Sponsored by Spectra Group
——————————————————————————————————————————————————————————————————————————————————————————————————————————————–
02 Oct 24. US Marine Corps Successfully Demonstrate Link 16 in Third XQ-58 Valkyrie Test Flight. The Marine Corps’ XQ-58A Valkyrie successfully completed its third test flight on Sept. 20, 2024, at Eglin Air Force Base in Florida. This flight was conducted in partnership with the Office of the Under Secretary of Defense for Research and Engineering, the Naval Air Warfare Center Aircraft Division, and industry partners.
The test demonstrated newly added Link-16 capabilities for the uncrewed collaborative combat aircraft prototype, marking the first time the Department of Defense controlled an air vehicle using offboard expeditionary methods.
Initial results indicate that the prototype met threshold requirements for autonomously exchanging relevant tactical information. These Link-16 capabilities significantly enhance the Marine Air-Ground Task Force’s ability to conduct integrated and joint operations, contributing to the Marine Corps’ mission to deter conflict and, when necessary, defeat enemies in complex and evolving scenarios.
This successful test was conducted in preparation for Emerald Flag 2024, a multiservice and multi-domain training exercise scheduled for October. The exercise will incorporate technology and focus on the efficiency of joint warfare. The XQ-58A has proven itself ready for this capstone event, allowing the Marine Corps to demonstrate cooperative kill chain closure between manned and unmanned strike platforms for the first time in a large-force exercise. (Source: UAS VISION/USMC)
01 Oct 24. US Army seeks new industry input for Next Generation Command and Control initiative. The PEO C3T released the RFI after the office held an industry day to provide more information on NGC2 to interested vendors.
The Army took the next step its pursuit of tech for its Next Generation Command and Control (NGC2) initiative by reaching out for industry’s ideas Monday.
In a request for information (RFI) posted online, the Army’s program executive office for command, control, communications-tactical (PEO C3T) announced it is seeking input on “experimentation, pilots and, prototyping” in establishing NGC2.
Monday’s RFI is the first one related to C2NG to come out of PEO C3T and came after the office held an industry day to provide more information to interested vendors on Sept. 16. The document was released “in accordance with the Army Futures Command (AFC) Characteristics of Need (CoN) requirement,” related to that office’s own interest in next-gen C2, which came out May 21, according to the RFI.
PEO C3T’s RFI includes questions about how industry would “design and manage a common services architecture for warfighting applications” while allowing for a “plug-and-plan” architecture, and how industry would use a common data layer to leverage capabilities to “meet war fighting needs.” Furthermore, it asks how industry sees the role of the Army’s Unified Data Reference Architecture — a broader service framework — in creating and managing NGC2.
The requirement will also include “maximizing vendor access to capabilities and users” all while aiming to bolster the relationship between industry and government.
Additionally, all services and products that are chosen to be part of NGC2 will be “heavily dependent” upon progressive software analytics, artificial intelligence and machine learning capabilities to assist feedback in performance, the RFI states.
NGC2, sometimes called C2 Next, is the service’s plan to create an integrated C2 structure focusing on data centricity “at every echelon,” which will be a “system of systems,” per the RFI. It’s designed to combine intelligence, C2 and fires all in one system so commanders can have information more readily available — a key driving idea behind the Pentagon’s wide Combined Joint All-Domain Command and Control effort.
The service will test out the NGC2 principle in March of 2025 at the Project Convergence capstone five event, Col Michael Kaloostian, the AFC’s networks and security director for NCC2, told Breaking Defense in August.
“We are in the S&T [science and technology] phase, and we’re still doing [research and development] on this project,” Kaloostian told Breaking Defense during an Aug. 22 interview.
“We’re going to learn [with] each step. … It’s always gonna be iterative, because technology is always going to improve,” he later added.
The RFI released Monday is currently open for comment and will close on Oct. 4 at 5 p.m. ET. (Source: Breaking Defense.com)
02 Oct 24. Germany: Defence sector faces heightened cyber espionage risks from North Korea-backed groups. On 1 October, international news outlets reported that the North Korean state-sponsored group ‘Kimsuky’ targeted a German weapons manufacturer in a highly sophisticated cyber espionage campaign. The campaign started with phishing emails pertaining to lucrative job opportunities for US defence contractor roles to trick potential victims into opening a malicious PDF file. This then downloaded malware on compromised systems, enabling Kimsuky to steal sensitive information. The group’s command-and-control (C2) infrastructure hosted content in German to conceal the operation, underscoring the campaign’s considerable sophistication and premeditation. It is also possible that Kisumky has targeted German users in additional information-theft campaigns, as the C2 server also contained malicious login pages mimicking legitimate telecommunications providers. Kimsuky routinely targets defence organisations and weapons manufacturers in espionage operations to bolster North Korea’s weapons and missile programmes. We assess this will sustain elevated cyber espionage risks for these sectors in the long term. (Source: Sibylline)
02 Oct 24. MilDef launches Dismounted Soldier concept suite at AUSA, engineered for excellence in every mission.
To empower each individual soldier on the battlefield, MilDef launches its Dismounted Soldier System (DSS) to provide state of the art situational awareness and seamless interoperability across all environments. Experience the concept at the AUSA convention in Washington D.C.
MilDef’s suite for dismounted soldiers offers uncompromised durability and performance and is built on a range of hardware and software components that are not only rugged and durable but also highly adaptable to meet specific mission requirements. Whether it’s extreme temperatures, rough terrains, or high-stress combat scenarios, the MilDef system is designed to serve in those conditions. Developed with input from mission experienced military commanders and soldiers, it’s built to meet the demands of the toughest environments.
“Our system integrates with existing or new platforms and technologies, including radios, and other mission-critical systems, offering unit leaders high resolution situational awareness, enhancing coordination and effectiveness on the ground. The system is hardware and software agnostic, allowing for easy integration with any third-party solutions and battle management systems. This adaptability ensures a future-proof system, capable of evolving with technological advancements and changing operational demands,” says Fredrik Persson, CTO and Deputy CEO MilDef Group.
Components in the MilDef Dismounted Soldier System suite
- Tactical Android Device, the T.A.D. End User Device – Rugged Android device (MIL-STD-810/IP67), 5G and WiFi 6 connectivity, support of multiple ethernet devices, >24h operating time, field replaceable battery, night vision etc.
- MilDef DSS HUB – 6-port USB 2.0 HUB with power management, 1 EUD port, 3 PAN ports, 2 power ports, STANAG 4695 / STANAG 4851 / Nett Warrior compliant connectors.
- OneCIS – Automated and rapid deployment and configuration of operating system, network configuration, applications, and services.
MilDef has substantial experience from delivering tactical system solutions mounted in military platforms. MilDefs Dismounted Soldier System is a natural extension of MilDefs capabilities and offer, as when integrated with GFE (Government Furnished Equipment), existing systems and new technology, it delivers enhanced operational effectiveness and mission success – when and where the stakes are the highest.
AUSA takes place Oct 14-16 Washington DC, Walter E. Washington Convention Center, booth 7941.
30 Sep 24. Lockheed Martin (NYSE: LMT) in collaboration with Altera, an Intel Company, completed a successful flight demonstration of our 12th Generation Electronic Warfare (Gen12) transceiver utilizing Altera’s Agilex™ 9 Direct RF FPGA (Multi-Chip Package, MCP-2).
The project, coined SWIFT (SHIP-enabled Wideband Transceiver Integrated Flight Test) by the Office of the Under Secretary of Defense for Research and Engineering (OUSD-R&E), established an aggressive requirement for Lockheed Martin to perform an electronic warfare flight demonstration utilizing Altera’s FPGA aboard a Group 2 Unmanned Air Vehicle (UAV) in less than 12 months.
Conducted at the U.S. Army’s Yuma Proving Ground, the SWIFT demonstration represented the first time Lockheed Martin used the Altera Direct RF FPGA in a government test environment, showcasing the device’s readiness to perform real-world missions. The event successfully proved the Gen12’s Electronic Support (ES) capability by performing the detect, identify and locate mission against real enemy emitters in a DoD relevant environment.
Through the success of this demonstration, Lockheed Martin and Altera proved how size, weight and power (SWaP) constrained airborne platforms can be utilized to deliver electronic warfare effects, while also allowing growth for new capabilities. The technology enables a low SWaP, Sensor Open System Architecture (SOSA) aligned digital transceiver that performs the Electronic Support (ES) and Electronic Attack (EA) missions using domestically produced semiconductors.
This demonstration serves as a proof point for the importance of OUSD-R&E State-of-the-Art Heterogeneous Integrated Packaging (SHIP) program and the ongoing need for sustainable U.S.-made microelectronics packages customized for DoD applications.
The Big Picture
- The success of the SWIFT demonstration and its profound impact as a proof point on the SHIP program was reiterated at a recent event held at Lockheed Martin’s newly renovated Global Vision Center in Crystal City, Virginia. The event’s purpose highlighted the Altera Direct RF FPGA’s readiness to transition into a variety of DoD programs of record.
- During the event, attendees watched footage of the flight test demonstration in a pre-recorded video highlighting the capability of MCP-2, along with the rapid insertion and successful integration in a UAV.
- Keynote speakers from DoD leadership along with executives from Lockheed Martin, Altera and OUSD-R&E gathered to highlight the success of this demonstration and spoke about how the benefits enabled by the SHIP program and MCP-2 development, enable advanced electronic warfare architectures with game-changing capability enhancements.
Strategic Perspectives
“This demonstration signifies an important step forward for Lockheed Martin’s strategic partnership with OUSD-R&E and Altera on ensuring warfighter access to state-of-the-art, U.S.-made microelectronics,” said Dr. Steven Walker, vice president and chief technology officer at Lockheed Martin. “The SHIP program’s transformative influence on DoD capabilities bolsters confidence in these ongoing advancements and paves the way for their integration throughout the military in support of our customers’ most critical missions.”
“Altera’s proud to participate in Lockheed Martin’s demonstration along with OUSD-R&E SHIP program. Leveraging decades of leadership in chiplet development and manufacturing has led to the rapid readiness and availability of production quality, SWAP-centric MCP-2 products for future mission requirements.” said John Sotir, Senior Director, Military Aerospace and Government Business and State-of-the-Art Heterogeneous Integration Packaging (SHIP).
What’s Next?
- The success of this demonstration shows promise for continued collaboration with industry and commercial partners using U.S.-built semiconductors to achieve DoD objectives.
- This technology can be used for future platforms in many different ways depending on the mission at hand. It can deliver targeting information and situational awareness for our allies.
- Lockheed Martin will continue to demonstrate Gen12 Electronic Support (ES) and Electronic Attack (EA) capabilities for customers and cultivate near-term transition opportunities into DoD Programs of Record.
Background
- The SHIP program focuses on the development, delivery and eventual transition of microelectronics devices into DoD systems. The SHIP program’s objective is to create U.S.-made, trusted microelectronics that enable significant SWaP reductions in DoD systems.
- The SHIP program is part of a broader effort to enhance U.S.-based, secure and economically viable capabilities to support critical warfighting missions.
- As part of the SHIP program, multiple MCP devices were created in record time by Altera. Lockheed Martin was the early access partner for the transition of the MCP-2 device through the Stimulating Transition for Advanced Microelectronics Packaging (STAMP) contract.
- Through the STAMP contract, awarded by OUSD-R&E, Lockheed Martin and Altera worked to develop optimized architectures that leveraged the Altera commercial MCP-2 chip to apply specifically to electronic warfare applications, accelerating the transition of capabilities to the warfighter.
27 Sept 24. Cyber Update Key points.
- A destructive operation against Russian entities will raise disruption risks posed by pro-Ukraine hacktivists (see Sibylline Cyber Daily Analytical Update – 23 September 2024 and our Technical analysis below).
- Unnamed threat actors are targeting Android users with a new variant of the ‘Necro’ trojan, elevating financial risks to individuals (see Sibylline Cyber Daily Analytical Update – 24 September 2024).
- Artificial intelligence (AI)-related cyber operations will increase security risks from low-skilled cyber criminals (see Sibylline Cyber Daily Analytical Update – 25 September 2024).
- The rise in cyber operations against critical national infrastructure (CNI) will prolong operational and security risks from threat actors (see Sibylline Cyber Daily Analytical Update – 26 September 2024).
- An ongoing, highly sophisticated operation targeting Pakistani entities elevates espionage risks posed by the Indian state-sponsored group ‘SloppyLemming’ (see Sibylline Cyber Daily Analytical Update – 27 September 2024 and our Technical analysis below).
Technical analysis of weekly stories
The pro-Ukraine hacktivist group ‘Twelve’ may have targeted Russian entities in a destructive cyber attack in June. While the group reportedly halted operations in the spring, the tactics used in this recent operation point to Twelve’s likely re-emergence. The group typically infiltrates targeted systems by hijacking user accounts from third-party services including virtual private networks (VPNs) and secure shell (SSH). Twelve then deploys web shells on compromised systems to execute arbitrary commands, conduct additional malicious activities and install open-source malware. This enables them to encrypt and erase victims’ data using ransomware (‘LockBit 3.0’) and wiper malware. Notably, the group does not request ransom payments for file decryption, underscoring the politically motivated and destructive nature of their attacks. Twelve’s tactics and infrastructure also align with the ‘DARKSTAR’ ransomware group, suggesting that there may be an overlap between the two groups. Additionally, Twelve’s operations frequently include the deployment of a backdoor (‘FaceFish’) to remotely control infected systems, as well as the use of PowerShell to achieve prolonged persistence. The group also evades detection from security analysts by using existing product names to conceal malware payloads and deleting event logs.
The Indian state-sponsored group SloppyLemming is targeting the law enforcement, government, technology, energy and education sectors in Pakistan in an ongoing cyber espionage operation. The campaign uses phishing emails to trick victims into clicking on a malicious link and downloading a custom tool (‘CloudPhish’). CloudPhish then enables the group to create a malicious Cloudflare Workers instance to steal victims’ credentials by hijacking an email provider’s login page. SloppyLemming subsequently deploys a script to collect email addresses from victims’ accounts to propagate the attack. The group also used Cloudflare Workers to steal Google OAuth tokens, effectively gaining unauthorised access to a victim’s Google account. The data collected during these operations is then sent to the actors’ command-and-control (C2) infrastructure for storage using the legitimate messaging application Discord. Additionally, SloppyLemming uses follow-on phishing emails to distribute a malicious file hosted on the file hosting platform Dropbox, further highlighting the group’s frequent exploitation of legitimate cloud services. This exploits a software vulnerability (CVE-2023-38831) to install a remote access trojan (RAT), likely to perform additional malicious activities, such as remotely accessing compromised systems and exfiltrating sensitive data. SloppyLemming’s complex attack chain, which exploits several legitimate cloud services, serves as a testament to the group’s sophistication.
Some non-exhaustive recommendations to mitigate against these threats include:
- Monitor devices and networks for suspicious activity.
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
- Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
- Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices including personal devices connected to corporate networks or applications.
- Ensure organisations implement secure backup strategies by storing data backups in different formats including air-gapped and off-site copies to ensure resiliency.
Our cyber word(s) of the week: Email Account Takeover (EAT)
(Source: Sibylline)
———————————————————————————————————————————————————————————————————————————————————————————————————————————
Spectra Group (UK) Ltd
Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.
Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.
With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.
Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.
In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.
Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.
Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.
———————————————————————————————————————————————————————————————————————————————————————————————————————————-

