• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

July 12, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

———————————————————————————————————————————————————————————————————————————————————————————————————————————————–

12 Jul 24. Cyber Update Key monthly trends. The increased emergence of operations from Chinese state-sponsored groups underscores elevated security and espionage risks to organisations in the Asia-Pacific region

Reports revealed several long-term cyber espionage campaigns from Chinese state-sponsored groups in June. The campaigns targeted government, telecommunications, academia, technology and diplomatic organisations in the Asia-Pacific region. The state-sponsored group ‘RedJuliett’ infiltrated multiple Taiwanese organisations, likely to steal sensitive information and intellectual property. The group reportedly exploited software vulnerabilities in internet-facing network edge devices to obtain initial access. Additionally, reports indicate that several Chinese-nexus actors (including ‘Fireant group’, ‘Needleminer group’ and ‘Firefly group’) have been targeting telecommunications providers in an unnamed Asian country since at least 2021. The groups used multiple custom backdoors to steal sensitive information from compromised systems, including credentials, while also likely pre-positioning themselves for future disruptive operations. Similarly, threat actors targeted an unnamed government agency in Southeast Asia in a long-term espionage campaign known as ‘Crimson Palace’ between March and December 2023. Crimson Palace is likely centrally co-ordinated by a single entity, pointing to the likely co-operation of several state-sponsored groups including ‘BackdoorDiplomacy’, ‘REF5961’ and ‘Earth Longzhi’. The first phase focused on conducting reconnaissance; the second and third phases prioritised achieving persistence and lateral movement. Notably, Crimson Palace exploited staff shortages in targeted organisations, highlighting the group’s extensive capacity for reconnaissance and planning. The likely co-operation, of multiple state-sponsored groups in different phases of the campaign, combined with the high sophistication of the groups’ tactics, techniques and procedures (TTPs), highlights the growing significance of cyber espionage operations as the Chinese government seeks to bolster their economic and security posture. Furthermore, the focus on targets in the Asia-Pacific region highlights a risk-intensive cyber security environment amid ongoing bilateral and regional tensions.

Ongoing malware development highlights elevated financial and cryptocurrency theft risks from financially motivated actors

Financially motivated actors continued to develop malware during June to garner illicit profit. A financially motivated campaign targeted Brazilian bank users with a new banking trojan, ‘Carnaval Heist’. The TTPs used throughout this campaign emulate those of other known banking trojans in Brazil, pointing to the potential collaboration between Latin American malware developers. Additionally, cyber actors resumed use of the ‘Medusa’ banking trojan, also known as ‘TangleBot’, in June. The campaign capitalised on security vulnerabilities exacerbated by the ongoing UEFA EURO 2024 football championship. The newest version of this malware requires fewer permissions to run, achieving prolonged obfuscation on compromised systems. It also contains new capabilities to capture screenshots and perform actions remotely, underscoring the growing sophistication of Medusa’s TTPs as well as the campaign’s wider capacity to steal financial information. Several Chinese threat actors also used a new remote access trojan (RAT), ‘NoodleRAT’ to target Windows and Linux systems in cryptocurrency theft operations. NoodleRAT shares similarities with other Chinese-made malware, pointing to the likelihood that the malware is sold to other threat actors or created via co-operating with other threat groups. The cyber actors also resumed the use of RAT ‘Agent Tesla’ in a new campaign targeting Spanish speakers. This new iteration infiltrates victims’ computers to steal sensitive information, such as login credentials, and exfiltrates them via the File Transfer Protocol (FTP), underscoring security risks. Furthermore, threat actors developed a new highly sophisticated malware, ‘Snowblind’, to target banking customers in Southeast Asia. The malware uses rare techniques to bypass anti-tampering code in legitimate Android applications, enabling threat actors to modify security mechanisms and conceal malicious activities on compromised systems. The resumption of existing malware operations and the development of new strains throughout June both emphasise threat actors’ commitment to developing TTPs to counter new security measures and detection mechanisms, underscoring sustained risk.

Cyber criminals demonstrate evolving TTPs, highlighting security, phishing and financial risks to financial institutions

We reported several highly sophisticated phishing campaigns in June, displaying threat actors’ growing knowledge of modern security mechanisms and capacity to harness advanced TTPs. Criminal actors used a new phishing-as-a-service (PhaaS) kit, ‘V3B’, to target customers from over 54 Europe-based financial institutions. The kit is distributed through social engineering and contains a sophisticated JavaScript that emulates local login and authentication techniques such as QR code login and SmartID processes. The script also contains several advanced detection evasion techniques, further highlighting its sophistication. Similarly, threat actors are also using another PhaaS kit, ‘ONNX’, to target employees of global financial institutions, likely to exfiltrate sensitive data for financial profit. Actors typically distribute ONNX via phishing emails containing a malicious QR code. The victim is then prompted to enter their credentials and authenticate via a two-factor authentication (2FA) process on a fraudulent Microsoft 365 login page. The threat actors subsequently hijack the user’s account. ONNX also possesses several detection evasion techniques in a similar manner to V3B, highlighting sustained security risks. Also in June, the cyber criminal group ‘Scattered Spider’ used social engineering techniques to compromise employee accounts belonging to a range of global financial firms. The group abused account permissions to access software-as-a-service (SaaS) environments, signalling a shift in their TTPs. These operations underscore some cyber criminals’ growing knowledge and sophistication in financially motivated campaigns, elevating security, phishing and financial risks to financial institutions in the long term.

Strategic risk trends

Sibylline observed several key strategic risk trends throughout June. We reported an increase in Malware operations compared to May; state-sponsored and cyber criminal groups created new and more sophisticated strains of malware to garner illicit profit and sustain strategic geopolitical objectives. These new strains consisted of banking trojans, backdoors, RATs and phishing-as-a-service kits. Both state-sponsored and cyber criminal groups continue to exploit software vulnerabilities. Consistent with May trends, these groups continued to exploit the software supply chain in June to obtain initial access to strategic targets. Although Sibylline only reported on a few major ransomware incidents in June, we assess ransomware operations will likely continue at a steady pace. State-sponsored operations continue to form a large portion of cyber attacks, with state-sponsored groups consistently prosecuting espionage campaigns. This particular trend is likely to continue into the next few months. (Source: Sibylline)

 

11 Jul 24. Comtech (NASDAQ: CMTL) (the “Company”), a global technology leader, today announced it recently completed the full migration and deployment of a Next Generation 9-1-1 (“NG9-1-1”) system in Saskatchewan-marking a significant milestone for the Company and Canada’s NG9-1-1 infrastructure.

In October 2023, Comtech helped Strathcona County in Alberta become Canada’s first Public Safety Answering Point (“PSAP”) to transition to NG9-1-1 services. With the Saskatchewan NG9-1-1 deployment, Comtech is now the first company, in partnership with leading Emergency Services IP Network (“ESInet”) provider SaskTel, to deploy a province-wide NG9-1-1 system in Canada.

“We are honored to build on our longstanding partnership with SaskTel to complete this critical NG9-1-1 transition in Saskatchewan,” said Aaron King, General Manager of Comtech’s Solacom Technologies Division. “With a government mandate to transition to NG9-1-1 services by March 2025, Comtech is partnering with Canada’s public safety agencies to lead the way in building one of the first national transitions to a NG9-1-1 infrastructure. This province-wide NG9-1-1 deployment paves the way for other NG9-1-1 migrations across Canada that will empower PSAPs throughout the country with the ability to leverage new technologies that can significantly enhance safety, reliability, and response in a wide range of emergency situations.”

In addition to the Saskatchewan NG9-1-1 deployment, Comtech also recently completed a local NG9-1-1 PSAP migration in Ontario, Canada. With these NG9-1-1 migrations complete, Comtech is the first public safety provider in Canada to partner with all three major ESInet suppliers in the country-SaskTel, Bell, and Telus-to build out the nation’s NG9-1-1 infrastructure.

As one of the most trusted providers of public safety technologies, Comtech is continuing to expand its NG9-1-1 call routing and call handling solutions, including the Company’s Guardian Call Management platform, for governments and emergency response providers across the globe. The Company’s NG9-1-1 offerings are designed to adapt and continuously evolve over time to meet the needs of emerging use cases as well as future applications.

 

11 Jul 24. Share and Share Alike. Chairing a study day on radar technology in London in late June was an absolute pleasure for your editor, save the capricious vagaries of the English weather. Hot and humid one minute, cold and clammy the next. West London’s microclimate never fails to surprise and disappoint in equal measure. Despite the mercurial meteorology outside, the conference hall was abuzz with discussion. Radar technology is moving at breakneck pace. The use of hypersonic missiles and drones in the ongoing Ukraine war is presenting radar experts with engineering challenges they must surmount. The key priority is to enrich the recognised air picture as much as possible without causing an information deluge. The targets that need to be seen must be done so in rich clarity, false alarms must be discarded. Artificial intelligence, machine learning and edge computing all have their role to play in meeting these objectives.

This rich data needs to be shared with those who defend the skies at strategic, operational and tactical levels. Air defence assets do not work well in a vacuum, they come into their own when connected and able to share their information at the speed of light. Sharing timely information demands robust, redundant and capable communications. Bandwidths must be sufficient to exchange radar plot and track data with minimal latency. Much as the radar engineers have their work cut out as they adapt their systems to emerging threats, so communications engineers must ensure requisite networking is available. It is interesting that it is all but impossible to now have a conversation about sensors without talking about communications. This synergy will only deepen in the future as military philosophies like multi domain operations gather pace.

 

09 Jul 24. Talking Dutch. The Dutch military’s Foxtrot programme will see a major enhancement of the communications used across the country’s armed forces. The MTBB phase of the project focuses on the procurement of new tactical radio hardware and software. Discussions concerning the procurement of new tactical radios to support the Dutch military’s Foxtrot communications modernisation programme are entering their final stages. The Netherlands Ministry of Defence (MOD) is in the process of deciding which radios will fulfil the requirements of the country’s Military Transmission Building Block (MTBB) programme. MTBB forms a key part of the wider Foxtrot military digitisation programme being rolled out across the Dutch armed forces. Foxtrot will transition the Dutch military into an integrated force capable of performing Multi-Domain Operations (MDO) according to reports. MDO stresses the intra- and interconnectivity of all forces to perform rapid, synchronous operations at all levels of war. MTBB focuses on the acquisition of the communications hardware and software necessary to facilitate Foxtrot. A spokesperson for the Dutch MOD told Armada that “(Foxtrot) is responsible for the modernisation of communication equipment within a vast number of vehicles, vessels, aircraft and other operational units.”

Recent radios

L3Harris was selected in November 2023 to answer the MTBB requirement. The Dutch military already uses the company’s products. In May 2023, L3Harris won a contract to provide AN/PRC-117G and AN/PRC-163 radios to modernise the Dutch military’s ground-to-air/air-to-ground radios. The AN/PRC-117G is a 20-watt/W backpack radio covering a 30 megahertz/MHz to two gigahertz/GHz waveband. The handheld, ten-watt AN/PRC-163 radio covers wavebands of 30MHz to 2.6GHz. These radios were procured outside the MTBB framework. Meanwhile, in 2020 Elbit Systems won a contract to supply its E-Lynx tactical radios, although precisely which radios were provided was not made public.

The spokesperson declined to specify exactly what radios were being supplied by L3Harris. Sources close to the programme told Armada that discussions were ongoing regarding specific models, as of June. While the specific radio types are yet to be defined, the source said that Type-1 encryption is an MTBB pre-requisite. Type-1 is a United States National Security Agency encryption standard representing one of the highest encryption standards used by the US government and select US allies.

Likewise, no details have been supplied on which waveforms these radios will accommodate. The spokespersons did say that “Waveforms are an essential prerequisite for interoperability in the mobile tactical domain and are thus an important part of MTBB.” Through the Foxtrot programme, the MOD is “committed to acquire multiple waveforms to create maximum interoperability with (inter)national partners.” Armada’s source confirmed that elements of the radio’s specifications are also subject to ongoing discussions. The spokesperson’s reference to procuring waveforms to foster “maximum interoperability” is interesting. This maybe a tacit indication that the Dutch MOD may be considering procuring the European Secure Software Defined Radio (ESSOR) High-Data Rate Waveform (HDRWF). More information on this waveform can be found here.

Moving forward

It remains unclear exactly which of the Dutch military’s existing radios will be replaced via the MTBB undertaking: “The exact radios that will be replaced have not been made public,” said the spokesperson. They added that several of the current radios are “several years past the end of their technical and operational life. Manufacturers provide limited support and maintenance for these assets, and they are increasingly difficult to replace or repair.”

It appears likely that the E-Lynx, AN/PRC-117G and AN/PRC-163 radios will remain in service, given their recent procurement. However, the Thales PR4G radios that the Dutch MOD procured in 2008 could be one candidate for replacement. Circa 10,000 of these Very High Frequency (VHF: 30MHz to 88MHz) were supplied to the Dutch military in various configurations. The Dutch MOD declined to state when deliveries of the L3Harris MTBB radios will commence. Nonetheless, given that discussions on the exact model of radios to be supplied are in the final stages, it is reasonable to assume deliveries will begin within the next two-to-three years. (Source: Armada)

 

10 Jul 24. New Radios for Ireland. The Irish Army is overhauling its tactical communications with a large acquisition of new systems to replace scores of legacy transceivers. The Irish Defence Forces have taken an important step forward in the modernisation of their communications with a procurement of new tactical radios.

Up to 6,000 tactical radios are being supplied by Thales to the Irish military, chiefly the company’s SquadNet and Synaps transceivers. The order breakdown covers 3,500 SquadNet radios and 2,500 Synaps systems, according to a Thales press release announcing the news. The press release continued that Synaps deliveries to the Óglaigh na hÉireann (Irish Defence Forces) have already begun. The first batch of SquadNet radios will be delivered during the second half of 2024.

SquadNet is a personal role radio using wavebands of 430 megahertz/MHz to 470MHz or 865MHz to 880MHz, depending on the variant. The radio provides voice-over-internet protocol communications. The company says that SquadNet’s point-to-point range is circa 2.5 kilometres/km (1.6 miles). The Synaps radios the Irish military is receiving are derived from the Contact radios Thales has developed for the French military. Covering Very/Ultra High Frequency (V/UHF: 30MHz to three gigahertz) wavebands, the Irish military will receive Synaps-H handheld radios, Synaps-V vehicular/naval transceivers and the Synaps-A airborne radios. As well as equipping the An tArm (Irish Army), Synaps-V radios will outfit the vessels of the An tSeirbhís Chabhlaigh (Irish Navy). Synaps-A will used by the aircraft of the An tAerchór (Irish Air Corps).

ESSOR for Ireland

The Irish military’s Synaps and Squadnet radios will be outfitted with Thales’ proprietary Geomux blue force tracking waveform. The Synaps radios will also carry the pan-European ESSOR (European Secure Software Defined Radio) High Data Rate Waveform (EHDRWF). The EHDRWF is a UHF waveform using a waveband of 225MHz to 400MHz. Up to 200 nodes can be housed on a single EHDRWF network. The waveform can handle data rates of up to one megabit-per-second. It can sustain full duplex data and voice-over-internet-protocol communications. Transmission security includes fast frequency hopping. EHDRWF can work in environments where global navigation satellite signals are badly degraded or denied.

The ESSOR project is being realised via an international effort involving Finland, France, Germany, Italy, Spain and Portugal. All six countries will be introducing the EHDRWF into their tactical communications over the coming years. The a4ESSOR consortium is the industrial element of the programme involving Bittium, Indra, Leonardo, Radmor, Rohde and Schwarz, and Thales. Ireland’s acquisition of the EHDRWF represents one of the first acquisitions beyond the ESSOR partner nations. Porting the EHDRWF into Ireland’s new radios will greatly enhance the European interoperability of the Irish military.

Sources close to the programme told Armada that dismounted troops will be outfitted with Squadnet, with their commanders using both Squadnet to communicate with subordinates and Synaps-H to communicate with higher echelons. Traffic can be moved between these radios simply by connecting both transceivers to a vehicle’s intercom, for example. The Synaps radios will also carry command and control traffic shared by the Irish Army’s Systematic SitaWare battle management system.

The contract to supply the radios is worth $81 m, according to Ireland’s Department of Defence. The new Synaps and Squadnet radios replace the Irish military’s existing ITT/L3Harris Single Channel Ground and Airborne Radio System (SINCGARS) tactical radio family. These radios were supplied to the Irish military sans accompanying US encryption standards. The new radios being delivered will include communications and transmission security standards such as AES-256. AES-256 is an advanced encryption standard established by the US National Institute of Standards and Technology.

The introduction of the new radios represents an important modernisation for the Irish military. Despite the small size of the country’s armed forces, they are energetically engaged in operations around the world, in particular supporting peacekeeping efforts. Ireland’s acquisition of the EHDRWF will also help deepen interoperability with her European allies who are also adopting this new waveform. (Source: Armada)

 

11 Jul 24. Crest of a Wave. Germany is the most recent entrant to the ESSOR programme having formally joined in 2020. Rohde & Schwarz was selected three years earlier in 2017 as the initiative’s German industrial national champion.

This year’s Eurosatory exhibition, held in Paris between 17th and 21st June, was an opportunity to learn about the status and plans for the ESSOR tactical communications waveform initiative.

The European Secure Software Defined Radio (ESSOR) project is multilateral initiative developing several radio-agnostic tactical communications waveforms which can be used by a plethora of transceivers. The project is being realised via an international effort involving Finland, France, Germany, Italy, Poland and Spain. The a4ESSOR consortium is the programme’s industrial element involving Bittium, Indra, Leonardo, Radmor, Rohde and Schwarz, and Thales. ESSOR is managed by OCCAR (Organisation Conjointe de Coopération en Matière d’Armement/Joint Organisation for Armaments Cooperation). OCCAR is a pan-European body tasked with managing European multilateral defence equipment programmes.

One of the key deliverables is the ESSOR High Data Rate Waveform (EHDRWF). The EHDRWF is an Ultra-High Frequency (UHF) waveform using a waveband of 225 megahertz/MHz to 400MHz. Up to 200 nodes can be housed on a single EHDRWF network. The waveform can handle data rates of up to one megabit-per-second. It sustains full duplex data and voice-over-internet-protocol communications. Transmission security includes fast frequency hopping. It can work in environments where Global Navigation Satellite System (GNSS) Position, Navigation and Timing (PNT) signals are badly degraded or denied.

All six countries will be introducing the EHDRWF into their tactical communications over the coming years. Two of the ESSOR nations, Finland and France, have already introduced the waveform into service with their land forces tactical radios. However, the EHDRWF is not the programme’s only deliverable. Narrowband and airborne waveforms are in the offing.

E3DWF

The ESSOR Three-Dimensional Waveform (E3DWF) is optimised for air-ground-air communications, a4ESSOR representatives told Armada. Covering similar UHF wavebands to those used by the EHDRWF the frequency-hopping E3DWF performs simultaneous voice and data transmission. Data rates are dynamic adopting to prevailing electromagnetic conditions. E3DWF uses Multi-hop Ad Noc Networking (MANET) with network synchronisation provided by GNSS PNT signals. The A4ESSOR representatives continued that up to 32 nodes can be accommodated on each E3DWF network.

ENBWF

The ESSOR Narrowband Waveform (ENBWF) complements the wideband EHDRWF for land tactical communications. The a4ESSOR officials said that ENBWF is optimised to support communications in urban, rural, littoral, undulating and mountainous terrain using a MANET architecture. Providing dynamic kilobits-per-second data rates, the ENBWF handles NATO (North Atlantic Treaty Organisation) Restricted voice and data traffic. The waveform can use frequencies of 30MHz to 88MHz, or 225MHz to 400MHz. Like the E3DWF, the ENBWF uses frequency hopping to help resist electronic attack. Network synchronisation is possible with or without a GNSS PNT signal. Up to 60 nodes can be accommodated on each ENBWF network.

Over the longer term, the ESSOR initiative plans to develop a Tactical UHF Satellite Communications Waveform (ESATWF). In the near term, the a4ESSOR officials said that development of the E3DWF could conclude by the end of 2024. Work on the ENBWF is ongoing and could be completed in 2025. Specifications for the EHDRWF have already been enshrined in a draft version NATO’s Standardisation Agreement 5651 (STANAG-5651). ENBWF specifications could be included in the second edition of NATO’s draft STANAG-5630, with E3DWF particulars enshrined in edition four of STANAG-4372.

Enshrining the specifications in the STANAGs would mean that waveforms designed to these stipulations would be compatible with the ESSOR waveforms discussed above. Standardising waveform design will help deepen European and NATO interoperability. Disparate radios used by different NATO forces but with wideband, narrowband and air-ground-air waveforms designed to meet the STANAGs will communicate directly with ease.

The ESSOR programme was launched in 2008 and its efforts are now bearing fruit. Increased adoption of the EHDRWF among and beyond the a4ESSOR nations will be seen in the future. Croatia and the Republic of Ireland are two nations outside the a4ESSOR membership adopting the EHDRWF in their tactical radios. Other militaries will follow suit in the coming years, with the E3DWF and ENBWF set for adoption by the ESSOR member nations and their allies. At a time when Europe faces an ever-growing threat from a resurgent Russia, these efforts to deepen tactical communications interoperability are highly relevant. (Source: Armada)

 

11 Jul 24. July Radio Roundup.

Kongsberg’s Thor multiband vehicular radio is equipping the Norwegian Army as part of the country’s overarching Mime communications modernisation programme.

Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.

Thor radios for Norway

Officials from Kongsberg have told Armada that the company will begin deliveries of its Thor tactical radio in the 2025 to 2026 timeframe. The officials were speaking during the Eurosatory defence exhibition held in Paris between 17th and 21st June. Thor has been selected by the Norwegian armed forces as part of the country’s overarching military communications modernisation initiative known as Mime. The Kongsberg officials said they expect to begin shipping Thor radios to the Norwegian military in the same timeframe. Thor is expected to be installed in Hæren (Norwegian Army) vehicles. The dual channel, multiband radio covers frequencies of three megahertz to three gigahertz. The 20-watt transceiver has embedded AES-256 encryption and handles data at between 600 bits-per-second to 2.5 megabits-per-second, according to company literature. Kongsberg officials added that the Norwegian military is expected to furnish their radios with standard waveforms such as the North Atlantic Treaty Organisation’s HAVEQUICK air-to-surface/surface-to-air protocol. As Jane’s reported in May, the Thor contract is valued at $22.9 m.

Bittium’s TAC WIN system is providing a new tactical communications backbone for the Croatian Navy. TAC WIN is complemented with the company’s Tough SDR radios which will provide fleet-wide communications.

TAC WINs

Bittium announced in early June that the company’s Tactical Wireless Internet Protocol Network (TAC WIN) and Tough SDR tactical radios had been accepted by the Croatian Ministry of Defence (MOD). A company press release announcing the news stated that the acceptance followed an implementation process performed by the Hrvatska Ratna Mornarica (Croatian Navy). Speaking during the Eurosatory exhibition, held in Paris between 17th and 21st June, Bittium sources said that TAC WIN will form the navy’s communications backbone. TAC WIN provides a deployable, secure, wireless internet protocol network with achievable data rates of circa 50 megabits-per-second. Tough SDR radios are deployed on Croatian Navy vessels to provide fleet-wide communications. These radios cover a waveband of 30 megahertz to 5.2 gigahertz. Bittium sources continued that the navy’s radios will include the European Secure Software-Defined Radio (ESSOR) waveform. This represents one of the first publicly declared provisions of ESSOR beyond the militaries of the ESSOR partner nations. The sources added that the Croatian MOD is expected to explore the modernisation of the tactical communications used by the Karlovac (Croatian Army) in the near future. (Source: Armada)

 

12 Jul 24. Asia-Pacific: New sophisticated malware points to raised espionage risks from China-backed groups. On 10 July, the cyber security company Zscaler reported that the Chinese state-sponsored group ‘APT41’ is targeting organisations in Southeast Asia with two new strains of malware, ‘DodgeBox’ and ‘MoonWalk’. APT41 first downloads DodgeBox onto compromised systems via a legitimate executable. Notably, the loader is able to conceal malicious activity from endpoint detection and response (EDR) security mechanisms, thereby achieving prolonged presence on the system. DodgeBox subsequently loads the backdoor MoonWalk to collect information from infected systems, as well as to download new configurations and to execute commands. MoonWalk then establishes communication with actor-controlled infrastructure via GoogleDrive to blend in with legitimate traffic and evade detection. Both malware strains contain several highly advanced anti-detection techniques, pointing to the extremely high sophistication of Chinese state-sponsored actors’ tactics, techniques and procedures (TTPs). APT41 routinely targets organisations in Southeast Asia in cyber espionage campaigns. As such, we assess that entities operating in the region will face elevated security and espionage risks in the long term.  (Source: Sibylline)

 

10 Jul 24. Global: Bot farm takedown signals elevated security, disinformation risks from Russian-linked actors. On 9 July, global news outlets reported that a joint international law enforcement operation with the US Department of Justice (DOJ) seized a large bot farm that was spreading Russian disinformation. The bot farm had primarily targeted users of the platform X (formerly Twitter) in multiple countries (including Germany, Israel, the Netherlands, Poland, Spain, Ukraine and the US) since at least 2022. It used artificial intelligence (AI)-enabled software to create authentic-looking social media accounts posing as real people from various countries. The bot farm then used these profiles to spread Russian propaganda and to influence narratives favourable to the Russian government. Notably, the incident underscores the wider adoption of AI tools by Russian actors to amplify the impact of disinformation campaigns. Additionally, Russian-linked groups have recently ramped up disinformation campaigns targeting November’s US presidential election and the Paris 2024 Olympic Games. We assess that security and disinformation risks stemming from Russian-linked threat actors will be elevated in the short-to-medium term. (Source: Sibylline)

 

10 Jul 24. L3Harris milestone in B-52 Stratofortress modernisation.

Advanced self-protection system sets a new benchmark in B-52 modernisation efforts.

L3Harris has tested an upgrade to the B-52 Stratofortress’ electronic warfare capabilities, marking a moment in the aircraft’s modernisation journey.

A 5.3-hour test flight, conducted over Texas, validated the performance of five newly enhanced Line Replaceable Units (LRUs) within the AN/ALQ-172 electronic warfare (EW) self-protection system. This breakthrough emphasises the aircraft’s continued evolution in response to increasingly sophisticated electronic threats.

Through its modernisation project, L3Harris is fronting efforts to keep the US Air Force’s (USAF) B-52 relevant. The recent test, a component of a $947m, 10-year contract awarded in 2021, demonstrated enhancements in maintainability and reliability, setting the stage for future advancements.

Acquired from Boeing in 1961-1962, the US Air Force has 76 B-52 Stratofortress bomber aircraft in its fleet, as highlighted by GlobalData’s intelligence on the US defence market.

Jimmy Mercado, L3Harris Programme Director, explained, “The electronic threat landscape grows more complex and contested every day, underscoring the importance of our continued EW enhancements to the B-52.

The flight test showed that we’re providing the advanced capabilities needed to ensure the aircraft and its crews remain mission-ready and effective well into the 2050s.”

So far in 2024, the US has invested $5bn in electronic warfare technology. This expenditure reveals America’s leveraging of electromagnetic spectrum capabilities to enhance its military operations. As nations like Russia and China expand their electronic warfare capabilities, competition in this arena is intense.

The road ahead

The MARS upgrade, central to this project, has already seen the redesign of seven out of nine LRUs, with the final two nearing completion. These upgrades are poised to enhance the USAF’s Global Strike Mission, bolstering the B-52’s role in modern warfare. Notably, the improvements also aim to simplify and reduce the cost of future updates.

L3Harris’ approach to enhancing the B-52 Stratofortress reveals the importance of solutions in maintaining aerial presence. The test flight demonstrates the legacy and future potential of one of the USAF’s most storied aircraft.

The US Air Force (USAF) faces dual challenges with its B-52 Stratofortress fleet. Recent audits revealed shortcomings in spare parts management amidst ongoing modernisation efforts. A Department of Defense’s Office of Inspector General report highlights deficiencies in addressing material shortages crucial to sustaining the ageing fleet.

(Source: airforce-technology.com)

 

10 Jul 24. U.S. Navy Funds Mercury to Advance Chip-Scale Technologies Needed to Reduce Electronic Warfare Design Timelines. Mercury Systems, Inc. (NASDAQ: MRCY, www.mrcy.com), a technology company that delivers mission-critical processing power to the edge, today announced an agreement with the U.S. Navy to advance sensor processing technologies that will allow radar and electronic warfare (EW) capabilities to be designed on much shorter timelines.

For decades, increasing system and software complexity has extended the timelines for developing and fielding military platforms. The Office of Naval Research’s Open Rapid Chipletized Approach (ORCA) program aims to reduce the time needed to design edge processing solutions by increasing the modularity of components at the chip level. Under a $13.2 m contract, Mercury will develop a next-generation RF System-in-Package (SiP) that integrates the latest commercial chips from major semiconductor providers within a smaller and lighter footprint.

This work will build on Mercury’s RFS1140 SiP, which integrates an AMD Versal FPGA, Jariet Electra-MA high-speed data converters, and Micron memory for a truly advanced solution to support sensor processing.

“ORCA represents a significant evolution of the Mercury Processing Platform that will drive down radar and EW system development timelines, allowing next-generation capabilities to be fielded much faster,” said Tony Trinh, Mercury’s Senior Director of Advanced Packaging. “The ORCA approach opens up incredible opportunities to integrate mission-specific pre-processing chiplets to rapidly upgrade systems on a wide variety of existing platforms and stay ahead of evolving threats.”

“Mercury is pioneering the way for on-shore advanced secure microelectronics integration and packaging capability with DMEA-certified full product lifecycle support, including concept, design, assembly, and test, to rapidly deliver application-tailored system solutions to the warfighter,” said Adam Miller, Office of Naval Research Program Officer.

 

09 Jul 24. State-sponsored and hacktivist groups will likely exploit the increased convergence of information technology (IT) and operational technology (OT) to target critical national infrastructure (CNI) amid ongoing conflicts and geopolitical tensions.

  • State-sponsored actors will likely increase espionage actions targeting global CNI to bolster the economic position of their sponsors. Bilateral tensions and ongoing conflicts will also foment pre-positioning and disruptive operations.
  • Escalations in regional tensions will likely result in a wave of disruptive attacks from state-aligned hacktivist groups.

Context

On 30 May, the technology company Microsoft reported an increase in attacks targeting internet-exposed and vulnerable operational technology (OT) environments since late 2023. The onset of the Israel-Hamas war in October 2023 engendered a wave of hacktivist attacks against US OT environments, many of which successfully infiltrated critical national infrastructure (CNI). In early Q1, pro-Russia hacktivists altered the normal parameters of water pumps and blower equipment, compromising the systems of several US water and wastewater providers and causing water tanks to overflow. This recent increase in OT cyber attacks is a symptom of the inadequate and outdated nature of OT security systems, which will likely continue to incentivise attacks against this sector.

Forecast

State-sponsored and hacktivist groups will likely seek to compromise OT equipment within critical national infrastructure amid ongoing conflicts and geopolitical tensions

Cyber attacks against critical national infrastructure rose by 140% in 2022, according to a 2023 report by Waterfall Security. OT is often responsible for critical functions within CNI, making it an attractive target for cyber threat actors. More specifically, OT professionals are increasingly adopting smart industrial devices or Industrial Internet-of-Things (IIoT) devices to automate the maintenance of national infrastructure. Despite reducing costs and increasing efficiency, IIoT devices expose OT environments to potential cyber attacks by transmitting data from industrial equipment to assets connected to the internet. The White House and Environmental Protection Agency (EPA) released an advisory in March, warning that water and wastewater utilities in the US are being routinely targeted by adversarial state-sponsored groups. The advisory specifically mentioned threats to OT environments with the potential to affect the safety and supply of drinking water, highlighting significant infrastructure risks. The continued convergence of IT and OT systems provides threat actors with unprecedented opportunities to achieve their strategic objectives by amplifying their ability to gather intelligence, disrupt adversarial infrastructure and hinder defences. As such, cyber attacks against CNI by state-sponsored and hacktivist groups will likely increase in the long term as ongoing regional conflicts and bilateral tensions persist and OT environments become increasingly exposed to threats from the internet.

Cyber actors undertaking espionage operations will highly likely intensify their targeting of OT environments within CNI systems

In February 2024, the Federal Bureau of Investigations (FBI) stated that the Chinese state-sponsored group ‘Volt Typhoon’ infiltrated hundreds of small office/home office (SOHO) routers since at least 2019. The group executed espionage operations against US critical infrastructure including telecommunications organisations, transportation hubs and US military bases in Guam. Additionally, unnamed North Korean state-sponsored actors targeted at least two South Korea-based semiconductor companies in March, stealing highly sensitive data (such as product design drawings and facility site photos) possibly to spur North Korea’s own efforts to produce semiconductors. Relations between China and the US remain strained as the two countries continue to compete for military, economic and technological dominance. On 21 June, the Biden administration announced measures to curb US investment in Chinese tech firms developing semiconductors, quantum computers and artificial intelligence (AI). The announcements signal rising trade tensions between the two countries and likely precede additional measures aimed at slowing China’s economic and technological development. Similarly, North Korea continues to face economic sanctions which reduce the country’s ability to advance its weapons and missile programmes. As such, both Chinese and North Korean state-sponsored groups routinely target OT environments within CNI systems to bolster their economic and technological posture. We assess that the competitive nature of these relations, combined with talks of further economic decoupling and ongoing sanctions, will likely elevate espionage risks to global OT providers in the long term.

State-sponsored actors will likely seek to disrupt OT environments within CNI systems amid regional tensions and ongoing military conflict

The tactics, techniques and procedures (TTPs) used by Volt Typhoon signal an intent to pre-position itself for future disruptive operations. The group infiltrated IT environments within CNI, likely to migrate to OT systems for potentially disruptive operations at a later stage. Another Chinese state-sponsored group, ‘ChamelGang’, has disrupted national infrastructure in a series of ransomware operations conducted since at least 2019. As geopolitical tensions persist, we assess state-sponsored groups will likely continue to infiltrate and pre-position themselves within IT and OT environments. This will elevate disruption risks in the long term.

In October 2023, the Russian state-sponsored group ‘Sandworm’ caused a power outage after deploying OT malware in one of Ukraine’s power plants. The group reportedly executed malicious code against the plant’s supervisory control and data acquisition (SCADA) instance which included commands to turn off substations. The attack notably coincided with a series of missile strikes on Ukraine’s electrical grid, indicating that Sandworm likely worked with the Russian army to aid kinetic operations and disrupt Ukraine’s ability to defend against the hybrid attack. In April, Sandworm disrupted information and communication systems for 20 Ukrainian energy, heating and water organisations. The group deployed two new backdoors in this campaign, indicating its focus on developing new and more sophisticated cyber capabilities to target. This attack is likely indicative of Russia’s long-term objectives for the war in Ukraine, which include weakening Ukraine’s defence capabilities by undermining its energy resilience. The war in Ukraine represents the first conflict to involve significant levels of cyber operations to support military action. This trend elevates security and disruption risks to OT providers in the long term. The escalation of regional tensions and military conflicts will likely engender a wave of disruptive cyber attacks from state-aligned hacktivist groups

Security agencies in Canada, the UK and the US have warned of a rise in pro-Russian hacktivist attacks against OT environments in North America and Europe in May following an increase in hacktivist attacks against CNI in these regions. Affirming these warnings, the Iranian-aligned hacktivist group ‘Cyber Av3ngers’ compromised an Israeli-made programmable logic controller (PLC) at the Municipal Water Authority in Aliquippa (Pennsylvania, US) in November 2023. Although the attack did not cause any operational disruption, the group displayed an anti-Israel message and vowed to continue targeting Israeli-made equipment. Similarly, the hacktivist group ‘SiegedSec’ claimed responsibility for a series of attacks against Israeli infrastructure and industrial control systems (ICS) in October 2023. The group primarily compromised human machine interfaces (HMIs) within the water and wastewater sectors, altering normal equipment parameters and causing minor tank overflows. Although none of these attacks resulted in major disruption, they display hacktivists’ capabilities and intent to target OT following the escalation of regional tensions and military conflicts. The continuation of the Israel-Hamas war and the war in Ukraine will sustain elevated disruption risks to OT providers within adversarial nations in the medium-to-long term. There is also a possibility that any escalation in combat or rhetoric will further prompt a rise in hacktivist cyber attacks targeting this sector. (Source: Sibylline)

 

08 Jul 24. $2bn AUD deal for top secret Aussie cloud with AWS.

The new cloud deal “will enhance Defence’s resilience, improve the ADF’s warfighting capacity, (and) strengthen interoperability with key international partners,” Australian Defense Minister Richard Marles said. The Australian Signals Directorate plans to spend more than $2bn AUD ($1.3bn USD) over the next decade buying a highly classified and custom-built cloud to serve its intelligence and defense needs.

The plan, announced on July 4 by both the Australian government and Amazon Web Services (AWS), “will provide a state-of-the-art collaborative space for our intelligence and defense community to store and access top-secret data,” Rachel Noble, director general of the ASD. said in a statement. “This will transform how we work together as agencies and partners.”

Australia, one of the Five Eye countries who share the most highly classified intelligence with each other, has been beset by a regular onslaught from Chinese and Russian cyber attacks, and is searching for secure ways to share intelligence and targeting data with the United States, Britain, Canada and New Zealand, the other members of the elect group. While the group has traditionally shared intelligence signals data with each other, the advent of artificial intelligence and the proliferation of targeting data means the need for highly secure and transferable data has only grown.

The deal with AWS was important enough to generate a statement by Prime Minister Anthony Albanese, emphasized the importance of the contract for domestic job creation.“My Government is bolstering our defense and national intelligence community to ensure they can deliver world leading protection for our nation,” he said in the statement. “This important investment today will help enhance our national security capabilities while creating up to 2,000 local jobs.”

Defense Minister Richard Marles spoke of capabilities more important to defense, noting that the new cloud deal “will enhance Defence’s resilience, improve the ADF’s warfighting capacity, (and) strengthen interoperability with key international partners.”

It’s important to note that this contract is not entirely new business. It is, as Noble noted in her statement, part of Project REDSPICE, which was announced by the last government.

“For ASD, this capability is a vital part of our REDSPICE program which is lifting our intelligence and offensive and defensive cyber capabilities,” she said in the statement.

REDSPICE stands for for Resilience, Effects, Defence, Space, Intelligence, Cyber, and Enablers. When it was first announced by the Australian government, it was cast as the “largest ever investment” in the capabilities of the ASD, the Aussie version of the National Security Agency. When Scott Morrison, then prime minister, announced the program in March 2022, he said it would “substantially increase ASD’s offensive cyber capabilities, its ability to detect and respond to cyber-attacks, and introduce new intelligence capabilities. It will also create over 1,900 new jobs, almost doubling the ASD’s size.”

AWS already supplies a similar capability to the CIA and the US Intelligence Community. which presumably helped the company win this contract.

Secure clouds are considered by most experts to offer greater protection, operational flexibility and the ability to upgrade the system more seamlessly. (Source: Defense News Early Bird/Breaking Defense.com)

 

05 Jul 24. Global: New ransomware-as-a-service operation elevates security, operational risks to firms. On 5 July, international news outlets reported on the emergence of a new ransomware-as-a-service (RaaS), ‘Eldorado’. Cyber criminals primarily use this new RaaS to target the real estate, education, healthcare and manufacturing sectors. Eldorado contains several customisation features to target Linux, Windows and VMware ESXi hypervisors, underscoring its highly tailored nature. The new RaaS also deletes backup copies on compromised machines to maximise impact and prevent recovery. Additionally, Eldorado automatically self-deletes from infected systems to evade detection, further highlighting its high level of sophistication. The ransomware has been active since March and has compromised 16 organisations in Croatia, Italy and the US, underscoring the growing scale of this operation. The emergence of Eldorado highlights the continued adaptability and growing development of RaaS operations despite recent law enforcement takedowns of large ransomware groups including ‘LockBit’ and ‘BlackCat’/’ALPHV’. The proliferation of Eldorado also indicates elevated security, financial and operational risks to global organisations in the long term. (Source: Sibylline)

 

02 Jul 24. BATM Advanced Communications Limited (“BATM” or “the Group”). Commercial Markets Cybersecurity Partnership.

Major milestone achieved with signing of strategic partnership agreement to sell BATM’s advanced cybersecurity solution to commercial markets globally

BATM (LSE: BVC; TASE: BVC), a leading provider of real-time technologies for networking solutions and medical laboratory systems, has signed a strategic partnership and cooperation agreement with a significant global technology, engineering and defence group (the “Partner”) to deliver the Group’s advanced cybersecurity solution to commercial markets. The Partner generated revenue of over $10bn in 2023 and serves customers in more than 100 countries, with operations spanning Asia, Europe, the Middle East and the U.S.

With this agreement, the Group will customise its advanced encryption platform to meet the requirements of its Partner, with the development work being funded by the Partner. The customised platform will be distributed globally by the Partner, with exclusivity in certain territories, to a variety of commercial markets and for critical national infrastructure. This agreement, and the corresponding launch of a cyber solution for the commercial markets, represents a significant increase in the Group’s addressable market, which the Group’s cyber solution is well-positioned to target thanks to the Partner’s substantial network and commercial reach.

BATM’s encryption platform is a hardware and software solution that secures data-in-transit at high speeds across a network. It incorporates the Group’s hardware security module, which provides enhanced hardware-based protection of encryption keys, which is becoming increasingly important due to the growing number of attacks targeting weak links in the supply chain, such as the equipment vendors. It offers seamless integration with Quantum Key Distribution systems to provide customers with protection against the emerging quantum computing threats. In addition, the Group expects it to be the only commercially-available encryption platform to offer a mix of speeds, enabling customers to grow their network without replacing the platform.

Over the next two years, the Group will receive a minimum of $2.1m from the Partner for the product customisation phase and the provision of an initial quantity of units, which will be delivered in three phases over the two years. The Group is due to commence delivering the units to the Partner by the end of the first half of 2025.

Moti Nagar, Chief Executive Officer of BATM, said: “To be partnering with such a large, well-established and global organisation to deliver our cutting-edge encryption platform to the commercial markets is transformational for BATM Cyber and is a fantastic endorsement of our solution. The introduction of a cybersecurity offering for non-governmental customers has long been an important objective for BATM, and this collaboration significantly boosts our commercial market entry by providing worldwide distribution networks and a partner with the resources to engage in considerable sales & marketing activities. We look forward to working closely with our strategic partner in the fulfillment of this agreement, which we expect to serve as a prominent catalyst for the growth of our cyber business in the near future.”

 

05 Jul 24. Cuba’s Upgraded Surveillance Site Enhances Chinese Intelligence Capabilities. A recent analysis by the Center for Strategic and International Studies (CSIS) reveals that a newly upgraded radar site in Cuba represents a significant enhancement in the country’s surveillance capabilities, potentially bolstering China’s ability to monitor U.S. military activities. Satellite imagery analyzed by CSIS indicates that the site, located east of Santiago de Cuba, could become a powerful tool for intelligence gathering once operational.

The CSIS report highlights that China has access to multiple spy facilities in Cuba, pinpointing four specific sites across the island. This latest development is believed to be part of an effort by Beijing to enhance its intelligence collection capabilities in the region, leveraging Cuba’s proximity to U.S. military installations.

The new facility features a circularly disposed antenna array, with a diameter between 130 to 200 meters, capable of tracking signals from 3,000 to 8,000 nautical miles away. This technology could enable China to intercept sensitive communications from U.S. military bases, monitor rocket launches from Cape Canaveral, and gather data on other strategic activities across the southern United States.

The Cuban government, however, has denied these allegations. Vice Foreign Minister Carlos Fernandez de Cossio dismissed the claims as part of an intimidation campaign, stating that there is no verifiable evidence of Chinese military bases on the island. Similarly, China’s embassy in Washington described the accusations as unfounded slander.

Despite these denials, the CSIS report highlights advantages such a surveillance site would provide. It would allow China to develop a sophisticated understanding of U.S. military operations, potentially enhancing its strategic posture. The site’s capabilities include monitoring radio traffic and intercepting data from U.S. satellites, further expanding China’s intelligence reach.

The U.S. government has expressed concerns about China’s presence in Cuba. State Department spokesperson Vedant Patel noted that the U.S. is closely monitoring the situation, acknowledging China’s ongoing efforts to strengthen its intelligence foothold in Cuba.

The radar site in Cuba follows a pattern of increased Chinese intelligence activities globally, with similar facilities being constructed on reef outposts in the South China Sea.

The location of Cuba, just 90 miles south of Florida, makes it an ideal spot for gathering signals intelligence (SIGINT). This proximity allows for effective monitoring of U.S. military activities, including those at critical installations like the Guantanamo Bay naval base and various space-launch complexes in Florida.

Historically, Cuba has hosted foreign espionage operations, such as the Soviet Union’s largest overseas intelligence site during the Cold War. The new developments suggest a continuation of this legacy, with modern technological advancements enabling more sophisticated surveillance capabilities. (Source: https://www.sofx.com/)

 

05 Jul 24. Cyber Update Key points.

  • A security breach by the Russian state-sponsored group ‘APT29’ points to sustained security risks via the software supply chain.
  • Exploitation of a new zero-day vulnerability sustains security risks by the Chinese state-sponsored group ‘Velvet Ant’ (see Sibylline Cyber Daily Analytical Update – 2 July 2024).
  • Critical vulnerabilities in an iOS and macOS software dependency manager highlight elevated security risks facing the software supply chain (see Sibylline Cyber Daily Analytical Update – 3 July 2024 and our Technical analysis below).
  • A new cyber espionage campaign targeting an unnamed South Korean defence company underscores the bilateral tensions and supply chain risks posed by North Korean cyber actors (see Sibylline Cyber Daily Analytical Update – 4 July 2024).
  • The resurgence of a Latin American banking trojan, ‘Mekotio’, underscores the elevated security and financial risks facing firms and customers in the region.

Technical analysis of weekly stories

There is a realistic possibility that three critical vulnerabilities (CVE-2024-38368, CVE-2024-38366 and CVE-2024-38367) have compromised ms of iOS and macOS users for over a decade. The vulnerabilities reside in CocoaPods, a software dependency manager that hosts code libraries for developing applications. CocoaPods stores software dependency pods for major companies including Amazon, Dropbox and Google. The first vulnerability (CVE-2024-38368) emerged in 2014 after CocoaPods asked its customers to reclaim ownership of dependency pods via a public application programming interface (API) following a server migration. However, several pods were never reclaimed by their legitimate owners. Threat actors could thus exploit CVE-2024-38368 to claim ownership of those unclaimed dependencies, injecting malicious code into the pods and compromising ms of iOS mobile applications and users. This first vulnerability is compounded by a second vulnerability (CVE-2024-38366) which enables threat actors to bypass authentication methods when claiming a dependency pod. More specifically, the new server only validates the domain of a claimant’s email address, effectively allowing threat actors to hijack customer accounts. These two vulnerabilities are supplemented by a third (CVE-2024-38367) which enables a zero-click account takeover by allowing threat actors to validate their ownership of the account via a spoofed URL. CocoaPods has since released patches for these vulnerabilities, underscoring mitigated security risks while emphasising the importance of strict patch management policies to prevent compromises.

Threat actors have resumed using the banking trojan ‘Mekotio’, targeting banking users in Latin America (LATAM). The malware is typically distributed via phishing emails, wherein threat actors impersonate tax agencies alleging that the user has unpaid tax obligations. The phishing email contains a ZIP file that executes Mekotio and establishes communication with actor-controlled servers. The malware then collects information from the compromised system including screenshots, keystrokes and banking credentials. Notably, Mekotio steals banking information by displaying a fake pop-up mimicking legitimate banking sites’ login pages. Additionally, Mekotio contains several persistence methods, such as adding itself to startup programs and creating scheduled tasks, highlighting the high sophistication of this malware. The stolen banking information is then sent to the actor-controlled infrastructure where it can be used for further malicious activities, granting actors unauthorised access to bank accounts to garner illicit profit. There have been numerous iterations of this malware since 2015, with this latest resurgence following the law enforcement takedown of ‘Grandoreiro’, another LATAM banking trojan. This highlights the dynamic, fluid and broad nature of financially motivated malware operations in the region.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering attempts.
  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Enforce strict patch management policies prioritising high-risk and remote code execution (RCE) vulnerabilities.
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices.

Our cyber word(s) of the week: Application programming interface (API) .

(Source: Sibylline)

————————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

————————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT