Sponsored by Spectra Group
————————————————————————
14 Mar 24. Thales eyes UK Personal Role Radio replacement programme. Thales is planning to pitch its SquadNet radio for the UK armed forces’ next-generation Personal Role Radio (PRR) replacement programme due to be announced in 2025, Janes learnt at SAE Group’s Future Soldier Technology conference held from 11 to 13 March. According to John Dix, Thales UK sales manager for land communications, SquadNet is a suitable replacement to PRR because of its small form factor, making it a cost-effective solution tailored for dismounted soldiers. The system being replaced is the Leonardo H4855 PRR, which has been in service with the army for more than 20 years. The PRR is a small, lightweight system designed for short-range communications suitable up to platoon level. The system has a 500 m operating range, weighs 1.5 kg, offers a 20 hour battery life, and has a 38.4 Kbps data rate. (Source: Janes)
14 Mar 24. ELT Group and the Qatar Armed Forces signed a Letter of Intention (LOI) to cooperate on strategic projects in the field of EMSO. During the last Doha International Maritime Defence Exhibition and Conference (DIMDEX 2024), ELT Group and the Qatar Armed Forces have signed a LOI stating their common will to cooperate on strategic projects in the field of Electromagnetic Spectrum Operations and in particular on the development of an EW and Intelligence Centre. The LOI was signed in the presence of the Commander of the Qatar Emiri Air Force, Major General Jassim Al-Mannai and the CEO and COO of ELT Group, Domitilla Benigni. This is a confirmation of a solid friendship and long term cooperation between the Group and the Qatar Air Force. ELT Group has been present in Qatar since 2017 with the opening of its commercial office, providing support within many national programs thanks to its portfolio of capabilities in the EMSO domain.
11 Mar 24. Bowman’s life to be extended … again!
The UK’s Bowman tactical communications and command and control system is to be upgraded once more because of the collapse of the EVO project. This latest initiative could extend the life of the Bowman architecture to at least 2031 and possibly to 2035.
The UK MOD’s long-running saga to replace the communications element of the Bowman tactical radio and C2 system used by British land forces enters a new chapter.
In February, Armada reported the cancellation of a major component of the United Kingdom’s Project Morpheus military communications system. Specifically, the Evolve to Open (EVO) stage of the programme was axed. EVO used the latest version of the Bowman tactical radio and Command and Control (C2) system as its baseline, known as Bowman Combat Infrastructure-5.6 (BCIP-5.6). The EVO initiative was being led by General Dynamics’ UK subsidiary. At the heart of EVO was a plan to evolve BCIP-5.6 into an open, modular design. The rationale was to ensure the Bowman radio infrastructure could easily and safely accept new hardware, software and capabilities as and when they become available. The MOD said this approach would “enable (it) to integrate and deploy new capabilities selected from across (i)ndustry in a faster and more cost-effective manner.”
Question time
On 14th December James Cartlidge, the UK’s minister for defence procurement, conceded the long-running problems the EVO project has suffered and that Armada reported on in the past. “We have been open that progress on the Morpheus project has fallen short of what was expected,” Mr. Cartlidge told the British parliament. Sources close to the programme told Armada that the MOD and General Dynamics were at an impasse over EVO’s expectations and deliverables. Although EVO is dead, General Dynamics will sustain Bowman to ensure it continues to support UK military commitments.
In early February, the Financial Times reported that Bowman’s life will now be extended to 2035 at the latest. The news was divulged in a response from Mr. Cartlidge to a written parliamentary question tabled by the opposition shadow secretary of state for defence. Mr. Cartlidge revealed that Bowman will be upgraded once more via an initiative called BCIP-5.7 which was originally commissioned in 2023. In another response to Mr. Healey, Mr. Cartlidge said that BCIP-5.7 is “still in development and subject to approvals.” The precise scope of BCIP-5.7 is unclear. That said, it appears that this might be a relatively straightforward extension of the Bowan radio infrastructure as opposed to the more ambitious EVO initiative.
Bye bye GD?
One thing that does seem certain is that General Dynamics’ role is likely to be confined solely to sustaining Bowman. An MOD source close to Morpheus told Armada that the company is unlikely to be allowed to bid for any future work involving Bowman. Nonetheless, they could be involved as a subcontractor to whichever company is selected for BCIP-5.7.
Despite the EVO setback and the need for BCIP-5.7 the Ministry of Defence’s wider Project Morpheus overhaul of UK land forces communications continues: “Bowman (provides) secure communications on the battlefield,” an MOD spokesperson told Armada. “Having received several upgrades, Bowman will be updated again, ensuring the army continues to operate a secure and capable communications system until Morpheus delivers.”
All eyes are now on whether and when BCIP-5.7 can be delivered and the likely effect of both this, and the EVO cancellation, on Morpheus as a whole. The pressure is on following another cliffhanger in the UK’s long-running tactical communications soap opera. (Source: Armada)
11 Mar 24. Clear Channels. Lt. Gen. Sir Jim Hockehull gave RUSI’s inaugural Profession of Arms Series lecture on 15th February where he cited loss rates for Ukrainian UAVs of around 10,000 per month.
An innovative approach to radio communications promises to enhance the survivability of Ukrainian uninhabited aircraft in a conflict increasingly characterised by the widespread use of UAVs.
Lieutenant General Sir Jim Hockenhull, commander of the UK’s Strategic Command, gave a speech at the inaugural Royal United Service’s Institute’s (RUSI) Profession of Arms Series lecture on 15th February. Gen. Hockenhull discussed threats, challenges and opportunities in the cyber and electromagnetic domains. A full transcript of his speech can be found here.
Gen Hockenhull highlighted research performed by RUSI in mid-2023 which noted that Ukraine was losing around 10,000 Uninhabited Aerial Vehicles (UAV) per month in its ongoing war with Russia. The US involvement in the Vietnam War was associated with development of the helicopter as a military platform. The Ukraine War is increasingly associated with the UAV’s coming of age as a tactical capability.
These uninhabited aircraft are proving their worth for both sides as valuable Intelligence, Surveillance and Reconnaissance (ISR) platforms. UAVs deliver ordnance against hostile assets like troops, weapons, vehicles, sensors and bases. Explosive-laden kamikaze UAVs crash themselves into targets.
RF Reliance
Such is the UAV threat in Ukraine that both sides have worked hard to develop and deploy Counter Uninhabited Aerial Vehicle (CUAV) capabilities focused on kinetic and electronic attack. The latter directs jamming against the Radio Frequency (RF) links these aircraft depend on. UAVs use radio links to connect the aircraft to its pilot, and to share ISR data and information on the aircraft’s health. Global Navigation Satellite System (GNSS) receivers aid navigation with satellite-transmitted PNT (Position, Navigation and Timing) signals.
Jamming works to disrupt these RF links. Civilian-standard UAVs typically, but not exclusively, use frequencies of 2.4 gigahertz/GHz and 5.8GHz to connect the aircraft to its pilot. Frequencies of 1.1GHz to 1.6GHz are used for GNSS PNT signals. Russian land forces have deployed scores of Electronic Warfare (EW) systems at the tactical and operational level to attack and jam frequencies used by UAVs. Details of these systems can be found here. If a UAV loses its RF links it may either automatically return to its point-of-origin, or land in situ.
Given the jamming threat, it is little surprise that Ukraine is taking strenuous efforts to avoid the threat posed by Russian EW systems. Armada has learned that around 90 percent of all tactical Electronic Warfare (EW) in the Ukrainian theatre is targeting UAVs. Encrypting UAV RF links can help as the aircraft will ignore all signals not matching the encryption keys. Using inertial navigation systems, which do not need RF, are another option. Sometimes, Ukrainian troops will deliberately fly their UAVs using the same frequencies as those used by Russian uninhabited aircraft. This means that the Russians will jam their own UAVs if they try to electronically attack the Ukrainian aircraft. Another tactic is to launch around 20 UAVs, all of which are using different frequencies. This forces the Russians to divide their EW force to detect and target each frequency in the hope that insufficient electronic warfare assets exist in the UAVs locale. The logic is that at least one or two of the aircraft will complete their mission.
Local Innovation
Innovation is moving at breakneck speed in Ukraine, accelerated by the necessities of war, and ultimately the country’s survival. Colibri Defence Dynamics shared with Armada that it has developed an innovative radio system that could help Ukrainian UAVs outflank Russian jamming. While radio frequency hopping offers some resilience it is limited says Jack De Santis, the company’s founder. The problem with frequency hopping is that it usually occurs across a relatively narrow band: “The Russians simply jam the entire band.” Anecdotal evidence from Ukraine recently shared with your correspondent said that any RF system transmitting 500 hops-per-second is easily jammed by Russian EW cadres.
Mr. De Santis and his innovators have taken a different approach developing an RF system which can equip a UAV, but which provides several communications channels across a very wide bandwidth. Understandably, Mr. De Santis declines to share the bandwidth this system works across. He did mention that all the RF processing is enclosed in a single printed circuit board which can easily outfit a UAV. Each UAV thus equipped will have scores of channels it can use simultaneously for its RF links. “The Russians cannot jam all these links at the same time,” he argues.
The wider the jamming bandwidth an EW system must attack, the less power it can direct against each frequency and the shorter the range this jamming becomes, progressively reducing its effectiveness. An alternative is to try to deploy yet more tactical CUAV systems but this is easier said than done: “The more EW systems the Russians deploy at the front the easier it is for the Ukrainians to find them.” Moreover, these systems are expensive, complex to produce, require trained personnel and are lucrative targets. All factors restricting how many CUAV systems Russian land forces can deploy at any one time. “The Russians, or any other EW force for that matter, are unable to jam every frequency known to humankind at once, no matter how much they spread their power.”
Russian CUAV systems at the front may be able to jam or spoof some of a UAV’s links but not all of them. Let us suppose that the RF channel one of the UAVs is using to share ISR data is suddenly jammed. Software immediately moves the ISR feed to an unjammed channel. Suppose false PNT information is received on another channel. The software discards this information as it does not match the PNT data received on the GNSS link. Mr. De Santis and his team call their approach channel parallelisation.
Ukraine is moving innovation forward in the electromagnetic sector at breakneck speed as the conflict’s UAV dimension illustrates. This is helped in no small measure by an efficient ‘lessons learned’ approach. Mr. De Santis and other innovators can quickly understand what is happening in the spectrum and react accordingly. (Source: Armada)
11 Mar 24. Check the Manual. Russian land forces are highly reliant on so-called FPV UAVs to gather ISR data, deliver weapons and perform kamikaze attacks. A recent Russian Army manual gives important clues as to how these aircraft are deployed on the battlefield.
Armada has obtained a Russian language military manual providing guidance on tactical first person view uninhabited aerial vehicle employment by Russia’s land forces.
The manual provides a treasure trove of details regarding the electromagnetic aspects of Russian tactical First Person View Uninhabited Aerial Vehicle (FPV UAV) use in the ongoing war in Ukraine. Mass UAV usage at the tactical edge is becoming a hallmark of the ongoing war in Ukraine.
The manual is a very recent publication having been drafted and published by the General Staff of the Armed Forces of the Russian Federation this year. The introduction makes clear that the manual provides guidelines for tactical commanders and FPV UAV operators. The manual stresses that its provisions “should be applied creatively, in accordance with the conditions of the situation.”
Aircraft Types
Russian land forces FPV UAVs are to be deployed to target enemy personnel, unprotected, lightly armoured and fully armoured vehicles. The aircraft provide intelligence, surveillance and reconnaissance support, and assist tactical command and control. Standard FPV UAVs deployed by Russian forces include Boomerang, Starling, XL-10, Kofer, Piranha-7, Lirian, IBX-10, Limba-7, TVH-1, IBX-2 and NBX-3. The latter aircraft, the manual notes, uses artificial intelligence in its software.
The manual recommends that a thorough analysis of the “radio-electronic situation is carried out by spectrum analysers” to determine whether enemy forces are already performing electronic attack prior to a sortie. The survey will help UAV operators decide the frequencies they will use to connect to and from the aircraft. To improve the survivability of the unit launching the drone, the manual recommends using decoy antennas. High points, tall buildings, telegraph poles and elevated objects should be employed to site actual, and decoy, antennas. These antennas can be dotted around the location of the UAV’s operator to transmit fake radio signals. The hope is that enemy communications intelligence cadres are frustrated in trying to find the actual antenna hosting the Radio Frequency (RF) link between the pilot and the aircraft.
Frequencies
Prior to the sortie UAV pilots are to notify local Russian EW units of their intention to fly, and the frequencies they wish to use, to avoid the latter inadvertently jamming the UAV’s RF links. This seems to imply that FPV UAVs Russian land forces are using cannot operate independently of Russian jamming in their locale. The manual continues that land forces typically use frequencies of 390 megahertz/MHz to 490MHz, 850MHz to 960MHz, and 1.2 gigahertz/GHz and 2.4GHz for aircraft control. Frequencies of 2.4GHz and 5.8GHz are employed for downloading video
The manual recommends that troops continue to share their experiences of using FPV UAVs with the armed forces so that these can be folded into future editions of the manuals. It even lists two email addresses for the Department for Summarising Combat Experience; and .
The Russian and Ukrainian armies are reliant on FPV UAVs at the tactical level. The manual provides insights into how these aircraft are deployed and their electromagnetic characteristics. Understanding such information will help those devising countermeasures, electronic or otherwise, against Russian uninhabited aerial vehicles. (Source: Armada)
11 Mar 24. March Radio Roundup. L3Harris performed tests of its DPAAS phased array satellite communications system in Alaska in October 2023. The company told Armada DPAAS is currently at Technology Readiness Level-7 denoting that a prototype has been demonstrated in an operational environment.
Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.
DPAAS Evolves
L3Harris announced in early February that it had demonstrated a digital phased array antenna system for satellite communications. The demonstration took place in Fairbanks, Alaska in October 2023 and involved the company’s Digital Beamforming Phased-Array Antenna System (DPAAS). During the three-month long initiative, DPAAS handled circa 300 satellite contacts daily, including eight simultaneous contacts. The company told Armada, via a written statement, that DPAAS established contacts with over 90 satellites. These included international meteorology satellites and US spacecraft. Defence applications for DPAAS “may include any mission requiring satellite command and control and/or downlink telemetry and mission data reception from many simultaneous satellites,” the statement said. Work continues to reduce the overall size, weight, power and cost of DPAAS. These objectives should be met by the end of this year. Production and delivery schedules are then “dependent on customer budgets and mission schedules.”
New Radios Support ACE Concept
The United States Air Force’s (USAF) Air Mobility Command (AMC) is receiving Persistent Systems’ MPU5 tactical radios, the company announced in late January. Under the terms of the $5.1 m contract Persistent Systems will supply over 280 MPU5s, along with ten Integrated Sector Antennas. The latter allows MPU5 coverage to be extended over a large area. These systems will be deployed by the AMC’s 621st and 821st Contingency Response Groups (CRGs) to support the USAF’s Agile Combat Employment (ACE) initiative. The ACE concept focuses on the air force rapidly deploying and securing foreign airstrips in host countries. The Persistent Systems press release disclosed that the USAF currently uses legacy handheld radios which cannot share video or imagery in a similar fashion to the MPU5. The Integrated Sector Antenna is typically “pole- or tower-mounted,” the company told Armada in a written statement: “It utilises various antenna polarities to maximise throughput to the MPU5s within its coverage range.” Meanwhile, “the high-bandwidth, easy-to-use, ad hoc nature of the MPU5s and Integrated Sector Antennas allow the CRGs to command and control US Air Force operations in austere and remote locations, as well as with partner nation forces.”
New Terminals
The US Department of Defence has emerged as the first customer for Ovzon’s new T7 Satellite Communications (SATCOM) terminal. According to the company’s official literature, the terminal transmits data at speeds of up to ten megabits-per-second/mbps. Data is received at speeds of 60mbps. A waveband of 12.76 gigahertz/GHz to 13.25GHz is used for transmission. Signals are received on frequencies of 10.70GHz to 11.45GHz. The T7 weighs 2.8 kilograms (6.2 pounds). Ovzon told Armada in a written statement that “pound-to-pound, megabits-by-megabits the Ovzon T7 is the smallest, lightest and highest-performing mobile satellite terminal on the market.” The terminal can be used for communications across the company’s Ovzon-3 satellite and work with Ovzon’s legacy SATCOM networks. The terminal’s on-board processor enables “operations in GNSS (Global Navigation Satellite System) denied environments, (permits) obfuscated traffic patterns to prevent enemy interception, (has) a very low signal-to-noise ration mode for operations requiring low probability of interception and (provides) detection and full mesh networking supporting ultra-small terminals in scenarios where ground-based teleports are unavailable.” (Source: Armada)
13 Mar 24. Red Cell Partners Launches Eyris to Revolutionize Data Protection and Cybersecurity. Eyris offers a suite of blockchain technologies to boost digital security for DoD, Armed Services, and private sector
Red Cell Partners (Red Cell), an incubation firm building rapidly scalable, technology-led companies that are bringing advancements to market in national security, cyber, and healthcare, has announced $3 m in pre-seed funding for Eyris, a digital infrastructure platform created to provide cybersecurity, secure communications, and data protection.
Eyris offers a suite of blockchain technologies that provide advanced security solutions and mitigation from ransomware for the Department of Defense (DoD), Intelligence Community, and the private sector. Since Eyris is cloud- and encryption-agnostic, it can work with various cloud providers and encryption methods, tailoring its solutions to customer needs.
Eyris, which emerged out of stealth in 2023, was co-founded by Kevin Keaton, a U.S. Army veteran and former Chief of Innovation for the National Security Agency (NSA). With 34 years of experience in the national security industry, Keaton understands the urgent need for a proven, secure technology to fortify enterprise IT environments and mitigate risk.
“Resilient and secure technological infrastructure is critical for the security of the United States as well as public and commercial entities worldwide,” Keaton said. “At Eyris, we are committed to delivering that infrastructure so we can provide an unmatched level of data protection that makes it harder for cybercriminals to inflict harm and easier for entities to safely operate and overcome attacks.”
Eyris is the first company to publicly launch under Red Cell’s newly formed Cyber Practice, which was established to drive innovation and strengthen cybersecurity and resiliency for government and commercial clients. The practice is led by George Barnes, the former Deputy Director of the NSA, and colleague of Keaton.
“Cybercrime presents a rampant and persistent threat to an ever-broadening span of victims, from private citizens to industries of all types and sizes,” said Grant Verstandig, Red Cell Founder, Chairman, and CEO, and Co-Founder of Eyris. “In 2023 alone, the FBI reported that it received more than 800,000 cybercrime-related complaints. It also revealed that victims experienced more than $12.5 bn in potential losses, a staggering figure that far surpasses the $6.9 bn in losses reported in 2021.
“That’s why we need a company like Eyris, which was purpose-built to secure infrastructure and data by utilizing state-of-the-art blockchain technology that easily interfaces with existing applications,” Verstandig added. “Eyris’s Number One goal is to deploy data protection technologies that thwart cyberattacks so that enterprises worldwide are more secure, resilient, and in control.”
The funding from Red Cell allows Eyris to start a pilot program with the DoD and extend its services to other federal agencies in the near future. Eyris’ technology seamlessly integrates with existing applications such as Outlook and Slack, making communications more resilient and secure.
“Through our tamper-resistant blockchain, encrypted copies of data and sensitive information will remain safe,” said Keaton. “We bring revolutionary advancements in cybersecurity, data protection, and resiliency to national defense and beyond.”
About Red Cell Partners:
Red Cell Partners is an incubation firm building and investing in rapidly scalable technology-led companies that are bringing revolutionary advancements to market in three distinct practice areas: healthcare, cyber, and national security. United by a shared sense of duty and deep belief in the power of innovation, Red Cell is developing powerful tools and solutions to address our Nation’s most pressing problems. Visit us at redcellpartners.com and follow us on social media (LinkedIn, Twitter, Instagram).
About Eyris:
Eyris is harnessing the power of blockchain technology to deliver unmatched cybersecurity and data protection for public and commercial entities worldwide. In addition to providing foundational data and communications security, Eyris is deploying technology that is applicable in countless use cases across the public and private (finance, cybersecurity, logistics, healthcare) sectors. Learn more at eyris.tech and follow us on social media (LinkedIn). (Source: BUSINESS WIRE)
13 Mar 24. Everfox Partners with Microsoft to Advance Cloud Solutions for National Security. Global high-assurance cybersecurity leader, Everfox, formerly Forcepoint Federal, and Microsoft announced a strategic partnership agreement whereby Microsoft will integrate Everfox’s cross domain technology into Azure’s cloud service offerings.
Everfox’s portfolio of accredited, defense-grade cross domain solutions is built to meet the most stringent security requirements of data access and transfer. Through partnership with Microsoft, warfighters and the intelligence community will be able to access the information they need at the scale and velocity that the mission requires.
“Everfox is committed to supporting the missions of our customers who must maintain decision dominance in a world of increasing nation-state and non-nation-state driven attacks,” said Sean Berg, CEO of Everfox. “By partnering with Microsoft, our combined innovation and industry expertise will realize expanded capabilities from cloud to tactical edge.”
“This partnership with Everfox will enable us to continue evolving our cloud solutions and delivering the accredited, secure collaboration capabilities critical to our government customers,” said Zach Kramer, Vice President, Mission Engineering at Microsoft. “When the power of Microsoft Azure is combined with Everfox’s defense-grade cybersecurity solutions, we enable improved security and a real-time experience for our government users and coalition partners worldwide.”
As a result of this new agreement, Everfox and Microsoft will work together to develop innovative new cloud products to ensure that federal employees, from warfighters to the intelligence community, from sensor to shooter, or from home base to military base, can access the information they need at the scale and velocity the mission requires. Consequently, Everfox and Microsoft will be able to deliver enhanced value creation for the consumer by prioritizing an on-demand cloud service with built-in cybersecurity features. (Source: BUSINESS WIRE)
11 Mar 24. UK MoD withholds spending approval on DSA programme.
The risk that comes with the programme down the line has impacted the next stage of radio procurement.
The UK Armed Forces’ Dismounted Situational Awareness (DSA) soldier solution will continue to experience delays, prompted by the Ministry of Defence’s (MoD) avoidance of any risk in its decision-making.
While the Armed Forces have the sufficient funding required to procure the radios they need for the next level of procurement, the MoD is unwilling to give its approval as they do not want to commit until the risks have subsided.
Already set back by a six-to-nine-month delay, DSA, a project that began in July 2021, was originally anticipated to last for two years with an option to extend the programme for another six months. The combined contract valuation option was not to exceed £9m ($11.5m).
Delivery uncertainty took a turn for the worse as the Minister for Defence Procurement, James Cartlidge, introduced new acquisition reforms at the end of February 2024 that placed importance on the exportability of the MoD’s new systems and a greater emphasis on spiral development.
“Delivering new equipment and technology more quickly is key to the overall reforms, and the concept of ‘spiral’ development will be at the forefront as new programmes are initiated,” the MoD observed.
“Rather than striving for perfection before delivering to the frontline, capabilities at 60-80% of their full potential will be provided to the user, allowing early application, and subsequent improvements to reach their full potential.”
However, the problem with DSA is that the Government is unsure how successfully it will be able to spirally develop these new radios for the long-term. Ironically, this curbs the MoD’s plans for delivering a faster acquisition process.
UK extends Bowman radio system
Currently the UK Armed Forces use the Bowman combat radio, a system supplied by General Dynamics UK since it was originally awarded a contract for the communications system since 2001. However, a planned update to sustain the in-service Bowman system is currently underway as future systems in development face delays.
“The update will deliver new hardware and software ensuring troops on the frontline continue to have a secure communications system.”
As the Bowman 5.7 project is still in development and subject to approvals the procurement strategy is yet to be confirmed.
Concerns over Morpheus
Another MoD tactical communications network programme – a £3.2bn programme known as ‘Morpheus’ – was said to be at risk of delays in May 2023.
A UK Public Accounts Committee (PAC) report “expressed series doubts” about whether the MoD Equipment Plan was affordable, or agile and responsive enough to react to a changing threat environment brought about by Russia’s invasion of Ukraine.
Given National Audit Office’s assessment of the MoD Equipment Plan for 2023-33 in December 2023 identified a deficit just shy of £17bn – the MoD’s largest shortfall in the history of the Equipment Plan – this is a legitimate concern.
There was a “significant risk” that the UK could not provide Nato with an operational Army division, with programmes such as the Ajax armoured vehicle and Morpheus communications system “beset by problems and delays”. (Source: army-technology.com)
14 Mar 24. Stronger together: International cyber partnerships. Leading cyber is a core priority, part of this is sharing our expertise with and learning from international partners so we can better protect global security.
In an increasingly uncertain world, new threats and technologies are constantly emerging. It is vital that we hone and adapt our cyber capabilities to compete with and deter our adversaries. Strong international relationships are pivotal to this success.
One of these partnerships is with the German Cyber and Information Domain Service (CIDS) which signed a bilateral arrangement with Strategic Command in July 2022. Recent staff talks, which were held at our Development, Concept and Doctrine Centre in Shrivenham, took our cooperation to the next level.
Major General James Roddis, Director Strategy, co-chaired the talks alongside Brigadier General Dietmar Mosmann, his counterpart from CIDS. Discussions focused on how best to develop our cyber people, joint training and exercising, support to multi-domain operations, and provide enhanced collaboration around information activities. These are areas where the UK and Germany can combine forces extremely effectively to drive change in our own institutions but more importantly into the NATO alliance.
While UK’s cyber and information relationship with Germany plays an important part in transforming NATO, whether this be on cyber, digitalisation or multi-domain operations, our alliances and partnerships extend far beyond NATO and have a global reach, including with Japan, Singapore and of course our close Five Eyes partners.
Key bilateral events with Australia have enabled us to further share best practice, with General Jim Hockenhull discussing our efforts to learn from the Australian Defence Strategic Review with Chief of the Defence Force General Angus Campbell.
Recent conversations with Japan’s Cyber Defense Command shared more about our role at the forefront of digital capabilities, following on from General Hockenhull’s visit to Tokyo last year and the signing of the Cyber Partnership agreement and the landmark Hiroshima Accord.
Having a strong digital defence will be crucial over the coming years. Rapidly evolving technology, the proliferation of AI, and our adversaries’ intent on unconventional ways of disruption mean the knowledge and capabilities shared through our international relationships will continue to be vital.
Read more on the cooperation agreement between the UK and Germany here: Cyber Co-operation with Germany Strengthens – GOV.UK (www.gov.uk).
Our relationship with the Japanese Cyber Defense Command is discussed in more detail here: https://www.gov.uk/government/news/strategic-command-shares-cyber-expertise-with-japan (Source: https://www.gov.uk/)
11 Mar 24. US: Microsoft breach signals heightened espionage, information theft risks for US-based tech firms. On 8 March, Microsoft revealed that the Russian-affiliated threat group ‘Midnight Blizzard’ accessed some of the company’s source code and proprietary information. The stolen information pertains to the core programming instructions behind Microsoft’s software. The group used information gathered during an earlier phase of this attack to obtain elevated privileges in the system. The attack started in January following the compromise of an inactive test account that granted threat actors prolonged access to Microsoft’s network. The confidentiality of the compromised information and the length of the campaign underscore the ongoing development and perseverance of state-sponsored threat actors. Technological advancement has become a primary objective for cyber espionage operations, with countries seeking to gain a competitive advantage amid rising global tensions. Subsequently, we assess that US-based technology companies are highly likely to be targeted in espionage and information theft operations in the short-to-medium term, primarily by non-Western state-sponsored groups. (Source: Sibylline)
08 Mar 24. US Army needs more industry input before pivot to ‘radio as a service.’ The U.S. Army is looking for additional input from industry about its nascent radio-as-a-service initiative, a move away from the traditional method of acquiring and maintaining communications gear.
The service has hundreds of thousands of radios, too many to quickly and cost-effectively modernize given looming security deadlines and cat-and-mouse competition with Russia and China, world powers with sophisticated signals intelligence capabilities. An as-a-service model may provide the military with the latest radios and support networks while driving down costs and promoting hardware and software flexibility.
At least one related request for information was published last year. It garnered more than a dozen responses, ranging from enthusiasm to rejection, officials said at the time.
The input was helpful to the Army, and that sort of dialogue with defense suppliers will continue, Undersecretary Gabe Camarillo told reporters March 7, 2024, on the sidelines of the McAleese defense conference in Washington.
“We were going to send an RFI out, we were going to enter into a very formal and elaborate conversation with industry about the economics of that buying model and get feedback,” Camarillo said. “I think we’ll continue to partner with industry on multiple RFIs, multiple discussions in different fora.”
Exploratory pilots could help iron out kinks, Camarillo said. Radio as a service could resemble a subscription offered by some makers of consumer products; it could also mirror other deals in which companies furnish goods and expertise on a rolling basis, keep them up to date and handle quality control.
Updated connectivity has for years been a priority for the Army, alongside demands for improved long-range precision fires, air and missile defense and aviation. Secure, reliable networking is a tenet of the Pentagon’s Combined Joint All-Domain Command and Control concept, which envisions insights seamlessly relayed across land, air, sea, space and cyber.
Army Chief of Staff Gen. Randy George at the same conference Thursday said the service must recognize the demands of today without losing sight of the potential leaps ahead of tomorrow.
“We have to get our soldiers the right technology, when it is relevant, with the ability to upgrade and adapt to the threat. If we don’t, then we are putting our men and women in the dirt unprepared to fight and win,” George said. “This isn’t just about product innovation, it’s about process innovation.”
The chief of staff previously said soldiers “need to shoot, move and communicate,” and that “technology should facilitate those fundamentals, not encumber them.” (Source: Defense News Early Bird/Defense News)
08 Mar 24. RFIDKNOW Unveils Innovative and Affordable FlexAntenna.
Technology pioneer RFIDKNOW has released its ground-breaking industrial RFID portal, designed to be scalable, robust and easy to deploy. The RFIDKNOW FlexAntenna completely transforms traditional RFID portal reading systems, by blending technology innovation with practicality. The result is a reader portal that is easy to ship, handle and install, with exceptional read performance. Demand for visibility into supply chains is driving the need for affordable, modular RFID reader portals in warehouses and distribution centers. Many existing RFID antenna solutions can be a challenge to ship and install at busy dock doors and conveyors. Ability to rapidly deploy industrial RFID systems without heavy equipment is crucial for large-scale deployments.
RFIDKNOW is uniquely positioned to offer a solution to RFID functionality and affordability. Its leadership has decades of experience advising companies on a wide variety of RAIN RFID projects. “It became clear that existing RFID portals were not cost effective, convenient, or accurate enough to meet industry needs,” says Joe Hoerl, the company’s principal consultant. “RFIDKNOW decided to take action and developed FlexAntenna.”
Developed in cooperation with industry-leading antenna design firm Innovoi, Ltd., the patent-pending FlexAntenna’s modular multilinear antennas represent a completely new engineering approach to RFID tag reading and portal manufacturing. With focused beams this innovative new technology captures RFID tag reads from all orientations for best-in-class performance.
The FlexAntenna is optimized for ease of transportation and installation. In addition to being modular, compact and lightweight to reduce shipping costs, FlexAntenna boasts a robust aluminum enclosure that withstands the rigors of industrial environments. Deployments are seamless, since the FlexAntenna can be fitted with leading RFID readers and associated software systems, right out of the box.
“RFIDKNOW’s FlexAntenna has not only proven its technical capabilities but also stands out in practicality. Its flexible design ensures ease of shipping, allowing for reduced logistics challenges, but has also surpassed the performance of other RFID portals,” says Danny Kwoka, RMS Omega Technologies’ business development manager. “After several series of rigorous tests, the FlexAntenna consistently outperforms its counterparts, showcasing its superior tag reading capabilities. RMS Omega Technologies is excited to announce its partnership with RFIDKNOW as a solutions integration partner.”
The FlexAntenna is manufactured in the USA and available at scale, today. RFIDKNOW provides custom branding.
About RFIDKNOW: RFIDKNOW is a high-tech antenna manufacturer and services consulting firm that leverages its years of wireless experience and successes to help solution providers plan, conduct trials, select technologies, and implement industrial RFID and short-range wireless IoT solutions best suited for each application. RFIDKNOW’s business is underpinned by our strong system integrator partner ecosystem along with advanced manufacturing methods, R&D, and a range of highly qualified team members. (Source: BUSINESS WIRE)
08 Mar 24. Cyber Update Key points.
- New multi-pronged phishing campaign underscores threat actors’ evolving tactics, techniques and procedures (TTPs), accentuating security and information theft risks to cryptocurrency users (see Sibylline Cyber Daily Analytical Update – 4 March 2024 and our Technical analysis below).
- North Korean threat actors targeted at least two South Korea-based semiconductor companies, highlighting elevated cyber espionage risks facing defence and technology firms (see Sibylline Cyber Daily Analytical Update – 5 March 2024).
- The active exploitation of two new zero-day vulnerabilities in Apple’s iOS platform signals heightened espionage risks facing Western entities (see Sibylline Cyber Daily Analytical Update – 6 March 2024).
- New malware campaign highlights the growing security risks third-party cloud services pose to companies (see Sibylline Cyber Daily Analytical Update – 7 March 2024 and our Technical analysis below).
- Remote access trojan (RAT) campaign points to growing espionage and security risks for firms via online meeting platforms (see Sibylline Cyber Daily Analytical Update – 8 March 2024).
Technical analysis of weekly stories
A new multi-pronged phishing kit, ‘CryptoChameleon’, targeted US-based cryptocurrency users and employees of the Federal Communications Commission (FCC). The campaign uses fake copies of legitimate single sign-on (SSO) pages to coerce users into disclosing their credentials and ultimately steal sensitive information. Potential victims are initially contacted via SMS, email or voice call by threat actors impersonating customer support. The user is then directed to a malicious site where they are prompted to complete a CAPTCHA challenge; this new tactic evades automated security detection tools while simultaneously enhancing the site’s authenticity. Subsequently, the victim is asked to input their credentials and complete Multifactor Authentication (MFA) via a sophisticated command and control (C2) method. This can include personalising SMS-based MFA where the victim is sent a message containing the last digits of their phone number. This new kit distinguishes itself from previous iterations due to its high level of sophistication. The threat actors demonstrated their awareness of modern security controls, leveraging them to bolster legitimacy. Additionally, the URLs, login pages and C2 methods employed all display high levels of complexity, further underscoring actors’ maturing TTPs.
A new malware campaign, ‘Spinning YARN’, is affecting misconfigured cloud services in Linux systems. The campaign primarily targeted the software platform, Docker. Threat actors initially employ malicious programs to identify and infect the misconfigured services. This allows them to create and control a new instance within the victim’s infrastructure, enabling them to establish consistent communication with the actor-controlled infrastructure. Subsequently, the actors execute an additional script that delivers a cryptominer to garner illicit profit. Notably, the campaign involves the use of two rootkits to conceal the malicious processes alongside utilising Secure Shell (SSH) credentials to maintain access to the compromised system. This malware emerged as part of a broader trend of developing TTPs, exploiting inadequate security policies and misconfigurations in third-party cloud services.
Some non-exhaustive recommendations to mitigate against these threats include:
- Monitor devices and networks for suspicious activity
- Enforce strict security policies including regular software and password updates
- Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing and other types of social engineering attempts
- Create network segmentation to limit potential damage from infections
- Add available Indicators-of-Compromise (IoCs) to the organisation’s security detection systems to detect potentially malicious samples on the network
- Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions
Our cyber word of the week: Rootkit
Definition: A collection of software tools used to gain unauthorised access and control of a computer system without being detected.
Example:‘Notably, the campaign also involves the use of two rootkits to conceal the malicious processes…‘ (see Technical Analysis).
Frequency of TTPs during this monitoring period: LOW frequency, MODERATE frequency, HIGH frequency
The MITRE ATT&CK framework is a globally accessible documented collection of information detailing the malicious behaviours of cyber threat actors; it is used as the foundation for organising the processes which threat actors execute during cyber operations. It provides an encyclopaedic reference for organisations, highlighting the tactics, techniques and procedures (TTPs) cyber actors employ in campaigns, while also providing suggestions for detecting and mitigating against specific TTPs to bolster organisations’ security mechanisms. The framework organises a threat actor’s entire operational lifecycle from reconnaissance to exfiltration and impact. (Source: Sibylline)
14 Mar 24. Global: Malware campaign points to security risks emanating from trusted third-party software. On 13 March, Zero Day Initiative (an international software vulnerability programme) reported the discovery of a malware campaign that exploits a patched vulnerability (CVE-2024-21412) in Microsoft Defender (antivirus software). The campaign starts with a phishing email coercing victims into opening a PDF file containing malicious links. These links then redirect the victim to actor-controlled web servers, leveraging the vulnerability to bypass Microsoft Defender’s routine security checks. Following initial access, the threat actors then deploy the ‘DarkGate’ malware, which enables them to evade detection and steal data from the compromised system. The abuse of legitimate third-party software often bolsters success rates for attackers as it exploits established (and trusted) applications while widening an organisation’s attack surface. Threat actors are increasingly exploiting vulnerabilities in the software supply chain to infiltrate corporate systems, highlighting the sustained security risks facing firms. Microsoft has since released a patch addressing this vulnerability, further stressing the importance of strict patch management and security policies. (Source: Sibylline)
14 Mar 24. France: DDoS attacks amplify disruption risks to government, public sectors in short-to-medium term. On 11 March, international news outlets reported that several French government institutions were targeted in multiple distributed denial-of-service (DDoS) attacks between 9 and 10 March. The threat actors targeted several government websites, rendering services temporarily unavailable. While the French government quickly restored these services, it reported that the attacks displayed unprecedented intensity. Additionally, the hacktivist group ‘Anonymous Sudan’ claimed the attacks on Telegram, though this has not been officially confirmed. The upcoming 2024 Paris Olympic Games and European Parliament (EP) elections are likely to present attractive targets for threat actors, increasing the likelihood of attacks and underscoring the disruption risks posed by state-sponsored and hacktivist groups. As geopolitical tensions remain strained across multiple regions, we assess that politically motivated threat actors will seek to influence elections and disrupt perceived adversarial entities by compromising high-profile events. Consequently, we assess that similar attacks targeting European officials and political bodies are highly likely in the short-to-medium term. (Source: Sibylline)
————————————————————————-
Spectra Group (UK) Ltd
Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.
Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.
With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.
Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.
In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.
Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.
Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.
————————————————————————-

