• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

November 1, 2024 by

Sponsored by Spectra Group

 

Spectra Group (UK) Ltd Home Page

————————————————————————————————————————————————————————————————————————————————————————————————————————————–

31 Oct 24. General Atomics Aeronautical Systems, Inc. (GA-ASI) collaborated with BAE Systems to demonstrate unique electronic warfare (EW) capabilities remotely controlled via a secure, jam-resistant Link 16 network on an MQ-20 Avenger® unmanned aircraft system (UAS). The Avenger is a jet-powered platform used extensively as a test bed for autonomous UAS development and the Collaborative Combat Aircraft (CCA) program. The demonstration helps accelerate emerging networked electronic attack capabilities for U.S. Air Force Autonomous Collaborative Platforms (ACPs).

The demonstration took place at GA-ASI’s Desert Horizon flight operations facility in El Mirage, California, and is part of an ongoing series of technology insertion and autonomous flights performed using internal research and development funding to prove important concepts.

“This effort featured novel mission system capabilities and the viability of autonomous payload control on our MQ-20,” said Mike Atwood, Vice President of Advanced Programs at GA-ASI. “We’re identifying key areas for improvement, while sharing investment and reducing risk.”

BAE Systems provided customized mission technology that included EW capabilities, a multi-functional processor (MFP), and a Link 16 terminal. The company successfully tested the integrated solution in its System Integration Lab to identify and jam threats autonomously and under control of an operator. Command, control, and status of the EW system was made possible through software-based, open-mission-system (OMS) compliant message translation hosted on the MFP. A secure Link 16 networking waveform was used to disseminate this information.

“We are working closely with General Atomics to highlight the maturity of autonomous EW mission systems in support of U.S. Air Force objectives,” said Scott Bailie, director of Advanced Electronic Warfare Solutions at BAE Systems. “We are combining proven EW technology and secure command and control on a rapid timeline in a small form factor well-suited for CCAs.”

 

31 Oct 24. Pentagon rolls out JWCC cloud accelerator initiative. The US Department of Defense (DoD) directorate, tasked with executing the Pentagon’s Joint Warfighting Cloud Capability (JWCC), is initiating a cloud accelerator initiative, designed to rapidly introduce secure commercial cloud services to the US armed forces down to the tactical level.

Announced in December 2022, the JWCC was designed to “provide the DoD the opportunity to acquire commercial cloud capabilities and services directly from” cloud service providers (CSPs) to facilitate global accessibility to cloud-based capabilities through a centrally managed data distribution process and allow secure network access via tactical edge devices. The JWCC was developed after Pentagon officials scrapped the controversial Joint Enterprise Defense Infrastructure (JEDI) cloud computing programme in July 2021.

Two years into the JWCC programme, which has cost the Pentagon roughly USD9 billion thus far, officials from the Defense Information Systems Agency (DISA) have partnered with CSPs at Amazon, Google, Microsoft, and Oracle, JWCC Program Manager Alee Long said. Those partnerships have allowed the US DoD to have “a direct relationship with those CSPs, [and] we are able to bring to our DoD partners the same commercial [services] but in a secure, sovereign cloud” network, Long said during a 24 October briefing.

DoD officials have also pushed commercial CSPs to provide “tactical edge offerings”, such as secure end-user devices and data centres, to the US armed forces, she explained. Getting those services down to the battlefield with low latency or network interference has been a key priority for newly minted DISA Director US Army Lieutenant General Paul Stanton, who took command of DISA in October. (Source: Janes)

 

31 Oct 24. Canada: Long-term cyber operation points to elevated espionage risks from Chinese threat actors. On 30 October, the Canadian Communication Security Establishment (CSE) reported that cyber threat actors affiliated with China have conducted a cyber espionage operation against Canadian government agencies since at least 2019. The unnamed threat actors compromised at least 20 government agencies, as well as several private sector entities. They reportedly exfiltrated sensitive information and intellectual property pertaining to the development of advanced technologies. The campaign also specifically targeted government officials who are critical of the Chinese Communist Party (CCP) in an email-based phishing operation. Notably, Chinese cyber activity spiked following diplomatic incidents between the two countries, underscoring China’s strategic use of cyber operations to aid its geopolitical pursuits. China consistently targets adversarial entities in cyber espionage campaigns, gathering information to bolster Beijing’s security and economic posture. As such, we assess that the latest development outlines the heightened espionage risks facing Canadian entities (among others) in the long term. (Source: Sibylline)

 

30 Oct 24. DOD Chief Digital and AI Office Hosts Responsible AI in Defense Forum. Today, the Department of Defense (DoD) Chief Digital and Artificial Intelligence Office (CDAO) concluded its “Responsible AI in Defense Forum,” a 3-day event that brought together defense leaders, AI experts, policymakers, and global innovators to focus on advancements in Responsible AI (RAI), held at the Hyatt Regency in Reston, VA, Oct. 28-30.

The Responsible AI in Defense Forum provided an opportunity to discuss technical capabilities and challenges with diverse stakeholders and to examine RAI in the context of international military cooperation.

“Over the last dozen years, as advances in machine learning yielded new breakthroughs, we’ve worked hard at the Pentagon to be a global leader in establishing responsible policies for military use of autonomous systems and AI,” said Deputy Secretary of Defense Kathleen Hicks during a keynote address delivered via video. “From the beginning, DoD’s approach to responsible AI has been guided by our understanding that AI will only be used and effective where it is trusted and trustworthy. Today we’re at the forefront of accelerating the adoption of trusted AI, and we can’t afford to fall behind.”

The multiple-day Forum was designed to explore a different topic each day, with participation aligned to the topic. On day one, CDAO led a meeting among the Partnership for Defense’s (PfD) 16 members to examine strategies and tools for enabling RAI across defense enterprises. On day two, CDAO convened government, industry, and academic experts for a series of discussions on operationalizing RAI in defense. Finally, day three featured a closed-door meeting focused on aligning NATO allies and partners with RAI implementation strategies. Each day of the Forum helped advance the CDAO’s critically important work around the responsible implementation of AI in defense.

CDAO Dr. Radha Plumb kicked off the Forum with the AI Partnership for Defense.

“The RAI in Defense Forum — and first-ever in-person PfD on Responsible AI — provided an unprecedented opportunity for the Department to connect its practical Responsible AI tools and guidance with critical partners to build leadership on global Responsible AI standards and practices,” stated Plumb.

The CDAO is pleased to have hosted this pivotal gathering, having achieved its key objectives of strengthening CDAO’s relationships with PfD partners, sharing RAI implementation lessons learned, and promoting RAI globally. As a result of this effort, the CDAO looks forward to accelerated progress in RAI, both at home and abroad.

About the CDAO

The CDAO became operational in June 2022 and is dedicated to integrating and optimizing AI capabilities across the DoD. The office is responsible for accelerating the DoD’s adoption of data, analytics, and AI, enabling the Department’s digital infrastructure and policy adoption to deliver scalable AI-driven solutions for enterprise and joint use cases, safeguarding the nation against current and emerging threats.

For more information about the CDAO, please visit our website at ai.mil. You can also connect with the CDAO on LinkedIn (@ DoD Chief Digital and Artificial Intelligence Office) and X, formally known as Twitter (@dodcdao). Additional updates and news can be found on the CDAO Unit Page on DVIDS. (Source: U.S. DoD)

 

31 Oct 24. Elbit Systems Ltd. has launched its next-generation soldier radio, the E-LynX™ SR, at the International Dismounted Soldier Conference in London. This new multi-channel radio is the latest addition to Elbit Systems’ renowned and market-leading E-Lynx lineup of Mobile Tactical SDR Solutions.

E-LynX™ SR Elevates Combat Connectivity:

The product is designed based on extensive field experience and accumulated knowledge. It is meticulously engineered to meet the needs of the soldier while supporting the broader forces that communicate and process transmitted data.

The E-LynX™ SR is a scalable, lightweight, and user-friendly tactical communication device, designed with the soldier in mind. It is the most advanced model ever produced by Elbit in the Soldiers Radio category. This device delivers enhanced connectivity and advanced networking capabilities by using multi channels technology. With broad frequency compatibility and multi-channel functionality, the E-LynX™ SR is interoperable with existing E-LynX™ systems and recognizes equivalent networks, optimizing operational efficiency across all battlefield levels—from individual soldiers to entire units. E-LynX SR can operate in wide spectrum range with different bandwidth, enabling full supports of Manned-Unmanned Teaming (MUM-T) devices such as robotics and autonomous platforms, further enhancing the force’s capabilities and effectiveness in modern combat environments.

Its compact, wearable design ensures comfort and accessibility, easily integrating into a soldier’s vest or harness for maximum portability and ease of use. Equipped with a headset, the body-worn device enables continuous communication, allowing voice, data, and video transmission with minimal handling. Equipped with advanced resilience and spectrum-sensing features, the E-LynX™ SR enables uninterrupted communication by neutralizing jamming threats, optimizing the use of available frequencies, and reducing interference, all without interrupting user operations. The system also supports connectivity to cellular networks (4G/5G) and satellite communication, providing flexible backhaul solutions and increased bandwidth as needed.

By providing real-time situational awareness, quicker decision-making, and improved safety, the E-LynX™ SR elevates the capabilities of tactical communications. This cutting-edge device equips soldiers with relevant tools needed to respond swiftly and effectively in dynamic combat environments, enhancing mission success and safeguarding lives.

 

30 Oct 24. 5G COMPAD showcases several 5G network deployment scenarios in a Global Demonstration in Latvia. On October 17, 2024, in Riga, Latvia, the European Defence Fund project 5G COMPAD (5G Communications for Peacekeeping and Defence) held its first global demonstration, showcasing various 5G network deployment scenarios at sea, in the air, and on land. The demonstration was organized by 5G COMPAD consortium member LMT and took place at the military base “Daugavgrīva.” During the demonstration, several innovative 5G network deployment options were presented. These included potential network coverage simulations, 5G drone tests, satellite communication integration, and other 5G applications on ships at sea. The 5G COMPAD demonstration in Latvia’s 5G testing environment allowed for the evaluation of 5G performance under various conditions and the exploration of new potential use cases. The global demonstration was attended by 5G COMPAD project partners, stakeholders, and representatives from the Ministries of Defense of European Union member states participating in the implementation of the consortium project. Several project partners took part in the organization process alongside LMT, including Ericsson, Leonardo, Thales, Nokia, Bittium, Cafa Tech, Inster, CNIT, Eight Bells, Space Hellas SA and Intracom Defense (IDE). Before the project’s demonstration, from October 14 to 16, preparation works were held in Latvia with the participation of the organizing team. The 5G COMPAD project was kicked off in December 2022 and will run for 36 months. The project consortium partners are Saab, Ericsson, Rheinmetall, Bittium, Nokia, Thales, Leonardo, Inster, Eight Bells, Intracom Defense (IDE), Cafa Tech, Telenor, Sintef, FFI (NO Gov), LMT, AIT, Synkzone, BHE, and APR Technologies, while the Sub-Contractors are CNIT, Fraunhofer FKIE, CEA and Space Hellas SA. Within the 5G COMPAD project, world-leading partners from the telecom and the European defence industries join forces to enable recurrent integration of 5G and beyond into multi-dimensional robust defence communication systems to sustain effective and efficient information superiority for European armed forces.

Project: 101103519 — 5G COMPAD — EDF-2021-C4ISR-D-2

 

30 Oct 24. Global: Highly sophisticated spyware variant will raise security risks for iOS users. On 29 October, the security company ThreatFabric reported on the discovery of a new, more sophisticated version of the ‘LightSpy’ spyware. This new version specifically targets Apple iOS devices and contains 28 plugins to compromise device functionality and security. Threat actors typically exploit software vulnerabilities to gain access to targeted systems, subsequently using jailbreaking techniques to bypass security mechanisms. This enables them to access core system functions and data to deploy malicious payloads (including LightSpy). LightSpy’s plugins can track users’ locations, collect sensitive information (such as payment data) and prevent a device from rebooting to ensure long-term persistence, underscoring this malware’s highly sophisticated and multifunctional nature. Notably, the spyware’s command and control (C2) infrastructure showed infected devices connecting to a suspected test Wi-Fi network, suggesting that this spyware variant may still be in its development phase. As such, we assess that this operation will raise security risks for iOS users in the medium term. (Source: Sibylline)

 

29 Oct 24. BAE Systems, Aerospike to Advance Real-Time Data Capabilities for US DoD. California-based Aerospike has joined BAE Systems’ Mission Advantage technology partnership to enhance operational efficiency and decision-making capabilities for the US Army and other defense programs.

Together with BAE, Aerospike will advance data mesh solutions using its real-time database to support the Army’s Unified Network, Army Data Platform, and other data-centric mission requirements.

Data mesh is a decentralized data management approach that allows various defense units and networks to control their data while ensuring secure and efficient access across the organization.

This strategy addresses the challenges of information distribution across the Department of Defense’s extensive network, including data surges that can overwhelm systems and personnel, latency (the delay between data request and response), and geographic challenges, particularly for military units in remote or hostile locations.

The partnership will “deliver real-time, mission-critical data at scale and help ensure technological advantage on the battlefield,” according to BAE Systems’ Director of Strategy & Technology Partnerships for the Intelligence & Security sector Daniel Perkins.

“Aerospike is foundational to our data-centric solutions for the US Army and DoD, as our customers push towards managing massive amounts of disparate data while leveraging advanced AI tools,” he added.

Aerospike Public Sector Vice President Cuong Nguyen described their multi-model database as offering “the lowest-latency, highest-throughput system to enable accurate, real-time decisioning even in contested environments.”

“As a vital component of the UNO technology stack, we’re proud to partner with BAE Systems to help them optimize and demonstrate the effectiveness of their data solutions,” Nguyen stated. (Source: News Now/https://thedefensepost.com/)

 

24 Oct 24. ASELSAN unveils ANTIDOT 2-U series of electronic warfare pods at SAHA EXPO 2024. ASELSAN, Türkiye’s leading defence company, has launched its latest cutting-edge electronic warfare pods at SAHA EXPO 2024. The newly revealed pods, named ANTIDOT 2-U LB/MB/HB, ANTIDOT 2-U, and ANTIDOT 2-U/S, are designed to enhance UAVs’ capabilities, transforming them into advanced electronic warfare platforms.

These systems, developed by ASELSAN’s experts, provide UAVs with advanced threat detection, classification, and jamming capabilities, offering protection to both the UAV and nearby friendly air assets. This significant development was unveiled in the presence of key officials, including Prof. Dr. Haluk Görgün, Secretary of Defence Industries, and Ahmet Akyol, ASELSAN President & CEO.

The ANTIDOT 2-U series represents a major leap in electronic warfare technology, enabling UAVs to counter air defence systems while supporting critical missions. The lightweight and versatile systems integrate seamlessly into tactical-class UAVs, providing mission flexibility without compromising on performance.

The electronic warfare pods are fully autonomous, featuring high output power, wide frequency coverage, and the ability to suppress and deceive enemy radars. With their compact design and advanced functionality, these systems significantly enhance the survivability and operational effectiveness of UAVs in contested environments. (Source: Defense Arabia)

 

29 Oct 24. Hicks Highlights DOD’s Commitment to Responsible AI Use. Deputy Defense Secretary Kathleen Hicks today spoke about the Defense Department’s commitment to being a world leader in forging sound ethical policies for military use of artificial intelligence.

Hicks’ remarks were broadcast remotely at the Responsible Artificial Intelligence in Defense Forum in Washington.

“Over the last dozen years, as advances in machine learning yielded new breakthroughs, we’ve worked hard at the Pentagon to be a global leader in establishing responsible policies for military use of autonomous systems and AI,” Hicks said.

She then pointed out DOD has lately doubled down on that commitment, and that the Pentagon’s leadership has been able to get in front of implementing an executive order that President Joe Biden issued almost one year ago to the day on safe, secure and trustworthy AI.

“As a result, our AI is more resilient and effective than ever,” Hicks said.

Hicks also pointed out that, since 2021, DOD has not only accelerated the drive toward a more data-driven, modernized and AI-empowered U.S. military; but it has also affirmed an adherence to ethical AI principles, updated DOD responsible-use policies and directives, and issued new strategies, guidelines, guardrails and practical toolkits and apps.

“We’re glad those resources are now used by many outside DOD; like other U.S. agencies, international allies and partners, and leading tech companies,” Hicks said.

She then announced that almost 60 nations — including the U.S. — currently endorse the Political Declaration on Responsible Military Use of Artificial Intelligence and Autonomy.

That document, launched in February 2023 at the Responsible AI in the Military Domain Summit in the Hague, “aims to build international consensus around responsible behavior and guide states’ development, deployment and use of military AI,” according to the declaration’s website.

“I can’t overstate the importance of this work,” Hicks said. “Because our values not only bring us together; they set us apart from our strategic competitors.”

Pointing out that DOD has always been guided by an understanding that AI can only be useful and effective where it is both trusted and trustworthy, Hicks cautioned that the Defense Department can’t fall behind in the adoption of quality AI.

Hicks then appealed to those attending the forum, saying that they are needed to help keep DOD in the lead with AI.

“Not just with speed and security, but also safety,” she said.

“Not just rapidly, but also responsibly,” she continued. “We don’t have the luxury of choosing one side or the other. It has to be both.”  (Source: U.S. DoD)

 

28 Oct 24. Global: Software vulnerabilities sustain information-theft, financial risks from ransomware groups. On 27 October, international news outlets reported that the ransomware groups ‘Fog’ and ‘Akira’ have exploited a software vulnerability (CVE-2024-40766) to breach at least 30 organisations since August. The vulnerability affects SonicWall virtual private network (VPN) devices and reportedly enables actors to bypass security mechanisms and access sensitive files. Fog and Akira likely used stolen credentials to hijack user accounts and infiltrate targeted organisations. The actors then likely exfiltrated sensitive files, deploying ransomware to encrypt the organisations’ data for financial profit. Notably, though SonicWall patched CVE-2024-40766 in August, all the affected organisations did not apply the patch and lacked other security mechanisms to prevent infiltration. This underscores the importance of secure patch management policies and the implementation of other security measures, including multi-factor authentication (MFA), to prevent future compromises. We assess that additional infections will likely emerge in the short term, raising information-theft and financial risks to vulnerable organisations. (Source: Sibylline)

 

28 Oct 24. Defense Department Tests AI Software, Advances to Improve Physical Security Posture. Hours before dawn, under the veil of a new moon, two figures in military fatigues grapple like Greco-Roman wrestlers within the razor wire perimeter of the Blue Grass Army Depot in Richmond, Kentucky.

Their movements are rigid but discreet, each maneuvering for leverage beneath the orange glow of the floodlights lining the depot’s security fence.

In the distance, a patrolling sentry squints, straining to make sense of the dimly lit commotion. He thumbs the two-way radio on his pistol belt but hesitates, worried he may frustrate his supervisor with an inaccurate report.

But before the fight can go to ground — and before the sentry can reassess and request support — a bright red reticle highlights the entwined bodies on a control room monitor several miles away. Scylla, the artificial intelligence algorithm powering the depot’s security architecture, has made sense of what the sentry cannot.

Scylla knows instantly that the image captured by the depot’s security cameras depicts a struggle. In seconds, the algorithm references a database of friendly and malicious faces, identifies the belligerents and fires a report to the watch captain: “An on-duty military police officer is trying to subdue an intruder — a known bad actor with presumed hostile intent.”

This fictional scenario described by Drew Walter, deputy assistant secretary of defense for nuclear matters, illustrates AI’s demonstrated capabilities and underscores its potential in the realm of physical security. Last month, the Defense Department tested Scylla at the Depot. Walter described the platform as a “considerable advancement in our ability to safeguard critical assets.”

“Its capacity to learn in real time and reduce nuisance alarms — which fatigue security personnel and inhibit responses to legitimate threats — addresses a long-standing challenge in physical security,” he said.

DOD is looking at AI’s ability to enhance existing surveillance capabilities and threat detection, aligning with the department’s broader strategy to integrate data, analytics and AI across its operations.

The Physical Security Enterprise and Analysis Group, which is testing Scylla, plays a pivotal role in the department’s mission to safeguard America’s strategic nuclear capabilities. “PSEAG does physical security well and has taken the reins in both the strategic and conventional realms,” Walter said. “By unifying disparate efforts under one umbrella, we can procure and field capabilities that meet Defense Department nuclear security requirements.”

PSEAG’s interest in AI is nested in the department’s strategic priorities. Last year, in a speech on “The state of artificial intelligence AI in the Department of Defense,” Deputy Defense Secretary Kathleen Hicks emphasized the importance of integrating AI swiftly and responsibly.

“As we’ve focused on integrating AI into our operations responsibly and at speed, our main reason for doing so has been straightforward: because it improves our decision advantage,” Hicks said. “From the standpoint of deterring and defending against aggression, AI-enabled systems can help accelerate the speed of commanders’ decisions and improve the quality and accuracy of those decisions.”

Chris Willoughby, electronic security systems manager at the Depot and project lead for Scylla, is working to give life to Hicks’ vision. “PSEAG is testing, evaluating and training Scylla’s artificial intelligence deep neural machine learning software to detect and classify persons’ features, behavior anomalies, armed and unarmed threats and objects by evaluating video surveillance systems in real time,” he said.

The demonstration at the Depot showcased Scylla’s ability to detect intruders, weapons and abnormal behavior using existing video surveillance systems and drones. In one instance, the software identified an armed individual climbing a water tower a mile away. “Scylla test and evaluation has demonstrated a probability of detection above 96% accuracy standards, significantly lowering … false alarm rates due to environmental phenomena,” Willoughby said.

Walter echoed Willoughby’s enthusiasm, lauding Scylla’s unique — and cost-effective — application to existing physical security architecture. “Scylla AI leverages any suitable video feed available to monitor, learn and alert in an instant, lessening the operational burden on security personnel,” he said. “While humans still make the final decisions regarding threat response, AI augments detection capabilities.”

Walter said Scylla’s most vital application could lie in improving the physical security of DOD’s strategic nuclear arsenal. “Scylla’s transformative potential lies in its support to PSEAG’s core mission, which is to safeguard America’s strategic nuclear capabilities when they are in the department’s care,” he said. “The ability to detect and respond to threats swiftly is paramount when dealing with assets critical to deterrence — be they Trident missile submarines, intercontinental ballistic missiles or strategic bombers.”

Beyond the Depot, the department is exploring Scylla’s potential in cold weather and maritime environments. In the coming months, Joint Base Charleston, South Carolina, will host Navy and Marine Corps-led assessments, ensuring that the algorithm meets their service-specific demands.

PSEAG officials said they are especially interested in testing AI’s ability to mitigate an emerging threat: unmanned systems capable of transcending domains by emerging from the sea to operate on land or in the air.

Though it faces challenges in the form of novel threats, conditions and environments, Walter and Hicks said AI is essential to maintaining the United States’ competitive technological edge.

The deputy secretary said the department has worked for more than a decade to be a global leader in the development and use of AI technologies. “By putting our values first and playing to our strengths — the greatest of which is our people — we’ve taken a responsible approach to that will ensure America continues to come out ahead.”

PSEAG’s investment in AI is born from the 2022 National Defense Strategy’s commitment to “driving commercialization … in emerging technologies,” like “artificial intelligence and autonomy,” and the algorithm’s noteworthy performance in Richmond, Kentucky, marks a fundamental milestone on the department’s path toward improved physical security and comprehensive AI adoption.

“By embracing advanced technologies, like Scylla, we are not just enhancing our current security measures,” Walter said, “we are setting the foundation for future innovations that will keep our nation safe.” (Source: U.S. DoD)

 

25 Oct 24. New operation points to increased financial risks from North Korean state-sponsored groups. On 23 October, the cyber security company Kaspersky reported that the North Korean state-sponsored group ‘Lazarus’ exploited a zero-day vulnerability (CVE-2024-4947) in order to target crypto currency users in May. Lazarus reportedly used several social media profiles to trick unknowing users into visiting an actor-controlled fraudulent domain to download a new video game. Notably, the group spent months building its online presence and hired influencers to promote the game, underscoring the sophisticated planning behind (and long-term nature of) this particular campaign. The group then exploited CVE-2024-4947 and an additional vulnerability in the Google Chrome browser so as to obtain full control over victims’ systems and to evade security mechanisms, further underscoring the high sophistication of this campaign. Lazarus likely deployed information-stealing and crypto mining tools onto compromised systems for financial gain. As such, this operation has re-emphasised the heightened financial risks facing global entities, especially as Lazarus expands its victim pool to include both users and organisations. (Source: Sibylline)

 

25 Oct 24.  Cyber Update Key points

  • The North Korean state-sponsored group ‘APT37’ exploited a zero-day vulnerability to target users in South Korea, elevating security and supply chain risks (see Sibylline Cyber Daily Analytical Update – 21 October 2024).
  • The resurgence of the ‘Bumblebee’ malware in new financially motivated operations will increase security risks stemming from cyber criminals (see Sibylline Cyber Daily Analytical Update – 22 October 2024 and our Technical analysis below).
  • An uptick in cloud-based cyber attacks points to heightened security and financial risks for organisations.
  • The adoption of new malware in a long-term malware operation will raise information theft and financial risks from the cyber threat group ‘TA866’
  • New financially motivated operation heightens financial risks to crypto currency users stemming from the North Korean state-sponsored group ‘Lazarus.’

Technical analysis of weekly stories

The Bumblebee malware loader has reportedly resurfaced using a new infection chain; this follows its takedown by European law enforcement in May. The infection starts with phishing emails tricking potential victims into downloading a malicious .ZIP file. This then executes the main Bumblebee payload by fetching a legitimate-looking Windows Software Installer (MSI) file. Bumblebee is stored directly into a system’s memory to avoid the creation of new files, thus evading early detection by security mechanisms. Additionally, the campaign boasts several other new anti-detection techniques including the use of legitimate installer names to conceal malicious files. These techniques underscore the sophistication and continuous development of this malware. Bumblebee is likely being used to deploy additional malware on compromised systems, including information stealers and banking trojans since it has previously been used to facilitate ransomware operations.

The cyber threat group TA866 has used the backdoor malware ‘WarmCookie’ in a long-term cyber campaign since at least 2023. The campaign has targeted multiple sectors including manufacturing, government and financial institutions across Europe and North America for financial profit and cyber espionage. TA866 typically uses malicious advertisements (malvertising) or phishing emails to gain access to targeted systems, subsequently installing first-stage JavaScript loaders to achieve persistence. This then enables the group to download a second-stage loader (‘WasabiSeed’) to deploy additional malware from the actors’ command-and-control (C2) infrastructure while remaining obfuscated. The group often uses several malware variants including ‘Screenshotter’ to capture screenshots, ‘Looper’ and ‘AHK Bot’ to collect keystrokes and credentials, the popular remote access tool ‘Cobalt Strike’ and the information-stealer ‘Rhadamanthys’. Additionally, TA866 has adopted WarmCookie since 2023 to maintain long-term access to compromised systems, deploy additional payloads, manipulate files and remotely execute code, demonstrating the group’s adaptability and development.

Some non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity.
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network.
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
  • Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices, including personal devices connected to corporate networks or applications.
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.

Our cyber word(s) of the week: Malvertising

(Source: Sibylline)

————————————————————————————————————————————————————————————————————————————————————————————————————————————–

Spectra Group (UK) Ltd

Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.

Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.

With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.

Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.

In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.

Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.

Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.

—————————————————————————————————————————————————————————————————————————————————————————————————————————————

 

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT