• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

August 2, 2024 by

 

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

—————————————————————————————————————————————————————————————————————————————————————————————————————————————-

31 Jul 24. The Japanese Ministry of Defense sets its first AI policy and seven priority areas.

On July 2, the Ministry of Defense adopted its first basic policy for promoting the use of artificial intelligence (AI).

The Ministry of Defense stated that they will plan to reduce the burden on SDF’s members and manpower by utilizing AI in order to maintain the SDF’s system despite a declining population. The ministry will also plan to use AI effectively in seven fields, including the detection and identification of targets using radar and satellite images.

The basic policy, which is called the “Basic Policy for the Promotion of AI Utilization”, states that it is pointed out that AI would decide aspect of warfare in the near future considering efforts by the U.S. and Chinese militaries to utilize AI. This also stated that it is urgent to respond to a “new way of fighting” involving space, cyber, and electromagnetic waves in addition to land, sea, and air and operate personnel efficiently. It is also pointed out that we are now at a crossroads whether we are falling behind and becoming an inefficient, old-fashioned organization or not.

It also recognized that AI also carries risks of error and bias and emphasized that what AI does is support for human decisions, and human involvement should be ensured.

The seven areas in which AI will be used mostly are: (1) target detection and identification; (2) collection and analysis of information from the Internet and radio waves; (3) decision support for commanders; (4) logistics support such as supply and maintenance; (5) control of unmanned vehicles; (6) improvement of cyber security capabilities; and (7) efficiency of administration work.

On the same day, the Ministry of Defense also announced a “comprehensive strategy to recruit and train personnel specialized in cyberspace.” The ministry plans to establish a new examination category for cyber in the Ground Self-Defense Force on the premise of being assigned to Cyber Defense Command which will begin accepting applications in fiscal 2025. The ministry also plans to double the number of GSDF students enrolled in the cyber education program at the GSDF High Technical School in Yokosuka, Kanagawa Prefecture, from 30 to 60 by the same fiscal year.

“AI and cyber can be technologies to overcome challenges such as declining population.” Defense Minister Minoru Kihara stated at a press conference after the cabinet meeting.

(Source: AMR

 

01 Aug 24. Claims and Counter Claims. Apparently, the prowess of Chinese radar design and networking has successfully defeated the state-of-the-art Electronic Warfare (EW) capabilities of the US Navy’s E/A-18G Growler EW jet. The staggering news was conveyed in the Eurasian Times in mid-July. The report quoted the Chinese academic journal Radar & ECM which articulated the incident in question that took place in late 2023. The debacle was so severe that the commander of VAQ-136, the US Navy electronic attack squadron to which the aircraft was assigned, was dismissed according to the report.

People’s Liberation Army Navy (PLAN) officials claimed that the ‘Type-55’ class destroyer Nanchang used Artificial Intelligence (AI) techniques to nullify jamming by the E/A-18G. The AI approaches in question comprised cognitive radar techniques. Moreover, a ‘kill web’ networked PLAN assets deployed in the South China Sea at the time of the incident. The kill web allegedly helped the Nanchang, and other PLAN ships, avoid the Growler’s jamming. These capabilities let the destroyer move 100 nautical miles (185 kilometres) north of the PLAN task group and prevent a US Navy Carrier Strike Group (CSG) entering an area where the PLAN was exercising. The Nanchang’s radar locked onto CSG surface combatants dissuading them from entering the exercise area. So successful was the PLAN effort that members of the Nanchang’s crew were decorated.

Do the PLAN’s claims add up? Possibly not. Firstly, the Radar & ECM journal article in question is not in the public domain. Although notionally available for purchase with an English language translation, the associated website does not appear to work; your editor tried it numerous times. It is difficult to examine the claims if the journal article in question cannot be read. Secondly, the argument about the dismissal of the VAQ-136’s boss are dubious. The commander in question was relieved due to a loss of confidence in their abilities; a catch-all term covering a variety of shortcomings. Thirdly, why was the E/A-18G allegedly jamming the Chinese vessels? The US and China are not at war. Despite the two country’s geopolitical tensions, using jamming signals in peacetime would be risky. It could send the wrong message that the US Navy CSG was preparing to attack the PLAN ships. Deploying jamming waveforms in peacetime risks handing your potential adversary information about tactics you might use in wartime. Fourthly, illuminating US Navy ships using a radar’s war modes is similarly risky. If such an incident had occurred it is likely to have drawn a full-throated public condemnation from the White House.

Instead, it seems that the alleged ‘incident’ is in fact PLAN propaganda intended for international consumption. China gets to flex its electromagnetic muscles, if only in an imaginary sense, showing that its navy can stand up to Uncle Sam. Even if the incident amounts to no more than propaganda, it is no reason to dismiss the PLAN as technologically inferior. China will continue to make her investments into sophisticated defence technology to reach technological parity, or even supremacy, with the US and her allies. This is a situation the United States and her allies must not allow to happen, and this latest alleged confrontation should serve as a reminder of China’s scientific direction of travel. (Source: Armada)

 

01 Aug 24. Persistent Systems Provides MANET Connectivity for U.S. Military Field Training Exercise. Persistent’s mobile ad hoc network (MANET) enabled geographically dispersed U.S. military commanders to move small, agile operational centers across the INDOPACOM region while maintaining contact with aircraft and ground forces.

Persistent Systems communications solutions have successfully supported Valiant Shield, a biennial joint Field Training Exercise conducted by the U.S. military in Guam and across the INDOPACOM Area of Responsibility (AOR). During the 11-day exercise, Persistent Systems Wave Relay® MANET and Cloud Relay™ networking capabilities enabled U.S. commanders operating from forward-deployed and fixed operations centers to test the Air Force’s Agile Combat Employment (ACE) concept through the MANET-Cloud High Mobility Radio (MCHMR) as well as conduct a run-through of the Joint Fires Network, a prototype battle management system.

Adrien Robenhymer, Persistent’s VP of Business Development, Air Force and Intelligent Community, said; “U.S. forces in the INDOPACOM AOR are under constant alert from threats marshaled by near-peer powers in the region. The U.S. must be prepared to counter by operating in a nimble, distributed fashion with a swift kill chain.”

Utilizing MCHMR’s MPU5-based MANET and cloud services facilitated by Persistent’s Cloud Relay network, Valiant Shield commanders at both fixed and deployable operations centers, as well as individual units at the edge, were able to track bombers and fighter jets in the air, personnel on the ground, and ships at sea.

Robenhymer added; “During the exercise, airmen and Marines were using our MANET technology to demonstrate the viability of the ACE concept. Commanders were rapidly establishing operations in Hawaii, Guam, and the First Island Chain, all while maintaining communication and tracking of their forces. We also showcased our ability to reduce the Joint Fires Network response time from minutes to seconds.”

Persistent’s involvement with Valiant Shield, say company officials, is yet another example of how it is leading the way in delivering a Joint All-Domain Command and Control (JADC2) capability today.

Robenhymer said; “The network is the key to enabling JADC2. By delivering a rapidly deployable, scalable network providing both connectivity at the tactical edge and strategic reach back; decision-makers are finally united with the sensors and effectors. MCHMR has turned the JADC2 vision into a reality, and we just demonstrated it across the Pacific.” (Source: https://www.defenseadvancement.com/)

 

30 Jul 24. Taking Stock of Vostok. The Vostok-3D radar produced by KB Group of Belarus may enter service in the country by the end of 2024. Marketing video reveals that at least one Vostok-3D radar has already been occasionally active in the vicinity of Minsk.

In partnership with EW Analytics LLC, we share details of the new Belarussian Vostok-3D ground-based air surveillance radar.

Built in Belarus, the KB Group Design Bureau’s Vostok-3D S-band (3.1 gigahertz/GHz to 3.3GHz) and Very High Frequency (VHF: 170MHz to 220MHz) ground-based air surveillance radar is a new system. The company’s literature says the radar has an instrumented range of 194 nautical miles/nm (360 kilometres/km). The Vostok-3D detects and tracks targets across 360 degrees’ azimuth, and between -3 degrees’ to 45 degrees’ elevation. Marketing video reveals that at least one Vostok-3D radar has already been occasionally active near Minsk.

Target range, azimuth and velocity are measured by the radar’s VHF transmissions. Azimuth is also measured by the radar’s S-band signals which, in addition, measure range and elevation. The radar determines range to within 200 metres (656 feet), azimuth to within 5.5 degrees, elevation to within 1.2 degrees and velocity to within 19 knots (35 kilometres-per-hour). The radar rejects jamming signals equal to, or greater than, 30 decibels/dB and rejects clutter equal to, or greater than, 50dB.

The radar tracks up to 250 targets simultaneously and can detect and measure bearings of up to ten jamming signals. When transmitting in VHF and S-band, pulse-to-pulse and train-to-train frequency turning is possible in automatic and semi-automatic modes. S-band signals use chirp modulation with the VHF signals using chirp and quadrature phase shift keying modulation.

Operating modes

EW Analytics LLC’s analysis notes that four signal modes are available when the radar is performing VHF transmissions with the same number of signal modes available when the radar is transmitting in S-band. The key difference between these modes are their pulse power, duration and repetition intervals. EW Analytics LLC’s study adds that it is unclear how these modes are used: Can different modes be used on different frequencies simultaneously? Are the radar modes automatically determined, set by the operator, or both?

The analysis has determined that the operator can set radar rotation speeds to either three- or six rotations-per-minute. It is noteworthy that the Vostok-3D’s VHF and S-band antennas are mounted back-to-back. EW Analytics LLC assesses that radar echoes from the VHF and S-band signals are probably merged into single tracks. Merging tracks in this way will help to provide a richer radar picture.

Targets are automatically classified as fixed- or rotary-wing aircraft, ballistic missiles, balloons or are left unidentified. Photographs of the Vostok-3D reveal that an Identification Friend or Foe (IFF) interrogator can be integrated below the S-band antenna. It is not thought that the interrogator is supplied as standard and may need to be added by the customer. Additional investigation by EW Analytics LLC has determined that target identity can be ascertained from an Automatic Dependent Surveillance Broadcast (ADS-B) system feed. ADS-B information is available to be displayed on the operator’s screen.

Into service

EW Analytics expects the Vostok-3D to enter service with the Belarussian military by the end of this year. As of 2022, KB Group was under United States government sanctions. These sanctions were imposed in retaliation for Belarussian support for the invasion of Ukraine and assistance given to Russia therein.

A VHF transmission that displays some Vostok-3D signal attributes and that possibly originates from Belarus can currently be found in an amateur radio channel that is publicly accessible on the Internet. Assuming the Vostok-3D’s service entry occurs as planned by the end of 2024, it is possible that signals from these radars maybe detected with increasing regularity in the coming years; especially if the Vostok-3D radar is not as “stealthy” as advertised. North Atlantic Treaty Organisation airborne signals intelligence collection assets appear to take a close interest in Belarus. Therefore, these assets may have the opportunity to collect potentially lucrative intelligence on this radar.

(Source: Armada)

 

01 Aug 24. MARS Attacks. Part of the control panel for the AN/ALQ-172(V)2 system which helps protect USAF B-52H Stratofortress strategic bombers. This system is undergoing a comprehensive upgrade via the MARS initiative to improve its resilience vis-à-vis emerging threats.

The US Air Force’s venerable Boeing B-52H Stratofortress strategic bomber is receiving important enhancements to its self-protection systems.

L3Harris was awarded a ten-year $947 m contract in 2021 to implement a host of improvements to enhance the B-52H’s AN/ALQ-172(2) self-protection suite. This contract forms part of the Stratofortress’ MARS (Maintainability and Reliability System) upgrade programme. According to reports, the AN/ALQ-172 has been in service onboard the B-52 series since the early 1980s. The original version was the AN/ALQ-172(V)1 fitted to now-retired B-52G bombers with the AN/ALQ-172(V)2 equipping the B-52H.

Capabilities and improvements

Open sources state that the AN/ALQ-172(2) can protect the aircraft against radar-guided air-to-air and surface-to-air threats. The system detects and jams low band (100 megahertz to two gigahertz/GHz), mid-band (two gigahertz to six gigahertz) and high-band (six gigahertz to 18GHz) threats. These threats can include simultaneous monopulse, multiple pulse, pulse Doppler and continuous wave radars.

According to L3Harris’ literature, the MARS upgrade extends the AN/ALQ-172(V)2’s frequency coverage. This may mean coverage has been extended upwards to circa 40GHz. Extending the system in this fashion would allow the AN/ALQ-172(V)2 to detect and jam K-band (24.05GHz to 24.25GHz) and Ka-band (33.4GHz to 36GHz) threats. K-band and Ka-band radars are often employed as seekers for active radar homing air-to-air and surface-to-air missiles. Field-programmable gate array technology has been added to the AN/ALQ-172(V)2 making the system easier to reconfigure in situ. The upgrade also added digital receivers while reducing overall weight and power consumption.

Stratofortress path

“There isn’t a single MARS contract,” says Jimmy Mercado, L3 Harris’ programme director for bomber electronic warfare. “The MARS campaign started as a series of form, fit, function (and) interface LRU (Line Replacement Unit) redesigns triggered by sustainment demand.” Mr. Mercado says that the first LRU to be redesigned was the system’s LRU-10 with work commencing in 2014. The AN/ALQ-172(V)2’s LRU-14 has also been redesigned via the MARS programme. As Mr. Mercado states both LRU-10 and LRU-14 are “in production and are fieldable”. He adds that “(a)ll but two LRU redesign contracts have been completed. The remaining two will complete in 2025. Production for MARS LRU-4 is expected to begin this year.”

Writ large, MARS heralds improvements “inherent from transitioning from analogue to digital technology, the use of digital receivers and high-speed signal processing, and increased accuracy and precision measurements,” Mr. Mercado continues. An open, modular approach has been taken to ease future upgrades. During a recent test flight five of the nine LRUs being upgraded were successfully evaluated. MARS shows there is growth potential for the EW systems protecting a bomber which may remain in service until 2050. (Source: Armada)

 

01 Aug 24. New Systems for the Space Force. One of the few existing images of the US Space Force’s Remote Modular Terminal satellite communications jamming system. The RMT is expected to soon enter service as a complement to the Space Force’s existing Counter Communications System.

The United States Space Force is set to enhance its electronic warfare capabilities with the service entry of the Remote Modular Terminal.

Reports in late July said that the US Space Force’s (USSF’s) Remote Modular Terminal (RMTs) jammers will enter service at undisclosed locations by the end of this year. The reports continued that 24 jammers have been ordered with eleven expected to begin deployment by late 2024. Four of the jammers are thought to have already been delivered. Few details exist regarding the RMT’s capabilities although they are intended to jam Satellite Communications (SATCOM). This may mean they transmit jamming waveforms into ground-based, airborne or ship-based SATCOM terminals. Specifically, the jammers may cover wavebands of circa 240 megahertz/MHz up to 40GHz. By covering these wavebands, RMTs could attack a raft of frequencies routinely used for SATCOM. This April, it was confirmed that the USSF had concluded Remote Modular Terminal testing.

Complementing CCS

Once in service, the Remote Modular Terminals will complement the USSF’s Counter Communications System (CCS) SATCOM jammers. Like the RMTs, much remains unknown vis-à-vis the CCS apparatus including the SATCOM frequencies it targets. CCSs operated by the Space Force are undergoing an upgrade dubbed Meadowlands. The $219 m Meadowlands programme is reducing the quantity of equipment racks used by the CCS; a reduction which will help reduce the CCS’s maintenance burden and ease of deployment.

It is unclear why the Space Force has moved ahead with the RMT acquisition. Previous analysis by the Secure World Foundation surmised that the CCS may attack C-band (5.925GHz to 6.425GHz uplink/3.7GHz to 4.2GHz downlink), X-band (7.9GHz to 8.4GHz uplink/7.25GHz to 7.75GHz downlink) and Ku-band (14GHz uplink/10.9GHz to 12.75GHz downlink) SATCOM frequencies. The Secure World Foundation is a thinktank based in Washington DC specialising in space policy.

Is it possible that the RMT has been procured to attack other SATCOM frequencies not covered by the CCS? The Russian SATCOM sector has made investments into Ka-band capabilities in recent years. Russian military SATCOM has already been confirmed as using C-band and Ku-band frequencies. Likewise, analysis of the SATCOM market confirms that the People’s Republic of China is investing in Ka-band. It would be prudent to ensure that the USSF has SATCOM jammers targeting frequencies used by US and allied strategic rivals.

Tactical and operational deployments

In the USSF’s own words the Remote Modular Terminals are compact, portable and cost-effective, and designed for deployment in difficult environments. The terminals have a small, modular design employing off-the-shelf components. One of the few technical specifications in the public domain is the terminal’s three-metre (ten-feet) diameter dish. It is possible that the larger CCS equipment will be statically deployed for SATCOM jamming at the operational/tactical level. In contrast, the RMTs may be intended for tactical level use at the halt and be easy to redeploy as the tactical situation warrants. Although details regarding the RMT remain scant, more maybe forthcoming once the system enters service later this year. (Source: Armada)

 

01 Aug 24. August Spectrum Sitrep.

Rohde & Schwarz is providing its RCESM system to furnish the Polish Navy’s three new frigates which will help enhance the electromagnetic situational awareness of these vessels.

Armada’s monthly round-up of all the latest electronic warfare news in the product, programme and operational domains.

New naval ESMs

On 9th July, Rohde & Schwarz announced that the company had concluded a contract with PGZ Stocznia Wojenna to support the Marynarka Wojenna (Polish Navy) Miecznik frigate programme. A press release revealed that Rohde & Schwarz will supply several Electronic Warfare (EW) systems. These systems include the company’s Radar and Communications Electronic Support Measures (RCESM) for the three new frigates. Rohde & Schwarz told Armada via a written statement that the RCESM is “adaptable and scalable to specific requirements.” The system “detects, identifies and locates complex and broadband radar emissions and captures enemy communications.” Signals intelligence collected by the RCESM is combined to provide “an extended picture of the entire electromagnetic spectrum.” The statement added that “(t)he solution’s particularly high sensitivity and accuracy results in an increased range coverage and early warning capability (and it) protects navy vessels against time-critical threats.” Rohde & Schwarz declined to provide details of the contract’s value and timelines for delivery citing confidentiality.

Got your back

The US Army’s Terrestrial Layered System–Brigade Combat Team (TLS-BCT) backpack Electronic Warfare (EW) apparatus is on course for service entry by the end of 2024. The backpack will be deployed with dismounted troops at the tactical level and is being developed and produced by Mastodon Design. In early July, the army’s Intelligence, EW and Sensors Programme Executive Office (PEO IEWS) announced it had awarded the company a contract worth $99.9 m. The contract encompasses “the procurement, training, and fielding” of the TLS-BCT backpack. The news was announced via a PEO IEWS press release. The document continued that the deployment of the first TLS-BCT backpacks should occur by the end of 2024. A PEO IEWS spokesperson told Armada that the equipment “provides a small form factor full spectrum signals intelligence, EW, and cyber-enabling, non-kinetic offensive operation capabilities to BCT commanders” near the tactical edge. TLS-BCT backpacks will be “fielded to infantry, armoured, and Stryker formations operating across regionally aligned areas of responsibilities.”

AFWERX work

HawkEye 360 has been awarded a Small Business Innovation Research (SBIR) Phase-2 contract by the US Air Force’s AFWERX programme. The AFWERX initiative aims to identify and nurture the innovations of small businesses which may benefit the air force. According to US Department of Defence definitions, SBIR Phase-2 contracts run for between twelve and 18 months and are typically worth up to $2 m. The contracts are intended to help move a technology or innovation towards a prototype stage. Under the terms of the contract, a HawkEye 360 press release said that the company will deliver its RFGeo signal mapping and RFIQ emitter analysis data to AFWERX. A statement from HawkEye 360 supplied to Armada said that these data will be delivered over the next twelve months. (Source: Armada)

 

30 Jul 24. Viasat Introduces Wearable Secure Wireless Hub for Advanced Network and Edge Communications. Viasat Inc. (NASDAQ: VSAT), a global leader in satellite communications, today announced the introduction of Viasat’s Secure Wireless Hub (SWH), a wearable tactical gateway solution for dismounted soldiers that is easy to carry and simple to use. The SWH solution was developed as part of a multi-phase effort with U.S. Special Operations Command (USSOCOM) to identify and develop advanced tactical communications capabilities for mobile ground forces.

The SWH is the first wearable addition to Viasat’s portfolio of tactical gateway solutions, providing a flexible, all-in-one design to enable faster set up for warfighters to improve user experience and support situational awareness within minutes. With a base of less than one kilogram, the SWH system offers significantly reduced size, weight and power (SWaP) to seamlessly integrate with body armor without adding unnecessary weight. In addition to reducing the physical load soldiers carry, the SWH provides an 85 percent reduction in cabling compared to other wearable hub systems, further simplifying ease of use for ground operators.

Viasat’s SWH is designed to provide the capability of much larger systems to meet expanding requirements for tactical edge compute and networking in a small form factor for dismounted users. As a complete solution, the SWH will offer a body-worn tactical gateway that can provide a level of interoperability only previously seen in larger transit boxes that are too big for dismounted operations. Viasat’s mobile software defined networking platform, NetAgility, will enable the SWH to utilize various tactical transports and advanced networking capabilities to improve situational awareness and data exchange. The edge compute capability will also offer a secure VPN, allowing the use of multiple transports and waveforms across a range of devices to provide resilient connectivity and safely share critical battlefield information.

“Tactical edge operators are seeking lightweight compute and resilient connectivity solutions to advance Battle Management Command, Control, and Communications (BMC3) capabilities. The Secure Wireless Hub is our latest tactical solution created to support this by addressing interoperability, automation, and security challenges for the dismounted user,” said David Schmolke, Vice President of Mission Connections and Cybersecurity, Viasat Government. “The SWH was designed with a focus on a user experience that enables the warfighter to focus on the mission and not the equipment.”

The SWH’s modular design allows tactical operators to integrate and configure connections for their mission, including LTE and Wi-Fi/Bluetooth for additional resilience. Users can also benefit from the Secure Wireless Hub App that seamlessly integrates with military devices as a single source configuration manager. As part of the development effort, Viasat worked with USSOCOM to undergo a full customer test and user assessment of the SWH system during the Strategic Level Joint SOF Fires Exercise last fall. (Source: ASD Network)

 

30 Jul 24. Kromek (AIM: KMK), a leading developer of radiation and bio-detection technology solutions for the advanced imaging and CBRN detection segments, is pleased to announce that its D3M detector has been named as the Personal Radiation Detector (“PRD”) under the UK Government Resilience Framework (the “Framework”). The Group has received its first order under the Framework from Merseyside Fire & Rescue Service, which will use the D3M for its Detection, Identification and Monitoring (“DIM”) vehicles.   The Framework is designed to strengthen the UK’s resilience system to prevent risks manifesting or crises happening where possible, addressing all serious threats to public safety and security. It focuses on the foundational building blocks of resilience, setting out a plan to 2030 to strengthen the frameworks, systems and capabilities that underpin the UK’s resilience to all civil contingencies risks.   The D3M is the only PRD that has been pre-approved for purchase under the Framework, which is scheduled to be in place for four years. As a result, all blue light service operators in the UK, such as fire, police, ambulances and first responders, can purchase the D3M detector for projects under the Framework without going through a separate approval process.

Merseyside Fire & Rescue service is the first of many potential customers in the UK to have bought the D3M under their Detection, Identification and Monitoring (DIM) Equipment Uplift project, which involves acquiring equipment to enhance their capabilities for detection of Chemical, Biological, Radiological, and Nuclear (“CBRN”) threats. The customers are all blue light services in the UK – ambulance, fire and police. This is a sole supplier framework for this a category of products which allows any blue light organisation to buy directly without tendering. The original UK potential order before cuts was estimated to be 8000 units, the amount now is estimated at 3500 units plus any exports. This updates an earlier release of this contract showing the possible new customers.

 

30 Jul 24. New malware variant accentuates security, information theft risks to Android users. On 29 July, the cyber security firm Kaspersky reported that unnamed threat actors have targeted Android users with a new version of the ‘Mandrake’ spyware since 2022. Threat actors distributed Mandrake via five fraudulent applications available on the legitimate Google Play platform. Upon installation, Mandrake establishes communication with actor-controlled infrastructure to collect data and prompt victims to download additional malicious packages. Although the objective of this campaign is unclear, there is a realistic possibility that threat actors sell sensitive data and access to devices on the dark web for illicit profit. The spyware notably hides its malicious code in a native library to achieve prolonged obfuscation. Additionally, it checks for the presence of security tools, highlighting the increased sophistication of the spyware’s detection evasion capabilities. This incident underscores threat actors’ ongoing development of Mandrake since it was first detected in 2020, accentuating security and information theft risks to global Android users in the short-to-medium term. (Source: Sibylline)

 

26 Jul 24. Cyber Update Key points.

  • New cyber campaigns capitalise on the CrowdStrike IT outages, raising security and disruption risks (see Sibylline Cyber Daily Analytical Update – 22 July 2024).
  • A new ‘Play’ ransomware variant heightens security and financial risks from cyber criminals (see Sibylline Cyber Daily Analytical Update – 23 July 2024 and our Technical analysis below).
  • A new industrial control systems (ICS) malware disrupted heating provision in Ukraine, elevating security and disruption risks to critical infrastructure (see Sibylline Cyber Daily Analytical Update – 24 July 2024).
  • New malware strains targeting organisations in the Asia-Pacific, sustain elevated espionage risks from the Chinese state-sponsored group ‘Evasive Panda’ (see Sibylline Cyber Daily Analytical Update – 25 July 2024 and our Technical analysis below).
  • The exploitation of three new vulnerabilities underscores elevated information theft and supply chain risks from cyber criminals (see Sibylline Cyber Daily Analytical Update – 26 July 2024).

Technical analysis of weekly stories

The ‘Play’ ransomware group targeted VMware ESXi virtual machines (VMs) with a new version of their custom ransomware. Play typically uses several tools such as the ‘Coroxy’ backdoor, NetScan and WinSCP to identify attack vectors and deploy the ransomware. Upon initial infection, the ransomware conducts a series of checks to ensure it is running in an ESXi environment before executing any additional commands. Notably, it evades detection by automatically terminating and deleting itself from compromised systems if it does not detect ESXi environments. The payload then identifies and powers down all VMs on the system by executing a series of shell script commands. This enables the threat actors to encrypt all VM files, issuing a ransom demand for illicit profit. Additionally, the URL hosting the Play payload can be traced back to another cyber criminal group, ‘Prolific Puma’, highlighting potential co-operation between the two groups. Prolific Puma typically generates domain names via a random destination generator algorithm (RDGA) and provides URL shortening services to enable other cyber criminal groups to evade detection. Play’s development of new custom ESXi malware likely points to the group’s intent to widen their victim pool and bolster success rates of ransom payouts.

The Chinese state-sponsored group ‘Evasive Panda’ has targeted organisations in Taiwan as well as US NGOs operating in China, with new versions of their custom malware. The group reportedly infiltrated targeted systems via the software supply chain or adversary-in-the-middle (AITM) attacks in multiple cyber operations. One of these campaigns installed an updated version of the ‘Macma’ macOS backdoor which provided the threat actors with additional espionage capabilities. These include the ability to adjust screenshot sizes and debug logging to obtain detailed information about compromised systems, alongside its original functionalities such as device fingerprinting, keylogging, audio capture and uploading and downloading files. Evasive Panda also exploited a vulnerability in Apache HTTP during one operation to deliver their ‘MgBot’ malware, highlighting the evolution of the group’s tactics, techniques and procedures (TTPs). We assess that these operations underscore Evasive Panda’s commitment and resources to continuously develop their custom malware. Additionally, the group has used a new backdoor, ‘Nightdoor’, since at least March alongside MgBot. Notably, the backdoor loads two files to establish persistence on compromised systems and contains embedded code to detect VMs, sandboxes and malware analysis environments as well as aid detection evasion. Furthermore, Evasive Panda used trojanised Android packages (APKs) as well as text and domain name system (DNS) interception tools in some of these operations, further pointing to the group’s likely ample resources and capabilities.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Enforce strict patch management policies to protect against known software vulnerabilities.
  • Implement network segmentation to segregate critical systems and networks and limit the spread of malware.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices.

Our cyber word(s) of the week: Domain generation algorithm

(Source: Sibylline)

—————————————————————————————————————————————————————————————————————————————————————————————————————————–

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

 

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

——————————————————————————————————————————————————————————————————————————————————————————————————————————————

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT