Sponsored by Spectra Group
———————————————————————————————————————————————————————————————————————————————————————————————————————————–
16 Oct 24. Thales Radios Successfully Tested by the German Armed Forces to Be Deployed Within the NATO Enhanced Forward Presence
- The German Armed Forces conducted operational tests with PR4G and SYNAPS-H Thales radios to demonstrate their suitability for the needs of the multinational Battalion Group deployed by NATO.
- Within one year, Thales has successfully delivered to the German Armed Forces radio equipment for the NATO enhanced Forward Presence (eFP).
- These 4-week operational tests demonstrated that Thales radios are interoperable and secure.
Thales radios for use in NATO enhanced Forward Presence were tested in an intensive four-week operational trial under the direction of the Army Development Office. These tests were conducted with the participation of the Army Development Office, the Federal Office of Bundeswehr Equipment, Information Technology and In-Service Support (BAAINBw), the German Army’s “Test and Trial” teams and Dutch and French Armed Forces.
The particular focus of the procurement was to provide modern, encrypted, electronic counter countermeasure (ECCM)-capable command and control radios for the multinational deployment of the enhanced Forward Presence, which can transmit voice in parallel with data and their own position.
“During the four-week operational test, Thales PR4G and SYNAPS-H radios met the requirements so effectively that the system is deemed suitable for introduction into the German Armed Forces.. We are very pleased that there are no more obstacles for the operational use of the radios in Lithuania, where the deployed forces will have protected, modern radios.” added Christoph Ruffner, CEO and Country Director, Thales Deutschland.
Although the soldiers had not received any training, only a short briefing, it was possible to establish operational readiness in under an hour..The radios also impressed with a stable radio network and in the range tests.
The purpose of NATO enhanced Forward Presence is to strengthen its defensive and deterrent posture on Europe’s eastern flank. NATO battlegroups are deployed to the Baltic states of Estonia, Latvia and Lithuania as well as to Poland and led by the United Kingdom, Canada, Germany and the United States respectively. (Source: ASD Network)
17 Oct 24. Cyber Update Key points.
- The Chinese state-sponsored group ‘Salt Typhoon’ infiltrated several US internet service providers (ISPs) in a cyber espionage campaign, elevating the security risks for government and critical infrastructure (see Sibylline Cyber Daily Analytical Update – 7 October 2024).
- The advanced persistent threat (APT) group ‘Awaken Likho’ used new software to target Russian government organisations, elevating the security risks facing related entities (see Sibylline Cyber Daily Analytical Update – 8 October 2024 and our Technical analysis below).
- A cyber attack on air-gapped systems by the APT group ‘GoldenJackal’ will increase the cyber espionage risks facing European government bodies (see Sibylline Cyber Daily Analytical Update – 9 October 2024 and our Technical analysis below).
- Increased exploitation of artificial intelligence (AI) chatbots in financially motivated operations will raise the financial and supply chain risks stemming from cyber criminals (see Sibylline Cyber Daily Analytical Update – 10 October 2024).
- A new ‘Lynx’ ransomware-as-a-service (RaaS) operation targeting Windows users points to the raised security and financial risks stemming from cyber criminals (see Sibylline Cyber Daily Analytical Update – 11 October 2024).
Technical analysis of weekly stories
The APT group Awaken Likho used new software to target Russian government organisations in a campaign between June and August. Unlike previous operations, this campaign used the open-source remote device management tool ‘MeshAgent’ to maintain access to compromised systems, marking a shift in Awaken Likho’s tactics as it continues to target Russian entities amid the war in Ukraine. The campaign likely started with phishing emails to trick potential victims into clicking on malicious attachments. The attachments then loaded self-extracting archives (SFX) onto compromised systems. They contained five malicious files masked with legitimate file names to evade detection. Notably, several files did not contain a payload and were likely added to the archives to mislead victims. Subsequently, MeshAgent is executed via a multi-stage process which establishes communication with the actors’ command-and-control (C2) infrastructure. The payload’s code was heavily obfuscated with additional empty text boxes, further underscoring the sophistication of the actors’ detection-evasion techniques. Additionally, we assess the group will likely exploit access to compromised systems to collect sensitive information and to deploy more payloads.
The APT group GoldenJackal compromised air-gapped systems within an unnamed European government organisation in a cyber espionage campaign between May 2022 and May 2024. The group also targeted air-gapped systems within an unspecified South Asian embassy in Belarus in a separate campaign in 2019. GoldenJackal used a highly sophisticated custom toolset to bypass air-gap isolation mechanisms and to exfiltrate sensitive information from targeted systems. The group likely gained access to targeted systems via malicious documents and/or remote access trojans (RATs) to deploy a new custom malware (‘GoldenDealer’). The malicious payload contained a worm component that enabled the file to copy itself onto any USB drives inserted into infected systems. When inserted into an air-gapped system by unknowing users, compromised USB drives display a folder icon containing the malicious payload. This tricks users into clicking on the file, thereby propagating the infection. GoldenDealer then collected information from compromised air-gapped systems, relaying it back to the actors’ C2 infrastructure after re-inserting infected drives into internet-connected devices. The malware exfiltrated data and communicated with the C2 server via several custom tools including a file collector (‘GoldenRobo’) and a new backdoor (‘GoldenHowl’), highlighting GoldenJackal’s ability to bypass security mechanisms. Notably, the group employed a multi-layered approach using several compromised devices to perform different tasks based on collected system data, further underscoring GoldenJackal’s sophistication. We assess that the volume of new custom tools showcased in this operation points to the group’s continuous development of malware.
Some non-exhaustive recommendations to mitigate against these threats include:
- Monitor devices and networks for suspicious activity.
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
- Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
- Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices, including personal devices connected to corporate networks or applications.
- Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.
Our cyber word(s) of the week: Air-gapped system
(Source: Sibylline)
17 Oct 24. Iran: Disruptive attacks indicate heightened cyber security risks to government, CNI. On 12 October, international news outlets reported that several government branches and nuclear facilities in Iran were targeted in a series of disruptive cyber attacks. The attacks also reportedly disrupted Iranian critical national infrastructure (CNI) including fuel distribution, municipal networks and transportation hubs. The attacks also reportedly exfiltrated sensitive data from affected systems. There is a realistic possibility that these attacks are linked to the Israeli government as Israel vowed to deliver a strong response to Iran following the launch of ballistic missiles against Israel on 1 October. As regional tensions will almost certainly persist in the short term, we assess that additional disruptive cyber operations against Iranian CNI and organisations affiliated with Iran-backed groups in the region remain likely in the coming weeks. Additionally, there is a realistic possibility that Iran will also use cyber attacks to retaliate against Israel; however, we assess that these operations are unlikely to escalate tensions. (Source: Sibylline)
17 Oct 24. Global: Malware variant will sustain elevated risks from North Korean state-sponsored groups. On 14 October, international news outlets reported that the North Korean state-sponsored group ‘Lazarus’ is using a new version of the ‘FASTCash’ malware to target global Linux payment systems. The group likely used social engineering attacks to access targeted payment switches and deploy the FASTCash payload. This enabled Lazarus to interject transaction requests between ATMs, point-of-sale (PoS) systems and financial institutions by exploiting native communication protocols. The group manipulated declined transactions to obtain approvals from banks, allowing money mules acting on their behalf to collect cash from an ATM. We assess that this newly discovered Linux version of FASTCash underscores Lazarus’ continuous development of more sophisticated malware to garner illicit profit. The group routinely targets financial institutions in financially motivated operations to bolster North Korea’s economy as well as its weapons and missiles programme amid international sanctions. We assess that this will sustain elevated financial risks to this sector in the long term. (Source: Sibylline)
16 Oct24. BAE Systems and Kongsberg sign teaming agreement for new platform situational awareness tool.
The Integrated Combat Solution tool will give Warfighters the situational awareness they need for any mission, as well as options to respond to potential threat
BAE Systems has entered into a teaming agreement with Kongsberg Defence and Aerospace to bring Integrated Combat Solution (ICS) to the U.S. defense market. The transformational battlefield situational awareness tool for combat vehicles will provide the Warfighter with the capability to link and share video streams, metadata, target information, slew-to-cue commands, and much more, reducing the typical threat response speed from minutes to seconds. Together, with Kongsberg developing the ICS tool and BAE Systems integrating it onto combat vehicles, the companies will support technology upgrades through the product lifecycles.
“The ability for troops to rapidly pass targeting information across the battlefield to other platforms and engage a target remotely is critical to their mission,” Andy Corea, vice president and general manager of BAE Systems’ Combat Mission Systems business, said. “The combined talents of Kongsberg’s innovation and expertise in remote weapon systems and our lead systems integration capability provides the Warfighter the opportunity to obtain fully integrated enhanced combat capability – helping them stay aware and unmatched in battle.”
ICS is a tool that can be used across the U.S. Marine or U.S. Army’s fleet of vehicles as a critical enabler of their mission. Built with an open-systems approach, ICS can be integrated on any battlefield platform equipped with a weapon system and on-board sensors – keeping troops aware and safer in the fight. ICS will give Warfighters more options to respond to potential threats, matching the rapid pace of warfare in the future. ICS uses an integrated network to link the sensors on different battlefield assets together, allowing command and control of weapon stations, turrets, jammers and other effectors from a single screen inside the vehicle.
“Together we will deliver ICS as a core enabler of modern warfare, providing all-domain visibility, command and control,” said Kjetil Reiten Myhra, executive vice president defence systems, Kongsberg Defence and Aerospace. “This force multiplier streamlines complicated threat responses, networking mobility platforms and other assets for increased combat capability.”
The ICS capability has already been demonstrated on the Amphibious Combat Vehicle (ACV) and Armored Multi-Purpose vehicle platforms, and the combined team of BAE Systems and Kongsberg looks forward to the opportunity to provide it across the ground combat forces. The ICS system is also featured at the BAE Systems booth (#6041) at AUSA this week on the Armored Multi-Purpose Vehicle (AMPV) platform, further demonstrating the team’s ability to integrate it on different combat vehicles.
14 Oct 24. Leonardo unveils new digital technology to revolutionise how armed forces suppress and defeat modern enemy air defences
- The new BriteStorm payload can fly ahead of friendly forces on-board Uncrewed Aerial Vehicles (UAVs) and launched effects, deceiving enemy defences with sophisticated digital jamming and deception techniques.
- Successful flights with the UK Royal Air Force’s Rapid Capabilities Office (RAF RCO), proving the capability, have already taken place.
- Leonardo launched the product at the Association of the U.S. Army (AUSA)’s Annual Meeting and Exposition in Washington D.C.
Leonardo has launched a new product, called ‘BriteStorm’, that will allow armed forces to operate deep within enemy territory, even when that territory is guarded by modern Integrated Air Defence Systems (IADS).
BriteStorm is able to perform ‘stand-in jamming’: an airborne electronic warfare capability, deployed ahead of the main force, to deliver high-powered interference against a wide spectrum of threats. By doing so, BriteStorm degrades the enemy’s IADS, supressing its ability to detect and lock onto other platforms, protecting friendly forces and enabling their mission.
The BriteStorm payload is designed to be installed on the widest possible range of UAVs and launched effects. It will equip each platform with an advanced array of digital deception techniques, deployable at long range.
The UK Royal Air Force’s Rapid Capabilities Office (RCO) is working with Leonardo in relation to the capability and has purchased payloads to conduct trials. Successful flights with the RCO proving the capability have already taken place.
Developed at Leonardo’s electronic warfare research and manufacturing base in Luton, UK, BriteStorm builds on the Digital Radio Frequency Memory (DRFM) technology underpinning Leonardo’s in-service BriteCloud countermeasure, the only DRFM-based expendable on the market to have been demonstrated effective in live tests. In contrast to BriteCloud, which is designed to disrupt incoming missiles’ radar guidance systems, BriteStorm has been engineered to confuse and suppress ground-based surveillance radars, preventing the enemy from tracking and then engaging friendly forces.
BriteStorm works by using Leonardo’s mission-tested DRFM technology to detect and evaluate the electronic warfare threat environment and then choose the most relevant countermeasure technique. Depending on the situation, BriteStorm’s effects can range from barraging the enemy system with electronic noise to more sophisticated techniques such as creating dozens of realistic ‘ghost’ fighter jet signatures, confusing and misdirecting the enemy response.
BriteStorm is small, lightweight and platform-agnostic. A standard BriteStorm fit incorporates a platform-specific antenna, transmit-receive modules and Leonardo’s Miniature Technique Generator. It is simple to integrate, making BriteStorm an accessible route to establishing a powerful, attritable, stand-in jamming capability. The BriteStorm development team has drawn on Leonardo’s company-wide programme of digital transformation to create a powerful and sophisticated product, whilst ensuring the payload can be considered attritable.
In addition to the UK Ministry of Defence, Leonardo views the U.S. Department of Defense as a key potential customer for BriteStorm, with the payload able to deliver a capability advantage to operators in contested electronic warfare environments, while being rapidly reprogrammable to match the pace of the threat. BriteStorm has been designed to be readily exportable, with demonstration units already in the USA. Leonardo is expecting to see further interest in BriteStorm from customers in Europe, the Middle East and Asia Pacific.
11 Oct 24. Cybersecurity Maturity Model Certification Program Final Rule Published. Today, the final program rule for the Cybersecurity Maturity Model Certification (CMMC) Program was released for public inspection on federalregister.gov and is anticipated to be published in the Federal Register, Tuesday, October 15.
The purpose of CMMC is to verify that defense contractors are compliant with existing protections for federal contract information (FCI) and controlled unclassified information (CUI) and are protecting that information at a level commensurate with the risk from cybersecurity threats, including advanced persistent threats.
This rule streamlines and simplifies the process for small-and medium-sized businesses by reducing the number of assessment levels from the five in the original program to three under the new program.
This final rule aligns the program with the cybersecurity requirements described in Federal Acquisition Regulation part 52.204-21 and National Institute of Standards and Technology (NIST) Special Publications (SP) 800-171 Rev 2 and -172. It also clearly identifies the 24 NIST SP 800-172 requirements mandated for CMMC Level 3 certification.
With the publication of this updated 32 CFR rule, DoD will allow businesses to self-assess their compliance when appropriate. Basic protection of FCI will require self-assessment at CMMC Level 1.General protection of CUI will require either third-party assessment or self-assessment at CMMC Level 2.A higher level of protection against risk from advanced persistent threats will be required for some CUI. This enhanced protection will require a Defense Industrial Base Cybersecurity Assessment Center led assessment at CMMC Level 3.
CMMC provides the tools to hold accountable entities or individuals that put U.S. information or systems at risk by knowingly misrepresenting their cybersecurity practices or protocols, or knowingly violating obligations to monitor and report cybersecurity incidents and breaches. The CMMC Program implements an annual affirmation requirement that is a key element for monitoring and enforcing accountability of a company’s cybersecurity status.
With this revised CMMC Program, the Department also introduces Plans of Action and Milestones (POA&Ms). POA&Ms will be granted for specific requirements as outlined in the rule to allow a business to obtain conditional certification for 180 days while working to meet the NIST standards.
The benefits of CMMC include:
- Safeguarding sensitive information to enable and protect the warfighter
- Enforcing DIB cybersecurity standards to meet evolving threats
- Ensuring accountability while minimizing barriers to compliance with DoD requirements
- Perpetuating a collaborative culture of cybersecurity and cyber resilience
- Maintaining public trust through high professional and ethical standards
The Department understands the significant time and resources required for industry to comply with DoD’s cybersecurity requirements for safeguarding CUI and is intent upon implementing CMMC requirements to assess the degree to which they have done so. The Department would like to thank all the businesses and industry associations that provided input during the public comment period. Without this collaboration, it would not have been possible to meet our goals of improving security of critical information and increasing compliance with cybersecurity requirements while simultaneously making it easier for small and medium-sized businesses to meet their contractual obligations.
Businesses in the defense industrial base should take action to gauge their compliance with existing security requirements and preparedness to comply with CMMC assessments. Members of the defense industrial base may use cloud service offerings to meet the cybersecurity requirements that must be assessed as part of the CMMC requirement. The DoD CIO DIB Cybersecurity Program has compiled a list of current resources available at dibnet.dod.mil under DoD DIB Cybersecurity-as-a-Service (CSaaS) Services and Support.
The DoD’s follow-on Defense Federal Acquisition Regulation Supplement (DFARS) rule change to contractually implement the CMMC Program will be published in early to mid-2025. Once that rule is effective, DoD will include CMMC requirements in solicitations and contracts. Contractors who process, store, or transmit FCI or CUI must achieve the appropriate level of CMMC as a condition of contract award. More information on the timing of the proposed DFARS rule can be found at https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202404&RIN=0750-AK81.
More information on the CMMC Program can be found at https://dodcio.defense.gov/CMMC/.(Source: U.S. DoD)
—————————————————————————————————————————————————————————————————————————————————————————————————————————–
Spectra Group (UK) Ltd
Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.
Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.
With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.
Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.
In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.
Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.
Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.
————————————————————————————————————————————————————————————————————————————————————————————————————————-

