• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

June 7, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

——————————————————————————————————————————————————————————————————————————————————————————————————————————————

05 Jun 24. There be Dragons!

Reports on social media emerged in April that Royal Air Force General Atomics MQ-9A Reaper uninhabited aerial vehicles are flying equipped with the Outdragon signals intelligence system.

Open sources have stated that Outdragon is primarily a podded airborne Communications Intelligence (COMINT) system. Outdragon’s role appears to be the detection, location and tracking of persons of interest via their electromagnetic signals. The analysis continued that these signals could include cellphone and wireless router transmissions, among others. Cellphones tend to use Ultra High Frequency (300 megahertz/MHz to three gigahertz/GHz) wavebands while wireless routers use frequencies of 2.4GHz, five gigahertz and six gigahertz. Taking these wavebands into account, it is reasonable to assume that Outdragon covers frequencies of circa 30MHz to six gigahertz. Extending frequencies into the Very High Frequency (30MHz to 300MHz) part of the spectrum would let the capability also detect, locate and track individuals using VHF communications systems. Outdragon equips the Royal Air Force’s (RAF’s) General Atomics MQ-9A Reaper Uninhabited Aerial Vehicles (UAVs)

The MQ-9A has an operational altitude of 25,000 feet/ft (7,500 metres/m). Outdragon could detect and process communications signals at a range of circa 192 nautical miles/nm (356 kilometres/km) at this altitude. The pod is likely to have impressive sensitivity. Assume there is a cellphone transmitting a 300MHz signal with 0.6 watts/W of transmission power from an antenna with a gain of 12 decibels/db across a 300km (162nm) range. The cellphone transmission will have a strength of circa -201dB by the time it reaches the pod. Generally speaking, the closer a negative decibel signal strength is to zero the stronger that signal will be.

Outdragon procurement

A Freedom of Information (FOI) request made to the British government did shed some light on the Outdragon capability. The UK government procured Outdragon from General Atomics in April 2018 for $5m as a Foreign Military Sale (FMS) from the United States. Additional information regarding Outdragon was not forthcoming with the FOI response citing national security interests. A further procurement was made in April 2019 worth $2.2m for the modification and integration of Outdragon onboard the RAF’s MQ-9As.

Mission set

UK Ministry of Defence (MOD) documents in the public domain provide some additional information: Outdragon can be fitted on the MQ-9A’s number 8 underwing hardpoint. The documents continue that Outdragon supports combat ISR (Intelligence Surveillance and Reconnaissance) missions. When performing combat ISR, Outdragon is carried alongside MBDA Brimstone-3 air-to-surface missiles, and Raytheon Paveway-IV GNSS (Global Navigation Satellite System) and laser-guided bombs. When flying non-combat ISR missions, the aircraft exclusively deploys the Outdragon pod. The combat ISR configuration enables persons-of-interest to be detected, located, identified and attacked should this be required by the mission. Amalgamating the COMINT capability with kinetics gives the RAF a highly responsive reconnaissance and strike asset. Such capabilities are particularly useful for Counter-Insurgency (COIN) operations. Reports have stated that RAF MQ-9As are routinely based at Ali Al Salem airbase in central Kuwait. This location is well-placed for supporting RAF operations, particularly COIN efforts, around the Middle East. Although the aircraft can be flown from the base in Kuwait, their flying operations may be controlled from RAF Waddington airbase, eastern England.

Off-the-shelf?

Much remains unknown vis-à-vis Outdragon. For example, it appears that Outdragon is not a product name per se but instead maybe a British codename for a US-supplied system. Given that the procurement was made directly from General Atomics this suggests the capability is one that the company directly produces. General Atomics’ Scalable Open Architecture Reconnaissance pod (SOAR) can be configured for electronic intelligence and COMINT gathering. SOAR has been developed in partnership with L3Harris. General Atomics also provides a podded electronic warfare system called Sledgehammer. Sledgehammer is a communications jamming system and there is no indication that Outdragon has such attributes. Certainly, Outdragon’s relatively inexpensive procurement price of circa $7.7 m seems to indicate it was an off-the-shelf purchase. The fact that it had been purchased as an FMS also points to an off-the-shelf procurement. Much remains unknown regarding Outdragon, but recent social media interest is helping cast some light on this intriguing capability.

(Source: Armada)

 

05 Jun 24. Difficult Decisions. Armada has been told that the United Kingdom Ministry of Defence (MOD) had considered supplying examples of the ALARM missile to Ukraine.

A senior Royal Air Force (RAF) source shared with Armada that consideration had been given to supplying the Ukrainian Air Force (UAF) with British Aerospace/MBDA ALARM (Air-Launched Anti-Radar Missile) examples left over from the type’s decommissioning. Armada understands that plans to supply the missile, and integrate it onto Ukraine’s combat aircraft, stopped amid concerns regarding the missile’s seeker head. It was uncertain if the missile’s Radio Frequency (RF) seeker would have been effective in detecting, and homing in on emissions from Russian radars.

Should it have been deployed, ALARM would have been used to engage Russian ground-based air surveillance and fire control/ground-controlled interception radars.  It was thought that ALARM had been formally retired from RAF service in 2013. The source added that examples of the missile had been retained until 2018. An undisclosed number of missiles were in the possession of the UK Ministry of Defence (MOD) at the time of Russia’s second invasion of Ukraine in February 2022. UAF jets tasked with deploying ALARM would have needed to be upgraded with the necessary software.

Into combat

The Royal Saudi Air Force (RSAF) is believed to be the last ALARM operator and was the missile’s only export customer. Armada has been told in the past that the RSAF deployed ALARM during the country’s intervention in Yemen’s civil war. The RSAF did not specifically deploy ALARM as an anti-radar missile, instead the weapon was used against general surface targets. The source cast doubt on whether the RAF had deployed ALARM during Operation Odyssey Dawn/Unified Protector. This was the codename for the US/North Atlantic Treaty Organisation operation mounted in 2011 to protect Libyan civilians from forces loyal to the country’s late dictator Colonel Muammar Gaddafi.

Tactical modes

ALARM could be deployed in several ways: After launch, the weapon could climb to 40,000 feet (12,192 metres) which gave the missile’s seeker the elevation to detect emissions over a wide area. When used in a direct mode, the missile would look for specific emitters from altitude. Once detected, ALARM would home towards the radar, using the radar signals as guidance. Alternatively, ALARM could be used in a loiter mode. The firing sequence would be similar to direct mode. Once at altitude, the missile would deploy a parachute and slowly descend to Earth while listening for radar emissions. If a hostile radar was detected the parachute would detach, the missile’s motor reignite and it would zoom towards its target. Alternatively, the missile could be programmed to listen out for hostile emissions in a specific area, such as around an airfield. It would be possible for the crew to fire two ALARMs with one set to direct mode and the other to loiter.

Other tactics were available to ALARM users: The missile could be fired on a specific bearing along which it would fly while the seeker would listen out for radar targets of opportunity. This tactic could be particularly effective when there was a need to sanitise an ingress or egress corridor of threats. ALARM could also be programmed before a sortie to strike specific, known targets using latitude and longitude. Coordinates could be changed in the cockpit should a new target emerge during the mission.

Ultimately, the decision not to supply ALARM to the UAF has probably not adversely affected Ukraine’s offensive counter-air and subsequent air defence suppression posture. Given the concerns over the missile’s RF seeker head, it is remains open to question how effective the weapon would have been. To be fair the missile, which was initially selected by the MOD for development in 1983, was built for another age. This late Cold War period was characterised by different radar threats used by Soviet and Warsaw Pact forces. Ironically, the RAF would meet many of these threats in the post-Cold War world in the skies above Iraq and Kuwait in 1991, and later above the Balkans in 1995 and 1999.

By all accounts, ALARM acquitted itself well during these conflicts. Fortunately, the United States has supplied the UAF with Texas Instruments/Raytheon AGM-88B/C High Speed Anti-Radiation Missiles (HARMs). These weapons continue their important work of making life miserable for Russian radar operators in Ukraine. (Source: Armada)

 

06 Jun 24. June Spectrum SitRep. MASS’ THURBON CEMA electronic warfare and intelligence mission data management system can hold and manage a mind-bending array of data related to electromagnetic emitters and their users. The software offers clear benefits not only for the military, but also for the intelligence and law enforcement communities.

Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.

THURBON enhancements

MASS has unveiled further enhancements to the company’s THURBON electronic warfare and intelligence mission data management system. The company revealed it has developed a new iteration of the software known as THURBON CEMA (Cyber and Electromagnetic Activities).

THURBON CEMA significantly increases the system’s capabilities regarding blue and red force electromagnetic emitters across sea, land and air domains. THURBON presents the battlespace in a cartographic form covering the area of operations. Blue and red force assets such as bases, sensors, weapons systems, platforms and even individuals can be populated with an array of electromagnetic information. This data includes everything from the radars used by a surface-to-air missile battery to the cell phone of an individual. In fact, all the communications systems used by an individual can be matched to the person and depicted. As with the legacy THURBON architecture, THURBON CEMA users can easily see all the electromagnetic information associated with a blue or red force asset by clicking onto the asset and extracting the information you want to see. Alternatively, assets in the operational area can be filtered.

For example, a user may want to see all white force (neutral) assets in the operational area using satellite phones. This information can be easily retrieved and presented. As relevant intelligence is collected it can be entered into THURBON CEMA to populate the relevant assets. The CEMA enhancements to the THURBON software allows the user to not only see the red force Electronic Order-of-Battle (EOB), the blue force EOB can also be presented. The latter is invaluable during blue force electromagnetic planning and command and control, ensuring that a convoy’s communications coverage is uninterrupted, for example. Interruptions could arise from red force jamming, but also be due to natural causes like rugged terrain interrupting communications lines of sight.

Additional useful information like taboo frequencies can be loaded into THURBON CEMA and presented. Likewise, intelligence concerning Remote-Controlled Improvised Explosive Devices (RCIED) can be processed and presented. RCIED intelligence can include the types of radio system used to detonate roadside bombs. Alongside THURBON CEMA’s applicability to the military domain, the software can be employed to support intelligence gathering and law enforcement.

PLATH’s NEMO COMINT system is shown here equipping a Heer (German Army) General Dynamics/MOWAG Duro wheeled vehicle. The Heer acquired three NEMO systems as technology demonstrators in 2014. PLATH ‘s SDI Core is being developed to provide additional COMINT processing to networked NEMO systems.

Core business

This year’s PLATH Intelligence Workshop took place on 13th May in the town of Lillestrøm, southeast Norway. The company presented its SDI (Software Defined Intelligence) Core which is designed to provide a remotely accessible software core that can support Communications Intelligence (COMINT) analysis. The SDI Core is designed to work with the company’s NEMO COMINT systems family.

Company representatives said that some COMINT can often be unclear or corrupted. Such signals may eclipse the processing capabilities of NEMO. NEMO users can send ambiguous or unclear signals to the SDI Core which performs additional signals analysis. The SDI Core accommodates a host of software applications which can execute this additional analysis in near real time. The results of this additional analysis can then be shared with the NEMO users, or with third parties.

Company representatives said that the SDI Core is at the experimental stage and currently at between Technology Readiness Levels Three and Four (TRL-3/4). According to European Union definitions, TRL-3 denotes the demonstration of a technology’s experimental proof of concept. TRL-4 denotes that the technology has been demonstrated in a laboratory environment. PLATH representatives continued that the SDI should reach TRL-5, when the technology is demonstrated in a relevant environment over the next year.

BAE Systems’ new Dual Band Decoy is being developed to outfit the US Navy’s F/A-18E/F Super Hornet fleet. It is expected to enter service in circa 2027.

Dual is cool

On 15th May BAE Systems announced its selection by the US Navy to develop a new Dual Band Decoy (DBD) to equip the service’s combat aircraft. A press release announcing the news said the decoy will be used to help protect aircraft from radar-guided threats. The release continued that the DBD will build on the work the company has already performed vis-à-vis its AN/ALE-55 fibre-optic towed decoy. Like the AN/ALE-55, the DBD will outfit the US Navy’s Boeing F/A-18E/F Super Hornet planes. Don Davidson, BAE Systems’ advanced compact electronic warfare solutions director, told Armada that the company cannot specify what wavelengths and frequencies the DBD will be effective against. However, Mr. Davidson did state that the initial operational capability for the DBD is expected to be declared in circa 2027. (Source: Armada)

 

06 Jun 24. USAF on verge of rapid electronic warfare updates.

The Air Force is “very close” to being able to rapidly update electronic warfare systems with fresh battlefield data in a matter of hours, one of the service’s commanders said Wednesday.

Col. Josh Koslov, commander of the 350th Spectrum Warfare Wing, has set an ambitious goal of updating EW systems within three hours, instead of days.

In a webcast hosted by C4ISRNET, Koslov said that three-hour goal — which he once referred to as a “moonshot” — is now within reach.

“We’re very close to that, if not exceeding, in most of the systems that we cover in the spectrum warfare wing,” Koslov said. He went on to say that more than half of the 70 EW systems his organization touches across the Air Force are either at or below the three-hour mark for updating.

But many of those systems have unique elements, he said, and the Air Force’s EW systems need to make more use of interoperability and open architecture standards to simplify the process for rapid data updates.

And Koslov said his wing will need enough resources to develop these data production methods that will allow the military to process this data on a large enough scale to work in war, and then transport the data back to the field.

Koslov and Brig. Gen. Ed Barker, the Army’s program executive officer for intelligence, electronic warfare and sensors, said in the webcast that in a future war against an advanced adversary, conditions on the battlefield, threats and targets will likely change so quickly that rapid updates to EW systems will be critical.

‘Data is the weapon’

“We have to be able to continue to add pressure to the adversary in a war in order to seize the advantage and achieve our objectives,” Koslov said. “Data is the weapon that will allow this to happen, and data processing is the way to do that.”

This will include combining data from all sources in the joint force, such as Army units on land, naval ships in the Pacific, or airborne platforms, he said, and then combing through that information to find new threats. The military must then use that data to develop a way to counter that new threat, and then get that new capability back to the field.

To achieve these kind of rapid data updates, Koslov said, the Air Force has revamped its tactics, techniques and procedures to have more of a “warfighting” focus.

When asked whether data updates could be made to systems remotely, or whether they would require something to be physically plugged in, Koslov said that would depend on the EW system. He said information would be transported to Eglin Air Force Base in Florida, where the 350th is located, or other reprogramming centers where more people can process the data.

That will be especially useful during a major conflict against a nation such as China or North Korea, he said, in which joint forces would be spread out across the Pacific region.

“When you come out with a new capability, it’s not good if you just get it into one pocket,” Koslov said. “You have to be able to get it across the force. And so centralizing that is going to be the right way to do that as we move forward.”

The Air Force activated the 350th in 2021, and has since been building up its capabilities by adding more units. Earlier this year, the wing stood up two new electronic warfare squadrons — the 388th at Eglin and the 563rd at Joint Base San Antonio-Lackland in Texas.

The 563rd is focused on building new EW software for operational units to respond to the threats they encounter in the field. And the 388th is focused on studying adversaries such as China to find ways to breach and thwart their digital capabilities.

Koslov said his wing is next focused on building out the 950th Spectrum Warfare Group at Robins, which is expected to be fully activated in 2027. The 950th will be in charge of assessing the EW systems in Air Force’s combat aircraft and improving EW capabilities.

“Everything has to be assessed from a platform perspective — does the platform do what we’ve asked it to do?” Koslov said. “But also our [tactics, techniques and procedures] have to be assessed. … How good are we at fighting and training in the [EW] spectrum?” (Source: Defense News)

 

06 Jun 24. Bittium Tactical Wireless IP Network™ System and Bittium Tough SDR Vehicular™ Radio Accepted as Tactical Communications Solutions for the Armament of the Croatian Armed Forces.

Bittium Tactical Wireless IP Network™ System and Bittium Tough SDR Vehicular™ Radio Accepted as Tactical Communications Solutions for the Armament of the Croatian Armed Forces

The Ministry of Defence of the Republic of Croatia has accepted the software-defined radio based Bittium Tactical Wireless IP Network™ (TAC WIN) system and Bittium Tough SDR Vehicular™ radio as tactical communications solutions for the armament of the Croatian Armed Forces. The acceptance follows an implementation phase of few years of the products by the Croatian Navy. The implementation phase was carried out in cooperation with Bittium’s Croatian partner IntellByte INFO, a supplier of IT solutions that acts as the integrator of the Croatian Navy’s tactical communications system entity as well as the contracting party with the Navy. The orders related to this cooperation, received during the implementation phase as well as the ones expected in the future, do not have significant impact on Bittium’s financial guidance for the year 2024, nor in achieving its long-term targets.

During the implementation phase, part of the Croatian Navy’s backbone network for communications was built with the modular and broadband TAC WIN system and Tough SDR Vehicular radios were used to connect the Navy’s vessels as part of the survivable tactical backbone network.

Based on the successful implementation, the Ministry of Defence of the Republic of Croatia has accepted Bittium’s TAC WIN system and Tough SDR Vehicular radios for the armament of the Croatian Armed Forces. In addition to the Navy, the products can be offered also to other branches of the Croatian Armed Forces. The implementation of the tactical communications network for the Croatian Armed Forces will take place gradually and the Armed Forces will issue possible separate purchase orders for Bittium’s products and solutions as the implementation progresses.

“The successful implementation of the TAC WIN system and Tough SDR Vehicular radios by the Navy and acceptance for the armament of the Croatian Armed Forces is an excellent demonstration of our products’ and systems’ performance and applicability for different use cases. The modular software-defined radio-based TAC WIN system works seamlessly with other systems in use. We are proud to offer our products and systems to all the branches of the Croatian Armed Forces together with our local partner IntellByte INFO. Together we can take the Croatian Armed Forces’ tactical communications into a new era,” says Tommi Kangas, Senior Vice President of Bittium’s Defense & Security business segment.

“Situational awareness, fast movement, and the ability to make quick decisions are the key elements of a modern warfare doctrine. In order to achieve these goals, the modernization of tactical communications is set as a development imperative for the Croatian Armed Forces. By implementing Bittium’s solutions we significantly raised performance and brought a new and advanced work experience to the Croatian Armed Forces. This was a visible ICT technological leap, both for us who implemented Bittium solutions, and for the Croatian Armed Forces who gained the possibility of using broadband technologies locally, but also globally by implementing intercommunication services that enable communication between military coalition troops,” says Jasmin Hodzic, IntellByte INFO’s CTO.

 

03 Jun 24. Eight new companies to bolster cyber defences of critical UK sectors. Digital Catapult, the UK authority on advanced digital technology, has announced that a new cohort of companies will join Digital Security by Design’s (DSbD) Technology Access Programme (TAP) to trial necessary new cyber security solutions. Building on the programme’s success to date, eight companies will have access to an Arm Morello board, a prototype evaluation hardware kit based on Capability Hardware Enhanced RISC Instructions (CHERI), to consider its application across critical UK sectors.

DSbD is an initiative supported by the UK Government that is set to revolutionise cyber security in modern-day computing. In partnership with the University of Cambridge and Arm, DSbD’s Technology Access Programme works towards creating a more secure digital environment, in which only planned access to data and operations is permitted. The CHERI Instruction Set Architecture (ISA) will open up new markets for cyber secure-by-design products, providing a competitive advantage to companies that understand its strategic value and identify new use cases, such as protecting device users.

The new cohort’s efforts come as the UK Government stated that cyber security issues are now on an equal footing with other threats such as financial and legal pitfalls to UK businesses, and as the programme’s technology recently received recognition from the UK Government and the White House for its cyber security value. If the hardware and software features are implemented correctly, evidence has established that they can prevent two thirds of hacks, cyber attacks and data breaches, demonstrating the strategic importance of the programme on a global scale.

Bolstering the security of the UK’s device and gaming sector will be critical to maintaining levels of inward investment in the industry, as HaC Arcade will use the Morello board and CHERI architecture to secure a networked gaming rig system that virtually connects players across the UK. Since vulnerabilities can occur on both the network and hardware, additional memory security is highly valuable. ExactTrak aims to improve the security of laptop devices by developing a platform that can securely manage employee devices while complying with government protocols for products used by security and intelligence services, and make this solution available across all enterprises.

The cohort will also look to enhance the safety and security of drivers and those that have fallen victim to cyber-attacks. Coventry-based Secure Elements will develop a solution that uses the Morello Board to identify new vulnerabilities in vehicles’ security systems, allowing for vulnerabilities to be flagged immediately to its cyber security application. Cyntegra, a company that offers solutions to fix systems after they have been attacked by malware, will integrate their own system into Morello and CHERI, to restore an entire system’s functionality back to normal after an attack.

Defence will also be a focus for the new cohort, as Kaze Consulting and Cyber Defence Service Ltd will experiment with and test the Morello board and CHERI architecture to uncover security vulnerabilities in their own products. Kaze Consulting will consider how cyber security can be improved by deploying CHERI devices to new environments, with a view to deploying CHERI to a specialist domain such as the satellite ecosystem, while Cyber Defence Service Ltd will explore how CHERI architecture could monitor and protect critical national infrastructure in the near future.

The remit of the cohort’s solutions extends beyond the UK, with Vividgrd aiming to transform commercial sites into microgrids globally, while OpenLX SP Ltd will deploy its hardware solutions worldwide, collecting data and controlling systems across various sectors. During the programme, Open LX will look to explore how Morello can bring more security to its ultra lightweight “Function-as-a-Service” that blurs the boundaries between on-premise servers, cloud, edge and devices for internet of things (IoT), while the latter will consider how to make digital security an integral part of its distributed internet of things IoT system.

Digital Catapult hopes that the new cohort’s participation on the programme will encourage the development of new security solutions in the long term, as several leading alumni of DSbD, including ScienceScope, have since planned additional development phases to enhance their security measures and solutions.

Jessica Rushworth, Chief Strategy and Policy Officer, Digital Catapult said: “Cyber security remains front of mind for businesses across almost every sector in the UK, and the success of the Digital Security by Design programme is testament to the strategic value and importance of the ongoing collaboration between Digital Catapult, the University of Cambridge, Arm and participating companies, both past and present. Security issues continue to inhibit business growth, so the development of new solutions to tackle real-world cyber security challenges is critical to achieving long-term commercial success. This fifth cohort will build on the groundwork laid by their predecessors, moving us closer to a safer cyber landscape.”

Prof. John Goodacre, Challenge Director, Digital Security by Design, UK Research and Innovation, said:  “With the announcement of this Fifth Cohort of the Digital Security by Design Technology Access Programme, we are delighted to offer further businesses across the UK the opportunity to engage with the DSbD Technology and provide applicants with the funding and support to understand how their products and services can benefit, blocking vulnerabilities so that their operations and customers can be better protected against the growing costs and harm of a cyber attack.”

Companies interested in taking part in Digital Security by Design’s Technology Access Programme can register their interest on the DSbD website and be notified when applications open again.

 

03 Jun 24. UK General Election will face increased cyber threats. On 23 May, UK Prime Minister Rishi Sunak announced that a general election will be held on 4 July.

SIGNIFICANCE

  • In the run-up to and during the election, state-sponsored actors are likely to conduct cyber attacks against the UK. These attacks will likely aim to influence the election’s outcome, to disrupt election infrastructure and to undermine trust in the electoral process. However, the impact of any such cyber activity on the formation of the government is unlikely to be significant.
  • Cyber criminals will also likely exploit the election during financially motivated operations, elevating phishing and information-theft risks for UK voters.
  • If the Conservative Party loses to the Labour Party, we assess that the consequent transfer of power would create further opportunities for cyber actors. This would possibly disrupt the creation of the new government and delay policy making.

FORECAST

We assess there is a realistic possibility that Chinese- and Russian-backed threat actors will target election infrastructure and conduct influence operations. Both countries have an interest in influencing or deterring the next government’s policies pertaining to London’s relations with Beijing as well as its ongoing military support for Ukraine. As such, Chinese and Russian actors will possibly target the electorate in influence operations to sway the voting population, as demonstrated by their interference in prior elections. The upcoming European Parliament (EP) elections also face similar risks (see Sibylline Special Report – 3 May 2024). Any such operations will likely take the form of artificial intelligence (AI)-generated content, including deepfakes; bots on social media platforms are also likely to spread dis/misinformation at increased levels.

We assess that Chinese and Russian state-sponsored actors will possibly target election infrastructure in disruption operations to inhibit the voting process. The UK Electoral Commission suffered a cyber attack in 2021 that was conducted by suspected Chinese state-sponsored actors. The attack granted the actors undetected access to electoral registers, employee emails and the commission’s computer systems for over a year. Consequently, state-backed actors will possibly target similar information sources. However, while the UK general election will face possible disruption and influence risks stemming from state-backed actors, it is likely that these actors will focus more on operations targeting November’s US presidential election.

We assess that cyber criminals are likely to exploit the general election to garner illicit profit via phishing and watering hole campaigns. UK residents will likely face an increase in election-themed phishing emails from actors who aim to steal information to sell on the dark web. It is also likely that more ‘typosquatting’ and ‘watering hole’ attacks will take place. ‘Typosquatting’ occurs when a user unwittingly types an infected URL in which there is a subtle typo into their web browser, while a ‘watering hole’ attack takes place when cyber actors infect a website they know their target(s) will visit. These domains will likely pretend to be related to particular candidates or other election themes in an aim to steal personal and financial information from users (again to sell on the dark web for profit). Ransomware will also pose moderate disruption risks for the electoral system. Consequently, there will be elevated phishing, fraud and identity-theft risks facing UK residents and voters in the run-up to the election.

We assess there is a realistic possibility that threat actors will exploit the potential transfer of power following the election via disruptive espionage operations. The instability that typically occurs during these transition periods will possibly exacerbate operational continuity risks for the UK government. In particular, state actors will possibly attempt to delay or influence the establishment of certain policies and/or legislation for their own country’s strategic benefit. State-sponsored actors and cyber criminals will possibly target government entities during the transition period after the election if the Conservative Party loses the majority vote. Attackers will possibly use ransomware to disrupt operations, while also conducting phishing operations to install backdoors on strategic networks for future long-term espionage campaigns.(Source: Sibylline)

 

31 May 24. Open DAGIR: DoD plans July industry day, experiments for new CJADC2 command apps. The Chief Digital & AI Office wants to bring in a wide range of software developers to rapidly create new applications for Combatant Commands worldwide, with the new apps plugging into Palantir’s open-architecture Maven Smart System.

Instead of a single megaprogram run by a single contractor, the Pentagon wants its nascent global battle network, called CJADC2, to evolve into a rapidly adaptive ecosystem, where dozens of different applications bloom and die as military needs arise and change.

So, just after awarding almost a half-bn dollars to Palantir Technologies to expand its Maven Smart System tenfold, the Chief Digital & AI Office (CDAO) announced a new initiative, Open DAGIR, to open the doors to other software developers.

While Palantir’s Maven will act as the de facto backbone for the global system, its “open architecture” design is meant to allow other companies’ code to plug in, quickly, with a minimum of integration work. That plug-and-play approach, in turn, should allow the operational Combatant Commands (COCOMs) around the globe to commission custom apps as needed from any vendor.

“We want America’s best talent solving DoD’s hardest problems,” said the new Chief Digital & AI Officer, Radha Plumb, in a published statement Thursday.

The first of those hard problems is CJADC2: Combined Joint All-Domain Command & Control — that is, linking all the US armed services (“joint”) and their coalition partners (“combined”) across the five “domains” of land, sea, air, space, and cyberspace. Last year, CDAO and the COCOMs used quarterly Global Information Dominance Experiments (GIDE) to speed-run development of a “Minimum Viable Capability” for CJADC2. Now, as the GIDE experiments continue, CDAO is looking to build beyond that “minimum,” a senior defense official told reporters Thursday.

“What we learned is, it’s not one company or one thing that makes advanced C2 capabilities,” the official said. “It’s making sure we have the data in a way that’s accessible to a broad range of talented software developers, across a range of companies….What we’ve done here is created a scalable way to do that.”

The push for “third-party capabilities” will kick off June 1 with “a six week sprint” by Pentagon experts in intellectual property, contracting, and software development, the official said. Their mission: to figure out a competitive process that will meet military commanders’ needs, build on Palantir’s technology, but also protect other contractors’ IP.

Then, in July, CDAO will hold an industry day for interested companies and run an initial round of experiments to try out software, as part of the same quarterly GIDEs the Pentagon has been using to thrash out CJADC2.

Triple DAGIR

Overall, Open DAGIR — short for “Open Data & Applications Government-owned Interoperable Repositories” — involves three interdependent but distinct layers, the official explained:

  1. Data Infrastructure: Data is the foundation for any functioning analytics or artificial intelligence, as Radha’s predecessor, founding CDAO Craig Martell, was fond of saying. That means the data is not only accessible but properly tagged, labeled, and structured so a variety of different systems can read it. The government will retain ownership and control of the data, but Palantir will build and operate the software “stack” required to manage it day-to-day. (This is a model known as Government Owned, Contractor Operated, or GOCO). However, third-party contractors will be able to access the Palantir-managed data as needed to make their software work, the official emphasized.
  2. Mature Applications: This layer is for software that has proven stable, functional, and cybersecure, and which the government decides to use on a large scale for a long time. Such apps will be purchased on an “enterprise license” basis, meaning CDAO will buy the rights for them to be used by an entire organization, like a COCOM or even the whole Department of Defense. Palantir’s Indefinite-Quantity, Indefinite-Delivery (IDIQ) contract for the Maven Smart System is the leading example here, and the only one the official mentioned by name, but others will presumably be added in the future.
  3. Competitive Environment: Even the most mature and regularly updated software program can’t meet all needs, however. That’s why the final layer of CDAO’s new approach is a “competitive environment” where COCOMs can issue new requirements, interested software developers of all sizes can compete to meet them, and the winning products can be fielded rapidly, using Other Transaction (OT) contracts. (All these developers will have access to the Palantir-managed but government-owned data). Successful software may eventually graduate to the “mature” layer and earn a long term contract, or it may simply meet an immediate need and fade away.

“They can be applications that are fit for a particular urgent or emergent need that we want to build and deploy rapidly, but we may not want to sustain for years or decades,” the official explained. “Those can be funded through the OT [Other Transaction Authority], delivered, fielded very quickly, and then…we can deprecate [them] as we no longer need them. The second class is the set of applications that are mature [and which] we want to be enduringly available, and those can be transitioned into the IDIQ itself, integrated with the Palantir stack.”

By using different types of contracts, and switching a given piece of software from one type to another as needed, CDAO should be able to exploit competition among companies to rapidly add new capabilities at the top layer — without having to change its foundation-layer contractor and laboriously rebuild everything from the bottom-up for every update. (That ordeal historically happened all too often with traditional systems where a single “lead systems integrator” built everything on a single contract using proprietary technology that was incompatible with other contractors’). In fact, although the official didn’t say so aloud, in theory it should even be possible to replace Palantir as the contract for the data infrastructure, for Maven, or both.

“Open DAGIR ensures the Department can leverage the innovative solutions from the world-class software developers in both the traditional and nontraditional industrial base,” Plumb said in her statement. “It allows us to ensure enduring access to government-owned, contractor-operated technology stacks and infrastructure and retain data rights while also maximizing the ability of other companies to develop applications with government data.” (Source: Defense News Early Bird/Breaking Defense.com)

 

31 May 24. Cyber Update.

Key points

  • A new highly sophisticated gift card scam underscores the elevated security and financial risks facing US retailers (see Sibylline Cyber Daily Analytical Update – 28 May 2024 and our Technical analysis below).
  • The adoption of new custom ransomware by the North Korean state-sponsored group ‘Moonstone Sleet’ will sustain elevated security and financial risks for the technology sector (see Sibylline Cyber Daily Analytical Update – 29 May 2024 and our Technical analysis below).
  • A new vulnerability affecting virtual private network (VPN) services has accentuated security and reputational risks via the software supply chain (see Sibylline Cyber Daily Analytical Update – 30 May 2024).
  • A new phishing campaign attributed to the Russian-aligned group ‘FlyingYeti’ highlights the sustained security and espionage threats facing Ukrainian civilians (see Sibylline Cyber Daily Analytical Update – 31 May 2024). Technical analysis of weekly stories. The cyber criminal group ‘Storm-0539’ is targeting US-based employees of retailers, luxury brands and popular fast-food chains in a new and highly sophisticated gift card scam. The campaign starts with phishing emails and text messages (smishing), which the group crafts after extensive reconnaissance to steal user credentials and session tokens through adversary-in-the-middle (AitM) phishing pages. It then uses these stolen credentials to access a targeted organisation’s cloud environment, registering its own devices on the victim’s system to  bypass authentication, achieve persistence and escalate privileges. This enables Storm-0539 to create fraudulent gift cards and sell credentials on the dark web to garner illicit profit. Notably, this campaign marks a shift in the group’s capabilities due to the sophisticated exploitation of cloud environments. Additionally, the group occasionally impersonates non-profit organisations to obtain discounted or free cloud infrastructure. This significantly bolsters the group’s success rates by enhancing its legitimacy. In one instance, an unnamed organisation detected Storm-0539’s activity on its system, implementing changes to prevent the creation of additional fraudulent gift cards; however, the group was able to adapt its tactics quickly, regaining access to corporate systems and demonstrating its ability to persist within targeted infrastructure.

The North Korean state-sponsored group ‘Moonstone Sleet’ (formerly tracked as ‘Storm-17’) has started deploying ransomware against software development companies and the defence sector. The group’s tactics, techniques and procedures (TTPs) typically align with known techniques associated with other North Korean groups, particularly ‘Diamond Sleet’, such as using social media to deliver trojanised software, malicious npm packages and tank games. However, Moonstone Sleet’s infrastructure now includes ransomware, highlighting the expansion of the group’s operations as well as its resources. The group has notably created several fake technology and software development companies to solicit co-operation with targeted individuals, while also seeking employment within targeted companies. This primarily aims to foster rapport with potential victims to trick them into downloading the group’s custom malware, ‘FakePenny’. Additionally, Moonstone Sleet’s pivot to conduct IT work within its campaigns possibly signals that it is starting to carry out financially motivated operations.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Conduct cyber hygiene awareness courses for users to enable them to recognise and report phishing and other types of social engineering attempts.
  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Enforce strict security policies including regular software and password updates to mitigate and prevent infections via leaked or stolen password credentials.
  • Ensure adequate security detection measures are in place, particularly behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.

Our cyber word(s) of the week: adversary-in-the-middle (AitM) attack

(Source: Sibylline)

 

—————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Spectra Group (UK) Ltd

 

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————–

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT