Sponsored by Spectra Group
———————————————————————————————————————————————————————————————————————————————————————————————————————————————
04 Jul 24. Glimmer and Taxable. Moving scenes graced the beaches of Normandy in early June as the 80th anniversary of the Operation Overlord D-Day landings was commemorated. Veterans remembered fallen comrades and the horrors which greeted them as they took this decisive action in the battle to free the continent from fascism.
Electronic Warfare (EW) was instrumental to the success of Overlord. Operations Taxable and Glimmer played key parts in fooling the Germans as to where the allied invasion would land. Both efforts involved Royal Air Force aircraft dropping large clouds of chaff which moved progressively closer to the Pas de Calais and Cap d’Antifer on the French coast. These two locations were north of the actual D-Day objectives in Normandy. The chaff clouds were dispersed in such a way as to create an image on German radars replicating an armada of vessels approaching at a steady speed of several knots. At the same time, a flotilla of small ships and boats headed towards the Pas de Calais and Cap d’Antifer. The boats were equipped with radar-reflecting balloons and could simulate naval communications traffic.
This combination of aircraft, boats and their adornments looked on radar screens like two incoming fleets of ships headed for northern France. As history shows, the ruse paid off and the German military took the bait. Both operations greatly contributed to the success of Overlord and showed the transformative power of EW, a legacy that continues today and into the future. (Source: Armada)
04 Jul 24. To Kill a Pantsir.
The wreckage of a Russian 96K6 Pantsir short-range air defence system lies smouldering in Ukraine. Electronic warfare has played an instrumental role in helping hunt down and engage these short-range air defence systems.
Armada has been briefed on some of the tactics used to engage and defeat the 96K6 Pantsir-S1 series SHORAD system.
The 96K6 Pantsir-S1 (NATO reporting name SA-22 Greyhound) series Short-Range Air Defence (SHORAD) system is deployed extensively with the Russian armed forces and has been exported to twelve nations. The 96K6 has been used operationally supporting Russia’s ongoing deployment in Syria to bolster the regime of President Bashir al-Assad, the country’s leader. 96K6s have also been supplied to Syria’s armed forces. The system has been deployed to Libya where it has served with Libyan National Army (LNA) forces loyal to warlord Field Marshal Khalifa Haftar. Recently, Russian forces have deployed 96K6 systems to support their ongoing occupation of Ukrainian territory.
In Russian military service, the Russian Aerospace Forces typically deploy three 96K6s with each S-400 (SA-21 Growler) high-altitude/long-range Surface-to-Air Missile (SAM) battalion. Two S-400 battalions form an anti-aircraft missile regiment with between two and five regiments forming an air defence division. The 96K6’s role is to provide SHORAD for the S-400 batteries. This is to protect the batteries against aircraft, Uninhabited Aerial Vehicles (UAVs) and anti-radiation missiles seeking to exploit blind spots in the low-altitude coverage of the S-400’s 91N6A/E (Big Bird) S-band (2.3 gigahertz/GHz to 2.5GHz/2.7GHz to 3.7GHz) and 96L6E (Cheese Board) C-band (5.25GHz to 5.925GHz) ground-based air surveillance radars.
Capabilities
The 96K6 uses a combination of 57E6 semi-active radar homing/optically guided SAMs with a range of 9.7 nautical miles/nm (18 kilometres) and a maximum altitude of 49,000 feet/ft (14,935 metres/m). The missiles are joined by two 2A38M 30mm autocannons with a maximum altitude of 9,842ft (3,000m) and range of 2.2nm (four kilometres). Target detection is provided by the system’s 2RL80 S-band radar with a range of circa 27nm (50km). Once a target is detected, engagement is managed using the system’s 1RS2-1 X-band (8.5GHz to 10.68GHz)/Ku-band (13.4GHz to 14GHz/15.7GHz to 17.7GHz) radar. The 1RS2-1 has a 15nm (28km) range.
Sources familiar with Pantsir’s deployment to Ukraine shared with Armada that the system’s presence in previous warzones such as Libya and Syria have proved useful. Significant Electronic Intelligence (ELINT) pertaining to the Pantsir’s radars has been gathered by key North Atlantic Treaty Organisation (NATO) nations during these deployments. This bedrock of ELINT has been used to programme Electronic Support Measures (ESM) to recognise and exploit Pantsir radar signals. The ELINT has proved similarly useful for programming electronic attack systems so that the 96K6’s radars can be jammed.
Pantsir in Ukraine
Ukrainian forces claim to have captured several 96K6s, one of which has been used to develop and test ESM and electronic attack system performance against the Pantsir’s radars. One tactic pioneered by the Türk Silahlı Kuvvetleri (Turkish Armed Forces) has been to use Aselsan’s Koral electronic warfare system against the Pantsir’s radars. Koral is a ground-based ESM used by the Türk Kara Kuvvetleri (TKK/Turkish Land Forces). Koral is thought capable of detecting, locating, identifying and jamming radio frequency signals across a waveband of two gigahertz to 18GHz. Recent enhancements to the system are believed to have increased this waveband to 40GHz.
Koral was used by the TKK to provide a ‘lane’ of jamming directed against the Pantsir’s radars. With the radars blinded, the system was unable to detect and track incoming Baykar Bayraktar TB-2 UAVs which would then attack the 96K6 kinetically. Although Russian radar engineers did work to adapt the Pantsir’s radar waveforms to outflank the jamming, this has often proved unsuccessful. The continued collection of ELINT regarding the Pantsir threat in the Ukrainian, Syrian and Libyan theatres means that the adaptation of jamming waveforms for use against the 96K6’s radars has been quick. In some cases, it is possible to develop a new jamming waveform for employment against a new Pantsir radar waveform within hours. In addition to using systems like Koral, UAVs have been incorporated in the fight. Some UAVs are outfitted with ESMs to find the Pantsir. Once located, other UAVs begin jamming the radars before the 96K6 is attacked kinetically.
One measure taken by Russian air defenders has been to ring fence Pantsir deployments with 1L122 Garmon L-band (1.2GHz – 1.8GHz/1.67GHz – 1.71GHz) ground-based air surveillance radars. The radars are deployed to provide early warning of incoming hostile UAVs. Nonetheless, emissions from these radars are relatively easy to detect and jam. Moreover, detection of a Garmon radar may indicate that a lucrative Pantsir target is nearby.
The 96K6 had a fearsome reputation when it entered Russian military service in 2012 although successive conflicts in Syria, Libya and Ukraine have betrayed its vulnerabilities. The open source oryxspioenkop website which documents equipment losses in the ongoing Ukraine war has said that Russia may have lost up to 19 96K6s as of September 2023. It is all but inevitable that electronic warfare will have played a prominent part in the destruction of these, and other, 96K6 platforms. (Source: Armada)
04 Jul 24. July Spectrum SitRep.
Northrop Grumman’s CIRCM system equips all US Army rotorcraft including Boeing CH-47 Chinook series heavylift helicopters shown here. It will also equip the army’s Future Vertical Lift rotorcraft.
Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.
Captain CIRCM
In early June Northrop Grumman announced that the company had delivered its 500th Common Infrared Countermeasures (CIRCM) system to the US Army. Reports stated that a further 336 CIRCMs remain on order with the total number of systems to be delivered to exceed 800. CIRCM reached an initial operational capability with the US Army in 2023 following the first field installation which occurred in 2021. Since then, the system has been installed across the US Army’s helicopter fleet. CIRCM is also expected to be installed onboard the army’s Future Vertical Lift rotorcraft platform. Bob Cough, Northrop Grumman’s vice president of aircraft survivability, told Armada that he expects CIRCM production to continue into the 2030s. CIRCM units currently under contract are expected to complete delivery by 2026.
Bad News for Jammers
Project BadB, led by Krattworks, has been awarded funding worth $6.4 m to develop technology to outflank Global Navigation Satellite System (GNSS) Position, Navigation and Timing (PNT) signal jamming. A press release announcing the news said the technology will be realised by employing satellite imagery data and machine vision algorithms. A key goal of the project is to ensure that platforms like Uninhabited Aerial Vehicles (UAVS) can navigate reliably without needing external radio sources such as PNT signals.
The funding has been awarded by the European Defence Fund (EDF). The EDF is a European Union (EU) initiative which, in its own words works to foster cooperation between companies and organisations in the defence sector, boost defence capability development, and help EU companies develop cutting edge and interoperable defence capabilities. Technologies to be developed include “a machine vision module, an image recognition system and development of a path planning system, based on sensor data, cross-platform data sharing and swarming,” said the press release.
