Sponsored by Spectra Group
—————————————————————————————————————————————————————————————————————————————————————————————————————————————–
23 Dec 24. Global: Espionage campaign by North Korean group points to risks facing nuclear, aerospace sectors. On 19 December, the cyber security firm Kaspersky reported that a North Korean state-sponsored group, ‘Lazarus’, targeted at least two employees at the same nuclear-related entity in a cyber espionage operation. The operation was highly likely part of a wider cyber espionage campaign (‘Operation Dream Job’) that has been ongoing since at least 2020. The threat actors deliver trojanised virtual network computing (VNC) software under the guise of a skills assessment for IT roles. Notably, the group was observed using the modular malware ‘CookiePlus’ to download additional malware on compromised systems, which is an uncommon strategy for Lazarus. We assess this highlights the group’s sustained efforts to improve its arsenal and detection-evasion capabilities. We also assess there are elevated targeting and security risks facing employees in the nuclear and aerospace sectors in the long term due to the longevity of Operation Dream Job and CookiePlus’ likely ongoing development. (Source: Sibylline)
16 Dec 24. Invited by NATO’s Allied Command Transformation (ACT), Indra demonstrated the concept and capabilities of a new last generation Cyber Situational Awareness System in one of the world’s largest collective cyberdefence exercises, CYBER COALITION 2024, held in Estonia from December 2 to 6. The platform (called CySAS, Cyber Situational Awareness System) provides a real-time view of operations being conducted in and through cyberspace by both allies and adversaries. The system analyses events occurring in Cyberspace and evaluates their impact on the mission’s course of action to assure its success. That means it offers a global vision of enormous value, helping to make the best decisions and react more quickly to any situation affecting an ongoing operation. Indra led the deployment of this concept and capability in the exercise, with the participation of Airbus (France) and Leonardo (Italy) as strategic subcontractors. The test and experimentation campaign, led by ACT, benefited from the collaboration of the Allied Command Operations (ACO), the Spanish Joint Cyberspace Command (MCCE) and the Allied Joint Force Command Naples (JFCNP). The feedback from the NATO community and other stakeholders during the CYBER COALITION 24 demonstration was extremely positive and the lessons learned will be used to further fine tune the concept, with the ultimate goal of securing the most advanced capabilities for the Alliance. Indra’s leadership in this initiative underscores the company’s confidence in driving NATO’s Digital Transformation and Cyberspace Operations Strategy. The conceptualisation of this capability facilitates NATO’s readiness to conduct multi-domain operations, where cyber defence is critical, given the presence of the Cyberspace domain in all other Defence domains. The conceptualisation of this capability facilitates NATO’s readiness to conduct operations in both the cyberspace domain and in multi-domain scenarios, where cyber defence is present and decisive. In addition to Indra’s role in the project, it is also the coordinator of the EU’s ECYSAP (European Cyber Situational Awareness Platform) project, one of the first and most important cyber defence initiatives fostered by the EU. This European project will now continue with ECYSAP EYE, where Indra will coordinate the development of even more advanced capabilities, which will, in turn, strengthen the capabilities of the European Union’s Command and Control System currently under development. All these projects contribute to strengthening Europe and NATO’s technological sovereignty and strategic autonomy, demonstrating Indra’s ability to bring together and coordinate consortia that drive the development of cutting-edge technologies and deliver new capabilities. It all means further progress towards achieving the objectives set out in Indra’s strategic plan, Leading the Future, of becoming a benchmark company in the sector that acts as a driving force in the industry. (Source: joint-forces.com
20 Dec 24. Cyber Update Key points.
- A new backdoor is being used to target firms in China and the US, elevating security and information theft risks from the Chinese state-sponsored group, ‘Winnti’ (see Sibylline Cyber Daily Analytical Update – 16 December 2024).
- The Russian state-sponsored actor ‘Earth Koshchei’ co-opted legitimate red team techniques to target government and military entities, pointing to increased security risks to the sectors (see Sibylline Cyber Daily Analytical Update – 17 December 2024 and our Technical analysis below).
- South Asian threat group ‘Bitter’ is targeting Turkish defence entities, heightening cyber espionage risks in the medium term (see Sibylline Cyber Daily Analytical Update – 18 December 2024 and our Technical analysis below).
- A new phishing operation to steal Microsoft Azure credentials has been targeting European entities, increasing the security and phishing risks to firms.
- New malware attacks against industrial control systems (ICS) highlight ongoing security risks facing operational technology (see Sibylline Cyber Daily Analytical Update – 20 December 2024).
Technical analysis of weekly stories
In October, the Russian state-sponsored group Earth Koshchei (also known as ‘APT29’) was observed abusing legitimate red team techniques in a cyber espionage campaign. It is suspected that the group used a rogue remote desktop protocol (RDP) attack methodology, dubbed ‘rogue RDP’, to obtain partial control over targeted devices. The attacks begin via spear phishing emails sent to academic researchers, government and military forces, think tanks and Ukrainian targets. The email contained a rogue RDP configuration file that, if opened, instructed targeted devices to connect to a foreign RDP server via one of the almost 200 RDP relays established by Earth Koshchei during their pre-planning phase. The rogue RDP technique uses a man-in-the-middle (MITM) proxy in front of the rogue RDP servers to intercept connection requests to a legitimate server and subsequently redirects the user to the rogue server. Upon establishing the malicious connection, the rogue server conducts various malicious activities including deploying malicious scripts and altering system settings on the infected device. This grants partial control, facilitating the exfiltration of strategic data. During the pre-planning phase, Earth Koshchei set up over 200 typosquatted domains for the malicious RDP connections highlighting the highly premeditated nature of the campaign. The use of red team techniques and tools in malicious operations is not uncommon. However, it underscores the security risks to businesses associated with publicising red team tools and techniques.
The South Asian threat group Bitter targeted defence organisations in Turkey in a spear phishing campaign during November for cyber espionage purposes. The phishing emails used by the campaign contained a compressed archive (RAR) file pertaining to banking and public infrastructure initiatives in Madagascar. If opened, a payload was executed to install the ‘WmRAT’ malware. If there was no successful communication from WmRAT, additional commands were run to download and install the ‘MiyaRAT’ malware. WmRAT is a standard remote access trojan (RAT) that gathers basic system information, downloads files and runs arbitrary commands on a targeted system. MiyaRAT is similar in functionality to WmRAT; however, MiyaRAT is used against specified high-value targets, as it is only used sporadically. This highlights the likelihood of future development of this malware and its increased usage against more strategic targets.
Some non-exhaustive recommendations to mitigate against these threats include:
- Monitor devices and networks for suspicious activity
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security-detection systems to detect potentially malicious samples on the network
- Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
- Ensure adequate security monitoring and detection capabilities, particularly for all external-facing services and devices; this includes personal devices connected to corporate networks or applications
- Adopt and review network authentication services, including virtual private network (VPN) services and multi-factor authentication (MFA)
- Avoid downloading applications from untrusted third-party websites or via unsolicited messages and only use official websites and application stores to install applications and tools on devices. (Source: Sibylline)
20 Dec 24. Global: New malware operations highlight ongoing security risks facing OT, ICS systems. On 17 December, the cyber security firm Forescout reported on new malware attacks against industrial control systems (ICS) that are capable of halting engineering processes. The research identified two attacks targeting Mitsubishi and Siemens engineering workstations between August and November. The first attack chain used ‘Ramnit’ against Mitsubishi workstations, a modular malware used to download additional plugins to steal data and establish prolonged persistence. Similarly, a new malware cluster (‘Chaya_003’) targeted Siemens workstations to conduct system reconnaissance and disrupt operations. Both attacks highlight an evolution in operational technology (OT)-specific cyber operations, in which existing malware is tailored to infect (and propagate within) ICS systems. Notably, the attacks used legitimate services for command-and-control (C2) to complicate threat detection, underscoring the sophistication of the campaigns. OT systems are increasingly attractive targets for various threat actors, especially in the absence of comprehensive security measures surrounding ICS and OT systems. As such, we assess that long-term elevated security risks will continue to face OT and ICS systems. (Source: Sibylline)
18 Dec 24. US Army extends Palantir’s contract for its data-harnessing platform. The U.S. Army has awarded Palantir a $400.7 m contract to continue providing its artificial intelligence-enabled Vantage system as the service’s main data platform, the company announced Wednesday. The contract covers a period of up to four years and could ultimately be worth nearly $620 m if additional options are exercised. The service first brought Palantir on to provide its Army Data Platform, or ADP, in 2018, taking roughly 180 disparate data sources across the enterprise and consolidating them into one ecosystem.
“The Army has leveraged Palantir’s software to transform how it uses data and artificial intelligence (AI) to more effectively perform essential missions and enable faster decision-making across the force,” the Dec. 18 company statement reads.
The capability grew from a focus on a data platform that could help understand personnel and combat readiness to a system that “powers warfighters at every echelon and supports a diverse set of use cases across every data domain including readiness, logistics, recruiting, force management, talent management, financial management, risk management and installation management,” according to the statement.
The Army plans to continue to grow the capability.
“Our continuous addition of new AI capabilities enables the Army’s own ability to develop applications and incorporate the benefits of effective data analysis across nearly every high-priority mission in the Army,” Akash Jain, Palantir USG president, said in the statement.
As emerging technologies are developed, they will be introduced into Vantage on a continuous basis, according to the company.
Vantage now has over 100,000 users within the service and that number is growing, Palantir said.
Palantir’s business with the Defense Department and particularly with the Army has grown dramatically since 2018 when it won, in a head-to-head competition with Raytheon, a contract to provide the Army a new tactical version of its Distributed Common Ground System-Army, or DCGS-A, an intelligence analysis platform.
The company famously sued the Army over its DCGS-A procurement strategy in 2016 — and won — prior to scoring the new contract for the system. Since then, the Army has taken different approaches in how it procures software capabilities and is developing a software acquisition policy that outlines how to best work with the software industry to obtain the right capability for the service at a much faster pace. (Source: Defense News Early Bird/Defense News)
19 Dec 24. UK and Norway join forces to counter eavesdropping. The UK and Norwegian governments are to share best practice and new technologies to detect and expose eavesdropping devices. The UK and Norwegian governments have announced an agreement to work more closely together on research and development of technical security. The agreement, between the UK National Authority for Counter-Eavesdropping (UK NACE) and the Norwegian National Security Authority (NSM), extends an already mature partnership which has seen the 2 authorities share national security information and best practice. Technical security includes the identification of covert devices used to transmit data, which can either be used to eavesdrop or to launch other types of attack, including cyber-attacks. UK NACE is part of the Foreign, Commonwealth and Development Office (FCDO) and is the UK’s dedicated National Technical Authority (NTA) for technical security. It provides guidance and training across government and national security communities in the UK and with international partners.
Stephen Doughty, Minister for Europe, North America and UK Overseas Territories said: “UK security is indivisible from European security – and we are stronger when we stand together. Norway is one of our closest defence and security partners, and I welcome this agreement, which will further strengthen our collective resilience against threats from hostile states as part of our new Strategic Partnership. The new agreement with the NSM builds on existing work between the UK and Norway, both members of the Joint Expeditionary Force group of nations. The agreement will see the 2 nations share resources, expertise and information to achieve mutual goals, and combine strengths for innovation and development.”
UK NACE is already partnered with leading UK universities on the development of technical security research and development, including developing new search equipment technology.
With its roots dating back to 1945, UK NACE was established as the lead government organisation in the field of technical security across the UK government after it became apparent that British embassies located in the newly-formed communist Eastern Europe were at risk from the threat of technical espionage attack. With eavesdropping and surveillance technology reaching new heights in its accessibility, capability and concealment, UK NACE is committed to collaboratively work on tackling modern technical threats with partners across government and friendly foreign governments. Its focus on research and innovation has helped it to enable effective risk mitigation strategies and has earned recognition and respect across the global national security community. (Source: https://www.gov.uk/)
18 Dec 24. In an important milestone for Northrop Grumman Corporation’s (NYSE: NOC) developed Integrated Battle Command System (IBCS), Poland’s Ministry of National Defense declared Initial Operational Capability (IOC) for the first IBCS-enabled battery of Poland’s WISŁA medium range air defense program.
- With the deployment of IBCS, a U.S. Army program of record, Poland will now field one of largest, most capable air and missile defense forces in the world, with the ability to integrate air and missile defense across U.S. and Polish forces during combined operations.
- A second battery is expected to achieve IOC by the end of this year.
- In February, the United States and Polish governments signed a letter of offer and acceptance for IBCS to also serve as the core battle management command and control system for Poland’s NAREW short range air defense program in addition to phase two of the WISŁA medium range air defense program.
Kenn Todorov, vice president and general manager, global battle management and readiness, Northrop Grumman: “Poland’s declaration of initial operational capability for IBCS proves the system’s readiness and groundbreaking capability to help warfighters defeat the complex threats of today and tomorrow. IBCS is seeing an increased demand from allies and partner nations worldwide looking to modernize their air and missile defense systems in our contested environment.”
Details on IBCS and the WISŁA and NAREW Programs:
In 2018, the Polish government selected IBCS to serve as the centerpiece for its WISŁA medium range air defense modernization program, becoming the first U.S. ally to acquire the system. Poland declared Basic Operational Capability last year.
Prior to the LOA signed in February, Northrop Grumman and Poland’s Ministry of National Defense signed an offset agreement enhancing Polish defense capabilities through Northrop Grumman technology transfers that will help Polish industry to manufacture, integrate and test IBCS’ critical defense technologies.
The offset agreements will support Polish industry and their sovereign production and maintenance capabilities for NAREW and WISŁA by creating high-technology jobs for Poland in several fields, including engineering, manufacturing, supply chain and logistics and maintenance support. Poland is working with the U.S. government for deliveries of IBCS equipment racks and software to be installed in operations centers designed, manufactured and delivered in partnership with Polish industry. This delivery approach is tailorable and allows for significant industrial participation and adaptation to meet Poland’s unique air defense needs.
IBCS is a revolutionary command and control system that unifies current and future systems regardless of source, service or domain. Through its network enabled, modular, open and scalable architecture, IBCS gives warfighters capabilities they never had before by fusing sensor data for a single actionable picture of the full battlespace. This ready now capability gives warfighters more time to make decisions on how best to defeat threats and is a foundational element for enabling joint and coalition, multi-domain operations. IBCS is in production, being fielded in Poland, and planned for deployment in Defense of Guam as part of the U.S. Army program of record for integrated air and missile defense modernization.
Northrop Grumman is a leading global aerospace and defense technology company. Our pioneering solutions equip our customers with the capabilities they need to connect and protect the world, and push the boundaries of human exploration across the universe. Driven by a shared purpose to solve our customers’ toughest problems, our employees define possible every day.
16 Dec 24. Partnership to Provide Portable Defense Communications Elsight and tukom’s partnership will bring a proven, portable wireless communication system to the DACH region, optimized for UAVs, UGVs, and for its non-line-of-sight capabilities. Elsight and tukom have formed a partnership to bring battlefield-proven, portable wireless communications to the DACH region, optimized for unmanned aerial vehicles (UAVs) and unmanned ground vehicles (UGVs). Located and active in the DACH region, tukom is dedicated to delivering best-in-class solutions and consulting services in the fields of telemetry, aerospace, and defense. Elsight has designed and developed a lightweight, highly reliable communications system known as Halo. After several successful years in the commercial market, Halo has been optimized for its non-line-of-sight (NLOS) capabilities. By aggregating multiple IP links from public and private cellular, satellite, and RF channels, the Halo provides securely bonded, uninterrupted C2, telemetry and video communications even in the most challenging environments. tukom offers expert sales, service, training, and consulting for the leading military-grade platforms across various industries including aerospace, defense, and telecommunications. tukom’s range of applications extend over the whole telemetry process, from data acquisition, the transfer and storage of telemetry data, data processing and analysis.
tukom CEO, Matthias Brechmann said, “Today’s CONOPS require a new set of capabilities to maintain communications throughout volatile terrains while being portable for all types of field operations. We view this partnership with Elsight as strategic in providing our customers with innovative connectivity given the changing military landscape.”
Yoav Amitai, CEO of Elsight, commented, “Given tukom’s knowledge base and experience in military-grade telemetry communications, they are the perfect partner to spearhead the penetration of the DACH market for our Halo and other connectivity products.
“Elsight excels in the development of highly reliable, secure wireless communication systems that fulfill many extreme requirements for performance, reliability and the surrounding environment. We are excited to work with tukom, helping them to expand their footprint in the region.” (Source: https://www.defenseadvancement.com/)
19 Dec 24. New Tactical Radio Test Set Unveiled for Military Communications Systems. Astronics has launched the ATS-3200 RTS, an advanced tactical radio testing solution that allows users to optimize both legacy and next-generation communication platforms with a single, versatile tool. Astronics Corporation is launching the ATS-3200 Radio Test Set (RTS), a next-generation tactical radio testing solution engineered for military communication systems. The benchtop solution builds on the company’s ATS-3000 and ATS-3100 series, and incorporates the same advanced technology selected by the U.S. Army in the competitively awarded TS-4549/T program. The ATS-3200 RTS is now available commercially, empowering users to optimize both legacy and next-generation communication platforms with a single, versatile tool. Designed with expandability and customization in mind, the ATS-3200 RTS delivers all the trusted capabilities of its predecessor, the ATS-3100 RTS, with breakthrough enhancements. New features include an integrated Unit Under Test (UUT) power supply and built-in MIL-STD-1553 functionality, ensuring seamless support for critical communication protocols such as SINCGARS, SRW, WNW, and HAVEQUICK. This platform enhances flexibility, enabling users to protect investments in legacy systems while seamlessly adopting emerging technologies. The ATS-3200 RTS is a flexible, software-driven, future-proof system designed for rapid upgrades to meet evolving technological demands. With its intuitive touch interface, the platform streamlines operations, enabling fully automated testing without requiring extensive operator training. Astronics offers a comprehensive library of Test Program Sets (TPSs) for tactical radios across virtually all Original Equipment Manufacturers (OEMs), providing flexibility and scalability for any mission. For added efficiency, operators using both the ATS-3200 RTS and the newly launched ATS-6100 handheld RTS can benefit from a unified interface, ensuring a smooth transition from depot to field.
Jim Mulato, President of Astronics Test Systems, commented, “In a world where reliable communication is mission-critical, especially on the battlefield, the ATS-3200 RTS transforms how tactical radios are tested and maintained. This innovative solution ensures that communication systems remain dependable, reduces maintenance costs, and maximizes mission readiness for our military personnel. Astronics is committed to delivering the tools our armed forces need to succeed in any environment.” (Source: https://www.defenseadvancement.com/)
———————————————————————————————————————————————————————————————————————————————————————————————————————————–
Spectra Group (UK) Ltd
Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.
Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.
With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.
Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.
In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.
Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.
Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.
————————————————————————————————————————————————————————————————————————————————————————————————————————————-

