Sponsored by Spectra Group
————————————————————————
27 Dec 23. Japan to develop AI with US for ‘Loyal Wingman’ UAVs. Japan and the United States will conduct joint research to develop artificial intelligence (AI) for new unmanned aerial vehicles (UAVs) that will be used in a ‘loyal wingman’ role alongside the Global Combat Air Programme (GCAP) sixth-generation fighter aircraft.
The Japan Ministry of Defense (MoD) and the US Department of Defense (DoD) signed an agreement on 22 December to initiate a “project arrangement” for the joint research, Japan’s Acquisition, Technology & Logistics Agency (ATLA) said.
According to the US Air Force (USAF), the project is known as Overwhelming Response through Collaborative Autonomy. The project’s objective is to merge “state-of-the-art artificial intelligence and machine learning (ML) with advanced unmanned air vehicles”, the USAF said.
According to ATLA, the AI developed during this joint research “will be used to determine the behaviour of unmanned aircraft”. The USAF added that the AI “is expected to be applied to UAVs operated alongside Japan’s next-generation fighter aircraft”. (Source: Janes)
27 Dec 23. First RAAF KC-30A gets comms-cyber upgrade. The first Royal Australian Air Force (RAAF) Airbus KC-30A Multi Role Tanker Transport (MRTT) has received a communications and cyber upgrade.
Australia’s fleet of seven KC-30As are having their secure high-frequency (HF) and very-high frequency (VHF) radios, encryption device, and tactical datalink systems enhanced under the so-called Crypto Remediation Project (CRP), according to the Australian Department of Defence (DoD). Janes understands that these systems have been largely sourced from the United States.
The upgrade programme was first announced in October 2020. Airbus has previously said theCRP will elevate the Australian fleet to the “latest enhanced A330 MRTT” standard.
“These improvements aim to provide safer and more efficient communication and improve command, control, and situational awareness,” the DoD said in a statement. “Additionally, upgrades will increase KC-30A data throughput by 300 percent.”
(Source: Janes)
22 Dec 23. Cyber Update Key points.
- An Israel-linked hacktivist group claimed responsibility for a disruptive cyber attack targeting Iranian gas stations (see Sibylline Cyber Daily Analytical Update – 18 December 2023).
- The ‘Play’ ransomware group continues to pose elevated operational risks to firms across Europe, North America and South America according to a joint advisory from Australia and the US (see Sibylline Cyber Daily Analytical Update – 19 December 2023).
- Following the seizure of its dark website by law enforcement, ‘BlackCat’ ransomware group told its affiliates that they will receive increased commission for continuing operations while also removing operational restrictions against specific industries, including healthcare (see Sibylline Cyber Daily Analytical Update – 20 December 2023).
- Iranian threat group ‘OilRig’ is targeting African telecommunications organisations in a cyber espionage operation (see Sibylline Cyber Daily Analytical Update – 21 December 2023 and our Technical analysis below).
- The threat actor ‘UAC-0099’ is targeting Ukrainian employees in a phishing operation that exploits a software vulnerability to install malware (see Sibylline Cyber Daily Analytical Update – 22 December 2023).
Technical analysis of weekly stories
The Iranian threat group OilRig’s recent espionage campaign targeting African telecommunications organisations utilises a variety of tools, including the MuddyC2Go infrastructure, legitimate remote access tools, ‘Venom proxy’ and a custom keylogger. The MuddyC2Go backdoor is first launched via dynamic-link library (DLL) files that run a Powershell code to connect to the command-and-control (C2) server before installing the backdoor. The Powershell code contains variables at the beginning of the code, which is likely done to evade security software detection. OilRig uses two legitimate remote access tools (‘SimpleHelp’ and ‘AnyDesk’) to establish persistence, underscoring the group’s ability to exploit legitimate tools for malign activities. This is further highlighted by the group’s use of the publicly-available penetration testing proxy tool, Venom proxy, which the group used to develop its own custom build which has been operationalised in campaigns since mid-2022.
Some non-exhaustive recommendations to mitigate this threat include:
- Monitor devices for suspicious traffic and activity
- Add available Indicators-of-Compromise (IoCs) to the organisation’s security detection systems to identify potentially malicious samples on the network
- Ensure there are adequate security detection measures in place, including end-point detection and response (EDR) solutions (such as anti-virus software)
- Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing attempts
The MITRE ATT&CK framework is a globally accessible documented collection of information detailing the malicious behaviours of cyber threat actors; it is used as the foundation for organising the processes which threat actors execute during cyber operations. It provides an encyclopaedic reference for organisations, highlighting the tactics, techniques and procedures (TTPs) cyber actors employ in campaigns, while also providing suggestions for detecting and mitigating against specific TTPs to bolster organisations’ security mechanisms. The framework organises a threat actor’s entire operational lifecycle from reconnaissance to exfiltration and impact.
Word of the week
Our cyber word of the week: Persistence (Source: Sibylline)
21 Dec 23. Liberty Defense Holdings Ltd. (“Liberty” or the “Company”) (TSXV: SCAN) (OTCQB: LDDFF) (FRANKFURT: LD2A), a leading provider of Artificial Intelligence (AI) based weapons detection and physical security solutions for high risk and secure facilities, announced that HEXWAVE™ achieved outstanding results in recent U.S. military and government agency trials.
HEXWAVE is a walkthrough screening portal that uses AI and millimeter-wave technology to identify both metal and non-metal concealed weapons or other targeted items.
“These trials are tasked with assessing new technologies that have the potential to support antiterrorism and physical security measures as part of a larger commitment to Force Protection, which is a collaborative defense effort shared by all NATO nations. The effort is focused on dissuading attacks to safeguard military personnel, their families, facilities, and resources,” said Bill Frain, CEO of Liberty Defense. “HEXWAVE has been receiving increasing interest from facilities critical to national security and defense such as nuclear research labs and ports of entry.”
HEXWAVE was selected to participate in the trials, which took place over three days in October. The trials assessed the technology to determine its ability to detect concealed Person Borne IEDs (PBIEDs).
Results from Day 1 were calculated and released, and HEXWAVE was assessed to have an outstanding overall detection performance of 95%, with a false alarm rate of just 3.6%.
HEXWAVE scored highly on several variables including:
- Uninterrupted screening and high throughput, without the need for pauses or stops
- No requirement to remove personal items, such as cell phones, keys, and wallets
- Detection capabilities for both metal and non-metal items including liquids, powders, plastic explosives, incendiary devices, and unauthorized weapons like 3D-printed ghost guns
- A clean user interface that displays the location of the identified threat for efficient alarm clearing
- Portability, with quick and easy setup
“Detection targets used during the assessment were comprised of a range of materials including powders, liquids, gels, glass, metal, and plastics,” added Frain. “This is where HEXWAVE really shines, with its ability to detect items made of any number of materials, rather than just metal. This combined with its mobility has made it very attractive to prisons, courthouses, airports, hospitals, stadiums, government facilities, and more.”
Results from Day 2 and Day 3 of the trials are expected in early 2024.
HEXWAVE continues to garner increasing interest from high-security facilities, including those critical to national defense, ranging from nuclear research labs to ports of entry and more. This includes Los Alamos National Laboratory, and several airports including, Toronto Pearson, Denver International Airport, Los Angeles International Airport, the Port of Oakland, and a New Hampshire-based Regional Airport. The company also is working closely with the TSA directly on security initiatives. (Source: PR Newswire)
22 Dec 23. Mangata Networks Forges Strategic Collaboration with Microsoft to Pioneer AI-Enabled Edge Cloud Connectivity via Satellite. Mangata Networks, a global company offering satellite-enabled connectivity & intelligent edge computing solutions, has signed a partnership with Microsoft aimed at developing an AI-enabled edge cloud product connected via satellite. This partnership represents a long-term commitment between Mangata Networks and Microsoft, marking the beginning of a sustained collaborative journey aimed at continuously advancing cloud technology through innovative satellite connectivity.
Partnership Accelerates Azure Adaptive Cloud Adoption
Mangata will provide seamless connectivity and intelligent cloud computing services around the globe, bringing the benefits of Azure innovation anywhere in the world.
The network is powered by a multi-orbit constellation of HEO (highly elliptical orbit) and MEO (medium Earth orbit) satellites and a terrestrial network of edge data centers.
“We are thrilled to develop this transformative product in strategic collaboration with Microsoft, further enriching the Microsoft commercial marketplace ecosystem. Microsoft’s direct sales channels will play a crucial role in scaling our innovative solutions to enterprises globally. Our offering is not just a product but an all-encompassing network, infrastructure, platform, and software service. With capacity bundled into the service, we provide a seamless, integrated SLA that simplifies the adoption of our services for customers.” said Brian Holz, CEO of Mangata Networks. “This is more than a partnership; it is a long-term alliance set to redefine how enterprises leverage the cloud and intelligent edge compute.”
Innovative Features and SLAs Redefining Edge Cloud Connectivity and Business Transformation
A core element of the partnership is a deep commitment to innovation, where Mangata Networks will collaborate with Microsoft and execute against an integrated Edge-to-Space-to-Cloud product roadmap.
Leveraging Microsoft’s generative AI and data analytics capabilities, Mangata will, in close collaboration with Microsoft, re-imagine the entire product innovation lifecycle. These efforts will include integrating AI capabilities end-to-end; from customer and partner feedback and requirements definition through to how we roadmap, create, code, test, deploy, run, and support customer solutions. This initiative will result in delivering Azure adaptive cloud solutions, specifically designed to address unique and complex business problems at the edge, enabling and accelerating customer outcomes in a culturally sensitive way.
Mangata’s managed service will extend the geographical reach and functionality of Azure adaptive cloud. These collaborative solutions will deliver an array of innovative features, including AI-enhanced network routing at the edge, remote bandwidth optimization, workload management, real-time data processing, digital twin support, advanced satellite backhaul management, end-to-end cloud-edge IoT applications, 5G integration standardization, and multivendor sub-system integration (for example, ORAN and RAN-based equipment).
The Mangata and Microsoft solution using Azure will be made available through the Azure Marketplace, offering end-to-end application-level Service Level Agreements (SLA) with bundled connectivity. This comprehensive approach ensures a seamless experience for users seeking advanced and integrated solutions. Under the terms of the agreement, Microsoft will position Mangata as an Independent Software Vendor (ISV) on the Azure platform. This move will empower Mangata’s growth trajectory, with Microsoft providing substantial support in terms of technology, resources, engineering, as well as go-to-market backing.
Processing Data at the Best Location
With powerful edge compute and data management capabilities, customers can process data where it is created, reducing latency and time-to-insight by hosting advanced analytics and AI-inferencing at the edge. Valuable data, previously discarded due to lack of available bandwidth, can now be sent to cloud services like Microsoft Fabric, an end-to-end, unified analytics platform that brings together all the data and analytics tools organizations need -where it can be used to train and retrain AI models- to yield deeper operational insights.
For highly regulated organizations and governments, and for geographies with strict data sovereignty rules, applications can process sensitive data at the edge, keeping it within national or regional boundaries and only sending what is allowed to the public cloud.
“In collaboration with Mangata, we look forward to delivering an end-to-end Cloud and Edge platform to enterprise and government customers. This platform will enable business and mission critical applications anywhere with committed availability through satellite connectivity. Mangata will leverage Microsoft’s portfolio of Microsoft Azure Space and Azure for Operators to run their satellites’ constellation and edge platform. This collaboration is key for our continued commitment to empower our customers with intelligent, secure, and resilient technology.” said Mitra Azizirad, President and Chief Operating Officer, for Growth, Innovation and Strategy, Microsoft Strategic Missions and Technologies.
Addressing Global Challenges and Closing the Digital Divide
This collaboration is set to address critical challenges on a global scale related to sovereign state requirements, enterprise innovation, maritime and digital ocean transformation, data gravity, and telecommunications access and capacity needs. Mangata’s mission to empower the exchange of knowledge through global connectivity and to revolutionize access to the digital economy aligns with the Airband Initiative, a collaboration between Microsoft and the United States Agency for International Development (USAID) focused on closing the global digital divide by bringing internet access to all.
A New Era of AI-enabled Edge Cloud Computing
The pilot phase of the pre-integrated solutions in customer trial networks is scheduled to commence in the late 2nd quarter of 2024, ahead of Mangata’s planned constellation launch.
This initiative is poised to revolutionize the way businesses and governments worldwide harness the power of edge cloud connectivity through satellite technology. Together, Microsoft and Mangata will create a new platform for highly reliable, scalable, and robust IoT and SCADA applications at the edge, all connected to and managed by Azure. The collaboration marks a significant step toward a more connected, intelligent, and accessible future. This collaboration is not just a milestone but a starting point for a long-term journey between Mangata Networks and Microsoft, where both entities are committed to a lasting partnership that evolves with technological advancements.
About Mangata
Mangata Networks is a global, satellite-enabled network services and intelligent edge computing company. Founded in February 2020, Mangata has operations in the United States, United Kingdom, Singapore, and South Korea. Mangata is backed by an international group of investors including venture capital firms, economic development groups, and strategic partners.
Powered by a multi-orbit constellation and terrestrial network of intelligent data centers, Mangata provides secure, high-speed, low-latency connectivity that is affordable and accessible to all. With AI-enabled computing at the edge of the network, our customers can access cloud applications under a unified, global, and secure system – anywhere in the world. www.mangatanetworks.com
About Microsoft
Microsoft (Nasdaq “MSFT” @microsoft) enables digital transformation for the era of an intelligent cloud and an intelligent edge. Its mission is to empower every person and every organization on the planet to achieve more. (Source: PR Newswire)
20 Dec 23. 2024 will see the AI conveyor belt move faster. During the past five years we’ve seen the U.S. and European militaries work hard to understand AI, plan for AI and invest in being ‘AI ready’.
This has included a lot of hiring of new skills, capacity building, investment in technology and data infrastructure, plus partnerships with the technology sector. However, over the past year or two, we’ve seen focus shift more squarely onto harnessing AI for strategic and tactical advantage in military operations across all domains.
The U.S. Department of Defense’s AI strategy announced last month, sets out to harness AI to achieve the following outcomes: battlespace awareness and understanding; adaptive force planning and application; fast, precise, and resilient kill chains; resilient sustainment support; and efficient enterprise business operations. Although, these broad outcomes belie the complexity of bringing in disruptive new technologies into an environment where they must integrate with people, process and existing technologies.
As we’ve seen over the past couple of years with U.K. and U.S. trials of unmanned vehicles, AI and expanded data analysis programmes, integration takes time and practice. Additional expert resources are almost always required, sponsorship from higher ranks is essential to effect change, and integrating with existing teams is often the hardest part. So military organisations must adopt some technology practices when it comes to development, testing and implementation.
The figuring out where AI fits in phase, seems to be tailing off and 2024 could be a year of faster AI adoption and expansion of key trials and programmes.
For example, the U.S. Navy stood up Task Force 59 under U.S. Naval Forces Central Command (NAVCENT), based in Bahrain in September 2021 to dramatically accelerate adoption of AI, big data and unmanned systems. Among other things, the new task force helped stage the world’s biggest naval unmanned exercise. A little more than 18 months after the formation of TF59, the U.S. Southern Command (SOUTHCOM), announced a cross-department AI programme, to drive AI and unmanned systems adoption across the 4th Fleet. Now AI and unmanned systems are being integrated to U.S. Navy operations around the world.
Another sign that adoption is accelerating is illustrated by the Navy’s increasing focus on offensive capabilities. Task Force 59 oversaw the U.S. Navy’s first missile firing from an autonomous unmanned surface vessel, the MARTAC T38 Devil Ray, in October:
Meanwhile, the Navy’s newly established Unmanned Surface Vessel Division One has dispatched two of its five medium-sized unmanned prototype vessels to Yokosuka Naval Base in Japan, for the first time. Both USVs are able to carry air-defense and anti-ship missiles, while the USV Mariner is equipped with an L3Harris autonomy system.
In 2024, we’re going to see the conveyor belt of new AI, data and unmanned systems technologies move a little faster, bringing new capabilities into operations all around the world. (Source: Armada)
20 Dec 23. UK and partners form The Tallinn Mechanism for cyber security.
UK and partners join together to establish The Tallinn Mechanism to bolster Ukraine’s cyber security.
As part of Russia’s unprovoked invasion of Ukraine, the world has witnessed an unrelenting cyber assault against Ukraine’s critical national infrastructure, from banking to energy supplies and innocent Ukrainian people.
As a result, The Foreign Ministries of Canada, Denmark, Estonia, France, Germany, The Netherlands, Poland, Sweden, United Kingdom and the United States have formalised the Tallinn Mechanism on 20 December 2023. It aims to coordinate and facilitate civilian cyber capacity building to help Ukraine uphold its fundamental right to self-defence in cyber space, and address longer-term cyber resilience needs.
The UK’s primary delivery agent of cyber capacity building in Ukraine is our CSSF UK-Ukraine Cyber Programme, expanded by Prime Minister Rishi Sunak in June 2023. The programme has delivered over £10m to bolster Ukraine’s cyber defences since the invasion.
Through this programme, the UK has stood side by side with Ukrainian cyber defenders. For example, the UK funded its partner Mandiant to combat a reported Russian cyber-attack it attributed to Sandworm, a unit within Russian Military Intelligence (GRU), against Ukraine’s energy infrastructure causing a power outage.
Minister of State in the Cabinet Office, and lead Minister for the Conflict Stability and Security Fund Baroness Neville-Rolfe said:
The UK and Ukraine are fighting side by side in the cyberwar against Russia whose appalling attacks know no bounds. Russia is attacking Ukraine’s cyber infrastructure in order to harm innocent people, choke the economy and sow confusion.
That is why the UK is supporting Ukraine with state of the art technology, tools and expertise to thwart these cruel attacks, including those on critical infrastructure. Our support remains steadfast.
The Mechanism aims to interface routinely with other donor initiatives, coordinate and de-conflict, including regular engagement with the EU and NATO. (Source: https://www.gov.uk/)
20 Dec 23. Global: Increased BlackCat ransomware operations are likely following dark web site seizure. Following the December seizure of its dark web site by US law enforcement, the ransomware group ‘BlackCat’ (also known as ‘ALPHV’) briefly freed the same website on 19 December to promote and encourage increased activity by its ransomware-as-a-service (RaaS) affiliates. A message from the group stated that its affiliates would receive a 90% commission for continuing to use its RaaS programme. The group also lifted its rules for its affiliates’ operations, removing restrictions on the targeting of hospitals and other critical infrastructure. This will elevate the operational risks facing these industries in the short-to-medium term. However, BlackCat affiliates are still forbidden from targeting Commonwealth of Independent States (CIS) countries, a common rule for organisations with ties to Russia. Notably, the group stated that the recent seizure of its dark web site by law enforcement has only affected a portion of its operations. A revivial of the group’s activity is therefore possible in the medium term. (Source: Sibylline)
19 Dec 23. Global: Ransomware continues to pose heightened operational, financial risks to global firms. In an advisory released on 18 December, the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and the US Cybersecurity and Infrastructure Security Agency (CISA) reported that the ransomware group ‘Play’ is impacting a wide range of firms, including critical infrastructure, across Europe, North America and South America. As of October 2023, the group has affected at least 300 organisations since the group first emerged in June 2022. The group’s modus operandi involves stealing sensitive documents from infected systems and threatening to leak the information to coerce victims into paying the ransom. The group also uses custom tools to steal files from locked backup copies and exploits software vulnerabilities for access, showcasing its sophistication. This underscores the severity that an infection can pose to organisations, particularly when a system’s backup files are also compromised. Ransomware operations will continue to pose elevated financial, operational and security risks to global firms into 2024 and beyond. (Source: Sibylline)
18 Dec 23. Lockheed Martin Skunk Works® (NYSE: LMT) and Verizon (NYSE, Nasdaq: VZ) demonstrated 5G streaming for real-time visualization content on edge computing devices to advance Department of Defense (DOD) sustainment missions.
As part of an ongoing strategic collaboration, the companies validated three key technology areas:
- 5G at the edge for latency critical interactions of complex visualization applications such as augmented, virtual, or extended reality experiences
- Streaming of real-time, complex, 3D visualization content
- Streaming to edge compute devices including tablets, mobile, Head Mounted Displays (HMDs), and more
These technologies enable Lockheed Martin’s “Maintainer as a Node” concept, by which a connected maintainer receives all the information where, when and how it is needed in a latency-critical environment.
“Streaming is the future, and through our strategic collaboration with Verizon, together we’re advancing crucial 21st Century Security technologies that drive speed, efficiency, quality and reliability where our customers need it most,” said Marc O’Brien, senior manager of Virtual Prototyping at Lockheed Martin Skunk Works.
This year, Lockheed Martin and Verizon focused on content streaming for sustainment use cases where advanced visualization capabilities are critical to supporting the maintainer with Resilient Logistics in a Contested Environment (RLCE). Examples of these use cases include:
- 3D step-based work instructions
- Augmented/virtual/extended reality content deployment
- Remote desktop of high-end, real-time, 3D applications scenarios
- Remote assistance and other 3D graphically intensive applications
The cases demonstrated a multi-user, augmented reality experience across multiple geolocations streaming a large 3D CAD airspace engine in real-time. The target display device was a HoloLens, which used the project collaborator Holo-Light’s streaming platform along with Verizon 5G Edge with AWS Wavelength over Verizon’s 5G network. The demonstration highlights the value of future streaming approaches for sustainment applications, ensuring that data is secure and content is efficient and effective.
“This effort demonstrates how Verizon’s partnership with Lockheed Martin leverages the immense capabilities of 5G and edge computing to transform data streaming and AR experiences to produce advanced capabilities for military sustainment operations,” said Chris Halton, vice president of Product Strategy and Innovation at Verizon.
This effort coincides with a broader collaboration between Lockheed Martin and Verizon to advance critical 5G.MIL® data-sharing applications for the DOD, improving security, resiliency, interoperability and performance with a combination of commercial and government-driven technology. This collaboration and demonstration are prime examples of Lockheed Martin’s 21st Century Security vision to rapidly deliver game-changing capabilities to U.S. military customers.
————————————————————————-
Spectra Group (UK) Ltd
Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.
Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.
With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.
Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.
In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.
Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.
Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.
————————————————————————-

