• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

December 14, 2023 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————

15 Dec 23. Cyber Update Key points:

  • The Russian threat actor ‘Star Blizzard’ is using increasingly sophisticated tactics in ongoing espionage operations against critical entities within countries that are part of the Five Eyes alliance (see Sibylline Cyber Daily Analytical Update – 11 December 2023).
  • The North Korean group ‘Andariel’ (a sub-group of the ‘Lazarus’ group) is deploying three new malware strains against victims using the pre-existing ‘Log4Shell’ vulnerability (see Sibylline Cyber Daily Analytical Update – 12 December 2023 and our Technical analysis below).
  • Russia’s Federal Tax Service (FNS) suffered a destructive cyber attack carried out by Ukrainian intelligence which resulted in a retaliatory attack against a Ukrainian telecommunications provider (see Sibylline Cyber Daily Analytical Update – 13 December 2023).
  • The Chinese state-sponsored group ‘Volt Typhoon’ is using a new botnet (‘KV-botnet’) to compromise small office/home office (SOHO) routers in a new campaign (see Sibylline Cyber Daily Analytical Update – 14 December 2023 and our Technical analysis below).
  • The Russian state-sponsored threat actor ‘APT29’ is exploiting an existing software vulnerability in TeamCity’s software to target global organisations (see Sibylline Cyber Daily Analytical Update – 15 December 2023).

Technical analysis of weekly stories

Andariel, a sub-group of the North Korean threat group Lazarus, is targeting agricultural, manufacturing and security companies in a campaign dubbed ‘Operation Blacksmith’. The campaign exploits a two-year-old software vulnerability (‘Log4Shell’) for initial access to a network to deploy three new malware strains (‘NineRAT’, ‘DLRAT’ and ‘BottomLoader’). The malware strains are written in Dlang, an uncommon coding language in cyber criminal operations. NineRAT uses Telegram as its command-and-control (C2) channel, likely to evade network and host detection measures. It contains components to write itself on the infected device so as to establish persistence. DLRAT acts as both a downloader and a remote access trojan (RAT) to deploy additional malware and receive commands from the C2. BottomLoader downloads and executes the next-stage payload (‘HazyLoad’). It can also establish persistence for the new payloads.

Some non-exhaustive recommendations to mitigate against this threat include:

  • Add available Indicators-of-Compromise (IoCs) to the organisation’s security detection systems to identify potentially malicious samples on the network
  • Ensure there are adequate security detection measures in place, including end-point detection and response (EDR) solutions (such as anti-virus software)
  • Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing attempts, to understand not to click on unknown or untrustworthy links and to avoid visiting suspicious sites
  • Ensure patches are applied immediately after they are released by the affected software provider to prevent unnecessary exploitation

The Chinese threat actor Volt Typhoon is using a new botnet, KV-botnet, to infect home routers to obtain access to targeted corporate networks as part of a supply chain campaign. The SOHO botnet is comprised of two activity clusters (KV and JDY) with the KV cluster used for manual malicious operations against high-value targets that are chosen by the JDY cluster. The KV botnet consists of routers from Cisco, DrayTek Vigor, NETGEAR PROSAFE and Axis IP cameras. The malware infection process for these devices consists of three separate phases, though it is unclear how the initial infection occurs. Botnets are used to mimic normal endpoint traffic and obfuscate its behaviours as existing processes to evade detection.

Some non-exhaustive recommendations to mitigate against this threat include:

  • Monitor devices for suspicious traffic and activity
  • Ensure there are adequate security detection measures in place, including end-point detection and response (EDR) solutions (such as anti-virus software)
  • Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing attempts, to understand not to click on unknown or untrustworthy links and to avoid visiting suspicious sites
  • Ensure endpoint devices have proper privileges established to mitigate against potential abuse or unapproved privilege escalation
  • Ensure routers and other devices are segmented from the main corporate network and require verification to prevent lateral movement
  • Ensure endpoint devices maintain adequate security measures, including patch management and robust security mechanisms

The MITRE ATT&CK framework is a globally accessible documented collection of information detailing the malicious behaviours of cyber threat actors; it is used as the foundation for organising the processes which threat actors execute during cyber operations. It provides an encyclopaedic reference for organisations, highlighting the tactics, techniques and procedures (TTPs) cyber actors employ in campaigns, while also providing suggestions for detecting and mitigating against specific TTPs to bolster organisations’ security mechanisms. The framework organises a threat actor’s entire operational lifecycle from reconnaissance to exfiltration and impact.

Word of the week

Our cyber word of the week: Botnet

(Source: Sibylline)

 

14 Dec 23. Northrop Grumman Corporation’s (NYSE: NOC) Integrated Battle Command System (IBCS) continues to demonstrate its role as the transformational cornerstone of the U.S. Army’s air and missile defense through its recent integration of the Lower Tier Air and Missile Defense Sensor (LTAMDS). During advanced live fire flight tests in November and December at White Sands Missile Range, New Mexico, with LTAMDS, IBCS once again demonstrated its ability to integrate sensors and effectors, fusing data across the battlespace to defeat complex air and missile threats.  During these recent tests, IBCS successfully:

  • Detected, identified, and maintained an accurate composite track of incoming low- and high-altitude threats by processing LTAMDS data.
  • Engaged and defeated an air-breathing cruise missile surrogate and a theater ballistic missile surrogate through fire control of a Patriot Advanced Capability – 3.

Northrop Grumman integrated the developmental LTAMDS sensor into IBCS, adding to the system’s ability to provide full battlespace awareness. The IBCS-enabled LTAMDS will replace existing Patriot radars when fielded in 2027.

Expert:

Rebecca Torzone, vice president and general manager, combat systems and mission readiness, Northrop Grumman: “Integrating LTAMDS into IBCS marks another critical milestone achieved for this unrivaled battle command system that continues to reshape the battlespace across multiple missions, optimizing current and future networked air and missile defense in a cost-effective manner. With the U.S. Army and global partners, Northrop Grumman will continue to advance IBCS as a paradigm-shattering system able to defeat the threats of today and tomorrow.”

Details on IBCS and LTAMDS:

IBCS is a revolutionary command and control system unifying current and future assets in the battlespace, regardless of source, service, or domain. Through its modular, open, and scalable architecture, IBCS gives warfighters capabilities not previously available by fusing sensor data for a single actionable picture of the full battlespace, enabling rapid, informed decisions to optimize shooters. This capability extends the battlespace, giving warfighters more time to make decisions on how best to defeat threats. IBCS is the centerpiece of the U.S. Army’s modernization strategy for air and missile defense.

LTAMDS is the U.S. Army’s next generation air and missile defense radar. The 360-degree, active electronically scanned array radar provides advanced performance against a range of threats, including manned and unmanned aircraft to cruise missiles, ballistic missiles and hypersonics.

14 Dec 23. Global: New botnet targeting SOHO devices elevates cyber espionage, operational risks to firms. On 13 December, the security firm, Lumen, reported on a new botnet (‘KV botnet’) being used to compromise small office/home office (SOHO) routers in a new campaign by the Chinese state-sponsored group, ‘Volt Typhoon’. The botnet targets NETGEAR and DrayTek routers to conceal malicious activity and then exploits those SOHO devices to move laterally to connected corporate networks. It is unclear how the KV botnet initially infects the SOHO devices. However, the malware is likely distributed via a multi-phase infection process. The recent infection of Axis IP cameras and changes to the KV botnet’s infrastructure indicate that Volt Typhoon is likely preparing a new operation that could occur around the holiday season when organisations tend to be shorter-staffed. Volt Typhoon primarily targets critical sectors for espionage and disruption, therefore these sectors face heightened exploitation risk into 2024. (Source: Sibylline)

 

12 Dec 23. Let There Be Light. Military interest in optical wireless communications is growing. In April, the US Army procured the Kitefin Li-Fi system shown here to support operations in Africa and Europe following a 2019 pilot study.

How can optical wireless communications help militaries satisfy their insatiable appetite for data as the radio spectrum becomes more congested and contested?

Much of Armada’s military communications coverage focuses on conventional radio and Satellite Communications (SATCOM) technology. However, other communications techniques are coming to the fore. Optical Wireless Communications, OWC for short, is one such example. Visible, infrared and ultraviolet light can all be used to move voice and data traffic. Light typically occupies a segment of the electromagnetic spectrum stretching from three terahertz up to three petahertz.

OWC is beyond the spectrum’s radio segment and has garnered military interest in recent years. In April 2023, the US Army announced a purchase of pureLiFi’s Kitefin Li-Fi (Light Fidelity) system. Kitefin Li-Fi was procured to support the US Army in Europe and Africa. The acquisition followed a 2019 US Army pilot study of the technology. In 2021, two researchers from Maharshi Dayanand University in Haryana, northern India, published an instructive paper entitled Emerging Military Applications of Free Space Optical Communication Technology: A Detailed Review. Papers have also been published by the US Army looking at OWC to support tactical communications.

Benefits

One of OWC’s key attractions is that, as it does not use the radio spectrum, it is not subject to the congestion and contention that characterises military use. Military radar, SATCOM and conventional communications must share, and occasionally yield, some of the spectrum to civilian users. This has the corresponding effect of reducing available radio spectrum for the military.

In addition, the radio spectrum is a contested place. Adversaries seek to deny its use by their opponents, even in peacetime. Witness recent examples of Global Navigation Satellite System (GNSS) disruption in the Black Sea. This disruption has been blamed on GNSS jamming by Russian naval vessels active there. The jamming is believed to be performed to protect Russian vessels from targeting by GNSS-guided weapons.

One key benefit of OWC is that it can potentially carry mind-bending quantities of data. Li-Fi technology, according to reports, can achieve data rates of one gigabit-per-second/gbps. Eavesdropping on optical wireless communications is challenging. Anyone wanting to intercept the communications will have to be so close to the beams of light that they could risk disrupting the link. An interruption would deprive them of the traffic they wish to exploit and alert legitimate users that something might be amiss if the link suddenly goes down.

OWC is clearly an emerging technology with much to offer military communications with some forces, notably the US Army, already taking the plunge. It was noteworthy that this year’s United Kingdom Defence Science and Technology Laboratory’s Operating in the Future Electromagnetic Environment (OFEME) symposium had a presentation on optical wireless communications.

Professor Harald Haas, chair of mobile communications at the University of Edinburgh, Scotland and co-founder and chief scientific officer of pureLiFi took delegates through some recent OWC developments. As noted above, capacity is a key benefit heralded by optical wireless communications. One terabit-per-second of data is needed to send a moving holographic human face across a link in real time. At a rate of ten bits-per-second such a task could require bandwidths of up to 100 gigahertz. This could simply overwhelm what is possible using current radio systems and available spectrum. Laboratory experiments cited by Prof. Hass have shown data rates of up to 105 gigabits-per-second using lasers.

Experiments

Prof. Haas and his colleagues have been involved in experiments on behalf of the North Atlantic Treaty Organisation’s (NATO’s) Science and Technology Organisation. Work has included examining ship-to-ship optical communications over distances of between 200 metres (656 feet) and 1.1 nautical miles (two kilometres). Data rates of between six gigabits-per-second and 600 megabits-per-second respectively were achieved during these experiments. The effect of the roll and movement of the ships on the communications was mitigated by tracking systems which ensured the two lasers remained precisely aligned. This helped avoid gaps in transmission.

OWC is not a panacea but neither is any single form of electromagnetic communications. For example, terahertz communications, which Armada has discussed in the past hold, promise regarding wideband links. Optical wireless communications, like terahertz, avoids a crowded radio spectrum promising impressive data rates. Militaries in the future will use an ensemble of links from conventional radio through to terahertz and optical capabilities to ensure connectivity. Thanks to optical wireless communications, the future is looking bright.

(Source: Armada)

 

11 Dec 23. How Hamas Talks. A raid by the Israeli Defence Force on Gaza City’s Al-Shilfa Hospital netted materiel the IDF claims was being used by Hamas including civilian handheld radios, examples of which can be seen here on the right-hand side of the large table in this picture.

Clues emerge concerning the communications systems Hamas relies on as hostilities continue in the Gaza Strip.

Israeli Defence Force (IDF) troops entered Gaza City’s Al-Shifa Hospital on 15th November, a facility the IDF asserted was being used by Hamas insurgents. The force had laid siege to the hospital since 11th November. The IDF had claimed that Hamas cadres were using a bunker buried below the hospital as a headquarters. Hamas denied this allegation. The Israeli government commenced military operations against Hamas from 7th October. Earlier that day Hamas insurgents attacked several targets in Israel killing and injuring over 8,600 people, taking a further 240 people hostage. 72 have since been released in exchange for Palestinian prisoners.

Following the raid, the Israeli government placed photographs on social media of what it claimed was Hamas materiel left at the facility. One of the pictures gives an insight into the tactical communications used by Hamas fighters. Four civilian-standard handheld radios, along with a single cellphone, can be seen laid out on a table. The use of such communications systems is corroborated by publicly available pictures of Hamas fighters. These photographs show civilian standard handheld radios affixed to Hamas fighters’ webbing.

Civilian radios

A study of some of these devices reveal that they may be Puxing PX-UV973 handheld, dual-band radios. The manufacturer’s information says these carry traffic across Very High Frequencies (VHF) of 136 megahertz/MHz to 174MHz and Ultra High Frequencies (UHF) of 400MHz to 470MHz. The radio produces five watts of VHF output power and four watts of power in UHF but with a range unlikely to be longer than a few kilometres. Ranges maybe further shortened on account of the dense built-up urban terrain of Gaza’s main conurbations. Moreover, these devices appear to lack any robust communications/transmission security. The Israeli Intelligence Corps’ Unit 8200 Signals Intelligence (SIGINT) service had routinely eavesdropped on Hamas handheld radios. Nonetheless, it ceased this activity in 2022. Israeli media reports stated that Unit 8200 believed this activity to be a “waste of effort.”

Cellphones have appeared in other pictures previously released by the Israeli government of equipment it says the IDF captured from Hamas, publishing photographs to this effect in 2021. These show a mix of legacy cellphone handsets and more modern smartphone designs. According to the Stockholm International Peace Research Institute (SIPRI) the Islamic Republic of Iran and the Democratic People’s Republic of Korea (DPRK) supply materiel to Hamas. SIPRI is a non-profit organisation based in the Swedish capital that studies conflict, the arms trade and the global defence industry.

Iran is home to companies which research, develop and produce tactical communications systems; Iran Communications Industries and the Tactical Communications Research Centre being two. Meanwhile, Glocom is a company with a presence in Malaysia. Despite Glocom’s Kuala Lumpur address it is believed to be a front company enabling the DPRK government to sell kit while avoiding United Nations sanctions. Glocom’s products include tactical radios. The DPRK remains under international sanctions because of her clandestine weapons of mass destruction programmes.

Military grade?

Two of Hamas’ alleged benefactors produce tactical radios including handheld, vehicular and backpack systems, yet no evidence appears in the public domain of Hamas using such kit. This prompts several questions: Firstly, is Hamas even in possession of such equipment? Photographic evidence would suggest not. Perhaps this is not surprising? The Iranian government maybe reluctant to supply its own tactical communications systems to Hamas lest they fall into the hands of the IDF. It would be safe to assume that Israeli SIGINT experts are already familiar with Iranian tactical communications. Why would Tehran take the risk, particularly if Hamas cadres can perform operations with handheld radios and cellphones? What about Glocom radios, or even tactical radios sourced from the People’s Republic of China (PRC)? Once again, perhaps the governments of these countries are reticent to supply this equipment should it end up in Israeli hands. Israel and the United States maintain a close defence relationship. There is every chance that captured DPRK or PRC tactical radios could yield their secrets to American, as well as Israeli, SIGINT experts.

Iranian defence electronics companies produce tactical radios such as the handheld transceiver shown here. However, systems like these do not appear to have been supplied to Hamas. Is this because the Iranian military are fearful of these radios being captured and analysed by Israeli SIGINT experts?

Comms doctrine

There is the possibility that Hamas does not need anything more sophisticated for the type of operations it performs.  The movement’s tactical communications doctrine may focus on handheld radio and cellphone use. Handheld systems may provide basic squad communications with cellphones linking upwards to higher echelons of command. Likewise, Hamas fighters may carry cellphones as a backup should their handheld communications be unavailable for any reason.

Moreover, reports showing an alleged Hamas command and control centre do not appear to show any military-grade radios in this facility. Instead, Hamas commanders are using what seem to be standard civilian landlines for communications. Given the extensive tunnel network Hamas has built below Gaza, communications with subterranean cadres are most likely performed using standard landlines. Radio can become temperamental when used underground.

For now, Hamas does not appear to be employing anything more sophisticated for communications than civilian handheld radios, cellphones and landlines. Such devices and links will be relatively easy to exploit for communications intelligence. Nonetheless, the work of SIGINT experts exploiting Hamas communications could become harder if the organisation receives military-grade radios from its backers in the future. (Source: Armada)

 

13 Dec 23. The Transporter. The US Space Development Agency is moving ahead with a large constellation of low Earth orbit satellites to support missile attack early warning and enhance SATCOM availability.

An artist’s rendering of the T2TL LEO satellite constellation. This graphic shows how the constellation can rapidly share information on ballistic missile launches over wide areas.

In late October, the United States’ Space Development Agency (SDA), itself part of the US Space Force (USSF), awarded contracts to build a constellation of 100 satellites. Known as the Tranche-2 Transport Layer (T2TL), the contract will provide “global communications access” in the words of an SDA press release.

Specifically, T2TL will provide encrypted communications to support beyond line-of-sight targeting, missile warning and missile tracking missions. T2TL forms a key part of the US Department of Defence’s (DOD’s) Proliferated Warfighter Space Architecture (PWSA). In a nutshell, the PWSA will develop, field and operate constellations of Low Earth Orbit (LEO) satellites. Established definitions state that LEO satellites orbit at altitudes below 2,000 kilometres/km (1,200 miles).

As a 2022 article in on the payloadspace.com website noted, the logic behind the PWSA is to take advantage of the cost and replaceability benefits of LEO satellites. Their lightweight and small size means that LEO spacecraft are less expensive to launch than their conventional counterparts. These cost reductions also mean they are less expensive to replace making them a relatively ‘disposable’ asset. Once launched, they will form part of the space connectivity for the DOD’s Joint All-Domain Command and Control (JADC2) system. More details on the composition and goals of JADC2 can be found here.

The T2TL satellites are being procured via two Other Transaction Authority prototype agreements worth a total of $1.3 bn. The two recipients are York Space Systems and Northrop Grumman. The former will deliver and operate 62 T2TL spacecraft with the latter delivering and operating 38.

Ka-band and Link-16

The SDA envisages an eventual fleet of between 300 and 500 satellites. The agency says that these LEO satellites will be placed at varying altitudes from 730km (394 miles) to 1,200km (648 miles) above Earth. The satellites will use optical inter-satellite crosslinks to move traffic between them. Traffic to and from Earth will be carried across Ka-band (26.5GHz to 40GHz uplink/18GHz to 20GHz downlink) channels.

Connectivity with Link-16 (960MHz to1.215GHz) Tactical Datalinks (TDLs) and the Integrated Broadcast System (IBS) will also be provided. Each satellite will carry a Link-16 payload. The IBS is an Ultra High Frequency (300 megahertz to three gigahertz) global US Army operational/tactical network. The key mission of the IBS is to facilitate delivery of the near real time intelligence to soldiers anywhere on Earth. Jonathan Withington, an SDA spokesperson, told Armada that the T2TL satellites will “provide the warfighter access to low-latency data connectivity via space-based extensions to existing tactical datalinks.” Employing Link-16 means US allies using this TDL can move data moved across the constellation, Mr. Withington continues.

Crucially the use of Link-16 and Ka-band makes the constellation compatible with communications systems already used by US forces. This removes the need to procure new SATCOM terminals so that personnel can access the T2TL. “To deliver capabilities into the hands of the warfighter, we must abide by our guiding principles, one of which says whatever we put up in our architecture must be compatible with receivers warfighters already use,” said Mr. Withington.

The T2TL constellation does not replace any existing US DOD constellations. Instead, it provides additional resilient satellite communications. The SDA press release continued that the T2TL satellites will be launched no later than September 2026. Mr. Withington said that he expects full deployment of the T2TL by 2027. US Space Force will operate the constellation from Redstone Arsenal, Alabama and Grand Forks airbase, North Dakota. (Source: Armada)

 

13 Dec 23. Pentagon eyes successor to Joint Warfighting Cloud Capability contract. One year after awarding the multibillion-dollar Joint Warfighting Cloud Capability contract, designed to centralize the military’s vast data-management needs, the U.S. Department of Defense will begin exploring a successor early in 2024.

The department tapped Amazon, Google, Microsoft and Oracle to supply digital services for the JWCC, itself the follow-up to the failed Joint Enterprise Defense Infrastructure venture, or JEDI, in December 2022 in an award worth as much as $9 bn over three to five years. The companies are in competition with one another for task orders, and each is only guaranteed $100,000.

Dozens of orders totaling hundreds of ms of dollars have already been logged using JWCC. The arrangement spans unclassified, classified and top-secret designations and is meant to connect far-flung front lines with established headquarters.

“When we announced JWCC, it was a three-year base with two option years, and we’re already in the one-year base of this,” Chief Information Officer John Sherman said Dec. 13 at the DODIIS Worldwide Conference in Portland, Oregon. “We said all along, in ‘24, in that timeframe, we’re going to start looking at what comes next.”

Sherman provided no timeline for what the Defense Department has previously advertised as full and open multi-cloud and multi-vendor competition. He did say, though, the Defense Information Systems Agency will play a key role in “JWCC 2.0.” DISA is the department’s de facto information technology authority.

“We are firmly committed to mutli-cloud, multi-vendor, and this is what we’re going to be doing moving forward,” Sherman said. “Watch this space. More to follow.”

The JWCC is considered the backbone of the Defense Department’s Combined Joint All-Domain Command and Control initiative, or CJADC2, in which forces and their databases across land, air, sea, space and cyber are interlinked.

Cloud is increasingly seen as a means to get the right data to the right people at the right time — the tenet of CJADC2. Sherman earlier this year instructed defense agencies, military services and other offices to prioritize JWCC, especially when cutting deals concerning the nation’s most sensitive information.

“The JWCC is not a cloud management or hosting environment,” he said in a memo made public in August, “but rather a key vehicle in the department’s technology arsenal for the acquisition of services for current and future DoD component managed and controlled cloud environments.”

Sherman’s directions for JWCC employment included carve outs for the National Reconnaissance Office, National Geospatial-Intelligence Agency, Defense Intelligence Agency and the National Security Agency. They rely on the intelligence community’s Commercial Cloud Enterprise, or C2E, which was awarded in 2020. It features the same vendors as JWCC, plus IBM. (Source: C4ISR & Networks)

 

11 Dec 23. Flashpoint and Scale AI Forge Strategic Partnership to Empower Government Clients With AI-Enhanced Threat Intelligence.

Integration of Flashpoint’s Leading Open-Source Intelligence With Scale’s Donovan AI Platform Bolsters National Security Through Accelerated Decision-Making and Expedited Workflows.

Flashpoint, the leader in high-fidelity threat intelligence and data-driven insights, and Scale AI, whose proprietary data engine powers the most advanced large language, generative, and computer vision models with high-quality data, announced today a groundbreaking partnership that unites Donovan, Scale’s AI-powered decision-making platform, with Flashpoint’s pioneering open-source intelligence. This strategic alliance promises to advance intelligence and security operations for government agencies, including the U.S. Department of Defense and Intelligence Community, substantially enhancing their ability to tackle complex global security challenges with advanced threat detection and in-depth analysis.

“Merging Scale’s advanced AI technology with Flashpoint’s unparalleled intelligence and data isn’t just about setting a new industry standard; it’s about revolutionizing how government agencies manage national security challenges in today’s digital landscape,” said Andrew Makridis, the former COO of the Central Intelligence Agency who serves on the advisory boards of both Scale and Flashpoint National Security Solutions (FNSS), a dedicated Flashpoint business unit that serves the unique needs of national security organizations. “This partnership will enable agencies to quickly adapt to emerging threats and leverage data-driven insights for strategic operations.”

“Flashpoint’s collaboration with Scale AI represents a significant expansion of our capabilities in national security intelligence,” said Flashpoint CEO Josh Lefkowitz. “Our tailored, actionable intelligence perfectly complements Scale’s AI technology, enhancing our ability to help organizations in the public sector identify and address evolving security challenges effectively.”

“Our partnership with Flashpoint is a game-changer. Through our Donovan LLM platform, we are helping analysts in the cyber and infrastructure security domain take advantage of the data trove Flashpoint delivers. We are enhancing decision-making and security frameworks for our government clients,” said John Brennan, General Manager of Scale AI’s Public Sector business unit. “We chose Flashpoint for their unparalleled cyber intelligence depth and actionability, a cornerstone in our joint efforts to fortify national and homeland security through artificial intelligence.”

Flashpoint will discuss the advanced capabilities from our partnership with Scale AI at booth #1937 during 2023 DoDIIS Worldwide Conference in Portland, Oregon, starting December 12. Visit our booth to learn about how this partnership will equip national security teams with the essential data, intelligence, and insights needed for mission success.

Flashpoint National Security Solutions (FNSS)

FNSS is a dedicated Flashpoint business unit that serves the unique needs of national security organizations. FNSS partners with teams across defense, federal law enforcement, federal civilian agencies, state and local government, and the intelligence community, to enhance global situational awareness and drive mission success through industry-leading technology and intelligence expertise.

About Flashpoint

Trusted by governments, commercial enterprises, and educational institutions worldwide, Flashpoint helps organizations protect their most critical assets, infrastructure, and stakeholders from security risks. Leading security practitioners—including physical and corporate security, cyber threat intelligence (CTI), fraud, vulnerability management, national security, and vendor risk management teams—rely on Flashpoint’s Ignite platform and its team of intelligence analysts to proactively identify and mitigate risk and stay ahead of the evolving threat landscape. Discover more at flashpoint.io or join the conversation on LinkedIn, Twitter, and YouTube.

About Scale

Scale unlocks AI for every industry. Our proprietary data engine powers the most advanced large language, generative, and computer vision models with high-quality data. Our experience partnering with leading AI companies allows us to provide the blueprint for any organization to apply AI. Scale is trusted by industry leaders including Meta, Microsoft, U.S. Army, DoD’s Defense Innovation Unit, Open AI, Cohere, Anthropic, Stability AI, General Motors, Toyota Research Institute, Brex, Instacart and Flexport. (Source: BUSINESS WIRE)

 

12 Dec 23. Global: Pre-existing vulnerabilities continue to pose elevated exploitation, infection risks to firms. On 11 December, the security firm Cisco Talos reported that the North Korean group, ‘Andariel’, (a sub-group of ‘Lazarus’ group) is deploying three new malware strains against victims using a two-year-old software vulnerability for access. Of the three malware strains, two are remote access trojans (‘NineRAT’ and ‘DLRAT’) and one is a downloader (‘BottomLoader’). The new strains are all written in the D programming language which is rarely observed used in cyber criminal operations, highlighting Andariel’s ongoing advancement and employment of new tactics to evade detection. The campaign using these malware strains, ‘Operation Blacksmith’, began in March 2023, targeting agricultural, manufacturing and security companies globally. The campaign exploits the two-year-old software vulnerability, ‘Log4Shell’ (CVE-2021-44228), underlining the ongoing lack of adequate patch management processes by enterprises globally. This will sustain elevated exploitation and infection risks by Andariel and other threat actors for firms. (Source: Sibylline)

 

12 Dec 23. Lockheed’s helicopter-borne jammer ‘defeats threats’ in US Navy test. Lockheed Martin said it successfully tested an electronic warfare pod it’s developing for use in helicopters to detect and deceive anti-ship missiles.

Trials of the Advanced Off-Board Electronic Warfare system, or AOEW, were conducted in collaboration with the U.S. Navy at Naval Air Station Patuxent River in Maryland. The jammer demonstrated the “ability to defeat threats” while mounted to a Sikorsky MH-60R helicopter, typically used for anti-submarine warfare, the company said Dec. 12.

Finer details about electronic warfare performance and programming are often not disclosed due to their sensitivity.

“The AOEW system is one of the most advanced, complex electronic warfare systems ever developed,” Deon Viergutz, vice president of spectrum convergence at Lockheed, said in a statement. “AOEW is a force multiplier for our sailors that will help them dominate and control the battlespace without ever firing a single shot.”

The U.S. military is attempting to reinvigorate its electronic warfare arsenal after years of post-Cold War atrophy. Weapons guidance, friendly communications and suppression of enemy observations all rely on manipulation of the electromagnetic spectrum. Access to the precious resource is expected to be hotly contested in a fight against Russia or China.

The AOEW is meant to extend a ship’s defense, which can be hamstrung by limited line of sight or slow, deliberate maneuvering. The system can work independently aboard the helicopter — either the MH-60R, as was tried, or the MH-60S — and can tie back to other systems aboard a vessel.

“It is designed with evolutionary capabilities, set up to be completely programmable so that it can develop, deliver and deploy new techniques as the threat landscape changes,” Viergutz said.

The AOEW was previously evaluated at Lockheed’s facility in Syracuse, New York. Reporters visiting in early November were shown the pod. Further testing with helicopters is planned for 2024, and Lockheed will incorporate the feedback. Delivery of the first AOEW units is expected in the coming year.

Lockheed is the largest government contractor in the world when ranked by defense-related revenue, according to Defense New Top 100 analysis. The Maryland-based company earned $63.3bn in 2022. (Source: C4ISR & Networks)

 

11 Dec 23. DISA launches cloud-based electronic warfare planning tool.

The Defense Information Systems Agency is rolling out software it says is critical to preparing and executing electronic warfare operations across the U.S. military.

The cloud-based Electromagnetic Battle Management-Joint tool, or EMBM-J, collates multiple streams of data into a simplified, shared interface for commanders. The first iteration is aimed at improved situational awareness and coordination across the services; future upgrades will bolt on additional applications.

“Command and control applies to both maneuver, offensive actions and defensive actions, how you array your forces, how you guide and direct them to execute missions, to meet the intent,” Kevin Laughlin, the deputy director for the Program Executive Office for Spectrum, told reporters Dec. 8. “And we want to do that within the electromagnetic spectrum domain.”

The Department of Defense is again prioritizing electronic warfare — and the manipulation of the spectrum, a precious resource — as it digs out of the Greater Middle East to confront the global ambitions of Russia and China.

Investment in sophisticated electronic warfare fell off in the years following the Cold War.

“What this does today, that warfighters don’t have in their hands, is that it provides the ability to bring a number of different information feeds, a number of different data sources, together in one picture,” Laughlin said. “That, more than anything else, allows the joint force to make sense and act much more quickly.”

As a result, EMBM-J aids the Defense Department’s pursuit of seamless connectivity known as Combined Joint All-Domain Command and Control, or CJADC2.

The software was specifically designed to work with the services’ existing visualizers and planners, such as the Army’s Electronic Warfare Planning and Management Tool and the Navy’s Real Time Spectrum Operations. A common data layer makes the sharing possible.

“Effective use of the electromagnetic spectrum is essential for successful military operations,” Air Force Brig. Gen. AnnMarie Anthony, director of the Joint Electromagnetic Spectrum Operation Center, said in a statement. “This system is crucial for the full integration and visualization of spectrum operations.” (Source: Defense News Early Bird/C4ISR & Networks)

 

11 Dec 23. Global: Ongoing sophistication of TTPs underscores elevated espionage risk for critical sectors. On 7 December, the US Cybersecurity and Infrastructure Security Agency (CISA) released an advisory alongside other governmental organisations from Australia, Canada, New Zealand and the UK (Five Eyes) on Russian threat actor ‘Star Blizzard’ utilising increasingly sophisticated tactics in ongoing espionage operations. Their most recent campaign conducts reconnaissance on potential victims and develops rapport prior to sending phishing emails. The group harvests credentials and session cookies to bypass two-factor authentication and employs new evasion tactics to prevent detection, underscoring their growing sophistication. Star Blizzard is almost certainly associated with the Russian Federal Security Service’s (FSB) Centre 18, highlighting Russia’s complex and robust cyber espionage operations with multiple security departments responsible for cyber operations. Star Blizzard targets the academia, defence, government, NGOs, think tanks and diplomatic sectors. Since 2022 the threat group has expanded to defence-industrial and energy sector targets. As Western relations with Russia remain strained, cyber espionage operations from Russian actors will continue against the Five Eyes alliance. (Source: Sibylline)

 

09 Dec 23. US Army eyes overhaul of theater-level signals intelligence tools. The U.S. Army plans to bundle existing signals-intelligence technologies already employed by commanders into a program of record in fiscal 2025. By doing so, the service hopes to more effectively sustain and modernize the so-called Theater SIGINT System, or TSIGS, officials involved with the effort said Dec. 5. The overall system is a collection of products that were quickly developed and deployed to counter pressing concerns; a less piecemeal approach is expected moving forward.

“It’s a conglomeration of existing capability that is out in the field today supporting theater intelligence collection,” Ken Strayer, a project manager at the Program Executive Office for Intelligence, Electronic Warfare and Sensors, or PEO IEW&S, told reporters. “These are the systems that have been built, in the quick-reaction capability world, in operation.”

The U.S. Defense Department is reassessing its technology spending and strategies as it pivots away from counterinsurgency operations to confront the global threats of Russia and China. The department is putting a premium on digital weaponry and advanced sensors, including jammers, hacking tools and devices that can quickly cue onto communications.