Alongside Krattworks, GIM Robotics, Kappazeta and Rigr AI are involved in Project BadB. Edward Dixon, Rigr AI’s chief executive officer, told Armada that the project is currently between Technology Readiness Levels (TRL) Two and Four. According to European Union definitions TRL-2 means the technology concept has been formulated. TRL-3 denotes that an experimental proof of concept has been realised. TRL-4 shows that the technology has been demonstrated in a laboratory. Mr. Dixon says that the aim of the project is to reach TRL-8 with a complete system being qualified. This is the penultimate level before the technology is proven operationally, and ready for deployment. The technology could be fielded on UAVs before the two-year project closes in circa 2026. (Source: Armada)
04 Jul 24. South Korea: New cyber espionage operation underscores bilateral tensions, supply chain risks. On 1 July, the security company AhnLab Security Intelligence Center (ASEC) reported that a North Korean threat group compromised a third-party enterprise resource planning (ERP) server to target a South Korean defence organisation in May. We assess that this report is likely accurate. The report suspects that ‘Andariel’, a subgroup of the North Korean state-sponsored group ‘Lazarus’, is behind the campaign. Andariel reportedly deployed the malicious file ‘Xctdoor’ on the compromised system to execute commands and steal sensitive information including keystrokes and screenshots. The group likely installed ‘XcLoader’ to inject Xctdoor into legitimate processes. North Korea routinely targets South Korean companies in espionage operations to steal intellectual property and to bolster its own economic and security posture. This highlights elevated security and espionage risks from North Korean state-sponsored groups amid ongoing bilateral tensions. Andariel’s likely exploitation of the ERP management software system to infiltrate a third-party organisation also points to elevated security risks via the software supply chain. (Source: Sibylline)
04 Jul 24. New Line of NATO Flange Vehicle Antennas Released.
Southwest Antennas’ latest line of ruggedized NATO flange vehicle-mount omni antennas are IP67 rated, can withstand significant impacts, and have been rigorously collision-tested. A new line of rugged vehicle-mount omni antennas has been released by Southwest Antennas.
The product line offers a range of antennas supporting L, S, and C frequency bands, along with a versatile dual-band option that combines L and S bands.
Each antenna is engineered for robust mounting, compatible with both 6-hole NATO and standard 4-hole USA vehicle mounting brackets. This ensures easy and secure installation on various military platforms, providing flexible and reliable communication solutions for defense operations.
The omni antenna range includes:
- 1073-003 – L-band antenna (1.35-1.45 GHz) with 5.2 dBi max gain
- 1073-001 – S-band antenna (2.2 – 2.5 GHz) with 5.6 dBi max gain
- 1073-002 – C-band antenna (4.4 – 5.0 GHz) with 5.9 dBi max gain
- 1073-004 – L & S-band antenna (1.35-2.5 GHz) with 2.6 dBi max gain
Engineered for compatibility with most leading tactical radio systems, the vehicle-mount antennas deliver 360-degree azimuth coverage for comprehensive communication capabilities and feature high-quality element designs that ensure optimal peak gain, enhancing signal strength and clarity. Equipped with a Type-N (female) RF connector they are designed to operate without the need for a ground plane, simplifying installation and improving operational flexibility.
Southwest Antennas’ rugged vehicle-mounted omni antennas are specifically engineered for the intense demands of military and law enforcement operations. Boasting an IP67 rating for exceptional ingress protection, they are built to endure harsh environments and challenging conditions.
Featuring heavy-duty spring bases, these antennas are resilient against snags and significant impacts. They have undergone rigorous collision testing at speeds of up to 30 mph, ensuring they maintain peak performance and durability even under extreme circumstances. (Source: https://www.defenseadvancement.com/)
03 Jul 24. Global: Critical vulnerabilities highlight elevated security risks via software supply chain. On 2 July, international news outlets reported that three vulnerabilities (CVE-2024-38368, CVE-2024-38366 and CVE-2024-38367) have potentially impacted millions of iOS and macOS users for over a decade. The vulnerabilities reside in CocoaPods, a software dependency manager that hosts code libraries for developing applications. CVE-2024-38368 enables threat actors to claim ownership of code libraries, allowing them to inject malicious code while CVE-2024-38367 can be used to bypass authentication processes, granting threat actors the capacity to hijack customer accounts. Additionally, CVE-2024-38366 allows for remote code execution, facilitating data theft and the installation of malware. CocoaPods is used by over three m applications across the Apple ecosystem as well as other organisations including Amazon, Meta, Microsoft and TikTok. These vulnerabilities highlight the widespread consequences of third-party security compromises and the resultant security risks to firms via the software supply chain. CocoaPods has since released patches for these vulnerabilities, emphasising the importance of strict patch management policies to prevent compromises and mitigate risk vectors. (Source: Sibylline)
02 Jul 24. Global: New zero-day vulnerability sustains security risks from Chinese state-sponsored actors. On 1 July, the technology company Cisco revealed that the Chinese state-sponsored group ‘Velvet Ant’ has been exploiting a zero-day vulnerability in its NX-OS software (CVE-2024-20399) since April. The vulnerability enabled threat actors with administrator-level credentials to execute arbitrary code against the targeted operating system. Velvet Ant exploited this vulnerability to deploy unnamed custom malware, allowing the group to remotely connect to compromised systems and upload additional malicious files. Notably, CVE-2024-20399 does not generate any data log messages upon executing commands, thereby allowing threat actors to remain undetected. In April, the Chinese state-sponsored group ‘UAT4356’ exploited multiple zero-day vulnerabilities in an espionage campaign targeting several government organisations worldwide. This incident highlights the ongoing exploitation of zero-day vulnerabilities by Chinese state-sponsored actors, illustrating sustained security and third-party risks to firms. Cisco has since patched this vulnerability, underscoring the importance of strict patch management policies in mitigating exploitation risks. (Source: Sibylline)
27 Jun 24. Pentagon to issue guidance on open radio access networks to support 5G.
As Department Defense looks to find the right mix of bespoke and openly available technologies to support 5G adoption and FutureG. initiatives, officials put an emphasis on open architecture Thursday.
At the TechNet Cyber conference presented by the Armed Forces Communications & Electronics Association International in Baltimore, leaders from the Pentagon discussed capabilities for public, private and hybrid networks. Officials acknowledged there’s a natural appetite for the most exclusive, secure networks in the national security space. And sometimes there is no wireless network infrastructure available in remote warfighting locations far from population centers.
So as the services determine appetite for private networks that offer more control over information sharing, the DoD is guiding them to use open radio access networks, or ORAN, said Juan Ramírez, the director of the 5G Cross-Functional Team at DoD.
“I think what industry wants to hear is there’s actually going to be requirements that come out that … necessitate an open RAN architecture,” he said at the conference. “So you’ll start to see those come out in the next couple of years, pending budgets.”
Certainly, private networks aren’t the only way to go. In fact, sometimes that’s not the best solution, said Lt. Col. Benjamin Pimentel, who leads the Camp Pendleton 5G experiment for Expeditionary Advanced Base Operations.
“Think about when we deploy in a theater,” he said. “A lot of countries that we go to or locations that we go to already have roads and bridges, and it’d be silly to then go and build my own private roads and my own private bridges separate and apart from that to get where I need to go. If those roads and bridges meet my transportation requirement, and they’re not going to fall under the weight of a ‘seven ton,’ we’re going to drive over it.”
But, somewhere like the first island chain, for example, may not have adequate coverage to put up sensors for long-range precision fires. In cases like those, he said, it would make more sense for units to bring private capabilities.
Given China’s rising aggression and U.S. efforts to deter it in the Taiwan Strait, what Pimentel described is the type of environment where current threats seem to colocate.
Regardless, to ensure there is connectivity wherever the need is, Ramirez said the department is looking at ORANs, which allow multiple vendors to operate as one network and provide more flexibility to scale.
ORAN is something the DoD has been pushing aggressively to explore as it simultaneously journeys toward more standard 5G adoption on military installations and “smart bases.”
Ramirez said the department is hopeful it will get additional support from Congress via future defense spending bills that will backup forthcoming requirements with dollars.
The Pentagon’s 2024 budget requested $143 bn in research, developing and testing of emerging technologies including 5G, but also artificial intelligence. Much of the spending in recent years has been for prototyping, and though the Office of the Secretary of Defense has the lion’s share, Ramirez said his office is offering direction to the services for them to budget for 5G.
“We think that pursuing ideas like [ORAN] advanced by the ORAN Alliance all the way to fully open-source code … provides the feature velocity the DoD needs and the ability to innovate quickly,” said Pimentel.
(Source: C4ISR & Networks)
28 Jun 24. Cyber Update Key points.
- A new campaign targeting Taiwanese organisations points to sustained espionage risks from Chinese state-sponsored groups (see Sibylline Cyber Daily Analytical Update – 24 June 2024 and our Technical analysis below).
- The increased targeting of the 2024 US presidential election elevates disinformation risks posed by Russian actor, ‘CopyCop’ (see Sibylline Cyber Daily Analytical Update – 25 June 2024).
- A new iteration of the banking trojan ‘Medusa’ is being used to target banking app users, elevating security and financial risks (see Sibylline Cyber Daily Analytical Update – 26 June 2024).
- Financially motivated threat actors are using highly sophisticated malware to target Southeast Asian banking app users, raising security and financial risks (see Sibylline Cyber Daily Analytical Update – 27 June 2024 and our Technical analysis below).
- Threat actors are exploiting legitimate third-party software as a malware delivery vector; this underscores sustained security, financial and reputational risks (see Sibylline Cyber Daily Analytical Update – 28 June 2024).
Technical analysis of weekly stories
The suspected Chinese state-sponsored group ‘RedJuliett’ is targeting Taiwanese government, academic, technology and diplomatic organisations in a new espionage campaign. The group reportedly exploits software vulnerabilities in internet-facing network edge devices such as firewalls, virtual private networks (VPNs) and load balancers to obtain initial access to targeted networks. Upon initial access, the threat actors deploy a SoftEther VPN service to establish persistent communication with actor-controlled infrastructure and perform reconnaissance. RedJuliett then used the ‘China Chopper’ web shell to establish persistence and to remotely execute code on the compromised system. Subsequently, the threat actors conducted structured query language (SQL) injections as well as directory traversal attacks to access sensitive files and escalate privileges. Additionally, RedJuliett also used ‘living off the land’ techniques upon infiltrating the system, and exploited a known Linux vulnerability to escalate privileges. This operation further underscores the continued focus on the exploitation of software vulnerabilities to gather sensitive data on China’s strategic targets, underscoring widespread security risks.
Threat actors are using new, highly sophisticated mobile malware (known as ‘Snowblind’) to target banking customers in Southeast Asia. The malware exploits a mobile sandbox mechanism known as secure computing, ‘seccomp’, and an application’s accessibility features to steal sensitive information and garner illicit profit. Snowblind is first injected into targeted applications before the anti-tampering code in the backend, thereby allowing threat actors to load additional malicious files. The malware then downloads a malicious seccomp filter to prevent any malicious activity from being detected by triggering a system error. Notably, the targeted nature of this filter allows for minimal performance impact and operational footprint, enabling the threat actors to achieve prolonged obfuscation. Subsequently, the threat actors can then exploit an application’s accessibility features to view the victim’s screen and input text. They also perform other malicious activities including stealing login credentials, hijacking a user’s banking session, disabling security features and exfiltrating personal information. Additionally, Snowblind can disable several other app security features such as two-factor authentication (2FA), further enabling the threat actors to remain undetected. The malware’s ability to bypass anti-tampering code, combined with its advanced anti-detection mechanisms, underscores the growing sophistication of cyber criminals’ tactics, techniques and procedures (TTPs) and highlights cyber security risks, especially for customers using banking software in Southeast Asia.
Some non-exhaustive recommendations to mitigate against these threats include:
- Introduce adequate network segmentation to isolate internet-facing services in a demilitarised zone (DMZ).
- Monitor devices and networks for suspicious activity, including the presence of follow-on activities such as the use of web shells, backdoors and lateral movement.
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
- Enforce strict patch management policies prioritising high-risk and remote code execution (RCE) vulnerabilities.
- Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices.
- Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
Our cyber word(s) of the week: WebSocket. (Source: Sibylline)
————————————————————————————————————————————————————————————————————————————————————————————————————————————–
Spectra Group (UK) Ltd
Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.
Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.
With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.
Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.
In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.
Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.
Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.
———————————————————————————————————————————————————————————————————————————————————————————————————————————————

