Sponsored by Spectra Group
————————————————————————
05 Oct 23. Spectra Group’s award-winning SlingShot satcom system selected for Project Capstone 4. Spectra Group, a specialist provider of secure voice, data and satellite communications systems, in partnership with Inmarsat, has been selected to support Project Capstone 4 (Army Futures Command’s premier integration and experimentation exercise in 2024) with their award-winning SlingShot satellite communications system. Spectra Group has a strong pedigree of successfully supporting previous command and control innovation and integration demonstrations for the USDOD and USSOCOM, the Army Maneuver Battle Lab (AEWE 2019) and the Fires Battle Lab (MFIX 2022).
SlingShot is a compact and user-friendly tactical radio range extension system designed to enhance Beyond Line Of Sight (BLOS) Communications On The Move (COTM) C2 (Command and Control) communications. This innovative system effortlessly enables in-service Ultra High Frequency (UHF) and Very High Frequency (VHF) radios to utilise L-Band satellite frequencies, extending their reach over thousands of kilometers. A standout feature of SlingShot is its intuitive plug-and-play capability, making it a reliable choice for both stationary and mobile setups. It serves as a direct augmentation to existing tactical radios. When paired with the Inmarsat L-TAC service, SlingShot significantly expands its user base and coverage, enabling the immediate transmission of voice, data and specialized military applications, such as artillery coordination and situational awareness, across vast distances.
Project Capstone leads the integration of all the domains that the US Army is dependent on — air, land, sea, space, cyberspace adopting a truly multi-domain/multi-national approach, while at the same time looking at concepts for the future. The Network Cross Functional Team (N-CFT) acknowledges that as national armies operate in multinational coalitions during future expeditionary operations, integration and interoperability of communications is paramount to ensuring battlefield success. Therefore, the N-CFT hosts foreign liaison officers from the armies of two close allies, the U.K. and Australia, to help shepherd information interoperability initiatives, concepts and goals and Spectra Group from the UK has been selected to support this project.
SlingShot plays a pivotal role in advancing interoperability among forces. By bridging communication gaps and ensuring seamless integration between different communication systems and networks, SlingShot fosters collaboration and coordination among diverse military units and allies. For broader connectivity, SlingShot can adeptly link the L-TAC networks to major, distant headquarters worldwide using cutting-edge digital RF-Over-IP technology. With a commendable track record, marked by over 7,000 units actively utilised by both specialised and regular forces globally, SlingShot has proven its mettle in the most challenging environments and diverse locales.
Pat Gallagher, General Manager Spectra Group (US) said: “SlingShot has a fantastic operational record with USSOCOM and is the perfect system to support AFC’s communication innovation and integration experiments as it can be added to any existing or future capability. When combined with the Inmarsat L-TAC service, SlingShot delivers the ultimate interoperability for secure voice, data and applications at scale for operations anywhere in the world.”
06 Oct 23. Cyber Executive summary.
- The North Korean threat group ‘Lazarus’ targeted an unnamed Spanish aerospace firm in a long-term social engineering campaign (see Sibylline Cyber Daily Analytical Update – 2 October 2023).
- The Iranian state-sponsored threat group ‘APT34’ targeted Middle Eastern entities in a cyber espionage operation using new malware (see Sibylline Cyber Daily Analytical Update – 3 October 2023).
- Concerns regarding cyber security have increased among small and medium-sized enterprises (SMEs) compared to 2022 (see Sibylline Cyber Daily Analytical Update – 4 October 2023).
- A zero-day in Atlassian Confluence is being actively exploited to establish unauthorised administrative accounts within organisations (see Sibylline Cyber Daily Analytical Update – 5 October 2023).
- A new Android trojan, ‘GoldDigger’, has targeted Vietnamese banking applications to steal financial information from users (see Sibylline Cyber Daily Analytical Update – 6 October 2023).
What you may have missed
Researchers from Threat Fabric have identified a connection between the Android spyware ‘DragonEgg’ and a modular iOS surveillanceware tool called ‘LightSpy’. The Chinese threat group ‘APT41’ is likely behind both. DragonEgg was first discovered in July as it attempted to steal sensitive data from infected Android devices. LightSpy was first discovered in March 2020 when Apple iPhone users in Hong Kong were targeted as part of ‘Operation Poisoned News’. It is likely that APT41 continuously develops its toolset to conduct surveillance operations against strategic targets. APT41 is known to conduct state-sponsored espionage and financially motivated campaigns, elevating the infection risks facing firms.
Word(s) of the week
Our cyber word(s) of the week: Social engineering (Source: Sibylline)
06 Oct 23. New £88m sensing equipment to protect UK Armed Forces.
New technology with capability to detect, identify and monitor the presence of toxic industrial chemicals and chemical warfare agents to be operational by 2028. UK Armed Forces personnel will be better protected on the battlefield through world-leading chemical detection sensors, under an £88 m contract announced today.
Led by Strategic Command alongside a pan-defence team, thousands of personnel across the British Army, Royal Navy and Royal Air Force will benefit from wearable personal chemical agent sensors, ensuring they can detect dozens of toxic chemical threats and take immediate action to protect themselves and others.
It will be a first of its kind for UK Armed Forces, as the wearable sensor will be able to detect multiple chemical threats from both vapours and aerosol – different ways in which chemical threats can be dispersed and affect an individual.
Under the contract, UK company Smiths Detection will develop three next-generation chemical sensor products for the MOD, to be operational by 2028. They are:
- Wearable personal chemical agent sensor – a device that continually monitors the environment around the user.
- Survey chemical agent sensor – a portable device to check potentially hazardous areas or surfaces.
- Remote capable, standoff chemical sensor – an enhanced sensor for use in fixed locations.
As new hazards emerge in the future, the equipment can be continually updated and improved, identifying a greater range of chemical threat coverage.
Supporting hundreds of skilled people at Smiths Detection and creating around a dozen new jobs at their Hemel Hempstead site, the contract boosts the Prime Minister’s priority of growing the UK economy. The company sources components and services from numerous UK suppliers, bolstering the UK manufacturing industry, and investing in British production capability.
Minister for Defence Procurement, James Cartlidge said:
It’s vital we protect our Service Personnel, and this cutting-edge technology is so important to reduce the threat posed by toxic chemicals across a range of environments globally.
Not only is it an impressive piece of equipment that will be designed and manufactured here in the UK, but the ability for it to be continually developed and improved is exactly how we want Defence procurement to be – deliverable, effective and ambitious.
Smiths Detection President, Roland Carter said: “We’re honoured to have been selected by the UK Ministry of Defence to supply this next-generation technology. Since our business inception, nearly 70 years ago, we have been designing, developing, manufacturing, and servicing chemical sensing technology. This technology protects defence forces, including the UK MoD, and communities from known and emerging threats. This award is testament to our leading technology and the knowledge, commitment and ingenuity of the people in our organisation who everyday help to make the world a safer place.”
Sensing chemical threats is a fundamental part of the UK’s Counter-Chemical Biological Radiological Nuclear capability. The contract, placed by the UK MOD’s procurement arm Defence Equipment and Support (DE&S) and supported by the Defence Science and Technology Laboratory (Dstl), will encompass the development, manufacture, and initial in-service support for the programme. (Source: https://www.gov.uk/)
05 Oct 23. Supporting NATO’s Cyber Posture. Insight from Strategic Command shared at CyberSec Summit 2023. Centred on cybersecurity and cyberconflict, the CyberSec Summit 2023 brought together influential decision-makers, experts, and stakeholders to discuss the theme of “shielding the digital frontier”.
As NATO contends with digital threats originating from both adversarial nations and cybercriminals, Deputy Commander Lieutenant General Tom Copinger-Symes joined a panel discussion on how we can support and strengthen the Alliance’s cyber preparedness.
The event follows on directly from the 13th Cyber Commanders Forum, hosted in Krakow by the Polish Cyber Defense Forces Component Command, at which the Deputy Commander also delivered the keynote speech on the role of cloud solutions in a modern Armed Forces.
Strategic Command is responsible for leading the cyber and electromagnetic domain for Defence and as an organisation we know we must adapt and evolve, exploiting digital technologies to the best effect in both our business and battlespace.
If we are to protect, engage, constrain and fight our adversaries, Defence must fully realise the opportunities of the cyber and electromagnetic domain.
The UK is a leading ally providing its support to NATO’s effort to strengthen cyber posture and adapt to new technologies. The UK remains committed to supporting NATO’s overall deterrence and defence posture through improved cyber defence. The launch of the Virtual Cyber Incident Support Capability (VCISC) at the Vilnius Summit and the Cyber Defence Pledge are recent examples of the Alliance’s progress in this domain of operations. (Source: https://www.gov.uk/)
04 Oct 23. Northern Exposure. Norway has acquired a new land forces electronic warfare capability for communications intelligence gathering.
A renaissance in land forces Electronic Warfare (EW) is being seen across the North Atlantic Treaty Organisation (NATO). Norway is the latest country to join the ranks of France, Germany, the Netherlands, the United Kingdom and the United States in overhauling her land forces EW systems.
On 12th September, Rohde & Schwarz announced it had supplied the Hæren (Norwegian Army) with the Heimdall (Watchman of the Gods) electronic warfare system. Sources close to the procurement told Armada that Heimdall will chiefly be used for tactical Communications Intelligence (COMINT) gathering. No details have been released regarding Heimdall’s capabilities. Nonetheless, it is highly likely that the system will detect and identify emitters across wavebands of at least 30 megahertz to six gigahertz.
Heimdall specifications
Publicity pictures of Heimdall show it equipping a Patria X-300 six-wheel drive armoured personnel carrier. The system should detect ground-based emitters at ranges of at least ten kilometres (six miles). The sources continued that the first Heimdall deliveries occurred in July and August. Deliveries are expected to conclude in late 2024. The installation of the Heimdall equipment is believed to have occurred at Rohde & Schwarz’ facilities in Germany.
The Norwegian Army is known to have one intelligence battalion which is the formation deploying Heimdall. The Intelligence Battalion is located at Setermoen in northern Norway. This makes sense as the battalion is deployed close to the Russo-Norwegian border. The border area is now a potential area of tension following Russia’s second invasion of Ukraine in February 2022. In wartime it is likely that Heimdall will deploy with this brigade. The platforms will also support wider NATO efforts within and without the Alliance’s area of responsibility.
Heimdall is believed to be replacing the Norwegian Army’s current Narvick Technology P6-300M tracked electronic warfare platforms. Deliveries of these vehicles to the army took place in the 1990s and they were equipped with EADS’ SGS-2000 Hummel COMINT and Communications Jamming (COMJAM) system. Given that the Norwegian Army has six of these vehicles, the may make a like-for-like Heimdall replacement.
Other new systems
The Heimdall procurement forms part of a larger overhaul of Norwegian land forces electronic warfare capabilities. Norwegian press reports say that the Fåvne initiative covers the procurement of an electronic attack capability. The reports continued that this should become available in the spring of 2024. Fåvne may comprise the addition of new Communications Jamming (COMJAM) capabilities to equip the Heimdall vehicles. Sources close to the procurement hinted that this is a possibility. Beyond Heimdall and Fåvne, the army will procure the Einherjer (Unicorn) system. Reports say that Einherjer will be configured to provide operational-level EW to the land manoeuvre force.
The Norwegian Army’s Heimdall system will be supplemented in the future by the Fåvne electronic attack system and the Einherjer operational-level electronic warfare architecture.
The addition of Heimdall to the Norwegian Army’s capabilities marks an important enhancement of its electronic warfare posture. With Fåvne and Einherjer also on the horizon the army will soon have one of the most potent EW forces in the Scandinavian and Baltic regions.
(Source: Armada)
05 Oct 23. NEWFIP Hones Spectrum Skills. In the North Atlantic Treaty Organisation’s (NATO’s) own words, Ramstein Guard is an annual exercise “designed to improve the effectiveness and capability of NATO Integrated Air and Missile Defence System (NATINAMDS) forces.”
This year’s exercise took place in northern Europe’s Baltic region. Choosing this area is by no means accidental. The Baltic nations of Estonia, Latvia and Lithuania, together with new NATO entrants Finland and Sweden, and long-time member Norway, all share close proximity with Russia. Those nations bordering Russia can be considered ‘frontline states’. NATO’s relations with an increasingly aggressive Russia, as shown by the latter’s actions in Ukraine, remain tense.
NATO’s Electronic Warfare Force Integration Programme, better known as NEWFIP, is a training component for exercises like Ramstein Guard. The alliance told Armada via a written statement that NEWFIP is “for selected nations to train and maintain a minimum level of EW proficiency.” NEWFIP efforts are not confined to the air domain. The alliance statement continued that at least three exercises per year incorporate EW assets and are coordinated by the NEWFIP. NATO’s Dynamic Guard maritime exercise hosted by Norway in February also included an NEWFIP component.
The key role of NEWFIP, and the programme’s participation in NATO exercises, is to hone the effectiveness and capability of forces like NATINAMDS units “to operate effectively in a hostile EW environment.” Russia’s armed forces have shown in the Ukrainian and Syrian theatres that they take EW seriously and work hard to restrict access to the electromagnetic spectrum.
The NEWFIP takes a scalable, graduated approach to EW training starting “with a basic approach to ensure the effective training of all operators on the ground and in the air,” the statement articulated. “The complexity can be increased to take all operators to a higher level.” NATO is keen to emphasise that the NEWFIP component of Ramstein Guard is not intended to be a test or evaluation. Instead, this component “is tailored training in the EW environment.”
Purpose
Ramstein Guard employed EW training for two purposes: The first was to ensure that command and control could be maintained between participating assets. The speed of air combat, coupled with the vast distances over which it usually occurs, makes robust communications essential, particularly for air defence. The Russian Army uses systems such as the R-934B, 1L269 Krasukha-2.0 and 1RL257 Krasukha-C4. The R-934B is a ground-based electronic attack system directed against airborne radios using frequencies of 20 megahertz to two gigahertz/GHz.
Air defence also relies on ensuring that the Recognised Air Picture (RAP) relied upon by NATO air defenders is as comprehensive as possible. Together, the 1L269 and 1RL257 jam airborne radars across frequencies of one gigahertz to 18GHz. Ensuring the resilience of NATO communications and airborne radars in the face of such threats is imperative. “This exercise focuses on the employment of defensive self-protection measures to overcome interference that would impact the alliance’s ability to conduct the tracking operations necessary to maintain a RAP.”
The NEWFIP is subordinate to NATO’s Allied Air Command based at Ramstein airbase, western Germany. The alliance’s Combined Air Operations Centres in Uedem, western Germany and Torrejón, central Spain are responsible for conducting the air exercises. Alongside the NEWFIP, the statement said NATO’s Joint Electronic Warfare Core Staff (JEWCS) “provides NATO commands and allied forces with EW expertise, support and training … for operations and exercises.”
Ramstein Guard shows that NATO is continually refining its EW skills in the air domain, as well as the maritime, land and space environments. With alliance members facing the threat of Russian aggression, initiatives like NEWFIP make an important contribution to help ensure alliance spectrum resilience. (Source: Armada)
05 Oct 23. Strategic Decision. In late July, the United States Strategic Command revealed it had activated the Joint Electromagnetic Spectrum Operations Centre.
Known as the JEC, a press release announcing the news said that the centre “will serve as the heart of the Department of Defence’s Electromagnetic Spectrum Operations.” The press release continued that the JEC aims “to consolidate and streamline electromagnetic spectrum management.”
Managing the use of the spectrum across the US military is vital given that this resource is expected to suffer congestion in the future. This congestion will be driven largely by the uptake of fifth-generation (5G) cellular communications protocols over the coming decade. 5G Americas, an advocacy organisation, said in April 2023 that it expects global 5G connections to reach 5.9 bn by late 2027. The same organisation said that 5G connections stood at just over one bn at the end of 2022.
The dynamics of a contested spectrum can be seen daily in the Ukraine theatre of operations. As Armada has chronicled, both Russian and Ukrainian forces are fighting preserve their use of the spectrum. Meanwhile, both occupiers and defenders are working to prevent their adversary’s use of this resource.
“The centre’s primary objective will be to ensure the availability, integrity, and resilience of the electromagnetic spectrum, enabling uninterrupted communication, information sharing, and precision targeting capabilities for US forces,” the press release added.
Consolidation
Brigadier General AnnMarie Anthony, the JEC’s director, told Armada that the unit will be headquartered at Offutt airbase, Nebraska, collocated with US STRATCOM (Strategic Command) headquarters. Placing the JEC under US STRATCOM’s responsibility reflects an executive decision. On 25th April, President Joe Biden designated US STRATCOM as operational lead for the electromagnetic spectrum enterprise. The enterprise encompasses all elements of the DOD involved in electromagnetic spectrum operations. An additional two organisations join the JEC: These are the Joint Centre for Electromagnetic Readiness (JECR) at Nellis airbase, Nevada and the Joint Electromagnetic Warfare Centre (JEWC) at Lackland airbase, Texas.
The JEC will have an important doctrinal and training role, says Gen. Anthony providing “force-wide training and education and continual force and capability assessment.” The JEC will standardise and accredit “joint EMS operations education curriculum, and accreditation of deployment certification standards and identifying EMS operations deficiencies, risks, and capability requirements.” The US DOD’s respective combatant commands will continue to plan, coordinate and execute their spectrum operations. These actions will be taken as per their prevailing authorities and doctrines.
Towards IOC and FOC
Gen. Anthony continued that the JEC, JECR and JEWC will increase their staffing levels to support their responsibilities with an initial operational capability to be declared by the third quarter of 2023. She added that a full operational capability is expected by 2025. Alongside the JEC’s day-to-day responsibilities, the organisation will work closely with academia, industry and US allies “to exchange information, develop best practice and stay at the forefront of electromagnetic spectrum operations.” Gen. Anthony added that “as technology advances and the spectrum becomes increasingly congested, the JEC will continue to evolve and grow, ensuring our forces maintain a decisive edge in an era of complex and evolving threats.” (Source: Armada)
05 Oct 23. October Spectrum SitRep. TCI ECS’ 953 COMINT system has been retrofitted with several enhancements including a counter-uninhabited aerial vehicle capability, new batteries and computers and an increase in instantaneous bandwidth.
Thurbon Goes Further
MASS has revealed several major enhancements for its Thurbon Electronic Warfare (EW) data management system. Thurbon is used by several North Atlantic Treaty Organisation (NATO) and allied nations to handle Electronic Warfare (EW) data. The system can be used to allocate specific data to specific platforms used by specific armed services. For example, signals intelligence operatives may collect details of waveforms transmitted by an attack helicopter’s fire control radar. These signal parameters are entered 6into the database and matched with that specific aircraft. Thurbon eases the management of red and blue force, and neutral, EW data. Officials from MASS told Armada that the system has received software updates allowing EW data to be allocated to specific individuals via the database. Suppose a High Value Individual (HVI) is known to use particular cellphones, laptops, Bluetooth or WiFi devices, and even wireless camera doorbells. Details of the HVI can be entered into Thurbon in a similar fashion to the details of an individual platform. This HVI entry can then be populated with details of the emitting electronic devices they use. This data can be teamed with other intelligence like pictures of the person or details on where they live, work and spend their leisure time. The officials continued that these new features give Thurbon a high degree of applicability beyond the military world into the law enforcement and intelligence communities.
COMINT Enhancements
This year’s DSEI exhibition in London saw several announcements regarding new Electronic Warfare (EW) systems and capabilities. TCI ECS revealed to Armada that the company has performed several enhancements of its 953 communications intelligence system. Designed to equip land forces, the 953 initially provided 40 Megahertz/MHz of instantaneous bandwidth. Company officials said that this has now been expanded to 80MHz. Other enhancements include the addition of internal batteries and processors with the batteries offering up to four hours of operation, depending on the mission. Other enhancements include the addition of a counter-uninhabited aerial vehicle capability. These modifications can be retrofitted onto existing 953 systems and will be provided as standard on new equipment. The company said that modernised 953 examples have been sold to four customers with deliveries ongoing.
New Roles for MicroESM
Elsewhere at DSEI ESROE exhibited a backpack version of the company’s MicroESM radar Electronic Support Measure (ESM) designed to be used by dismounted troops. According to the company’s literature, the MicroESM detects, identifies and locates radar signals across a two gigahertz/GHz to 18GHz waveband. Providing a bearing accuracy of ten degrees for signal direction finding, two or more MicroESMs can be networked to triangulate signals of interest. The product is currently available in a stand-alone, tripod-mounted configuration. However, company officials told Armada that they are seeing significant interest in a backpack version of the apparatus to equip dismounted troops. This would help land forces electronic warfare cadres collect Electronic Intelligence (ELINT) alongside the conventional communications intelligence mission. ELINT concerning red force weapons locating radars could be particularly useful for blue force artillery when executing counter-battery fires. Alongside the backpack configuration, ESROE officials mooted that developments are afoot for MicroESM variants to equip uninhabited aerial vehicles and for marine applications.
ESROE showcased a backpack version of its MicroESM radar electronic support measure at this year’s DSEI exhibition. The ability to collect radar ELINT on the battlefield could be particularly useful for supporting counter-battery missions. (Source: Armada)
04 Oct 23. Europe: Inadequate cyber security measures increase financial, reputational risks for businesses. On 2 October, Sharp Europe released research indicating that cyber security concerns among small and medium-sized businesses (SMEs) have risen significantly since 2022. In a pan-European survey, 38% of SMEs reported that they are more worried about cyber security threats than in 2022, with a third reporting a security breach in the last year. Phishing, malware and data theft operations were the most frequent types of attacks against SMEs between 2022 and 2023, and continue to occur at an elevated rate. While 61% of SMEs reportedly lack confidence in their business’s ability to mitigate a cyber security event, 60% of UK small businesses stated that their IT security budgets will not increase in 2024. This highlights the ongoing disparity between organisations’ decision-makers and security departments. Insufficient security budgets often exacerbate businesses’ likelihood of suffering a cyber incident without sufficient prevention or mitigation capacities. Inadequate cyber security measures and low budgets heighten the risk of long-term impact on cyber operations, sustaining risks of financial loss and reputational damage for SMEs. (Source: Sibylline)
03 Oct 23. Middle East: Persistent security risk posed to Saudi Arabian entities in cyber espionage operations. On 29 September, researchers from cyber security firm TrendMicro released a report on the Iranian state-sponsored threat group ‘APT34’ (also known as ‘OilRig’ and ‘Helix Kitten’). It used novel custom tools for cyber espionage purposes against entities in the Middle East during a new phishing campaign. Initially discovered in August, the campaign used a new malware, ‘Menorah’, which is capable of identifying a target’s device, reading and uploading files, and downloading other files or malware onto the infected device. The phishing document purported to be related to a CV and employment opportunity; it also contained pricing information in Saudi riyal (SAR). As such, there is a realistic possibility that at least one intended target organisation is based in Saudi Arabia, elevating risks for in-country firms. ‘APT34’ primarily collects sensitive information in pursuit of Tehran’s strategic goals within the Middle East, using phishing operations and advanced techniques to maintain persistence inside a network. Iranian state-sponsored entities have previously targeted critical infrastructure, government entities and telecommunications organisations, and the risk to these sectors remains heightened in the longer term. (Source: Sibylline)
02 Oct 23. ARMA Instruments Launch Zero Trust G1 Mark II Secure Messaging Communication Device. Launch in Kyiv and Silicon Valley with cyber security consultancy Midnight Blue and author and cyberterrorism expert Winn Schwartau underscore the need for communication technology capable of dealing with current cyber terrorism and cyber warfare threats
Switzerland-based ARMA Instruments AG announces the launch of their ARMA G1 Mark II Secure Messaging Device. Developed with zero trust principles, the device is a closed mobile system for person-to-person messaging at the highest security levels to counter advanced adversary attacks. The device will be beneficial for NGOs, defense agencies, cybersecurity operations, financial organizations, embassies, and global corporations.
The Russian invasion of Ukraine has ignited an arms race in the theater of cyber warfare. Zero trust is the operative term for military, defense sectors, and governments across the globe. U.S. intelligence agencies and international partners recently published a report warning of the new Russian malware program Sandworm, likely targeting Ukrainian interests in its ongoing war, and U.S. defense agencies set a deadline of 2027 for implementation of zero trust cybersecurity environments [FedTech, August 2023].
In this environment of advanced global threats, Switzerland-based ARMA Instruments AG announces the launch of their ARMA G1 Mark II Secure Messaging Device in Kyiv this month. Developed with zero trust principles, the device is a closed mobile system for person-to-person messaging at the highest security levels to counter advanced adversary attacks.
“ARMA was created in response to the lack of security products capable of dealing with advanced adversaries, such as hostile nation-state actors,” says Pim Donkers, founder and CEO of ARMA Instruments AG. “The G1 device was inspired by Article 12 of the U.N.’s Universal Declaration of Human Rights, that no one shall be subject to interference with privacy or correspondence, especially in conflict zones where humanitarian situations are compromised.”
Donkers and CTO Andrey Loginov will unveil the G1 device at the Kyiv event with presentations by Netherlands-based cyber security consultancy Midnight Blue detailing TETRA:BURST, their recent exposure of the TETRA standard vulnerabilities, and U.S.-based author and cyberterrorism expert Winn Schwartau, at both events.
The G1 uses cellular networks, has no microphone or third-party applications, and does not use WIFI, NFC, Bluetooth, GPS, or connectors. It charges wirelessly and has an anti-tampering mechanism capable of destroying all secrets on the device to protect sensitive information.
Using end-to-end encryption and Tor, a public ‘onion routing’ network, data is anonymously routed through random encrypted relay servers across the globe, making sure that there are no data breaches or infrastructure to attack. ARMA’s patented Dynamic Identity as part of ARMA’s proprietary virtual SIM, prevents users from becoming a target of cyber-attacks or anti-personnel attacks.
“Anti-personnel attacks that use a targeted individual’s smartphone as a means of a homing device for, let’s say, a drone rigged with explosives, are the future attacks of tomorrow,” Donkers continues, “Dynamic Identity is the only solution out there that protects our clients against such attacks to date.”
The ARMA G1 device will benefit communications security for NGOs, defense agencies, cybersecurity operations, financial organizations, embassies, and global corporations.
For media interested in attending, please email . For more information on the Kyiv and 24 October Silicon Valley event visit: https://armainstruments.com/launching-the-arma-g1-mark-2-events/
ARMA Instruments is a secure communication systems technology provider and creator of the world’s first secure communications messaging device, the ARMA G1. Based in Baar, Switzerland, and founded in 2017 by CEO Pim Donkers, ARMA is based on zero-trust principles, and stays politically neutral. The ARMA G1 is powered by their patented Dynamic Identity solution and is a closed mobile system. ARMA is an acronym for Advanced Relay Mission Applications in response to products technologically incapable of dealing with current cybersecurity and cyber terrorism threats, advanced adversaries, and nation-state actors. For more information visit www.armainstruments.com (Source: BUSINESS WIRE)
02 Oct 23. NATO’s ‘Dynamic Messenger’ test uses 5G mesh to link underwater drones. A recent NATO military exercise highlighted the value of weaving 5G marine testbeds into the Alliance’s operations for use with unmanned underwater vehicles.
On Sept. 29, the second edition of Dynamic Messenger, organized by NATO’s Allied Command Transformation and Allied Maritime Command, concluded in the areas of Tróia, Sado River, and offshore from the Sesimbra Peninsula, in Portugal.
The eleven-day event focused on testing the maturity of maritime unmanned systems, or MUS, and demonstrating their level of interoperability with NATO assets. It brought together 16 allies and one partner nation: Belgium, Canada, Denmark, France, Germany, Turkey, Greece, Italy, Latvia, the Netherlands, Norway, Poland, Spain, Sweden, the U.K. and the U.S.
In addition, other non-NATO nations sent observers, including Japan, New Zealand and South Korea.
One of the interesting conclusions shared by a NATO official who took part in Dynamic Messenger, was concerning the fielding of MUS and 5G technology.
“The utilization of unmanned underwater vehicles and 5G mesh networks for the passing of information in the underwater realm has much promise,” the military official told Defense News in an email.
The concept of developing 5G sea testbeds, at least within the military sector, is fairly new. Ultimately, it would allow for the seamless integration of several 5G-ready devices, sensors, vehicles and endpoints to provide for an advanced communication capability in remote operations.
In August, Lockheed Martin delivered the final Phase 1 initial prototype of the 5G testbed variant for the Open Systems Interoperable and Reconfigurable Infrastructure to the U.S. Marine Corps program.
OSIRIS is a 5G communications network infrastructure experimentation that was awarded to the defense company in 2021. The second phase will see the integration of specific mission applications onto the network for evaluation.
In the commercial sector, Vodafone developed last year a private 5G network operated by the Plymouth Marine Laboratory in the U.K., to serve as a testing ground for sea applications. According to a company statement, the infrastructure is open for use by local and international companies to create 5G marine use cases for free.
Experts in the field of naval warfare have suggested that 5G may also offer the potential of modernizing navies’ undersea systems without intrusive environmental operations, such as digging trenches for underwater cables.
Other uncrewed potential
In the context of the DYNMS exercise, several warfare areas were identified to experiment with deployed maritime unmanned systems supported by other autonomous air and surface assets.
These realms included protecting critical undersea infrastructure; enabling mine warfare operations with crewed-uncrewed teaming when possible; force protection with an emphasis on convoy escort operations and counter-unmanned aerial systems; and conducting light and fast amphibious operations from ship to shore.
“UAS such as Scheibel’s Camcopter S-100 and [Portuguese-made] Ogassa OGS42 provided outstanding persistent air surveillance capability while others such as the Spanish Kaluga DS USV allowed for covert identification of suspicious surface activity,” the NATO official participating in who Dynamic Messenger said.
“Autonomous underwater vehicles such as the Gavia [manufactured by Teledyne Marine] and its side scan sonar allowed for the detection of anomalies and informed decisions on how to best deal with potential threats or disruptions to critical underwater infrastructure,” the military official added.
A total of 34 systems were deployed comprising three AUVs, two unmanned underwater vehicles, one autonomous surface vehicle, eight unmanned surface vehicles and thirteen drones. (Source: Defense News)
02 Oct 23. Spain: Social engineering campaign underscores security risks from North Korean actors. On 29 September, cyber security company ESET reported that the North Korean-linked threat group, ‘Lazarus’, had targeted an unnamed Spanish aerospace firm in a social engineering campaign aimed at stealing sensitive information. This campaign is part of the ‘Operation DreamJob’ espionage operation, where Lazarus actors impersonate Meta recruiters on LinkedIn and contact employees as part of an attempt to install a backdoor known as ‘LightlessCan’. The backdoor is a stealthier and more sophisticated variant of the group’s BlindingCan backdoor, which was used to target the Indian aerospace sector in 2019 in a campaign coinciding with India’s Chandrayaan-2 moon landing attempt. The development of the LightlessCan backdoor with new features to evade detection and analysis indicates that Lazarus is continuously improving its existing malicious toolset, elevating the security risks posed by its malware. The operation was likely conducted to steal sensitive information to enhance North Korea’s missile programmes, underscoring persistent risks to firms in the aerospace sector with Lazarus likely employing social engineering tactics against similar firms in the long term. (Source: Sibylline)
29 Sep 23. Cyber Executive summary.
- Three China-affiliated threat actors have targeted an unnamed Southeast Asian country in several cyber espionage campaigns since 2021 (see Sibylline Cyber Daily Analytical Update – 25 September 2023).
- A sophisticated Android banking trojan, ‘Xenomorph’, has targeted US banking customers since August (see Sibylline Cyber Daily Analytical Update – 26 September 2023).
- A new Ransomware-as-a-Service (RaaS) affiliate, ‘ShadowSyndicate’, has been distributing multiple ransomware families to users since late 2022 (see Sibylline Cyber Daily Analytical Update – 27 September 2023).
- A China-affiliated threat actor, ‘BlackTech’, has been installing backdoors into Cisco routers to steal information from multinational companies as part of a recent cyber espionage campaign (see Sibylline Cyber Daily Analytical Update – 28 September 2023).
- A Chinese threat group, ‘Budworm’, is using a new variant of its custom malware to target critical infrastructure in the Middle East and Asia (see Sibylline Cyber Daily Analytical Update – 29 September 2023).
What you may have missed
Business Email Compromise (BEC) attacks against the US healthcare sector have increased by 279% this year, according to research conducted by Abnormal Security. There was reportedly also a 167% increase in advanced email operations targeting the sector, including via BEC attacks, credential phishing, malware and extortion. BEC campaigns pose significant financial risks; the FBI stated that the average BEC attack costs around USD 125,000 in victim losses. BEC attacks typically emanate from legitimate domains; they often impersonate high-level employees, such as CEOs and company presidents, to trick staff into sharing sensitive financial information. The US healthcare sector will continue to face elevated BEC-related risks in the coming months.
Word(s) of the week
Our cyber word(s) of the week: Banking trojan (Source: Sibylline)
29 Sep 23. Middle East-Asia: Chinese espionage operations pose heightened security risks to government sector. Since August 2023, a Chinese state-sponsored threat group, ‘Budworm’, also known as ‘APT27’ or ‘Emissary Panda’ has conducted a cyber espionage campaign to gather intelligence from a telecommunication firm in the Middle East and an unnamed government entity in Asia. The campaign used a previously unseen variant of their custom ‘SysUpdate’ backdoor, highlighting the group’s sophistication and development of tools for future operations. In this attack, the only malicious activity conducted by Budworm was credential harvesting, suggesting that the campaign was halted early on during execution, either due to the implementation of adequate security measures by infected organisations or the group intentionally paused the operation after obtaining strategic credential information. Budworm frequently targets the government, technology and defence sectors with espionage operations in pursuit of Beijing’s strategic goals. As the group continues to develop its malware and tactics, organisations in these sectors remain at elevated risk of Chinese-sponsored cyber espionage campaigns. (Source: Sibylline)
————————————————————————-
Spectra Group (UK) Ltd
Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.
Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.
With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.
Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.
In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.
Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.
Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.
————————————————————————-