The Army is also leaning into larger formations, such as the division and corps, to conduct future fighting. The brigade, long relied upon in the Greater Middle East, is not suited for the expansive battles envisioned across Europe or the Indo-Pacific, according to service officials.

The TSIGS bundle is designed to “really provide the tactical commanders, at echelons above corps, with a forward deployable and remotely, or even locally, controlled signals-intelligence system,” Brig. Gen. Ed Barker, the leader of PEO IEW&S, said. “We were designated as the office of primary responsibility for that effort this year.”

The executive office Barker heads up helps build and upgrade everything from reconnaissance payloads to missile-warning suites to biometric tools. (Source: C4ISR & Networks)

 

08 Dec 23. Cyber Update Key points.

  • A new backdoor, ‘Agent Racoon’, is being used in suspected cyber espionage operations against organisations in Africa, the Middle East and the US (see Sibylline Cyber Daily Analytical Update – 4 December 2023 and our Technical analysis below).
  • A new threat actor, ‘AeroBlade’, was observed targeting a US aerospace organisation in a suspected cyber espionage operation (see Sibylline Cyber Daily Analytical Update – 5 December 2023 and our Technical analysis below).
  • Elsewhere, the Russian state-sponsored threat group, ‘APT28’, is actively exploiting a vulnerability in Outlook email services to obtain unauthorised access to accounts on Exchange servers (see Sibylline Cyber Daily Analytical Update – 6 December 2023).
  • Unknown threat actors are actively exploiting an existing software vulnerability to target US government entities (see Sibylline Cyber Daily Analytical Update – 7 December 2023).
  • Finally, a new remote access trojan (‘Krasue’) in targeting Thai telecommunications firms for long-term foothold in the network (see Sibylline Cyber Daily Analytical Update – 8 December 2023).

Technical analysis of weekly stories

A new backdoor, ‘Agent Racoon’, is being used in cyber operations against Africa, the Middle East and the US. The backdoor is written using the .NET software framework and uses the domain name service (DNS) protocol to establish a connection with the command-and-control (C2) server. The backdoor is capable of executing commands and uploading/downloading files. While it does not contain any mechanism to establish persistence, the backdoor executes scheduled tasks which ensures the backdoor remains on the infected machine. The developers behind the malware attempt to disguise the malware code as Google or Microsoft updates to evade detection. Agent Racoon is installed after threat actors obtain account credentials using ‘Ntospy’ and a customised version of ‘Mimikatz’, dubbed ‘Mimilite’. Mimilite and Agent Racoon were only used in attacks against non-profit and government organisations, indicating the likelihood that these are solely for cyber espionage purposes by possible state actors.

Some non-exhaustive recommendations to mitigate this threat include:

  • Add available Indicators-of-Compromise (IoCs) to the organisation’s security detection systems to detect potentially malicious samples on the network.
  • Ensure there are adequate security detection measures in place, including end-point detection and response (EDR) solutions (such as anti-virus software).
  • Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing attempts, prevent clicks on unknown or untrustworthy links, and avoid visiting sites that may be untrustworthy or suspicious.

A new threat actor ‘AeroBlade’ is targeting the United States’ aerospace industry to conduct corporate cyber espionage. The campaign initiates with phishing emails directed at target organisations, with a document containing malicious code that installs a reverse shell payload. Once a user enables content on the phishing document, the final payload drops which is a dynamic link library (DLL) that acts as a reverse shell to connect to a hard-coded C2 server. The reverse shell allows AeroBlade to open specific ports on an infected machine that enables the actor complete control over the device. Persistence is obtained via Windows Task Scheduler. The most recent July 2023 campaign also uses anti-analysis techniques, underscoring the rapid development of the actor’s operations.

Some non-exhaustive recommendations to mitigate this threat include:

  • Monitor devices for suspicious traffic and activity.
  • Ensure there are adequate security detection measures in place, including end-point detection and response (EDR) solutions (such as anti-virus software).
  • Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing attempts, and prevent clicks on unknown or untrustworthy links.

Frequency of TTPs during this monitoring period: LOW frequency, MODERATE frequency, HIGH frequency

The MITRE ATT&CK framework is a globally accessible documented collection of information detailing the malicious behaviours of cyber threat actors; it is used as the foundation for organising the processes which threat actors execute during cyber operations. It provides an encyclopaedic reference for organisations, highlighting the tactics, techniques and procedures (TTPs) cyber actors employ in campaigns, while also providing suggestions for detecting and mitigating against specific TTPs to bolster organisations’ security mechanisms. The framework organises a threat actor’s entire operational lifecycle from reconnaissance to exfiltration and impact.

Word(s) of the week

Our cyber word(s) of the week: Command and Control (C2)

(Source: Sibylline)

————————————————————————-

Spectra Group (UK) Ltd

 

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————-

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT