07 Feb 25. Evolving tactics sustain raised security risks from North Korean state-sponsored groups. On 4 February, the cyber security company AhnLab Security Intelligence Center reported that the North Korean state-sponsored group ‘Kimsuky’ is using a new custom remote desktop protocol (RDP) wrapper in an information theft campaign. The campaign starts with spear phishing emails to trick potential victims into opening a malicious attachment disguised as a legitimate PDF and/or Word document. The attachment then executes a PowerShell script to deploy malicious payloads onto compromised systems. This includes the custom RDP wrapper which enables remote desktop connections and prolongs detection evasion because RDP connections are often viewed as legitimate traffic by security tools. The wrapper also facilitates external access by bypassing firewall and network address translation (NAT) restrictions, showcasing the tool’s sophistication. Kimsuky subsequently deploys information-stealing malware and exfiltrates credentials from web browsers. We assess that this new wrapper underscores Kimsuky’s continuously evolving tactics, thus raising long-term security and information-theft risks to global firms. (Source: Sibylline)
07 Feb 25. OPTIMAS Starts European Project for Cybersecure Communications in Free Space with Collaboration of Schiebel. OPTIMAS, a European project led by “monodon by Navantia”, has begun with the aim of developing an advanced free-space optical communication system for multi-domain defence applications in collaboration with Schiebel. OPTIMAS is an ambitious project that seeks to provide high-speed data transfer communications with an exceptional level of security, integrating cutting-edge encryption technologies, such as quantum key distribution (QKD). OPTIMAS will mark a milestone in the development of airborne laser communication systems, providing secure and high-speed communications. It is designed to operate in satellite constellations with applications for space, air (drones), naval and ground units. The project’s final demonstrator will focus on achieving high-speed, secure, bidirectional optical communications. It will enable advanced satellite pointing, acquisition and tracking capabilities in Low Earth Orbits (LEO). Application in Medium Earth Orbits (MEO) and Geostationary Orbits (GEO) will be also explored, expanding the scope and possibilities of the system. OPTIMAS is a European consortium with Spanish leadership. It is a powerful group made up of 12 entities from 7 countries, highlighting a strong Spanish presence with 6 organizations involved. Among these, monodon by Navantia assumes the role of project coordinator, reaffirming Spain’s leadership in advanced defence and communications technologies. Schiebel’s CAMCOPTER S-100 will be the dedicated Unmanned Air System (UAS) for this project and the company is in charge of integrating a novel optical laser communication technology into the S-100, enabling the communication between the air segment and a satellite. The project is developed within the framework of the 2023 work programme of the European Defence Fund (EDF), consolidating international cooperation in technological innovation for defence.
OPTIMAS is formed by:
- monodon by Navantia (Spain) as coordinator
- CAILABS (France)
- Centro de Láseres Pulsados – CLPU (Spain)
- TECNOBIT SLU (Spain)
- GMVIS SKYSOFT SA (Portugal)
- Instituto de Astrofísica de Canarias (Spain)
- MBRYONICS LIMITED (Ireland)
- ODYSSEUS Space SA (Luxemburg)
- REFLEX AEROSPACE GMBH (Germany)
- SCHIEBEL ELEKTRONISCHE GERAETE GMBH (Austria)
- SENER (Spain)
- Universidad de Valencia (Spain)
- Universidad de Vigo (Spain)
OPTIMAS is positioned as a key project in the advancement of cyber-secure laser communications, consolidating European collaboration and the technological leadership of Schiebel in the field of multi-domain defence.
Project funded by the European Union. (Source: UAS VISION)
06 Feb 25. $8m boost to develop next-gen AUKUS electronic warfare tech. Australian Minister for Defence Industry and Capability Delivery Pat Conroy has announced Advanced Strategic Capabilities Accelerator contracts worth more than $8m for Advanced Design Technology and Penten in support of AUKUS Pillar II objectives. The government announced that Advanced Design Technology (ADT) and Penten have entered into contracts with the Advanced Strategic Capabilities Accelerator (ASCA) following their successful participation in the inaugural AUKUS Innovation Challenge to continue developing electronic warfare technology under a program designed to produce critical capabilities for all three AUKUS nations. This initiative forms part of a broader strategy to modernise Australia’s defence capabilities and support homegrown technological advancements, ensuring the armed forces remain at the forefront of global security innovation. This challenge is a key element of the AUKUS partnership, which brings together Australia, the United Kingdom, and the United States to pool their expertise and resources, leveraging each nation’s strengths to develop cutting-edge defence solutions.
Minister Conroy said, “I look forward to seeing the cutting-edge capabilities ADT and Penten will deliver for the Australian Defence Force and AUKUS to secure a competitive advantage and deter potential threats to regional security.”
The contracts – worth more than $8 million – will provide essential financial support to both companies, enabling them to continue their groundbreaking work while also creating over 150 local jobs. This investment not only boosts the domestic defence industry but also strengthens Australia’s capacity to contribute to multinational projects and maintain its competitive edge in high-tech warfare.
In addition to fostering innovation, the funding will support the development and demonstration of electronic warfare prototypes that meet the operating requirements of the Australian Defence Force (ADF). These prototypes are critical for enhancing situational awareness and ensuring robust communication across all domains, even in contested environments where adversaries may attempt to impair Australia’s capabilities. By addressing these challenges, Australian industry is playing a vital role in building the advanced electronic warfare capabilities outlined under AUKUS Pillar II.
“The AUKUS Innovation Challenge Series is a powerful example of how ASCA is accelerating advanced capabilities for our ADF while ensuring local innovators are at the forefront of Australia’s growing sovereign industrial base,” Minister Conroy said. (Source: Defence Connect)
06 Feb 25. Royal Navy delivers first next-gen electronic warfare system. The Royal Navy has rolled out the first in a series of enhanced electronic warfare systems, known as the Maritime Electronic Warfare System Integrated Capability (MEWSIC), for installation on current and future warships, according to a press release. MEWSIC is described as “a sensor upgrade to the Navy’s existing EW capability, which is a cornerstone of identifying enemy forces, equipment and movement” in the press release. It will be fitted to the Queen Elizabeth-class carriers, Type 45 destroyers, and the new Type 26/31 frigates. The first production model is now undergoing final checks at Elbit Systems UK in Bristol, while its updated Combat Management System is being tested at Portsdown Technology Park near Portsmouth. This development is part of the broader Maritime Electronic Warfare Programme (MEWP), which also includes Ancilia, a trainable launcher for electronic warfare decoys intended to “confuse anti-ship missiles.” Ancilia can swivel to “face threats directly,” removing the need to manoeuvre a ship to counter incoming missiles. It replaces the Seagnat system on older vessels and is set for installation on the Royal Navy’s newest warships. (Source: News Now/https://ukdefencejournal.org.uk/)
06 Feb 25. LM Supports USMC Exercise with Advanced 5G Capabilities. Lockheed Martin (NYSE: LMT), along with support from Intel Corporation and Radisys Corporation (NASDAQ: RSYS), conducted 5G military demonstrations during the U.S. Marine Corps (USMC) exercise, Steel Knight 2024. In partnership with USMC, the Office of the Under Secretary of Defense for Research and Engineering’s (OUSD(R&E)) FutureG Office, and various industry partners, the Open Systems Interoperable and Reconfigurable Infrastructure Solution (OSIRIS) system was deployed as a standalone 5G network to support operations across all domains. Led on the ground by the Marine Corps Tactical Systems Support Activity (MCTSSA) 5G team, the capstone event was an effort to test tactical wireless capabilities in support of Expeditionary Advanced Base Operations (EABO). During the exercise, the OSIRIS testbed integrated with unmanned air vehicles (UAVs), both free-flying and tethered. The system allowed operators to establish and host a secure connection through the OSIRIS testbed to multiple UAVs simultaneously, and a wireless connection, over 5G, between a USMC Ground/Air Task-Oriented Radar (G/ATOR) and a USMC Air Command and Control System (AC2S). Operators were able to send and receive battlefield data to enable realtime decision making in a variety of operational scenarios.
The Big Picture
- Steel Knight is an annual real-world military exercise using at-scale test facilities to enable rapid experimentation to address multiple Department of Defense (DoD) mission areas.
- The OSIRIS testbed deployed with Marine Air Control Group (MACG) 38 to Marine Corps Base Camp Pendleton to showcase 5G capabilities tested throughout the experiment to include: persistent Intelligence, Surveillance, and Reconnaisance (ISR) using UAS platforms; 5G failover capability using tactical radios; aerial 5G base station and a domestically produced 5G solution.
- The exercise provided valuable insight as to how 5G capabilities can be used to support the USMC’s goals for Littoral Operations in a Contested Environment (LOCE) and the complementary EABO efforts.
o LOCE aims to to develop the capability to conduct expeditionary, distributed, and networked naval and ground operations in the littorals, or the coastal regions.
o EABO refers to USMC’s ability to rapidly deploy and operate expeditionary advanced bases in support of naval and joint operations. These bases can be established on land or at sea, and are designed to provide flexible and scalable logistical, command and control, and firepower capabilities to support a range of military operations.
- The OSIRIS testbed consists of three configurations used during the exercise:
o Nomadic Tower
o Mobile Relay
o Stand-alone Integrated Access and Backhaul (IAB)
- IAB, which was demonstrated at tactical relevant distances for the first time during the Steel Knight exercise, enabled expanded 5G mesh coverage between nodes.
- The OSIRIS system is an ORAN compliant private 5G system, consisting of Intel FlexRAN™ reference software, Intel Xeon processors, Radisys software, and other 5G subsystems integrated by Lockheed Martin, and further enhanced to address USMC expeditionary requirements.
Strategic Perspectives
“The OSIRIS demonstration during exercise Steel Knight was an important proof point in showing Lockheed Martin’s 5G.MIL® capabilities,” said Erika Marsall, vice president, Lockheed Martin C4ISR. “Conducting demonstrations with our partners is a critical final step to understanding how these applications can be applied to real-world missions. We will continue to invest in commercial technologies, to develop solutions that can be tailored in a variety of ways, and bring the best capabilities to our warfighters.”
“Nomadic wireless backhaul enables real-time communications in environments where physical infrastructure is either lacking or disabled,” said Cristina Rodriguez, vice president and general manager, Communication Solutions Group at Intel. “This Lockheed Martin-led demonstration utilizing Intel 5G technologies showed the advancements we’ve made together in creating a robust testbed capable of enabling 5G connectivity across multiple domains.”
The Steel Knight exercise is a critical milestone for the Lockheed Martin led OSIRIS program to provide secure, reliable connectivity for 5G.MIL use cases,” said Munish Chhabra, Radisys Head of Software and Services Business. “Radisys is proud to support Lockheed Martin 5G.MIL objectives with our suite of commercial technologies, starting with 5G FR1/FR2 Connect RAN IAB Donor-Relay Node, 5G Core software and in future via 5G NTN, enabling reliable connectivity in challenging environments.”
What’s Next?
The OSIRIS program will complete its delivery of the supporting equipment and remaining documentation to include test results, user guides, and final reports from the experiment. Further testing and experimentation with infrastructure will also allow for the connection of various 5G-ready user devices, sensors, vehicles and endpoints to explore the military utility of commercial 5G technologies and pave the way for onboarding of new technologies.
Background
- Lockheed Martin was awarded the OSIRIS contract in 2021 as a $19.3 million Prototype Project Agreement (PPA) to create a 5G communications network infrastructure testbed for expeditionary operations experimentation for OUSD (R&E) and the U.S. Marine Corps.
- The OSIRIS testbed is a key initiative of Lockheed Martin’s 5G.MIL® programs which are positioned to help its customers field, scale and integrate 5G technology rapidly and affordably across all operations on land, water, in air, space and cyber.
- The delivery of the Phase 1 Initial Prototype 5G testbed marked the beginning of 20 months of mobile network experimentation.
- In Phase 2, the USMC and Lockheed Martin team leveraged the 5G testbed to conduct four distinct experiments, called mission sprints, using different 5G use-case applications within the context of EABO doctrine.
- Throughout Phase 2, lessons learned during the mission sprints were used to drive further 5G application enhancements to address opportunities for improved performance and utility in anticipation of Phase 3 and the Steel Knight capstone demonstration.
- Phase 3, the Steel Knight demonstration, added elements of field user assessments by Fleet Marine Forces to complement the data captured in previous phases.
(Source: ASD Network)
06 Feb 25. No Excuses. Christmas Day turned to disaster last December when Azerbaijan Airlines flight 8243 slammed into the ground. 67 souls were aboard the Embraer E190AR airliner and 38 died when the aircraft crashed near Aktau International Airport on Kazakhstan’s Caspian Sea coast. The flight had commenced from Heydar Aliyev International Airport in Baku bound for Grozny, southwest Russia. In this month’s newsletter we analyse the electromagnetic elements of the disaster in our Someone had Blundered article. Worryingly, the crew of flight 8243 reported losing GNSS (Global Navigation Satellite System) PNT (Position, Navigation and Timing) signal reception after entering Russian airspace. Survivors reported an explosion with shrapnel striking the aircraft; consistent with a Surface-to-Air Missile (SAM) detonation. The crew declared an inflight emergency and headed to Aktau. Tragically, the aircraft never made its destination, crashing three kilometres (1.6 nautical miles) from the airport. Reports noted that Azerbaijani investigators blamed a Russian Pantsir-S1 (NATO reporting name SA-22 Greyhound) for attacking the aircraft. GNSS PNT jamming was also blamed for disrupting the aircraft’s Automatic Dependent Surveillance-Broadcast (ADS-B) transponder transmissions. Russia’s President Vladimir Putin apologised, calling the crash a “tragic incident” but took no responsibility. Instead, he blamed Ukrainian air attacks targeting Grozny as necessitating high levels of alert by Russian air defenders. Russia has form when it comes to shooting down airliners: On 17th July 2014, Malaysian Airlines flight 17 was destroyed down by a Russian 9K37 Buk (SA-11 Gadfly/SA-17 Grizzly) SAM system over Ukraine. All 298 people onboard were killed. The 9K37 had been deployed into Ukraine in support of Russia’s initial 2014 invasion. It is hard to find any excuses for Russia’s latest destruction of a civilian airliner. That air defenders are on a state of alert because of Russia’s invasion and occupation of Ukrainian territory is understandable. However, enhancing local defences cannot be done at the expense of civil air navigation safety. Jamming GNSS PNT signals, which badly affects GNSS-dependent ADS-B transmissions, is reckless. Launching a SAM at an airliner is unforgivable. (Source: Armada)
04 Feb 25. Not Listening Anymore. Controlled Reception Pattern Antennas are important capabilities in the fight against GNSS PNT jamming. They can null areas where GNSS jamming maybe coming from reducing the degradation such attacks can cause to navigation. Controlled Reception Pattern Antennas (CRPAs) have been removed from the United States government’s International Traffic in Arms Regulations (ITAR) control, official documents have revealed. Having been removed from ITAR strictures, CRPAs will now be classified under less restrictive Export Administrative Regulations (EARs). Whereas ITAR is administered by the US Department of State, EARs are the responsibility of the Department of Commerce. The news is a step forward in helping safeguard users against Global Navigation Satellite System (GNSS) Position, Navigation and Timing (PNT) signal spoofing and jamming. GNSS jamming refers to electronic attack tactics to deny a PNT signal to a GNSS receiver. GNSS spoofing relates to the signal’s manipulation to convey false information. Deliberate disruption to GNSS PNT signals is a growing problem. On 20th January Nkom, Norway’s telecommunications regulator, revealed it had detected incidents of GNSS spoofing in the country’s airspace.
Low power signals
CRPAs are an innovative technology. An informative article by everythingrf.com explains that CRPAs are adaptive beam steering antennas. This means the antenna can adjust the direction from which it receives signals. Known as creating ‘nulls’ this process lets the antennas ignore dubious signals coming from a specific direction. Suppose an unusually powerful PNT-like signal is detected by a GNSS receiver coming from a bearing of 45 degrees. PNT signals are notoriously weak by the time they reach Earth, usually with an amplification of circa -125 decibels/dB. An unusually powerful signal should trigger suspicion.
Decibels measure signal amplification. In RF engineering, the closer a signal is to zero decibels, the stronger it is and hence the easier it can be for a radio antenna to receive. GNSS PNT signals use radio waves usually on frequencies of between 1.1 gigahertz/GHz and 1.6GHz. One GNSS PNT jamming technique involves transmitting much stronger, but fake, PNT signals towards a targeted GNSS receiver. The strength of these false PNT signals can wash out the real signal, preventing the receiver from obtaining the latter. False PNT signals can also be modulated with fake information, primarily false timing signals. Navigation is a function of measuring speed and direction over distance. An accurate timing signal derived from atomic clocks equipping GNSS satellites and transmitted as part of the PNT transmission is essential. Transmitting fake PNT signals into a GNSS receiver can cause the system to develop and display navigation errors.
In our above example, we have assumed that the GNSS receiver is obtaining false PNT signals from a bearing of 45 degrees relative to the receiver’s position. The unusually high power level of the false PNT signal is eliciting suspicion from the GNSS receiver’s processor. The system takes remedial action and blocks out a ‘slice’ of coverage between 40 degrees and 50 degrees allowing the receiver to ignore the fake signal. The CRPA simply no longer monitors that azimuth for PNT signals. The GNSS receiver can still obtain PNT signals, but not from the direction of where the fake transmissions are coming from. The asset of the CRPA is it performs this blanking electronically, making it highly responsive to the appearance of a fake signal. US government documents say such antennas can response thus in less than one second. Moreover, other directions from where additional fake signals maybe coming from can be blanked out.
Share and share alike
In the words of the official US government documents lifting the ITAR restrictions on CRPAs, “certain anti-jam antennas no longer provide a critical military advantage.” Some CRPAs will remain under ITAR restrictions as the US Department of Defence “seeks to control only the most sensitive and effective anti-jam antennas in (the) USML (US Munitions List).” Furthermore, “in removing CRPAs for PNT (from ITAR restrictions), the Department intends to facilitate civil global navigation system resiliency.”
As illustrated by recent incidents involving GNSS jamming, the danger of such occurrences is not limited to military GNSS users. Civilians are also at risk and air travel can be particularly affected. Air Traffic Control (ATC) secondary surveillance radar protocols like the Federal Aviation Administration’s Automatic Dependent System-Broadcast (ADS-B) depend on GNSS PNT signals. These signals help an aircraft determine its position when out of ATC primary surveillance radar range. Protocols like ADS-B let the aircraft’s position be shared with air traffic controllers via its transponder following SSR interrogation.
Unavailable or false PNT signals do not prevent an aircraft from navigation safely. Other techniques like radio navigation and dead reckoning are provide redundancy and prevent single points of failure. However, false PNT signals may hinder ATC efficiency with the risk of attendant flight delays. Some airports also require GNSS PNT signals for approach and landing procedures. This was the case for Tartu Airport in southern Estonia. In April 2024 Finnair was forced to suspend flights between Tartu and Helsinki as Russian GNSS jamming was affecting the PNT signals pilots relied upon to land at the airfield. The airport has since modified its landing and approach procedures so they no longer depend on GNSS transmissions.
Sharing the availability of CRPAs will help improve navigation safety by outflanking GNSS PNT attacks. Moreover, US companies who provide formally ITAR-controlled CRPAs can now do so under a much less restrictive regime. (Source: Armada)
05 Feb 25. Architectural Award. The ISA programme is focused on sensor fusion by simplifying the protocols sensors use to share their data, while breaking down stovepipes to ease data sharing and improving data sharing security. US Army electronic support capabilities will take an important step forward with the realisation of the Integrated Sensor Architecture. The US Army’s Integrated Sensor Architecture (ISA) first emerged in the public domain in 2014. In the words of official US government documents explaining ISA, the architecture is “an interoperable solution that allows for the sharing of information between sensors and systems in a dynamic tactical environment.” Sensor fusion and intelligence sharing is a vital element of the US Department of Defence’s (DOD) ongoing Combined Joint All-Domain Command and Control (CJADC2) initiative. CJDAC2 is the manifestation of the DOD’s embrace of the Multi-Domain Operations (MDO) philosophy. Disparate sensors can plug into ISA and share their information. Information shared with ISA can be fused into intelligence and distributed to those who need it.
Programme goals
The ISA effort is managed by the Army’s Programme Executive Office for Intelligence, Electronic Warfare and Sensors (PEO IEWS). PEO IEWS documents seen by Armada summarised the existing challenges concerning Army sensor data sharing. Firstly, sensors might use different proprietary protocols to move data from the sensor to the user. This can create stovepipes as information shared using one protocol might not be easily compatible with another. As the PEO IEWS document notes, data may be encoded in Variable Message Format (VMF), Joint Interface Control Document 4.2 (JICD 4.2) or CMOSS languages to name three. CMOSS translates as the Command, Control, Communications, Computer and Cyber Intelligence, Surveillance, Reconnaissance Modular Open Suite of Standards. JICD 4.2 is used for intelligence sharing by the Five Eyes nations of Australia, Canada, New Zealand, the United Kingdom and the United States. VMF is a tactical military information message format used by NATO (North Atlantic Treaty Organisation). Connections between sensors and command and control systems might not always have redundancy should links become congested or contested. Sensor data protocol security classification levels may also differ.
These concerns are being addressed by ISA’s realisation which will develop sensor data sharing protocols that are, in the words of the PEO IEWS document, “modular and adaptable”. Encryption and authorisation will help enhance sensor data security, sensor alerts and dynamic data processing. The later relates to the pace at which data can be received, analysed and shared. At the heart of the ISA approach is a desire to improve sensor-to-shooter response times. The documents stress that the ISA approach will be suitable for all sensors, including those collecting Signals Intelligence (SIGINT).
Work is underway getting ISA capabilities into the hands of troops. In early January QinetiQ was awarded a task order worth $31.5 by the PEO IEWS to advance the ISA sensor and system interoperability. The company told Armada, via a written statement that the “ISA is fundamentally a data model and application programming interface framework that allows for sharing sensor and system data dynamically across networks.” Essentially, ISA “operates with a single semantic data model across all sensor types and security enclaves, enabling sensors to be interoperable without requiring point-to-point connections. This provides dynamic discovery of sensor capabilities without requiring pre-knowledge of the systems.” The gooddata.com website provides a useful definition of semantic data models which “describe objects in a database and their relationship to one another in their specific application environment.”
Into service
PEO IEWS documents continued that ISA’s full operational capability is expected in 2025. QinetiQ said it will support “the design, development and integration activities for the ISA programme.” Specifically, “we are collaboratively working to enhance sensor management, collection management, data reduction, and intelligent processing capabilities that enable seamless data sharing across battlefield networks. The task order is expected to last five years and will be responsive to US Army needs: “The work will evolve based on the needs of the U.S. Army customer and future requirements for enhanced data sharing across battlefield networks.” The company added that it will perform this work in the United States in conjunction with the US Defence and Counterintelligence Security Agency.
The ability to easily federate and distribute disparate data from disparate sensors marks an important step forward for US Army sensor fusion, particularly regarding SIGINT data. Accelerating the pace at which this data can be captured and shared is vital if hostile emitters are to become aimpoints. ISA’s realisation will be an important capability in the quest for operational and tactical electromagnetic superiority and supremacy. (Source: Armada)
06 Feb 25. Someone had Blundered. The loss of an Azerbaijan Airlines aircraft during a routine flight from Baku to Grozny on 25th December raises some troubling questions about Russian air defence command and control. Azerbaijan Airlines flight 8243 from Baku to Grozny in southwest Russia never reached its destination. Instead, the Embraer E190AR airliner crashed at 10.28 Azerbaijan (AZT) time on 25th December, hitting the ground three kilometres/km (1.9 miles) from Aktau International Airport on Kazakhstan’s Caspian Sea coast. The aircraft had left Baku at 07.55AZT, according to reports, bound for Grozny International Airport in southwest Russia. At around 08.20AZT the aircraft entered Russian airspace and soon after the crew reported the loss of Global Positioning System (GPS) PNT (Position, Navigation and Timing) signal reception. GPS, like most Global Navigation Satellite Systems (GNSSs), transmits PNT signals on frequencies of between 1.1 gigahertz/GHz and 1.6GHz.
Theirs not to make reply
The loss of the GPS signal had a knock-on effect on the aircraft’s Automatic Dependent Surveillance-Broadcast (ADS-B) transmissions. ADS-B responds to interrogation challenges from Air Traffic Control (ATC) Secondary Surveillance Radars (SSRs). When challenged the aircraft’s SSR transponder will squark on frequencies of between 978 megahertz/MHz and 1.090GHz. ADS-B information conveys several details about the flight including the aircraft’s identity, route and position. The latter factor is derived from the aircraft’s GNSS PNT receiver. With this information unavailable, it appears the aircraft was unable to share information on its location. The loss of the GPS signal was reported by the crew to air traffic controllers. According to flightradar24, the aircraft stopped sending GPS data between 08.25AZT and 08.37AZT. From 08.37AZT until 08.40AZT flight 8243 was transmitting incorrect position information. GPS transmissions stopped once more between 08.40AZT and 09.03AZT. They briefly reactivated between 09.03AZT and 09.04AZT before another gap in transmissions which lasted until 10.07AZT. From 10.07AZT until the crash at 10.28AZT the aircraft was transmitting correct GNSS information. Reports on 26th December by the Associated Press alleged that GPS jamming may have been a contributing factor for the crash.
Analysis performed by the gpsjam.org website reveals that Grozny, and its surrounding area, was subjected to high levels of GNSS interference on 25th December 2024. Grozny International Airport is to the north of the city and would have been subjected to that interference. The interference has been blamed on Russian GNSS jamming above the city and its environs. Russian authorities acknowledged that GNSS jamming was being performed at the time to protect the city against Ukrainian kamikaze Uninhabited Aerial Vehicle (UAV) attack. Jamming and spoofing the incoming GNSS PNT signals UAVs may rely on to navigate to their targets is a standard counter-UAV tactic. This may explain why flight 8243 lost the GNSS signal, possibly because of jamming, and then transmitted incorrect GNSS information, possibly because of Russian GNSS spoofing.
Theirs not to reason why
GPS jamming may not have been the only contributing factor. Pictures of the aircraft’s wreckage show the fuselage pockmarked with holes consistent with shrapnel. Fragmentation warheads employing shrapnel are commonly used in Surface-to-Air Missiles (SAMs). Euronews reported on 24th January that the aircraft was downed by a 96K6 Pantsir-S1 (North Atlantic Treaty Organisation reporting name SA-22 Greyhound) series short-range air defence system. Open sources state that the Pantsir-S1 employs 57E6 radio frequency/optically guided SAMs equipped with high-explosive fragmentation warheads.
The Pantsir-S1 is equipped with two radars; one of which is used for target acquisition and the other for fire control. Target detection is provided by the system’s 2RL80 S-band (2.3GHz to 2.5GHz/2.7GHz to 3.7GHz) radar which has a range of circa 27 nautical miles/nm (50km). Once a target is detected, engagement is managed using the system’s 1RS2-1 X-band (8.5GHz to 10.68GHz) and Ku-band (13.4GHz to 14GHz/15.7GHz to 17.7GHz) radar. The 1RS2-1 has a 15nm (28km) range. Sources suggest that the Pantsir-S1 is fitted with an integral Identification Friend or Foe (IFF) interrogator embedded within the 2RL80 radar. The interrogator operates in the Ultra High Frequency (UHF: 300MHz to three gigahertz) waveband. This should mean that the 2RL80, and hence the Pantsir-S1, easily receives ADS-B transmissions. However, if these ADS-B transmissions are being disrupted through jamming, can they still be received by the IFF?
Was there a man dismayed?
If the track on the radar screen of a Pantsir-S1 air defender is showing no ADS-B information, or that information is shown as incorrect, is that air defender going to presume the track is hostile? Armada has performed analysis of Russia IFF systems in the past and noted some of their shortcomings. For example, Russia’s Parol IFF system was said to be unable to receive civilian SSR squarks. Friendly military aircraft will have their Parol IFF transponders activated and will be responding positively to friendly interrogations. Hence, all aircraft not responding to the Parol interrogations are assumed as hostile, even if they cannot answer a challenge.
If GNSS jamming did prevent the Pantsir-S1 crew receiving ADS-B squarks, there are other ways that an aircraft’s identity can be verified. Simply having a laptop with a feed from a site such as flightradar24 could be helpful. Matching radar track data of the local area with the website feed may have informed the Pantsir-S1 crew that the aircraft was friendly. However, if the airliner’s transponder was unable to relay correct ADS-B information, this could have affected the quality of track data the website was showing. When playing back the flight on flightradar24, there is a gap between 08.07AZT and 10.07AZT. During this time no information regarding the flight appears to be available. Does this mean that the aircraft simply looked like an unidentified track to Russian air defenders and hence a potential target?
This image from flightradar24.com’s website shows the path of flight 8243’s journey from take-off in Baku until its crash near Aktau International Airport. The white box in the top lefthand side of the picture shows where the aircraft’s ADS-B data become unreliable possibly because of suspected GNSS PNT jamming and spoofing.
Even if this had been the case, why was someone in the local Russian air defence command and control structure responsible for protecting Grozny and its locale not monitoring ATC chatter? A simple air-band radio, with a suitably sited antenna, would have picked up radio traffic between the aircraft and air traffic controllers in range. Flight 8243’s crew warned that they had lost GPS navigation after entering Russian airspace. Surely this should have prompted an immediate ‘weapons tight’ order to Russian air defenders given that either incorrect ADS-B information was being shared, or that this information was unavailable for a particular flight? Were local air defenders warned that GNSS jamming was taking place and that this may affect civilian ADS-B transmissions? The loss of flight 8243, and 38 of its souls, has prompted many questions, whether Russian authorities provide answers remains to be seen. (Source: Armada)
05 Feb 25. Fast-track armed forces recruitment launched to boost UK cyber defence. Armed forces recruits will be fast-tracked into specialist roles to tackle the growing cyber threat to the UK via a new recruitment scheme.
- New ‘cyber pipeline’ will see recruits complete bespoke training within a matter of weeks.
- Successful applicants will be in operational roles by the end of 2025, strengthening UK response to emerging cyber threats and national security.
- The scheme is the latest government action to tackle recruitment and retention challenges in the armed forces and deliver on the Plan for Change.
The new, bespoke entry route for aspiring cyber professionals and those with existing digital skills will see basic training reduced from 10 weeks to around one month, after which recruits will undergo 3 months’ specialist training. This will be conducted at the Defence Cyber Academy in Shrivenham.
By the end of 2025, new recruits will be embedded into operational roles, either securing defence’s networks and services at the digital headquarters in Corsham, or conducting cyber operations to counter those who would do the UK harm as part of the National Cyber Force.
Serving to enhance the UK’s ability to conduct operations in cyberspace, specialist recruits will receive one of the highest armed forces starting salaries of over £40,000, with opportunities for additional skills-based pay as they gain expertise and experience.
It comes as the Ministry of Defence has had to protect UK networks from increasing numbers of ‘sub-threshold’ attacks – more than 90,000 in the last two years.
In an increasingly volatile world where technology is rapidly advancing, the nature of warfare is changing. Cyber capabilities present the threat of hybrid attacks which the UK must be able to protect against to ensure our national security and deliver on the government’s Plan for Change. It is paramount that the armed forces are fit to face the threats of the future.
Minsters will argue today that cyber represents “a new front line”, with UK military systems targeted every day by adversaries. The new recruitment programme has been developed to bolster capabilities in response to these growing threats amid a global shortage of cyber talent. Looking ahead, the government’s Strategic Defence Review is closely assessing the threats we face, including the technological developments of the future.
The launch of the new scheme is the latest action by the government to tackle the recruitment and retention crisis in the armed forces.
Secretary of State for Defence, John Healey MP, said:
Fast tracking cyber warriors into our military will help ensure our Armed Forces are better equipped to face our adversaries in the 21st century and defend the country from the changing threats we face.
After years of hollowing out, our government is making Britain secure at home and strong abroad, delivering on our Plan for Change and the hardworking British people.
Launching the scheme on a visit to Corsham, the Minister for the Armed Forces, Luke Pollard MP, said: “With more than 90,000 cyber-attacks on UK military networks over the last two years, it is essential that we step up our cyber defence, fast-tracking the brightest and the best cyber specialists to help protect the UK and our allies. We are in a new era of threat, with cyberspace as a new front line. Our government will deliver for defence by boosting recruitment efforts, cementing our national security as the foundation of our Plan for Change.”
The new initiative seeks to attract individuals with relevant aptitude, interest, or existing skills into cyber careers, while still offering the unique benefits of a career in the armed forces.
Since July last year, ministers have delivered the largest pay rise for service personnel in over 20 years – including a 35% pay increase for new recruits – scrapped more than 100 outdated policies that slow down or block recruitment, and progress through Parliament legislation to establish an Armed Forces Commissioner to champion Service Personnel and their families.
Recruitment into cyber roles in 2025 will initially be through the Royal Navy and Royal Air Force, with the British Army joining for subsequent recruitment campaigns from early 2026.
04 Feb 25. Cyber operation highlights elevated security risks from Chinese state-sponsored groups. On 4 February, the cyber security company Fortinet reported that the Chinese state-sponsored group ‘Evasive Panda’ has been conducting a reconnaissance and information-theft operation against global entities since at least November 2024. Upon obtaining access to targeted systems, Evasive Panda deploys a malware dropper to check whether the device is already compromised before executing its own malware. It then checks the system’s privileges to execute additional malicious payloads including a secure shell (SSH) library that acts as a backdoor. The backdoor conducts system reconnaissance, exfiltrates sensitive information and then remotely executes commands after establishing communication with actor-controlled infrastructure. Evasive Panda injects the backdoor into the system’s SSH daemon to obfuscate malicious traffic and evade detection, showcasing the sophistication of the group. The group typically conducts cyber espionage operations as well as supply chain attacks to obtain strategic information, highlighting elevated security and information theft risks in the long term. (Source: Sibylline)
05 Feb 25. Assac Networks, a member of the Aspis Technologies Group, and a specialized provider of cyber solutions for the comprehensive protection of communication devices used by government agencies, defense, and commercial organizations, announced today the acquisition of a significant contract from a government organization in South America. The agreement involves the implementation of ASSAC’s cutting-edge ShieldiT system, designed to provide robust cyber defense for the organization’s entire communication infrastructure. The ShieldiT system will deliver a comprehensive security solution, including managed secured communications for smartphones and desktop devices, a monitored threat-safe messaging system, and integration with the organization’s telephony switch, creating an all-encompassing secure environment. As Assac Networks’ flagship product, ShieldiT offers unified, managed anti-hacking and anti-tapping capabilities for smartphones, recognized as the most vulnerable points in organizational networks. Its advanced features include real-time link analysis, behavioral analysis, network layer protection, and application risk analysis, protecting against prevalent mobile threats such as mobile phishing and QR code phishing.
Shimon Zigdon, CEO of Assac Networks, emphasized the critical nature of mobile security: “Recent studies indicate that most ransomware attacks on organizations originate through employees’ mobile phones connected to management systems and organizational emails. ShieldiT stands as the only application offering complete protection against both tapping and hacking attempts, addressing the urgent need for comprehensive mobile security in government and enterprise environments. This agreement underscores our commitment to expanding ASSAC’s solutions in the governmental market. As a company specializing in cyber protection services for government, corporate, and cellular subscribers, we are delighted to extend our offering globally and strengthen our position in the South American market.”
The implementation of the ShieldiT system is scheduled to commence in the coming months, marking a significant step forward in the organization’s cybersecurity posture. This contract reinforces ASSAC Networks’ position as a leading provider of cybersecurity solutions for government and enterprise clients worldwide.
About Assac Networks
Established in 2011 by seasoned veterans of the Israeli defense and security industries, Assac Networks develops and implements unique end-point security solutions. The company develops, integrates, and markets network-forensic and security products and solutions in the fields of mobile and landline communication – as well as cyber protection systems for ISPs, mobile carriers, governmental agencies, and commercial organizations. Among its clients are law enforcement and intelligence agencies and large enterprises around the world.
04 Feb 25. The L3Harris Technologies (NYSE: LHX) all-digital electronic warfare (EW) suite, Viper Shield™, has completed its first flight in a single-seat Block 70 F-16 operated by the 412th Test Wing at Edwards Air Force Base, California. Viper Shield provides the most advanced EW capability to F-16 fighter fleets for six international partners.
“This flight launches the latest capability enhancement for the F-16 and our warfighters. The Viper Shield system combined with a Block 70 airframe creates a leap in capability compared to the traditional Block 50 Viper I grew up flying,” said Maj. Anthony Pipe, F-16 Experimental Test Pilot, U.S. Air Force. “The EW advancements this system brings will ensure pilots flying these aircraft continue to make it home.”
The flight included a series of risk reduction tests related to the mission computer and other avionic subsystems compatibility, as well as interoperability with the APG-83 active electronically scanned array (AESA) fire control radar.
“Our building block approach to test hardware and software in labs, demonstrate functionality in dense radio frequency environments and validate the EW system on the ground prepared us for Viper Shield’s successful first flight,” said Ed Zoiss, President, Space and Airborne Systems, L3Harris. “With this milestone, we are ready to continue flight testing and deliver systems in late 2025 as Viper Shield is the only advanced EW solution that is funded and in active production for international F-16 partners.”
Viper Shield is a low-risk, low-cost system that counters modern radar threats with immediate detection and advanced jamming responses to disrupt the adversary’s kill chain. Unlike other EW system providers, Viper Shield will integrate across all F-16 Blocks with minimal modifications to the aircraft, and it is fully configurable with both the current Mission Modular Computer and the Next Generation Mission Computer. (Source: BUSINESS WIRE)
31 Jan 25. South Asia: Data-theft campaign highlights elevated security, information-theft risks from APT group. On 29 January, the cyber security company Palo Alto reported that a new advanced persistent threat (APT) group (‘CL-STA-0048’) targeted high-value government and telecommunications organisations in South Asia in an information-theft campaign between May and October 2024. CL-STA-0048 reportedly exploited software vulnerabilities in three internet-facing services as initial attack vectors. The group then deployed the ‘PlugX’ backdoor to achieve persistence within compromised systems, before executing a structured query language (SQL) query for data exfiltration. It also employed domain name system (DNS) requests to send stolen data to threat actor-controlled infrastructure, as well as multiple simultaneous payloads to enhance detection evasion. The rarity of these techniques points to the group’s resources and high sophistication. CL-STA-0048’s targets and modus operandi resemble those of the Chinese-speaking group ‘DragonRank’, which suggests a possible affiliation with Chinese state-backed cyber threat actors. The report underscores the elevated long-term security and information-theft risks facing high-value entities in the South Asia region. (Source: Sibylline)
04 Feb 25. Rheinmetall successful with TaWAN LBO for the Bundeswehr – digitalisation of the armed forces is picking up speed. Rheinmetall has been awarded a contract in another important large-scale project for the Bundeswehr in the field of digitalisation. As the prime contractor, Rheinmetall Electronics GmbH will be responsible for setting up an integrated communication network, the so-called ‘Tactical Wide Area Network for Land Based Operations’ (TaWAN LBO). The volume of the awarded framework-contract for a deployable, platform-based communication/directional radio management system is worth several billion Euro. The framework-contract for the procurement of TaWAN LBO has a term of 10 years and was signed by representatives of the Federal Office for the Equipment, Information Technology and In-Service Support of the Bundeswehr (BAAINBw) and Rheinmetall Electronics GmbH. At the same time, an initial order worth €1.88bn gross was placed under the framework-contract to equip a division of the Bundeswehr. Delivery of this communications network will take place between the end of 2026 and the end of 2029.
Armin Papperger, CEO of Rheinmetall AG: “We are thankful for the great trust that the Bundeswehr is placing in us regarding its ambitious digitalization efforts. Now that the Bundeswehr will be receiving TaWAN LBO and D-LBO from a single source, the conditions for a synchronized coordination concerning the introduction of both systems are given. It is our ambition to provide the Bundeswehr with a seamless and reliable communication network within the given timeframe – one which can be considered a flagship of digitalisation in Germany”.
The core function of TaWAN LBO is to provide an open transport network for Federated Mission Networking (FMN) based on Protected Core Network (PCN) to connect the forward tactical D-LBO networks to the rear-echelon core network CIR. Following the contracts awarded at the end of 2024 as part of the Bundeswehr’s Digitalised Land-Based Operations (D-LBO) programme, TaWAN LBO will be a further milestone for the end-to-end command capabilities of the armed forces. In connection with D-LBO, the TaWAN LBO network is to ensure connectivity deep into the rear area at high data rates. As part of the TaWAN LBO project, Rheinmetall is also supplying protected 8×8 HX trucks from Rheinmetall MAN, which serve as carrier vehicles for the large directional radio systems and are equipped with mobile high extendable antenna masts. One of the vehicles will hold the mast system, another will carry the 20-foot functional container with workstations, servers and other equipment. Rheinmetall MAN will be delivering a total of 102 vehicles. Other vehicle platforms are used in conjunction with smaller mobile extendable antenna masts (small directional radio system). A software-based directional radio management system is part of the overall solution which will ensure the functionality of the directional radio system, and can be used to plan and execute operations.
04 Feb 25. Thales Unveils its Cyber Trends 2025 Report.
In its latest report on 2025 cybersecurity trends, Thales’ Cyber Threat Intelligence team highlights the main trends that will shape cybersecurity in the coming year and calls on organizations to strengthen their resilience against these new threats.
Increased sophistication of attacks and growing threats to businesses: Key cybersecurity trends for 2025:
- Targeted ransomware and extortion: Cybercriminals refine their strategies by exploiting sensitive company data to maximize their financial gains.
- Supply chain vulnerabilities: Attacks against suppliers and partners are multiplying, endangering entire business ecosystems.
- Exploitation of connected devices (IoT): With the proliferation of connected devices, hackers have a broader attack surface, necessitating enhanced network protection.
- Threats from state actors and hacktivists: Espionage and political destabilization are becoming key strategies for some states, while hacktivists exploit vulnerabilities to amplify their ideological messages.
- Artificial intelligence, opportunities and risks: AI is a major lever for both attackers and defenders. Its use in cyberattacks requires appropriate countermeasures.
- Software vulnerabilities and exploitation: Attacks targeting open-source software and unpatched vulnerabilities remain a major concern.
In the face of escalating cyber threats, an adaptive and multi-layered approach is essential. The adoption of new technologies, continuous monitoring of IT and OT systems, and increased collaboration between the public and private sectors will be crucial pillars to preserve the integrity of IT systems.
To download our Cyber Trends 2025 report: White Paper – Cyber Trends 2025
https://lp.thalesgroup.com/cybertrends2025
31 Jan 25. Cyber Update Key points.
- A large-scale cyber operation underscores the elevated information-theft risks stemming from the Russian cyber criminal group ‘Crazy Evil’ (see Sibylline Cyber Daily Analytical Update – 27 January 2025 and our Technical analysis below).
- A spike in third-party data breaches underscores the elevated security and information-theft risks facing various key sectors (see Sibylline Cyber Daily Analytical Update – 28 January 2025).
- A new highly advanced backdoor (‘TorNet’) points to the elevated security and financial risks facing users in Germany and Poland (see Sibylline Cyber Daily Analytical Update – 29 January 2025 and our Technical analysis below).
- A new multi-pronged cyber operation (‘Phantom Circuit’) highlights the heightened security and financial risks stemming from the North Korean state-sponsored group ‘Lazarus’ (see Sibylline Cyber Daily Analytical Update – 30 January 2025).
- A data-theft campaign against South Asian telecommunications and government entities highlights the increased security and information-theft risks from the advanced persistent threat (APT) group ‘CL-STA-0048’
Technical analysis of weekly stories
The Russian cyber criminal group Crazy Evil has targeted high-value cryptocurrency, technology and gaming influencers in at least ten highly sophisticated scam operations. The operations typically start with the promotion of fake services (such as fake asset management platforms, artificial intelligence (AI)-operated productivity and/or virtual meeting software) on social media to trick potential victims into clicking on a malicious link and/or a malicious file installer. This then covertly installs malware onto compromised systems, enabling threat actors to steal credentials and digital assets, as well as to hijack user accounts for financial profit. The group’s toolkit encompasses highly advanced information-stealing malware such as ‘Stealc’ and ‘Atomic macOS Stealer (AMOS)’. Crazy Evil comprises six sub-groups (‘AVLAND’, ‘TYPED’, ‘DELAND’, ‘ZOOMLAND’, ‘DEFI’, and ‘KEVLAND’) that manage their own phishing pages, pointing to the overall sophistication of the group’s enterprise. The group boasts approximately 3,000 followers on two public Telegram channels; it uses three separate channels as discussion forums and to organise operations. It also continues to recruit more affiliates via a complex recruitment process which we assess further highlights the scale and complexity of Crazy Evil’s operations.
A new backdoor (TorNet) has been used to target users in Germany and Poland in a financially motivated campaign since at least July 2024. The campaign uses phishing emails as initial attack vectors to trick potential victims into opening a malicious .GZIP attachment. The email impersonates financial institutions, logistics firms and/or manufacturing companies, purporting to send money transfer confirmations and/or order receipts. Once opened, the attachment executes the ‘PureCrypter’ malware onto compromised systems to establish persistence and covertly download the main TorNet payload. PureCrypter loads directly onto the system’s memory and conducts several anti-analysis checks upon deployment. It also disables network connections before executing TorNet, underscoring the sophistication of its detection-evasion capabilities. Subsequently, TorNet establishes communication with command-and-control (C2) infrastructure and connects to the Tor network. It also conducts additional anti-analysis checks similar to those of PureCrypter, emphasising the highly obfuscated nature of this operation.
Some non-exhaustive recommendations to mitigate against these threats include:
- Monitor devices and networks for suspicious activity
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communication to malicious IP addresses associated with known malware
- Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
- Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering
Our cyber word(s) of the week: The onion router (Tor) network. (Source: Sibylline)
31 Jan 25. Ready for the Future NAVWAR: IAI has Successfully Integrated its ADA GNSS Anti-Jamming System With the M-Code GPS Receiver. IAI achieved a major milestone with the successful integration of the ADA Anti Jamming system, with the new M-code GPS military receiver for International customer. This integration enables the ADA system to deal with evolving and emerging threats to GPS signals. The ADA system, designed to protect GPS signals from RF interference, has successfully integrated with M-Code GPS receiver, providing a powerful combination for enhanced GPS immunity. In ground tests and flight tests, the ADA system together with M-code receiver has demonstrated its effectiveness in suppressing attacks on GPS, making it a trusted choice for military users all over the world.
President and CEO of Israel Aerospace Industries, Boaz Levy: “The modern battlefield is saturated with increasingly sophisticated Global Navigation Satellite System (GNSS ) jamming systems that are posing a growing threat to military operations worldwide. As Israel’s Center of Excellence for Navigation, we take pride in our ADA system, a resilient navigation solution to meet emerging GNSS jamming challenges. Like the Arrow-3 system developed some years ago, which is still relevant to current threats, ADA was designed flexibly to address both current and future challenges. Achieving the milestone of M-Code compliance will enable our customers to have a robust navigation solution for their most up-to-date operational requirements. Systems produced by IAI have demonstrated excellence in handling the challenges of the modern battlefield, and we are confident in their ability also to optimally deal with those in the future.”
Guy Barlev, Executive Vice President of IAI’s Systems, Missiles & Space Group: “By combining the ADA system with M-Code, our solution offers unparalleled protection against both GPS jamming and spoofing threats and takes GPS immunity to the next level. In recent modern conflicts, the ADA GNSS anti-jamming system has proven itself as a reliable and combat-excellence solution. Its robustness and effectiveness have been tested in various operational scenarios, ensuring the continuity of GPS-based operations and maintaining assured Position, Navigation and Time (PNT) for the military platforms. With its proven track record in modern conflicts with thousands of flight hours and the integration with M-Code receiver, this system offers unmatched GPS immunity and combat-readiness, making it the ideal choice for military users.”
The ADA product portfolio, developed by IAI, is compatible with a broad range of satellite navigation systems (GNSS). Its state-of-the-art technology implements multiple mitigation methods and specialized digital signal processing algorithms. The system’s versatility facilitates the integration in numerous platforms. IAI has over 20 years of proven experience in supplying a wide range of GNSS Anti-Jam solutions for the most demanding requirements, and vast experience in integration immune navigation solutions into airborne (manned and UAV), surface, maritime and guided munitions. (Source: ASD Network)

