementation.

“But make no mistake – success will require dedication and commitment. We must dedicate sufficient resources to this initiative to ensure that the SANDF and defence sector remain at the forefront of technological innovation in Africa and beyond,” he added.

Dr Moses Khanyile (Director: DAIRU) underscored the opportune timing of the event, aligning with the drafting of the African Union’s formulation of a Continental AI Strategy.

“The uneasy peace that has been in existence between the superpowers for the last seven decades is directly attributable to the possession of nuclear weapons,” Khanyile noted. “However, the discovery of artificial intelligence technology has ignited a new global digital arms race.”

This has far-reaching implications if left unregulated and he emphasised the imperative for oversight.

“As things stand,” Khanyile told the assembled dignitaries, “there is no consensus on the rules of the game, how AI should be regulated, both as dual-use technology and as an asset to humanity.” This sentiment encapsulates the urgency and complexity surrounding AI governance.

The SANDF has already established a cyber command within the Defence Intelligence Division and the Space Command Section within the South African Air Force and these capabilities need continuous flows of highly skilled AI practitioners, such as those produced by the DAIRU.

This includes research and development on AI capacity, strengthening the country’s cyber resilience, improving maritime and border security, combating illicit trade and trafficking and boosting the SANDF’s operational efficiency on and off the battlefield.

In modern warfare, AI can assist human decision-making processes by rapidly processing vast amounts of data from diverse sources. Specific applications include AI-driven drones, targeting systems and image analysis, which have already demonstrated their value in military operations. AI can also be leveraged to counter disinformation, enhance cybersecurity, and predict/prevent cyber-attacks.

Institutions like the South African AI Institute and military academies are pivotal players in preparing national defence forces for digital warfare.

The DAIRU seeks to achieve these objectives by, amongst others, utilising resources within the government, Stellenbosch University (the Military Academy houses the Faculty of Military Science) and the private sector. The establishment of the Defence AI Research Unit exemplifies a commitment to spearhead AI applications in defence within the African context. (Source: https://www.defenceweb.co.za/)

 

03 May 24. Cyber Update Key points.

  • A cyber attack on local election infrastructure points to ongoing security and disruption risks facing election personnel and infrastructure (see Sibylline Cyber Daily Analytical Update – 29 April 2024).
  • An uptick in cyber attacks via stolen third-party credentials demonstrates elevated security risks from the software supply chain (see Sibylline Cyber Daily Analytical Update – 30 April 2024 and our Technical analysis below).
  • Sophisticated tactics by Chinese state-sponsored actors underscore heightened security and disruption risks facing global organisations (see Sibylline Cyber Daily Analytical Update – 1 May 2024 and our Technical analysis below).
  • New campaign targeting non-profits, among other sectors, highlights sustained security, espionage, phishing risks from Iranian state-sponsored actor, ‘APT42’ (see Sibylline Cyber Daily Analytical Update – 2 May 2024).
  • Data breach exposing sensitive customer information exacerbates security and financial risks from third-party services (see Sibylline Cyber Daily Analytical Update – 3 May 2024).

Technical analysis of weekly stories

A newly identified Chinese state-sponsored group, ‘Muddling Meerkat’, has been targeting global organisations since 2019. The group distinguishes itself from other known Chinese state-sponsored groups due to their unique ability to craft special domain name system (DNS) requests. The Great Firewall of China (GFW) typically restricts internet access by responding to these types of requests with randomised IP addresses, thereby blocking unauthorised websites. However, the group can bypass these restrictions by sending special requests for open mail exchanger (MX) records which obtain a response even when no mail service is configured. As a result, the group is able to build a potential victim pool to compromise for future malicious activities. Although the motivations behind the group’s activities are unclear, the intermittence of requests and type of activity are possibly in line with slow drip attacks, a type of distributed denial-of-service (DDoS). Additionally, the group blends in with normal network activities by scattering requests and limiting the amount of activity normally captured by logging. This allowed the group to achieve prolonged obfuscation, pointing to their sophistication and in-depth knowledge of modern IT and DNS systems.

There was a significant spike in credential stuffing attacks targeting customers of the authentication platform Okta reported between 19- 26 April. Threat actors attempted to compromise customers’ accounts by using a list of usernames and passwords likely obtained from previous unrelated data breaches and/or phishing and malware campaigns. Notably, all the recent attacks originated from anonymised sources such as The Onion Router (TOR) and other residential proxy services; the former conceals a user’s IP address while the latter routes traffic via third-party devices, thereby enabling the threat actors to remain undetected. This latest wave of attacks is possibly related to a recent surge in brute-force attacks targeting varying devices such as virtual private network (VPN) and Secure Shell (SSH) services. The threat actors’ use of anonymisation tools to remain undetected further indicates the continuous adaptation of actors’ tactics, techniques and procedures (TTPs).

Some non-exhaustive recommendations to mitigate against these threats include:

  • Identify and eliminate DNS open resolvers as well as external domains for active directory or DNS search domains.
  • Enforce strict security policies including regular software and password updates to prevent infections via leaked password credentials.
  • Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing and other types of social engineering attempts.
  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions.

Our cyber word of the week: Slow Drip Attack. (Source: Sibylline)

 

06 May 24. Anduril touts Pulsar jammers that rapidly adapt to changing threats. Anduril Industries pulled back the curtain on its line of portable, rapidly reprogrammable electronic warfare tools that the U.S. military has been quietly using around the globe.

The defense tech company on May 6 made public its Pulsar products, which it said are capable of countering drones, geolocating forces and neutering improvised explosive devices. The equipment comes in variants for fixed use, mounting aboard ground vehicles, and integration on aircraft. A version that can be slung onto troops’ backs is also being eyed.

Electronic warfare represents a battle over the electromagnetic spectrum, which militaries rely on to communicate, discern friend from foe and guide munitions to targets. Pentagon investment in sophisticated EW atrophied in the years following the Cold War, but fighting in Eastern Europe and the Greater Middle East reignited interest.

“There’s a realization that the United States military is not where it needs to be, in terms of operating in this kind of high-EW threat environment, and then having the types of agile capabilities to defend our forces and fight back offensively,” Chris Brose, Anduril’s chief strategy officer, told reporters at a briefing.

“We’re not going to go talk about ideas that we have, share glossy renderings of what they might look like in the world, and then go seek to build them and deliver them years later,” he added. “We tend to do the opposite.”

The Pulsar line has been in development since 2020 and was funded internally. It is software-defined, meaning updates can be dished out quickly and constraints imposed by hardware are lessened, and leans on advanced computing to retool for novel threats.

A war with Russia in Europe or China in the Indo-Pacific, for example, might introduce previously unseen technologies and electronic signatures. The time it takes to counter them could mean the difference between victory and defeat.

“Each system can process the data where it is, and then many systems that are networked together can learn from each other, just using small metadata,” said Sam El-Akkad, the general manager of radio frequency and EW systems at Anduril. “If one system sees something new, all the other systems are trained to see that new thing and recognize it in the future.”

While Anduril declined to specify where Pulsar has been used, deployment was described as happening across “multiple continents.”

The company in 2022 mentioned the EW equipment after winning a nearly $1 bn counter-unmanned aerial systems contract from U.S. Special Operations Command. A memo obtained by Defense News that same year described it helping to “mitigate incoming threats.”

“Pulsar is not just a figment of our imagination,” El-Akkad said. “At a high level, we’re in production of these systems, so we’re pumping them out and they are being used.” (Source: C4ISR & Networks)

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

Spectra Group (UK) Ltd

 

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

  • « Go to Previous Page
  • Page 1
  • Interim pages omitted …
  • Page 3
  • Page 4
  • Page 5
  • Page 6
  • Go to Next Page »

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT