Sponsored by Spectra Group
—————————————————————————————————————————————————————————————————————————————————————————————————————————————-
21 Jan 25. New phishing operation points to elevated data-theft, security risks for Microsoft 365 users. On 20 January, international news outlets reported that a new Phishing-as-a-Service (PhaaS) kit, ‘Sneaky 2FA’, is targeting Microsoft 365 accounts in an information-theft campaign. The campaign reportedly starts with phishing emails containing a malicious QR code that redirects victims to threat actor-designed phishing websites. The websites emulate legitimate Microsoft login pages and enable threat actors to steal user credentials and authentication codes so as to conduct follow-on unauthorised activities. Notably, the QR codes require victims to use their phones to initiate the campaign, possibly reducing the number of people impacted. The kit can be purchased for approximately USD 200 on the messaging platform Telegram, allowing low-skilled actors to purchase Sneaky 2FA. The PhaaS kit can also check whether threat actors are subscribed in real-time and is managed centrally on Telegram, underscoring the scale of the operation. We assess this points to the elevated security and information-theft risks facing global Microsoft 365 users in the short-to-medium term. (Source: Sibylline)
23 Jan 25. Global: Supply chain attack raises espionage, third-party risks posed by China-nexus groups. On 22 January, the cyber security company ESET reported that a new China-nexus advanced persistent threat (APT) group (‘PlushDaemon’) targeted a South Korean virtual private network (VPN) service in a supply chain attack between 2023 and mid-2024. PlushDaemon compromised legitimate VPN installer files (available on the provider’s website) to infiltrate victims’ systems. The compromised files executed a custom backdoor (‘SlowStepper’) onto targeted systems to conduct network reconnaissance, exfiltrate sensitive data, and record audio and video. SlowStepper was downloaded by a variety of VPN customers, showcasing the broad scope of this campaign. We assess that the attack highlights the widespread and prolonged impact of supply chain compromises since it reportedly affected users in multiple countries (including China, New Zealand and the US). This will raise long-term supply chain and cyber espionage risks to global organisations as PlushDaemon continues to develop sophisticated techniques and improve its detection evasion capabilities. (Source: Sibylline)
23 Jan 24. HENSOLDT has successfully completed the modernisation project “Einsatzunterstützungsanlage Neue Technologien“ (EUA NT) after testing the system at four Bundeswehr helicopter bases. The aim of the project, which was commissioned by the Federal Office of Bundeswehr Equipment, Information Technology and In-Service Support (BAAINBw) in May 2022, is to upgrade the EUA, which has been in use for more than a decade, for the next 15 years of operation. The modernised EUA NT is a deployable complete system for supporting the Bundeswehr’s rotorcraft, consisting of two types of container: The system container contains a fail-safe IT base system with network technology for connection to IT systems of the Bundeswehr at the operational level up to the classification level of VS-GEHEIM (classified up to secret), modernised application software and the communication systems required for data and radio communication with the aircraft. The system container can be deployed as the smallest fully functional, relocatable command cell with two IT workstations to support NH90 and Tiger helicopters, for example, before, during and after the mission.
The personnel container supplements the system container with a control centre and additional ergonomic workstations for six additional operators. Up to three personnel containers can be combined with a system container. Furthermore, several EUA-NT systems can be linked to form a data network.
The radiation-shielded units are identically equipped in terms of air conditioning and power supply. They have a power generator that starts automatically when used on vehicles or when the power supply is unstable, and an uninterruptible power supply that ensures IT operation at all times. In the next step, HENSOLDT will implement the series production, the retrofitting of the systems in use and measures for replication. With the EUA NT, the Bundeswehr is receiving a modern, commercially available system whose modular and open architecture not only represents the ground station platform for the Bundeswehr’s current rotorcraft but is also equipped for future requirements and weapon systems.
“With the New Technologies Mission Support System, we are creating a future-proof solution based on an established system that will sustainably strengthen the operational capability of the Bundeswehr. Close cooperation with the customer and end users, as well as the consideration of operational experience from Afghanistan and Mali, have made it possible to develop a new system that is modular and highly flexible and thus ready for the challenges of the coming years. In addition, provisions have been made to further improve usability for future weapon systems,” says Alex Irmscher, programme manager for ground stations at HENSOLDT.
23 Jan 25. Silvus StreamCaster First MANET Radio to Receive FIPS 140-3 Level 2 Validation. Silvus Technologies, a global supplier of advanced wireless networking solutions, has announced that its StreamCaster MANET radios are the first and only tactical radios with cryptographic modules to receive FIPS 140-3 Level 2 validation. By achieving FIPS 140-3 Level 2 validation, Silvus reinforces its position as a trusted provider of secure, resilient communication solutions that defense, law enforcement agencies, and critical infrastructure operators rely on for mission-critical communications in any operational environment. StreamCaster MANET radios provide high-fidelity video, voice, and IP data communications – delivering actionable intelligence at the speed of relevance. At the heart of every StreamCaster MANET radio is Silvus’ battle-proven MN-MIMO waveform, capable of linking hundreds of nodes with unmatched range, data throughput, EW resiliency, and scalability. Applicable radio models now available with FIPS 140-3 Level 2 encryption include SC4200, SC4400, SL4200, and SM4200.
“We are proud to achieve FIPS 140-3 Level 2 validation, a milestone that highlights our dedication to providing the most advanced tactical communication solutions,” said Weijun Zhu, Vice President of Engineering at Silvus Technologies. “Certification of StreamCaster MANET radios ensures that our customers can operate with confidence, knowing their sensitive communications are safeguarded from compromise in even the most contested environments.”
Federal Information Processing Standards (FIPS) 140-3 Level 2 validation, established by the National Institute of Standards and Technology (NIST), ensures that StreamCaster MANET radios meet the U.S. Government’s highest security requirements for cryptographic modules to protect sensitive data.
This standard provides operators with the confidence that their communications remain secure in high-risk, mission-critical operations. Silvus’ achievement of FIPS 140-3 Level 2 validation brings significant advancements over the previous FIPS 140-2 standard, including:
- Alignment with ISO/IEC 19790:2012 for global interoperability and consistency with global cryptographic security
- Enhanced Level 2 Security provides additional protection including physical tamper evidence and role-based authentication, where access to the cryptographic module is controlled by user roles allowing different levels of permission
- Lifecycle security evaluations from design to deployment
- Mandate for more advanced cryptographic algorithms, including SHA-3 as the primary hashing algorithm and AES as the only approved symmetric encryption algorithm.
Governments worldwide are transitioning to FIPS 140-3 to bolster cybersecurity. In the United States, federal agencies are required to use FIPS 140-3 validated modules, with September 2026 set as the sunset date for FIPS 140-2 certificates. Through the Cryptographic Module Validation Program (CMVP), Canada’s Communications Security Establishment (CSE) jointly validates FIPS 140 modules with NIST, ensuring compliance across North America.
Additionally, FIPS-validated modules are widely adopted by governments and organizations in countries like the UK, Australia, and Japan to ensure robust cryptographic protections for their national security and critical infrastructure.
Current Silvus customers are now able to access FIPS 140-3 Level 2 encryption and capability enhancements through a software update in the StreamScape 5 network management software.
(Source: UAS VISION)
21 Jan 25. US Army kicks off NGC2 prototyping effort. US Army leaders are seeking industry input for the development of prototype systems to support the ground service’s Next Generation Command and Control (NGC2) initiative, according to a newly released request for information (RFI). The 14 January RFI, issued by the Program Executive Office for Command, Control, Communications, and Network (PEO C3N) is designed to “provide commanders and units at echelon an open and modular C2 ecosystem across hardware, software, and applications with access to a common and integrated data layer”, according to a service statement accompanying the 14 January RFI.
“Contracting and delivery of Next Generation Command and Control capabilities will be deliberate and iterative, geared toward commander needs and dependent upon the innovation of industry,” said Program Executive Officer for PEO C3N Mark Kitz said in the statement.
NGC2 programme officials at PEO C3N anticipate issuing a follow-on draft request for proposals (RFP) by late January 2025, with the final version of the RFP slated for release by the end of February 2025, service officials said in the statement.
Once issued, contract awards for NGC2 prototypes are scheduled to be issued to industry by May 2025, “with initial prototype deliveries to occur within six months” of the contract award date, the officials said. “Each stage of the process will generate industry feedback and inform the [NGC2] contract approach and resultant contract … as well as future evolution of the capability,” they added. (Source: Janes)
21 Jan 25. Hanwha Systems’ proprietary cybersecurity solution for ships was E27 certified by the American Bureau of Shipping(ABS) for the first time in Asia. With this certification, Hanwha Systems will accelerate its advance into the global shipbuilding and maritime cybersecurity markets. Hanwha Systems(led by CEO Jae-il Son) announced today that its cybersecurity solution ‘SecuAider®’ has obtained E27 TA(Type Approval for cyber resilience of on-board systems and equipment) certification from the American Bureau of Shipping(ABS). Hanwha Systems received an official certification from the American Bureau of Shipping (ABS) held at the Hanwha Building in Janggyo-dong, Jung-gu, Seoul, on the afternoon of the 20th. SecuAider also acquired certification from the Korean Register (KR) in December of last year.
The E27 TA certification involves a stringent evaluation process that assesses the performance and safety of ship equipment across all stages, including product design, manufacturing, operation, and maintenance, with a focus on cybersecurity of ships. Notably, SecuAider® marks the first such certification among Asian nations, which currently lead the global shipbuilding industry.
*E27 TA: Certification published by international class such as ABS when it is assessed that on-board systems and equipment qualified requirements to cyber resilience.
On-board systems or equipment that has ABS E27 TA certification will be eligible to export and supply to various global shipyards and shipping companies certified by ABS. The International Association of Classification Societies(IACS) which is registered with global classes including ABS, DNV, Lloyd’ Register or Korean Register, published new regulation to apply cyber resilience to ships built after July 2024, therefore, on-board systems and equipment of ships must also have cyber resilience certification of E27.
Hanwha Systems’ SecuAider® is a cybersecurity solution that protects data and networks, which is installed in the ship’s network and linked to on-board systems and equipment. With SecuAider®, ships would enhance cyber resilience to protect against advanced cyberattacks such as ransomware, DDoS attacks or malicious code infections, which have been rapidly increasing in recent years. It analyzes and controls cyber situations in real-time without degrading performance of legacy on-board systems and equipment of a ship. It provides advanced functions such as AI-based anomaly detection, cyber threat hunting, and real-time remote response.
Developed entirely with Hanwha Systems’ proprietary technology for decades, SecuAider® draws on Hanwha Systems’ extensive expertise in advanced ship systems and its years of experience in ICT technologies. The solution offers highly compatible and flexible standardized interfaces for different types of equipment in network and cybersecurity, seamlessly integrating with both domestic and international commercial ship equipment currently in operation.
“Leveraging SecuAider®, which has been certified as a world-class cybersecurity solution, we aim to strengthen the cybersecurity of various commercial ship line-up and defense companies, both domestically and internationally,” said a Hanwha Systems spokesperson. “We are also exploring opportunities to expand into major markets, including the United States.”
13 Jan 25. Trouble at The Top. As our Change of Name, Change of Culture article in this month’s Military Communications Newsletter explains, the People’s Liberation Army (PLA) has performed a major reorganisation of its Strategic Support Force (SSF). The SSF was a PLA combatant command. One of the SSF’s key missions was deploying, managing and modernising the strategic, operational and tactical communications the PLA relies on. The SSF was disbanded in April 2024 and then reconstituted as the Information Support Force. The exact reasons for this course of action remains unknown. In December 2024, the US Department of Defence’s 2024 Military and Security Developments involving the People’s Republic of China Annual Report to Congress speculated that the changes may have occurred because of politico-military concerns over the SSF’s leadership. The report noted that the SSF’s head General Ju Qiansheng was removed from his post in February 2023. It speculated that this may have been the result of the incident in the United States one month earlier when a Chinese surveillance balloon was flown over America. Gen. Ju was not replaced before the SSF was disbanded. Likewise, the Lieutenant General Shang Hong, commander of the SSF’s space force, was not replaced following his departure that same year. The report speculated that both officers may have been involved in corrupt procurement practices. The same document also noted wider corruption in the PLA, and purges by the Chinese politico-military leadership to this end. Assuming corruption did take hold in the SSF, this will have hampered the PLA’s continued pursuit of modernised communications systems and networks. Corruption in defence procurement never leads to the procurement and sustainment of the best capabilities. Instead, proficiency suffers as warriors must make do with inferior materiel. Graft contaminates the workforce; efficiency suffers and motivation declines. China maybe a feared and respected near-peer rival, but corruption in PLA circles may be more severe than the country’s leadership dares admit. This may yet retard the pace, breadth and depth of PLA military communications modernisation. Anything that slows this process will benefit the US and her allies as they confront an increasingly strategically assertive China. (Source: Armada)
16 Jan 25. Comms Collapse.
The rapid end of Syria’s civil war, and the fall of the Assad regime, may have highlighted shortcomings in Russian tactical communications, and the proficiency of Turkish electronic warfare.
The lightning dash across Syria by the Ha’yat Tahir al-Sham (HTS) Islamist militia group came as a surprise. Syria had been gripped by civil war since 2011. An uneasy peace took hold from July 2017 following a ceasefire brokered by Jordan, Russia and the United States which collapsed in late November 2024. HTS led an advance by a coalition of organisations opposing the regime of Syria’s dictator Bashir al-Assed. HTS forces initially captured the city of Aleppo in the north. Hama in western, central Syria was the next conurbation to fall. By 6th December the western city of Homs was in the opposition’s hands with the capital Damascus falling on 8th December. Mr. Assad fled to Moscow with his family on the night of 6th/7th December while HTS declared victory.
HTS and its associates seemed to meet little meaningful opposition from Syria’s military as they drove across the country. Reports state that 261 Syrian, Iranian and Russian cadres were killed during the battles, with 21 Syrian troops captured. Both the governments of Russia and Iran were enthusiastic backers of Mr. Assad’s regime. Meanwhile, HTS and supporting groups lost 371. Why the regime and its military collapsed so quickly will be studied for years. One strategic factor highlighted in recent analysis has been the lack of willingness of Moscow and Tehran to continue supporting Mr. Assad. With both his major supporters now essentially quitting, did the Syrian military still have the stomach for a fight?
Turkish EW
Another reason for Syria’s military collapse which has come to light is the alleged proficiency of Turkish Communications Jamming (COMJAM) systems. Information began to circulate on social media that these capabilities were successful in attacking Syrian military communications networks. With their radios jammed, Syrian command and control was significantly impeded. As the intelligenceonline.com website later confirmed, Turkish Electronic Warfare (EW) assets were integral to the HTS advance.
Turkey’s government had supported the Free Syrian Army in its efforts to unseat Mr. Assad’s regime since the eruption of the civil war. Ankara invaded northern Syria in 2016 to attack Kurdish insurgent organisations, and Islamic State of Iraq and Syria cadres, operating there. Open sources state that Aselsan’s Milkar-A42 and Ilgar-3LT COMJAM platforms proved particularly useful. These systems were deployed to areas controlled by the Turkish military in and around the northern Syrian city of Idlib.
The Milkar-A2 is a vehicle-mounted COMJAM system which attacks High Frequency (HF: three megahertz/MHz to 30MHz) communications in support of land force manoeuvre, according to Aselsan. The Milkar-A2 can also demodulate HF traffic allowing it to be exploited for communications intelligence. The Ilgar-3LT provides similar capabilities against Very/Ultra High Frequency (V/UHF: 30MHz to three gigahertz) communications traffic. It is understood that these systems were particularly effective against Р-168 Акведук (R-168 Aqueduct) HF and V/UHF, Р-187П Азарт (R-187P Excitement) V/UHF tactical radios. More information on both radios can be found here. These transceivers are believed to have been supplied to Syrian forces and were also used by Russian troops in Syria. Russia deployed forces into Syria to support Mr. Assad’s regime from 2015.
Russia is though to have deployed R-168 Aqueduct multiband radios to Syria to support her deployment there, and to furnish the Syrian military. It is possible that R-168 transceivers were targeted by Turkish Milkar-A2 and Ilgar-3LT COMJAM systems.
Assessment
Jamming these radios and their networks may have helped precipitate the Syrian military’s collapse in the face of the HTS advance. Turkish electronic warfare acumen has come to the fore in recent years, illustrated by the proficiency of Turkish EW cadres in Syria. Turkish electronic warfare equipment supplied to Ukraine has also performed well. The Ukraine theatre of operations has provided a laboratory in which Turkish EW equipment can be tested and improved. Improvements based on electromagnetic observations in Ukraine can then be cycled back into electronic warfare system design and performance enhancements. Despite the R-168 and R-187P being among the most modern and secure tactical radios deployed by Russian land forces they appear vulnerable to Turkish jamming. Such vulnerabilities can only be good news for the North Atlantic Treaty Organisation. Likewise, the inadequacy of Russian communications kit is an additional embarrassment for the regime of Russia’s President Vladimir Putin. Mr. Putin is already having to face the humiliation of backing the losing side. (Source: Armada)
15 Jan 25. Change of Name, Change of Culture?
A bureaucratic reorganisation in one of China’s combatant commands may be indicative of problems and challenges the Chinese military is experiencing in modernising its military communications.
In what has become an annual tradition the United States Department of Defence (DOD) released its 2024 Military and Security Developments involving the People’s Republic of China Annual Report to Congress in late December. In its own words the document “charts the course of the PRC’s national, economic, and military strategy and offers insight on the People’s Liberation Army’s (PLA) strategy, current capabilities, and activities as well as its future modernisation goals.”
The document remains a useful source, providing an authoritative snapshot of the People’s Republic of China’s (PRC’s) strategic goals and foreign policy objectives, defence and security priorities, military force structures and military modernisation goals. The report articulates observations regarding People’s Liberation Army (PLA) efforts to overhaul its strategic, operational and tactical military communications.
Writ large, the report states that the PLA “has sought to modernise its capabilities and improve its proficiencies across all warfare domains to become a joint force capable of the full range of land, air, and maritime as well as nuclear, space, counterspace, electronic warfare and cyberspace operations.” This quotation underscores how communications modernisation is central to the PRC’s embrace of the Multi-Domain Operations (MDO) philosophy. The PLA’s version of MDO is termed Multi-Domain Precision Warfare. It exploits “command, control, communications, computers, intelligence, surveillance, and reconnaissance … network that incorporates advances in big data and AI (Artificial Intelligence).” The strategic objective of Multi-Domain Precision Warfare is to “rapidly identify key vulnerabilities in the US operational system and then combine joint forces across domains to launch precision strikes against those vulnerabilities.”
Information Support Force
One of the most dramatic illustrations of Chinese military communications modernisation has been the reorganisation of the erstwhile PLA Strategic Support Force (SSF). The SSF is no more, having been dissolved by China’s Central Military Commission (CMC) in April 2024. In the alphabet soup of Chinese military acronyms, the CMC is the PRC’s supreme politico-military leadership. Why the SSF was dissolved remains unknown. The report speculates that “(t)he … decision to dissolve the SSF after only eight years reveals compelling concerns over its contribution to joint operational effectiveness as well as severely inefficient management and leadership.” The report cites several changes in SSF leadership between 2023 and 2024 which may indicate concerns over the SSF’s leadership and management. The coordination and management of the PLA’s military communications now falls within Information Support Force (ISF). The ISF is directly subordinate to the CMC, as was the SSF. The status of the ISF is analogous to a combatant command in the US military.
The SSF had three directorates: The Network Systems Department (NSD) was responsible for cyberwarfare, electronic warfare, information warfare, technical reconnaissance and psychological warfare. The SSF’s Space Systems Department (SSD) was responsible for the PLA’s use of space, and counterspace activities. Finally, the Information Communications Base was the custodian of PLA communications networks and was responsible for defending these networks. The SSD and NSD have been moved out of the ISF and are now under the Central Military Commission’s direct control. However, the Information Communications Base is thought to continue as a constituent part of the ISF headquartered in Beijing.
It remains to be seen what effect the SSF disbandment and ISF activation will have on the PLA’s military communications capabilities. To paraphrase the quotation of Zhou Enlai, Chinese Communist Party ideologue and PRC stateman when asked about the consequences of the 1789 French Revolution, it is probably too soon to say. On the one hand, the reorganisation reflects the PLA’s commitment to continue prioritising communications modernisation and investment. On the other hand, SSF leadership problems may have adversely affected the pace and quality of PLA military communications modernisation. Time will tell. (Source: Armada)
20 Jan 25. Airbus Defence and Space equips in close collaboration with HENSOLDT the “German Airborne Weapon Systems Electronic Warfare Center” with new up-to-date software and hardware to provide a streamlined, service-oriented approach to improve the support of mission-specific “Electronic Warfare Mission Data” for the aircraft operated by the German Armed Forces. This joint effort ensures that weapon systems are tailored to each mission and maintain the readiness of the “German Airborne Weapon Systems Electronic Warfare Center” in face of current and future threats. The agreement starts in January 2025 and includes mission-critical software solutions. The highly integrated system will offer an increased amount of automation and allows reduced response times to the end user. Airbus` state-of-the-art operating systems will enhance usability while integrating future-proof technology compatible with advanced weapon systems. It not only paves the way for future integration with additional platforms, but also increases mission effectiveness and enables efficient mission preparation and conduction seamlessly. HENSOLDT provides essential IT services and deployable hardware for mobile operations, including server hardware and workstation computers for personnel. The collaboration between Airbus and HENSOLDT marks a significant step in strengthening Germany’s defence capabilities, ensuring mission effectiveness and readiness in a complex and technology-driven defence environment.
14 Jan 25. Of Strelets and Andromeda. The YESU-TZ operational-level command and control system is used at the Russian armed forces’ National Defence Command Centre in Moscow. A new book sheds light on the organisation of Russian land forces’ command and control, and the digital battle management systems they employ at operational and tactical levels. Armada was delighted to receive a review copy of the Lightning Press’ latest volume examining the Russian military. OpFor Smartbook-3: Russian Military Forces, Operations and Tactics is a comprehensive work examining Russia’s armed forces in their entirety. The work also discusses Moscow’s strategic goals and foreign policy preoccupations. As noted in another recent article, the book provides an excellent overview of the Russian military’s Electronic Warfare (EW) posture. Equally useful is the volume’s analysis of Russian land forces Command and Control (C2). Russian land manoeuvre force C2 can be shrouded in conjecture and contradiction. Norman Wade, the Lightning Press’ publisher and the book’s author, does great work demystifying this aspect of land manoeuvre force posture and organisation.
YESU-TZ
The strategic echelons of Russia’s joint high command use the ЙЕСУ-ТЗ (YESU-TZ – Unified Command and Control System for Troops and Weapons) digital C2 architecture. As Mr. Wade notes, YESU-TZ is vital for turning the political intentions of Russian’s civilian leadership into military objectives. YESU-TZ receives and processes data sent by subordinate echelons, and disseminates information, orders and situation reports. It appears YESU-TZ performs C2 from the National Defence Command Centre in Moscow through to Russia’s constituent Military Districts (MDs). Russia’s military is spread across five MDs; Moscow and St. Petersburg in the north and west of the country, plus the Central, Southern and Eastern Military Districts. Land forces in each MD are typically organised into Combined Arms Armies (CAAs). CAAs are operational-level formations consolidating Russian Army manoeuvre forces in that MD with other land manoeuvre elements like Russia’s airborne forces and naval infantry, both of which function as separate forces. For all intents and purposes, YESU-TZ also provides operational level C2 for the CAAs.
Tactical manoeuvre force C2
The principle tactical manoeuvre unit in the Russian Army is the motorised rifle/tank division/brigade. As Mr. Wade notes other C2 systems are used, at the brigade/division level. He writes that the Акация-М (Akatsiya-M) C2 architecture is employed for logistics, general force organisation and battle management. Akatsiya-M terminals can be installed on vehicles or used at deployed bases. Russia’s airborne forces have the Андромеда-Д (Andromeda-D) C2 system. Andromeda-D “provides a near real-time plot of the battlefield situation to coordinate the actions of airborne forces,” says Mr. Wade. He adds that Andromeda-D capabilities are like those of the Стрелец (Strelets) C2 system used by Russian Army dismounted infantry.
The Russian Army has deployed the Strelets C2 system with its dismounted troops. The capabilities of command and control architectures like the Andromeda-D used by Russian airborne forces are similar to those of Strelets.
Ground-Based Air Defence (GBAD) employs the Акация-Э (Akatsiya-E) C2 system. Akatsiya-E is used for operational and tactical air battle management. To this end, Akatsiya-E will link directly with tactical GBAD C2 systems like the 73Н6МЭ Байкал-1МЭ (73N6ME Baikal-1ME), Универсал-1Е (Universal-1E), Фундамент-1Э (Fundament-1E) and Поляна-Д4М1 (Polyana-D4M1). These latter systems are tactically deployed to provide C2 to individual GBAD surface-to-air missile and anti-aircraft artillery batteries. By integrating these disparate systems, Akatsiya-E provides a consolidated recognised air picture.
Artillery units make use of the 1В168 АСУНО-С (1V168 ASUNO-S) tactical C2 system. The author writes that the 1V168 ASUNO-S has an integral Global Navigation Satellite System (GNSS) terminal. The terminal automatically registers the position of firing platforms under command. Digital maps provide local topographic information. Target data is downloaded automatically in near real time by the 1V168 ASUNO-S with firing solutions calculated as rapidly. Mr. Wade writes that a BM-20 Smerch 300mm multiple rocket launch system can fire a 40-second volley of rockets against targets 90-kilometres (56-miles) away two minutes after receiving target data from the 1V168 ASUNO-S. Last but not least, Russian land forces EW employ use the РБ-109 Былина (RB-109 Bylina) tactical C2 system.
Assessment
The adoption of digital C2 systems by Russia’s land forces reflects the acknowledgement of the country’s military that the automation of battle management is essential for contemporary and future conflicts. Mr. Wade argues that the adoption of the systems discussed above helps increase “the stability, continuity, speed and security of (C2) actions.” Digital C2 enhances the commander’s “ability to quickly assess the battlefield situation, supports rapid decision-making and transmits those decisions to units and subunits.” Above all, these C2 systems help deepen combined arms operational and tactical coordination. By doing so, Russia’s military writ large hopes to accelerate the pace at which it can navigate the OODA (Observe, Orient, Decide, Act) loop with better quality decision-making than its adversary. Achieving this ambition, as Mr. Wade stresses, can mean the difference between success and failure on the battlefield. (Source: Armada)
13 Jan 25. January Radio Roundup.
Banshee Tactical Radio for Backpack
Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains. Nokia recently publicised its 5G Banshee Flex Radio which enables 5G connectivity across the battlefield, providing a coverage footprint of up to 154 square kilometres (60 square miles).
New Nokia tactical 5G networking
Nokia has unveiled the latest member of its Banshee tactical radio family. Known as the 5G Banshee Flex Radio the system uses fifth generation (5G) cellular protocols. Previous Banshee tactical radios used fourth generation (4G) cellular standards. The company stated in a press release that the 5G Banshee Flex Radio can be deployed to provide a tactical 5G network over the battlefield. Troops can then use their 5G devices to connect to this network, and to each other. By enabling 5G communications, the radio provides “advanced edge compute capabilities, mesh networking, band flexibility, operational security and deployment simplicity,” according to the press release. Moreover, the radio “delivers unparalleled 5G throughput with 100 (megahertz) carriers and extreme operational range with multiple power options.” Nokia told Armada, via a written statement, that the 5G Banshee Flex Radio supports legacy 4G communications. The company continued that data rates of 800 megabits-per-second are achievable. The 5G Banshee Flex Radio provides 5G coverage across a seven-kilometre (4.4 mile) radius. Power output levels of between five watts/W and 20W per transmission port are available. Regarding customers, the company said it is “actively working with defence ministries and other strategic partners on the deployment of the 5G Banshee Flex Radio. While we are not able to disclose specific customers … we are focused on meeting the secure and flexible 5G needs of mission-critical applications.” (Source: Armada)
20 Jan 25. Global: Large-scale DDoS attacks elevate disruption risks stemming from newly discovered botnet. On 17 January, the cyber security company Trend Micro reported that a newly discovered botnet conducted large-scale distributed denial-of-service (DDoS) attacks against global organisations since at least the end of 2024. The botnet infiltrates Internet-of-Things (IoT) devices via software vulnerabilities and/or weak password configurations. It then executes malware (likely derived from the known Mirai and Bashlite botnets) through a multi-step process to establish communication with actor-controlled infrastructure and execute additional malicious activities. This includes conducting DDoS attacks against targeted networks to cause temporary operational disruption while deactivating security mechanisms. Threat actors often exploit vulnerable IoT devices to launch DDoS attacks since such operations can propagate disruption to entire IT networks. This trend highlights the elevated security risks stemming from these devices. Additionally, the botnet has been used to target critical national infrastructure sectors (including telecommunications and financial services), illustrating heightened disruption risks in the short term as part of an ongoing campaign. (Source: Sibylline)
20 Jan 25. Silvus Technologies Partners with Safeware to Expand Public Agency Access to Advanced StreamCaster MANET Radios. Silvus Technologies, Inc., a leader in advanced wireless communications systems, has announced a new resale partnership with Safeware, a leading safety solutions provider.
With StreamCaster MANET radios now available through Safeware, first responders, law enforcement, and disaster relief agencies across the nation can establish robust, decentralized communication networks, improving coordination and efficiency in emergency response.
“We’re thrilled to partner with Safeware to extend the reach of StreamCaster MANET radios to agencies on the front lines of public safety,” said Jimi Henderson, Vice President of Sales at Silvus Technologies. “This partnership ensures that first responders will have access to reliable, secure, and robust communications when it matters most.”
The Silvus family of StreamCaster MANET radios deliver high-fidelity video, voice and data communications with class-leading output power, range, and mobility. At the heart of every StreamCaster MANET radio is Silvus’ leading-edge MN-MIMO waveform technology that creates a self-healing, self-forming and adaptive mesh network – capable of linking hundreds of nodes with unmatched data rate throughput, EW resiliency, and scalability.
Silvus StreamCaster SC4200
Also available as an extension of the MN-MIMO waveform is Spectrum Dominance – an expansive suite of advanced interference avoidance and cancellation capabilities that provide secure and protected mesh network communications in high RF traffic environments including disaster areas, sporting events, parades, and rallies, without sacrificing performance. This allows teams to stay connected and on mission in a wide range of operational scenarios without worrying whether communications will fail.
“At Safeware, just like Silvus, we’re dedicated to providing first responders and public safety teams with the best communication tools available,” said Connie Stallings, Senior Vendor Relations Manager at Safeware. “By including Silvus StreamCaster MANET radios to our list of partners, we’re helping agencies build strong, reliable communication networks that hold up in the toughest situations.”
Interested agencies can contact Safeware for more information.
About Silvus Technologies, Inc.
As the world’s leading provider of advanced MANET and MIMO communications systems, Silvus Technologies is reshaping mesh network technology for mission-critical applications – on the ground, in the air, and at sea. Its battle proven StreamCaster family of MANET radios and proprietary MN-MIMO waveform provides the vital communications link for defense, law enforcement, and public safety agencies around the world, and in the toughest operational environments. Developed by a team of top PhD scientists and design engineers, Silvus Technologies continues to innovate communications technology for the tactical edge with unmatched range, data throughput, EW resiliency, and scalability. Silvus Technologies is privately held with world headquarters located in Los Angeles, CA.
About Safeware
– Safeware is a leading provider of safety solutions, specializing in assessing, distributing, and training advanced technologies to mitigate risks and enhance safety across various industries. With a commitment to innovation, quality, and customer satisfaction, Safeware remains at the forefront of safety excellence, empowering organizations to protect lives, assets, and the environment. (Source: UAS VISION)
16 Jan 25. US Army to competitively develop Next-Gen Command-and-Control prototype. After spending a year working on pilot programs for a future battlefield command-and-control capability, the U.S. Army is on the brink of starting an effort to competitively prototype a next-generation system, according to the service’s program office in charge of the activity. Next-Generation Command-and-Control, or NGC2, as the Army calls it, represents a new approach to providing commanders and units an “open and modular” command-and-control, or C2, ecosystem “across hardware, software and applications with access to a common and integrated data layer,” the Army said in a statement. The service’s Program Executive Office for Command, Control, Communications and Network, seeking industry feedback ahead of launching the prototyping effort, released a request for information Monday to industry addressing its NGC2 priorities.
“The goal of NGC2 is to help organize and operationalize data for warfighting applications — including real-time operational modeling of the potential outcomes of commanders’ decisions and courses of action, as well as the ability to tailor and reconfigure elements to meet their missions,” the Army said.
The service launched a pilot in roughly a year ago to examine what could realistically be achieved for C2 using a clean sheet design. Entirely ignoring all current C2 capabilities, the Army partnered with industry to provide soldiers with an agile system capable of functioning off of laptops inside a tank, for example, rather than consisting of giant server stacks in climate-controlled tents easily detectable to the enemy.
“I think we’re learning that we can probably go pretty quick on this given where technology is at,” Army Chief of Staff Gen. Randy George told Defense News in an interview last fall. The Army needs to move away from “big systems and server stacks and all of that stuff,” he said. “That can all be an app.”
As a major element of the pilot, the Army focused not just on how a fresh C2 system might bring capabilities to the soldier in the field but how to transport data to enable all of those functions, according to Doug Bush, the Army’s acquisition chief.
“The ability to move the data around at speed, at a vast scale and under attack by an enemy, that is a very difficult challenge,” Bush told Defense News in an interview last fall. “The good news is, this time around, the tech is much closer to being able to enable that.”
A request for NGC2 proposals is expected to be released in late February, according to the RFI posted to federal contract opportunities website Sam.gov. The service plans to award contracts by May, with the delivery of initial prototypes within six months of award.
The planned contract awards are structured to enable multiple opportunities for defense companies to contribute to NGC2, the Army said, with the service intending to onboard new vendors for additional components available after the initial prototyping awards.
Specifically, the Army emphasizes “tailorable and intuitive capabilities” and “agility in requirements and governance” for the next-gen technology, according to Army Futures Command’s NGC2 character of needs statement.
Recent updates to the character of needs statement include a focus on mission partner interoperability, operating in challenging tactical communications environments and “an integrated ‘tech stack’ approach that reaches from the communications transport layer through compute, integrated data and applications layers,” the Army said.
“We have an incredibly tech-savvy formation,” Maj. Gen. Patrick Ellis, director of AFC’s Command and Control Cross-Functional Team, said in the statement. “Commanders understand the network better than they ever have, and divisions are eager to be a part of the process and part of the user-informed solution.” (Source: glstrade.com/Defense News)
17 Jan 25. Cyber Update Key points.
- Global spam operation highlights raised security risks posed by the Chinese state-sponsored group ‘Muddling Meerkat’ (see Sibylline Cyber Daily Analytical Update – 13 January 2025).
- A cyber operation against Central Asian countries points to raised espionage risks from the Russia-nexus group ‘UAC-0063.’
- Increases in cryptocurrency theft highlight elevated financial risks posed by North Korean state-sponsored groups.
- A new ransomware operation (‘Codefinger’) is targeting cloud storage services, pointing to elevated financial risks to global users (see Sibylline Cyber Daily Analytical Update – 16 January 2025 and our Technical analysis below).
- A noteworthy spoofing operation distributes malware and heightens security risks stemming from the ‘MikroTik’ botnet (see Sibylline Cyber Daily Analytical Update – 17 January 2025).
Technical analysis of weekly stories
The Russia-nexus group UAC-0063 is targeting organisations in Kazakhstan and other Central Asian countries in a large-scale cyber espionage operation. The campaign likely started with spear phishing emails to trick potential victims into opening a malicious Word document. UAC-0063 uses high-profile official documents (including correspondence letters, draft documents and administrative notes likely stolen during a previous cyber espionage campaign) to boost legitimacy and intrusion success rates. This then downloads the ‘HatVibe’ and ‘CherrySpy’ payloads onto compromised systems via a Double-Tap infection chain to bypass security mechanisms. HatVibe typically acts as a loader and establishes communication with actor-controlled infrastructure to download and execute additional malicious files. CherrySpy is a backdoor that can be used to monitor victims’ systems and exfiltrate strategic information to the actors’ command-and-control (C2) servers. Notably, UAC-0063’s modus operandi overlaps with that of the Russian state-sponsored group ‘APT28’, suggesting that the operation is possibly state-sponsored and that there is possibly a connection between the groups.
A new ransomware operation (‘Codefinger’) is exploiting encryption settings to target Amazon Simple Storage Service users. Codefinger reportedly uses stolen Amazon credentials to access and hijack cloud storage user accounts. The actors then generate new encryption keys to block user access to their data, abusing encryption settings typically used by customers to protect stored data by creating customer encryption keys. Subsequently, Codefinger demands a ransom payment for file decryption, warning affected customers that it will delete all files within seven days if the payment is not made or if users attempt to change account permissions. Additionally, affected customers can only recover encrypted data by paying the ransom since Amazon does not store any pre-existing customer-made keys. This underscores the continued exploitation and sustained security risks posed by third-party cloud services. Codefinger encrypts customer data directly within Amazon’s infrastructure to further prevent any alternative attempt at decrypting affected data, highlighting the sophisticated nature of the operation.
Some non-exhaustive recommendations to mitigate against these threats include:
- Monitor devices and networks for suspicious activity
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communication to malicious IP addresses associated with known malware
- Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
- Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering
- Implement password management policies to prevent compromises via stolen and/or exposed credentials
Our cyber word(s) of the week: Encryption
(Source: Sibylline)
————————————————————————————————————————————————————————————————————————————————————————————————————————
Spectra Group (UK) Ltd
Spectra Group (UK) Ltd, internationally renowned award-winning information security and communications specialist with a proven record of accomplishment.
Spectra is a dynamic, agile and security-accredited organisation that offers secure Hosted and Managed Solutions and Cyber Advisory Services with a track record of delivering on time, to spec and on budget.
With over 15 years of experience in delivering solutions for governments around the globe, elite militaries and private enterprises of all sizes, Spectra’s platinum and gold-level partnerships with third-party vendors ensure the supply of best value leading-edge technology.
Spectra was awarded the prestigious Queen’s Award for Enterprise (Innovation) in 2019 for SlingShot.
In November 2017, Spectra Group (UK) Ltd announced its listing as a Top 100 Government SME Supplier by the UK Crown Commercial Services.
Spectra’s CEO, Simon Davies, was awarded 2017 Businessman of the Year by Battlespace magazine.
Founded in 2002, the Company is based in Hereford, UK and holds ISO 9001:2015, ISO 27001:2013 and Cyber Essentials Plus accreditation.
—————————————————————————————————————————————————————————————————————————————————————————————————————————

