• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

May 24, 2024 by

Sponsored by Spectra Group

Spectra Group (UK) Ltd Home Page


———————————————————————————————————————————————————————————————————————————————————————————————————————————————
23 May 24. South China Sea: New suspected Chinese group underscores elevated security, espionage risks. On 22 May, the cyber security company Bitdefender Labs announced the discovery of a new threat group, ‘Unfading Sea Haze’, which is reportedly targeting countries in the South China Sea. The group mainly targets high-level military and government entities in espionage operations. Unfading Sea Haze’s tactics, techniques and procedures (TTPs) comprise spear-phishing emails containing malicious payloads as initial attack vectors, as well as an extensive malware arsenal for data extraction, including the remote access trojan (RAT) ‘Ghost RAT’ and other custom tools. The longevity and stealth of the group’s operations combined with its malware arsenal and chosen target set indicate that Unfading Sea Haze is likely to be a Chinese-backed state-sponsored group. China routinely leverages cyber espionage operations to bolster its security and military posture in the face of perceived adversaries. As such, we assess that Chinese-affiliated cyber actors will highly likely sustain elevated security and espionage risks for organisations operating in the South China Sea region in the long term. (Source: Sibylline)

 

22 May 24. The US has spent $5bn on electronic warfare in 2024 alone. China, Russia and India are projected to eat into the US’ outsized share of global electronic warfare spending in the coming years.
The US is the world’s largest investor and developer of electronic warfare, spending an estimated $5bn on the signal technology in 2024 so far alone, according to a new report.
GlobalData’s Electronic Warfare report details that, between 2021 and 2023, the US military accounted for the largest share of electronic warfare spending by a significant margin – 45% of global expenditure compared to Russia’s 14% and China’s 13%.
Washington’s stranglehold on the electronic warfare market looks set to be challenged, however.
The report predicts that Russia, China and India’s share of the electronic warfare market will only increase over the next decade.
Total expenditure by the world’s nine main electronic warfare militaries will surpass $16bn by 2033, the report adds, up from more than $11bn this year. (Source: naval-technology.com)

 

21 May 24. Netherlands acquiring new radios and C4I system under Foxtrot. The Netherlands Ministry of Defence (MoD) is equipping its armed forces with the AN/PRC-160 HF manpack radio from L3Harris Technologies in a bid to upgrade its tactical communications as part of the Foxtrot communications programme.
The authority is also planning to acquire a new tactical command, control, communications, computers, and intelligence (C4I) network for its special operations forces (SOF).
Both are new requirements stipulated in the Defence Projects Overview (DPO) 2024, published on 15 May, which provides an outline of all the planned materiel, IT, and real estate projects valued over EUR25 m (USD27.2 m).
With regard to the radio requirement, the MoD is undertaking a new, comprehensive programme to replace its ageing high-frequency (HF) communication equipment across the armed forces. Radios such as the HF7000 long-range radio, which has reached the end of its technical service life, will be replaced with L3Harris Technologies’ AN/PRC-160 radio. (Source: Janes)

 

17 May 24. France turns to AI for signals analysis in underwater acoustics war. The French Navy is turning to artificial intelligence to help its submariners detect enemy vessels in a growing sea of underwater sounds.
The Navy’s acoustic recognition and interpretation center CIRA in Toulon is working with French startup Preligens on AI-powered analysis of underwater acoustic signals, the center’s head, Vincent Magnan, said in a presentation here Thursday. France expects to test the technology onboard its submarines by the end of the year, with operational deployment scheduled for 2025.
As France equips more and more vessels with increasingly powerful passive acoustic sensors, the amount of data collected for analysis is growing exponentially. The Navy is counting on AI to help its acoustics analysts, nicknamed “golden ears,” cut through the noise, both at the Toulon center and on board its submarines.
More sensors and greater detection ranges will result in “a massive flow of data,” Magnan said. “To be able to analyze all this data, and especially to be able to isolate from it the useful and decisive information for the conduct of our combat operations, we need to resort to technological innovations, including artificial intelligence.”
In addition to submarines, frigates and aircraft fitted with passive sensors, the near future will bring drones and underwater gliders that capture acoustic data, according to Magnan. The amount of such data gathered by CIRA has increased to around 10 terabytes in 2024 from 1 terabyte in 2020, and is expected to approach 100 terabytes or more by 2030.
Interest in “passive acoustic warfare” is growing because it allows surface vessels and submarines to detect underwater sounds during operations at sea and derive tactical elements in “all discretion,” without an adversary knowing about it, Magnan said. A particular propulsion pattern might allow the Navy to define a target’s speed, which can then in turn determine a tactical maneuver.
The Toulon center is using AI to filter out those acoustic signals of interest, after which humans can carry out high-value added analysis. The goal will be broadly similar at sea, with AI allowing human operators to focus on the useful signals.
“So we use technology to discard or filter the standard part of the signal, the almost useless part, and we rely on humans to exploit the useful part,” Magnan said.
Sifting through 12 days of acoustic data recorded in the waters off Toulon takes two “golden ears” more than 40 working days, Magnan said. With the AI demonstrator from Preligens, extracting useful signals from those same recordings can be done in 4 to 5 hours, with an additional five to six days of human analysis. “So you can already see that the gain is enormous”
Whereas in the 1990s and 2000s CIRA analyzed acoustic recordings of around 5 minutes targeted at a particular threat, the center now deals with data stretching over forty-day periods that requires “a great deal of human capacity” to process, according to the head of the center.
In the early 2000s, a sonar operator could see around 20 kilometers and would monitor 10 simultaneous acoustic contacts, by 2020 that had increased to more than 200 kilometers and a hundred tracks, Magnan said. France’s third-generation ballistic missile submarines will have even greater sensor capabilities, creating a real need to ease the detection task, the commander said.
France currently operates four Le Triomphant-class nuclear-powered ballistic missile submarines and is in the process of replacing its Rubis-class nuclear-powered attack submarines with six Suffren-class vessels.
The AI model has shown “very encouraging results,” able to distinguish hobbyist boats from commercial vessels, and identify propeller speed, propulsion systems and even the number of propeller blades, according to Magnan. A future step will be combining the AI models applied to acoustics with other sources of information, including satellite, radar, visual and electromagnetic.
The team working on acoustics detection has created a tool to automatically detect and identify various acoustic sources and sound emissions that will be demonstrated at the Viva Technology show in Paris next week, said Julian Le Deunf, an expert at the Armed Forces Ministry’s newly created agency for AI in defense.
“The promising results over these last few months also encourage us to test all these capabilities in real-life conditions, so to take the jump onboard the submarine and test these models directly at sea,” Le Deunf said. “The goal for the end of the year is really to succeed in plugging the model directly behind an audio stream, behind a sensor.”
The AI project has been running at CIRA since 2021, after Magnan met with Preligens executives in October of that year. French military intelligence was already using the company’s AI products to analyze satellite imagery, and Magnan said his discussions with Preligens led to the idea that the model could be replicated to make sense of underwater signals.
Eventually, the AI algorithms will be able to identify ambient noises such as a pump starting up or a wrench falling in a hold, according to Magnan.
“The idea in the long run is obviously to find models that are effective and efficient over the whole acoustic spectrum of the sources we encounter at sea,” he said. (Source: Defense News)

 

17 May 24. Cyber Update Key points.
• A new malware campaign has underscored the elevated cryptocurrency-theft risks facing financial firms (see Sibylline Cyber Daily Analytical Update – 13 May 2024).
• The ransomware group ‘Black Basta’ targeted US critical national infrastructure (CNI), highlighting elevated security and disruption risks (see Sibylline Cyber Daily Analytical Update – 14 May 2024).
• Cyber criminal groups exploited a new vulnerability to deploy the ‘QakBot’ malware, underscoring increased security and financial risks facing global firms (see Sibylline Cyber Daily Analytical Update – 15 May 2024 and our Technical analysis below).
• The emergence of new backdoors highlights security and espionage risks stemming from the Russian state-sponsored group ‘Turla’ (see Sibylline Cyber Daily Analytical Update – 16 May 2024 and our Technical analysis below).
• A new campaign targeting artificial intelligence (AI) experts has accentuated the information-theft risks facing technology firms (see Sibylline Cyber Daily Analytical Update – 17 May 2024).
Technical analysis of weekly stories
The Russian state-sponsored group ‘Turla’ is using two new backdoors, ‘LunarMail’ and ‘LunarWeb’, in an espionage campaign targeting an unnamed European ministry of foreign affairs and its diplomatic missions in the Middle East. It is likely that the threat actors exploited misconfigured networks and used spear phishing techniques to install the malware on the victims’ systems. In order to distribute LunarMail, Turla masked a DOCX file as a DOC file to hide malicious content and used native tools to decrypt the malicious payload. Additionally, the malware is installed as an Outlook add-in to communicate with (and exfiltrate information to) actor-controlled servers while disguised as an email. Conversely, LunarWeb conducts several security checks when first downloaded onto a victim’s system, self-deleting itself if any of these checks fail. Furthermore, the malware impersonates legitimate traffic to communicate with the threat actor’s command and control (C2) infrastructure. These methods underscore threat actors’ continuous development of sophisticated evasion techniques to achieve prolonged obfuscation and persistence within targeted networks. Both backdoors collect system information in different stages, starting with the collection of environment variables and email recipients.
A newly disclosed zero-day vulnerability (CVE-2024-30051) is being exploited in a new financially motivated campaign to deliver the ‘QakBot’ malware. The vulnerability affects the Desktop Windows Manager (DWM) service and can only be exploited after initial compromise. Threat actors can exploit this vulnerability in a heap-based buffer overflow attack, whereby they corrupt and overwrite portions of a system’s memory. This enables them to escalate their privileges, offering them the ability to move laterally within the compromised system, to execute malicious code and to access sensitive information. In their most recent campaign in April, threat actors deployed the Qakbot malware to steal credentials, website cookies and credit card details so as to garner illicit profit. The rapid integration of the vulnerability into QakBot’s arsenal points to the importance of timely updates and vigilance as actors quickly advance their tactics, techniques and procedures (TTPs).
Some non-exhaustive recommendations to mitigate against these threats include:.
• Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing and other types of social engineering attempts.
• Apply patches to software vulnerabilities as soon as they are released to prevent exploitation.
• Enforce strict and timely patch-management policies and ensure adequate software configuration.
• Monitor devices and networks for suspicious activity.
• Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
• Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions.
Our cyber word(s) of the week: X-as-a-service (XaaS) (Source: Sibylline)

 

17 May 24. US: New campaign points to accentuated information-theft risks facing technology firms. On 16 May, the cyber security company Proofpoint released a report on a new information-theft campaign targeting ten US-based artificial intelligence (AI) experts. The campaign starts with an AI-themed phishing email that tricks potential victims into downloading a remote access trojan (RAT) called ‘SugarGh0st’. The malware is reportedly a custom version of ‘Gh0st RAT’. It is therefore likely that a Chinese threat actor is behind the campaign. SugarGh0st notably contains new functionalities for reconnaissance, data exfiltration, lateral movement and code execution, highlighting the continuous development and sophistication of threat actors’ tactics, techniques, and procedures (TTPs). Conversely, the similarities between SugarGh0st and Gh0st RAT, such as offline keylogging, suggest that the campaign likely aims to steal secretive data on generative AI. As the theft of intellectual property is a prominent way for Chinese-affiliated actors to bolster China’s economic posture and technological advancements, we assess that this campaign underscores the accentuated information-theft risks facing technology firms in the long term. (Source: Sibylline)
——————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Spectra Group (UK) Ltd
Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.
With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.
Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.
In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.
Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.
Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.
———————————————————————————————————————————————————————————————————————————————————————————————————————————————–

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT