14 Feb 25. Patria has signed an agreement with Airbus Defence and Space for SIRTAP datalink solution. Patria has signed an agreement with Airbus Defence and Space in Spain to participate in SIRTAP High capability Tactical UAS delivering a wide band line-of-sight datalink solution, covering aerial vehicles and ground systems in series production. The wide-band datalink solution is based on Patria CANDL products. Patria CANDL is designed for secure and jamming resistant communication for applications requiring robust high speed data transfer between UAVs and ground control stations even in the most demanding missions in challenging operational environments.
“We are convinced that Patria CANDL will provide high value for the SIRTAP end-users around the globe. We are glad to be a part of the Airbus’ value chain in the SIRTAP programme“, says Hugo Vanbockryck, Senior Vice President, Market Area Europe of Patria.
Furthermore, Patria CANDL offers low probability of intercept and detection, dynamic networking and beyond line-of-sight capabilities between multiple assets, making it superior also in manned-unmanned teaming. Native IP (Internet Protocol) communication for both payload data and the control protocol enables seamless integration with modern Operational Flight Programs and ground control applications. Patria CANDL is qualified for operation in harsh environments and it is easy to integrate with a wide range of aerial and ground platforms.
12 Feb 25. Doing it for Themselves. Armada’s February Military Communications Newsletter includes an article entitled Supporting Space Autonomy. The piece looks at the European Union’s new Infrastructure for Resilience, Interconnectivity and Security by Satellite programme. IRIS2, as the initiative is known, will provide secure, wideband government and military communications to European Union (EU) member states, both inside and beyond the EU area. Commercial Satellite Communications (SATCOM) services also form part of the IRIS2 remit. The IRIS2 constellation should start providing these services from 2030. The programme will cost the EU taxpayer $6.7bn, the remaining $4 bn required will come from the private sector. This works out at around $15 per EU inhabitant. The advent of IRIS2 could not come at a better moment. Militaries can never have enough connectivity, and EU armies, navies and air forces are no exception. Secure, broadband SATCOM provides line-of-sight and beyond-line-of-sight communications. Better communications mean better and quicker decision-making, translating into better and quicker strategic, operational and tactical action. Strategically, IRIS2’s realisation makes sense. The so-far tepid support of NATO by the new US administration makes it vital that the EU can go it alone if Uncle Sam choses not to help out in the event of a continental crisis. Part of this autonomy is European Union sovereign ownership of force enablers like broadband SATCOM which will help deepen EU military interoperability. Relying on the provision of private sector broadband SATCOM can have its own challenges. Starlink terminals have been provided by SpaceX to Ukraine and have been vital on the battlefield. Nonetheless, SpaceX’s founder, CEO and chief engineer Elon Musk has threatened in the past to deactivate Starlink provision to Ukraine. On at least one occasion the order was allegedly carried out. There are clear and present dangers in allowing secure military SATCOM to be at risk of such capricious actions. Fortunately, IRIS2 places the reigns firmly in the hands of the EU. (Source: Armada)
12 Feb 25. Comtech Telecommunications Corp. (NASDAQ: CMTL) (“Comtech” or the “Company”), a global communications technology leader, today announced the launch of the Company’s new multipath radio (“MPR”) platform. As the first-ever terrestrial high data rate over-the-horizon integrated radio of its kind, MPR will empower first responders, warfighters, and commercial operators with new high data rate communications capabilities on a single antenna agnostic platform. Built on the proven success of Comtech’s next-generation Troposcatter systems, the MPR platform’s multimode functionality, diverse antenna support, and advanced signal processing techniques empower users to establish secure, reliable and resilient communications links in challenging environments where traditional radios struggle. Today, MPR supports line-of-sight (“LOS”), obstructed-line-of-sight (“OLOS”), and beyond-line-of-sight (“BLOS”) scenarios.
“Comtech’s MPR is optimized for on-the-move, at-the-halt, and fixed applications in a flexible, low Size Weight and Power (“SWAP”) terrestrial over-the-horizon communications platform,” said Daniel Gizinski, President of Comtech’s Satellite and Space Communications Segment. “MPR’s functionality and ease of use is a true game-changer for end users, demonstrating the ability to be set up and deployed in less than 10 minutes as well as delivering industry-leading data rates continuously over long distances. The software-defined nature of Comtech’s MPR platform also enables the system to adapt and incorporate new capabilities over time.”
In the past, terrestrial BLOS communications systems were limited due to large size, high-power requirements, and complexity of operation. Leveraging over 40 years of multipath radio technology leadership, Comtech’s MPR is revolutionizing high data rate communications capabilities by providing a rapidly deployable, transportable, low SWAP solution for military and commercial operators.
Comtech’s Multipath Mitigation Technology Advantage:
Today, reliable communications in diverse environments are essential for military and critical infrastructure applications. However, multipath propagation, where radio signals travel along multiple paths before reaching the end user, disrupts signal integrity, causing a drop in communications or total loss of connectivity. Comtech’s MPR solves multipath disruption by a unique combination of diverse techniques, advanced forward error correction, and adaptive coding and modulation, that represent a first for the industry.
Operational Value for End Users:
- BLOS without SATCOM: MPR provides real-time data connectivity over-the-horizon up to 150 miles; this capability can be critical in satellite contested environments or when limited space segment is available.
- Reliable Communications: The MPR ensures clear and consistent communications across echelons, overcoming signal degradation caused by terrain or obstacles.
- Enhanced Situational Awareness: Reliable data exchange facilitates a shared understanding of a variety of scenarios ranging from military operations to disaster response, which is crucial for informed decision-making.
- Improved Interoperability: The MPR is over the air compatible with Comtech’s entire Family of Troposcatter Systems. To enhance network and information interoperability, MPR provides an easy-to-use Layer 2 interface integration package for all IP based MESH and MANET radio networks.
- Common Digital Architecture: MPR is designed to leverage a common digital architecture across the Company’s other product lines, including Comtech’s Digital Common Ground modems.
- Low SWAP: The MPR provides users maximum SWAP flexibility against varied environments. The small footprint and rapid set up provide users with a true expeditionary capability.
- Enhancements: Comtech’s MPR has a series of planned enhancements, including point-to-multi-point, which will allow simultaneous communications to multiple on-the-move platforms and stationary sites, eliminating the need for multiple systems at the hub location.
Recent U.S. Department of Defense Demonstrations Validate MPR Capabilities:
During an initial Joint Service demonstration along Florida’s panhandle, Comtech’s MPR delivered 14 megabits of data continuously over a 101-mile BLOS link using no vertical lift.
During the U.S. Navy’s Silent Swarm 2024 exercise, Comtech’s new MPR platform completed a long-range ship-to-shore connection for an unmanned surface vessel-revolutionizing at-sea command, control, communications, computers, cyber, intelligence, surveillance, and reconnaissance mission support. For more information Comtech’s new MPR platform, please visit our webpage: https://comtech.com/capability/mpr-platform/.
11 Feb 25. High Frequency in the High North. New analysis comes to light regarding high frequency trunk communications used by Russia’s strategic integrated air defence system. Regular Armada readers will be aware of our deep interest in Russian military radar, electronic warfare and communications systems. Our fascination with these capabilities is enabled in no small measure by the work of EW Analytics LLC. Based in the United States, the company uses publicly available information to produce highly respected analysis of Russian military electromagnetic capabilities. EW Analytics LLC regularly shares its analysis, which we summarise for our readers, and you can find some previous examples of our summaries here. The company shared its recent analysis of two High Frequency (HF: three megahertz/MHz to 30MHz) antenna arrays located in Russia’s Arctic region. The Russian military has an Arctic Trefoil installation in the Franz Josef archipelago in the north of the region. Arctic Trefoil installations follow a similar design, ‘Trefoil’ being a reference to the installation’s three-wing building design. Next to the installation are two fenced fields each covering an area of one square kilometre (0.38 square miles). Each field contains an antenna array that EW Analytics LLC has discovered is connected to RPDRUM-1/5 HF radios, the antenna array of interest being referred to as Vh-60/12 in Russian. The analysis continued that these antennas have been installed in a distinctive sloped/inclined configuration intended to increase the directionality of the transmitted signal as compared to conventional HF antenna performance which can be especially problematic in the Arctic. EW Analytics LLC has found that this distinctive sloped/inclined HF antenna array was part of a Russian Arctic-wide HF communication architecture that was proposed circa 2017. This was around the time that Arctic Trefoil became operational. Given that the antennas of this distinctive array are 60 metres (197 feet) in length it is likely that they handle traffic on frequencies of around five megahertz. The orientation of the antennas suggests them pointing south to areas like the Kola Peninsula. The peninsula is 1,550 kilometres (963 miles) to the southwest. It is home to several Russian military installations including Russian Naval Aviation’s Olenya airbase and the Zapadnaya Litsa naval base.
Arctic Trefoil
The Arctic Trefoil facility under examination is collocated with the airbase at Nagurskoye on Alexandra Land, one of the largest islands in the Franz Josef Land archipelago. Adjacent to the Arctic Trefoil is a set of three radomes; the one atop a mast containing a 12A6 Sopka-2 S-band (2.7 gigahertz/GHz to 2.85 GHz) air surveillance radar. EW Analytics LLC speculates that one of the HF radios/antenna arrays may provide trunk communications to share track data gathered by the Sopka-2 radar. The company believes the HF antenna array nearest the Sopka-2 radar is used for this role since it is collocated with an Aviation Guidance Point (AGP). AGPs are the Russian equivalent of Integrated Air Defence System (IADS) control and reporting centres. This HF link could help feed track data into the Leningrad Military District’s (MD’s) IADS. The Leningrad MD’s IADS will develop a Recognised Air Picture (RAP) of the airspace above the military district, and air approaches to it.
This RAP will be shared at the national level to help populate Russia’s strategic RAP covering the air and space above and around the country as far as the radar horizon allows. Whether this HF link is used all the time is unknown. EW Analytics LLC posits that the link may form a back up to trunk satellite communications which may support routine track data sharing. Interestingly, the analysis states that unlocated Russian air defenders have been reported to share track data across HF using Morse Code. Such transmissions are occasionally detected by European-based radio amateurs monitoring Russian high frequency channels. The other HF radio/antenna array at the base is close to the facility’s administrative and accommodation building. EW Analytics LLC deduces that this latter HF radio/antenna array may be used to carry non-tactical traffic.
Future deployments
Additional Arctic Trefoil bases have been constructed for the Russian military; one on Wrangel island in Russia’s far east Arctic region and one on Kotleny island in the country’s central Arctic region. EW Analytics LLC states that, so far, only the Arctic Trefoil facility at Nagurskoye appears to have been equipped with the Vh60/12 HF antenna array; an indication perhaps that this Arctic Trefoil has unique communications requirements. It will be interesting to see if other Arctic Trefoil facilities receive similar HF equipment in the future. Armada will share further details on this subject, and others, as and when they become available from EW Analytics LLC. (Source: Armada)
12 Feb 25. Polish Comms Modernisation. WB Group’s Perad-6010 handheld tactical radio has been approved for use by the Polish military. The transceiver forms part of the Tytan infantry soldier system. The Polish Army is overhauling its tactical radio inventory with a new domestically designed, developed and produced handheld transceiver. The Wojska Lądowe (Polish Army) is moving forward with the modernisation of its tactical communications. In late December, defence24.com revealed that WB Group’s Perad-6010 handheld radio has been approved for acquisition by the country’s Armaments Group procurement agency. The reports continued that the Perad-6010 forms part of Tytan infantry soldier system equipping the army. WB Group’s literature says that the Perad-6010 radio is an ultra-high frequency (300 megahertz to three gigahertz) transceiver. The radio produces one kilowatt of output power. Its narrowband waveform handles data at rates of 75 kilobits-per-second. The integral and universal wideband waveforms move data at rates of between one-megabit and four megabits-per-second. Communications security protocols include frequency hopping at rates of up to 700 hops-per-second plus embedded encryption. The Perad-6010 is cleared to handle North Atlantic Treaty Organisation (NATO) traffic with a restricted classification. As well as equipping the Tytan ensemble WB Group told Armada in a written statement that the radio furnishes the company’s Gladius Uninhabited Aerial Vehicle (UAV). The statement added that initial Perad-6010 deliveries will furnish army manoeuvre units including mechanised infantry and armoured formations. Deliveries will also be made to the force’s missile and artillery units. The company expects the radio to be used by dismounted infantry and specialist troops including UAV crews.
Vehicle programmes
According to WB Group the Perad-6010 is the first individual handheld radio to be introduced into Poland’s armed forces, excluding transceivers equipping the country’s special forces. Plans are afoot by the Polish military to order several thousand of the radios. The company expects deliveries to commence in the middle of 2025, adding that some schedules will depend on other programmes. For example, the Polish military is receiving PGZ Borsuk amphibious infantry fighting vehicles. These vehicles will include Perad-6010 radios, as will forthcoming KTO Rosomak wheeled armoured personnel carriers. The Perad-6010 will become the standard handheld radio in the Polish Army in the coming years. This marks an important modernisation milestone as the force enhances its strength on NATO’s eastern flank. (Source: Armada)
13 Feb 25. Supporting Space Autonomy. The European Union’s (EU) IRIS2 satellite constellation is an important step forward in enhancing the EU’s strategic autonomy while helping to deepen European military interoperability, and command and control. 16th December 2024 marked an important date in the evolution of European Union satellite communications strategic autonomy. That day, the European Commission, the EU’s executive body, signed a concession contract for constructing the Infrastructure for Resilience, Interconnectivity and Security by Satellite provision. Better known as IRIS2, the European Space Agency (ESA) will procure and operate the capability. ESA signed the contract with an industrial consortium known as SpaceRISE. The consortium comprises a trio of companies namely Eutelsat, Hispasat and SES. The satellite constellation will provide secure government and military communications, and commercial links with IRIS2 costing circa $11bn. The EU will provide $6.2bn, $4.2bn will be provided by the private sector with $570.4m coming from ESA. Defence and security considerations are front and centre of IRIS2’s philosophy. The EU’s own documents foresee the constellation playing a “crucial role in transforming the defence and security field, improving border and maritime surveillance, crisis management such as humanitarian aid and protection of essential communications and infrastructure.” The constellation will help support EU external operations while providing deeper European Union military connectivity. The latter point is particularly important from a strategic, operational and tactical Command and Control (C2) perspective. Improving EU military C2 is vital for external operations and for protecting the European Union against external aggression. The EU currently leads military missions in Mozambique, the Central African Republic, Somalia and Ukraine. EU military operations are underway in Bosnia-Herzegovina; the Red Sea, Indian Ocean and the Persian Gulf, in the Mediterranean and off the Horn of Africa.
Architecture
Laurent Jaffart, ESA’s director of connectivity and secure communications and head of the ESA’s European Centre for Space Applications and Telecommunications, told Armada that launches of the IRIS2 satellites will start in 2029, with full provision of SATCOM services commencing one year later. Mr. Jaffart added that development of the satellites and their accompanying infrastructure is already underway. Satellite production should commence in 2026. IRIS2 will have use a multi orbit constellation of 292 satellites with 264 satellites in a high Medium Earth Orbit (MEO). MEO orbits are between 1,079 nautical miles/nm (2,000 kilometres/km) and 19,323nm (35,786km) above sea level. A further 18 satellites will be in standard MEO orbits with ten in Low Earth Orbit (LEO). LEO satellites typically orbit at altitudes below 1,079nm. Mr. Jaffart says that the constellation will carry secure military/government K-band (18 gigahertz/GHz to 27GHz) links. Government communications will also be possible using Ka-band (26.5-40GHz uplink/18-20GHz downlink) transmissions. Commercial SATCOM services will be provided using Ku-band (14GHz uplink/10.9-12.75GHz downlink) links. He continued that IRIS2 encompasses the development of military Ka-band terminals. Development of these terminals will be in addition to the ground infrastructure that will be rolled out to support the constellation. Bandwidths in the order of tens of megabits-per-second are expected to be provided by the constellation. Mr. Jaffart stressed that government and military link provision includes a transparent mode. This means that existing secure waveforms used by militaries on the frequencies above can be carried across the constellation. He says that robust communications and transmission security has been built into the IRIS2 architecture from the outset. This provision includes state-of-the-art cryptography and cyber resilience. As the capability is owned and operated by the EU this will guarantee service provision. Privately-owned SATCOM is at the mercy of the markets, or of the owner deciding to cease service provision. Over the longer term, Mr. Jaffart adds that techniques like quantum key encryption could be used to enhance security. (Source: Armada)
10 Feb 25. February Radio Roundup. Persistent Systems’ new PT5 module enables the company’s MPU5 handheld radios to access 5G cellular and WiFi connectivity, the latter of which can be used to connect external devices to the transceiver. Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains. A January press release from Persistent Systems announced the launch of the Personal Transport-5 (PT5) accessory for the company’s MPU5 mobile ad hoc networking handheld radio. The PT5 connects with the MPU5 to provide simultaneous local network, or deployed, fifth-generation (5G) and Wi-Fi connectivity. Users can then perform line-of-sight and beyond-line-of-sight cellular communications over these 5G networks. Two WiFi 6e access points facilitate a personal area network to connect external devices like computers, cameras and sensors. Legacy 2.4 gigahertz/GHz WiFi-enabled devices can be linked to the PT5 along with five gigahertz and six gigahertz 6e systems. The press release stated that the PT5 has two layers of accredited encryption. This communications/transmission security protocol allows traffic to move securely across third party 5G networks. The company trialled PT5 devices with the US Army Special Operations Command and the US Department of Energy. Persistent Systems told Armada that the PT5 continues to be used by these organisations and is now available for wider acquisition. The PT5 connects directly with the MPU5 via any of the latter’s ports and can also be connected via cable if preferred.
Terminal Upgrades
Gilat DataPath, a subsidiary of Gilat Satellite Networks, recently won a contract to provide field services, upgrades and maintenance for DKET Series 2000 satellite communications terminals, and other similar products, in use with the US military and with other armed forces around the world. On 21st January, Gilat Satellite Networks announced that the company’s Gilat DataPath subsidiary in the United States had won a contract worth over $5 m from the US Department of Defence (DOD). The contract covers maintenance, upgrades and field services for the company’s Satellite Communications (SATCOM) terminals. Recipients for these services include SATCOM terminals used by the US military and allied forces around the world. Nicole Robinson, Gilat DataPath’s president, told Armada that the company had already delivered over 6,000 SATCOM terminals to customers globally. The company will provide the services for its DKET SATCOM terminals, and related systems “in support of defence users from the US as well as allied nations in Europe and the Asia-Pacific.” Ms. Robinson added that one upgrade covers the provision of beyond-line-of-sight satellite communications capabilities to an undisclosed US uninhabited aerial vehicle manufacturer. Additional upgrades will be provided to the company’s DataPath 3000 series and DKET 2000 series terminals. Numerically, most improvements are being conferred on terminals employed by the US Army. (Source: Armada)
13 Feb 25. Allen-Vanguard launches its next-generation RF Multi-Function Cyber Electromagnetic Activities (CEMA) Platform at IDEX 2025. Allen-Vanguard, a global leader in providing customised solutions and enabling technology for Radio Frequency (RF) spectrum monitoring and RF defeat of Unmanned Air Systems (UAS) and Radio Controlled Improvised Explosive Device (RCIED) threats employed by terrorists and extremists, is launching its next-generation core technology at IDEX 2025. As modern battlefield threats evolve, Allen-Vanguard is responding by launching the cornerstone of their latest RF multi-function CEMA platform that provides the necessary flexibility and adaptability for front-line troops to quickly and easily dominate the CEMA space; a capability that is particularly important when providing security in the Middle East. Allen-Vanguard is very excited to announce at IDEX 2025, the advanced core that will underpin its next-generation family of multi-function CEMA platforms. This new capability leverages the very latest in analogue signal processing technology and is the culmination of significant strategic investment and massive engineering development that the company has placed in its future program of systems, the ‘NXT’ family. This technology delivers a highly integrated mixed-signal front-end technology, combined with enhanced RF processing power to deliver increased flexibility and improved detect and defeat capability for the end user. This new technology enables direct RF sampling, without the use of tuners, across the entire RF spectrum used by UAS and RCIED devices. Allen-Vanguard has engaged best-in-class experts to collaborate on this exciting new project which enables this new more powerful software-defined radio (SDR) platform to form the core of their new products and help dominate the EW space. The new platform comprises of an RF System on Module (SOM) and a customisable product-specific application interface card which means users can detect, protect and defeat a wider range of threats from each system. Allen-Vanguard will be showcasing this and its current range of products at IDEX 25 on stand C3-006 from 17-21 February at the ADNEC Centre, Abu Dhabi.
Bobby Strawbridge, President of Allen-Vanguard said: “The Middle East has been a core market for Allen-Vanguard for a long time, and we have used our experience gained from supporting our clients in the region to help design and develop this new technology. Not only is it exciting from an engineering perspective and enables the EW capabilities that our customers demand, but it also should be of interest to any OEM in the EW sector. This card delivers best of breed metrics in a small, customisable footprint at a fraction of the price of standardised formats. I am very grateful to our partners and our in-house design team, who together, have pushed the boundaries of what is possible in the CEMA space.”
13 Feb 25. Global: Attack elevates security, cyber espionage risks from Chinese state-sponsored groups. On 11 February, international news outlets reported that an unnamed Chinese state-sponsored group is conducting a cyber espionage campaign against global suppliers within the manufacturing sector. The campaign reportedly exploits zero-day and/or existing software vulnerabilities to infiltrate network edge devices (such as routers and virtual machines). The group then likely deploys malware onto compromised systems to steal intellectual property and other sensitive information. Chinese state-sponsored actors routinely exploit vulnerable network edge devices as initial attack vectors to target organisations and exfiltrate sensitive data to bolster China’s economic and security posture. The campaign primarily targets suppliers of chemical products and physical infrastructure components, highlighting the elevated security and espionage risks facing these sectors amid long-term bilateral hostilities and economic competitiveness. The impact of this campaign will likely persist in the short-to-medium since it is likely that this cyber operation remains ongoing. (Source: Sibylline)
11 Feb 25. L3Harris, KSSL partner to enhance C4ISR capabilities in India. The two-year agreement will see both companies working closely and contributing to national security. L3Harris Technologies has signed a memorandum of understanding (MoU) with Bharat Forge’s subsidiary Kalyani Strategic Systems Limited (KSSL), setting the stage for joint efforts to deliver advanced defence and security systems within India. The agreement, which spans two years, will see both companies working closely to explore opportunities in command, control, communications, computers, intelligence, surveillance, and reconnaissance (C4ISR) technologies. Through this MoU, L3Harris gains a robust partner in KSSL to enhance its operational capacity within the Indian market. The partnership aims to leverage L3Harris’s extensive experience in tactical communications networks and its significant global presence, which includes more than one m deployed radios used by the US Department of Defense and allied forces worldwide.
L3Harris International vice president Dave Johnson said: “This MoU sets the stage for future partnerships and opportunities in India, where the combined strengths of L3Harris and KSSL can contribute to bolster national security for the country. We are excited to move forward and increase our delivery speed in advanced tactical radios and equipment to the Indian Armed Forces.”
The partnership, designed to focus on the Indian market, also aims to build supply chains for global commitments outside of India.
KSSL president and CEO Neelesh Tunger said: “This collaboration unlocks new strategic capabilities and will lead to harnessing new opportunities for quick delivery of sophisticated defence products to the Indian Armed Forces. Aligned with the evolving doctrines and emerging warfare paradigms, this collaboration between KSSL and L3Harris is aimed at serving future strategic requirements, including joint and integrated ISR capabilities.”
L3Harris has been operating in India for 21 years, with established facilities in New Delhi and Bengaluru. The company’s contributions to India’s defence include advanced tactical radios, crewed airborne electro-optic/infrared systems. The collaboration between L3Harris and KSSL also aligns with the US-India Defense Industrial Cooperation, which promotes the advancement of defence technologies and capabilities. In the year 2016, India attained the status of a “Major Defence Partner” in relation to the US. Subsequent to this designation, the two nations proceeded to execute a sequence of fundamental accords spanning from 2016 through 2023. These agreements encompassed areas such as military logistics, secure communications, and geospatial intelligence cooperation. (Source: army-technology.com)
13 Feb 25. The Munich Security Conference (MSC) – founded in 1963 – is the world’s leading forum for intensive dialogue on international security policy issues. From 2023, ESG Elektroniksystem- und Logistik-GmbH is responsible for implementing secure TETRA communication for the Munich Security Conference, which this year takes place from 14 to 16 February, and for the following main conferences until 2025. With ESG, which has been part of HENSOLDT since April 2024, as the contract holder and the experienced team of HENSOLDT’s Multi Domain Solutions division, secure TETRA communication will also be guaranteed at the 61st MSC. Together with Stadtwerke München, HENSOLDT is contributing to the success of the conference under the most demanding security requirements: on behalf of HENSOLDT, Stadtwerke München are setting up two TETRA base stations in the Hotel Bayerischer Hof and integrating them into their highly available and secure TETRA network. This ensures uninterrupted and secure TETRA communication in the hotel itself and in the relevant surrounding area. Due to the constant growth of the conference, a record number of TETRA terminals and their accessories will be used for the employees of the Munich Security Conference, the German Armed Forces and the participating security organisations at this year’s security conference. Furthermore, the realisation also includes comprehensive on-site service and support by HENSOLDT and Stadtwerke München specialists. As in previous years, they are specially designed to be worn discreetly and are therefore ideally suited for the range of applications during the conference. The project once again highlights the outstanding capabilities of HENSOLDT’s Multi Domain Solutions division and Stadtwerke München, particularly in the areas of IT and communications and system integration, in a highly complex security-critical environment. The MSC traditionally takes place in the renowned Hotel Bayerischer Hof and due to the constant further development of the conference, also in parts in the neighbouring Rosewood Hotel. Once again, a large number of participants from all over the world will be attending. Heads of state, members of government, leaders of international organisations, and leading representatives from business, the media, research and civil society are expected to exchange their perspectives and ideas on international security. Accordingly, the requirements for ensuring the security of all participants are high.
12 Feb 25. Cyber Update Key points.
- The increased intensity of botnet-operated distributed denial-of-service (DDoS) attacks will heighten disruption risks to global operational technology (OT) and information technology (IT) environments, as well as Internet-of-Things (IoT) devices.
- The increasingly large volume of software vulnerabilities affecting OT and IoT environments will facilitate the proliferation of botnet operations, elevating operational and disruption risks in the medium term.
- Botnets will continue to provide cyber criminals with several avenues of profit; this will likely raise financial and second-order security risks amid the increased commercialisation of cyber criminal enterprises and the evolving cyber threat landscape.
Context
In January, the security company Cloudflare reported that varying cyber threat actors used known botnets to conduct 73% of detected HTTP DDoS attacks, highlighting the potentially disruptive impact of these tools. This followed a general uptick in the number of reports concerning botnet activity since the end of 2024; cyber criminals increasingly exploited software vulnerabilities to create new botnets and/or expand existing ones alongside conducting cyber attacks via known botnets for financial profit. Botnets allow threat actors to propagate cyber attacks via a network of infected devices, underscoring the sophistication of botnet-operated cyber campaigns. We assess that this will elevate security, disruption and financial risks to global entities in the medium-to-long term amid the spike in botnet operations and the evolving cyber threat landscape. (Source: Sibylline)
12 Feb 25. New investment in Royal Navy fleet communications to boost jobs. A £250m upgrade to naval communications will support more than 100 high-skilled UK jobs, delivering on the Government’s Plan for Change. More than 100 high-skilled jobs will be secured in the UK thanks to a new £250m contract to upgrade the communications systems of the Royal Navy’s warship and submarine fleet. Jobs at Thales sites in Portsmouth, Plymouth, Crawley, Reading and Bristol will be supported after the company was awarded the largest-ever contract for the provision of naval communication capabilities. This large-scale investment helps to support the objectives of the upcoming Defence Industrial Strategy – to drive investment to UK-based businesses and boost defence jobs in every nation and region of the country. The 10-year long contract for Maritime Communications Capability Support (MCCS), awarded by Defence Equipment & Support, will upgrade the Royal Navy’s internal and external fleet communications, strengthening the UK’s continuous at sea deterrent and supporting global operations. Contracts like this one are a key part of the UK Government’s Plan for Change, safeguarding national security whilst raising living standards across the UK with good, skilled, productive jobs. It is estimated the new contract will also save the Royal Navy up to £30m in costs over the next decade.
Minister for Defence Procurement and Industry, Maria Eagle MP, said: “This new contract is a vital step in ensuring our forces remain secure at home and strong abroad. By enhancing the capabilities of our naval operations, we are reinforcing the UK’s ability to respond to threats wherever they arise. In an increasingly volatile world, robust communication is the backbone of operational success. In the face of global threats, the upcoming Defence Industrial Strategy will ensure defence is an engine for growth, boosting British jobs, and strengthening national security. Communication systems on Royal Navy Units are a critical component of a platform’s ability to operate and fight. To meet and sustain global commitments requires resilient and enduring support contracts to maintain mission-critical equipment at the highest levels of operational capability and availability. ”
The MCCS arrangement replaces the previous Fleetwide Communications contract which Thales UK has overseen for the past seven years. Thales UK will also provide “waterfront” office services, recovery for ageing equipment and inventory management, ensuring spare part availability and ongoing defect repairs as required.
A key element to the contract is fostering closer collaboration between DE&S, the Royal Navy, and Thales UK, effectively delivering a ‘one defence’ team which reduces bureaucracy while boosting efficiency.
Commodore Phil Game, Director of Sense, Decide & Communicate at DE&S, said: “First and foremost, this announcement ensures the Royal Navy continues to have effective and secure communications equipment with continuous support from Thales, which has Europe’s largest team of marine communications engineers, supporting its vital work keeping the UK and our allies safe. Crucially, we have looked at outcomes from other successful defence programmes and applied the lessons learned from those, in particular cutting unnecessary red tape and bureaucracy allowing Thales much more freedom to get the job done. We estimate that the scope of this contract will save between £25m and £30m in through life costs to the Royal Navy over the 10-year support period by working in a much more collaborative way with Thales UK, underlining our ‘one defence’ philosophy. This investment demonstrates the government’s commitment to national security and follows the launch of the consultation for the Defence Industrial Strategy – which will place deterrence at the heart of a new approach and ensures the defence sector is an engine for growth in every region and nation of the UK.”
Phil Siveter, CEO Thales in the UK, said: “At Thales we are delighted to continue supporting the Royal Navy in its vital mission to protect our nation. This long-term fleetwide support framework reflects our unwavering commitment to ensuring the Royal Navy remains combat-ready and equipped with world-class communications capabilities, today and into the future. Building on seven years of trusted partnership, we are proud to provide the technical excellence and on-the-ground support that keeps ships, submarines and installations operational and mission-ready. By working as ‘one team’ across the Naval Enterprise, we are driving innovation and systems integration to place the Royal Navy at the cutting edge of defence technology for the next decade.” (Source: https://www.gov.uk/)
11 Feb 25. USMC seeking new modular tactical radio. US Marine Corps (USMC) programme officials are soliciting industry options on development of a new modular, advanced-architecture combat radio to support tactical command-and-control (C2) voice and data networks. Service officials issued a request for information (RFI) for the Modular Advanced Radio Architecture (MARA) Small Form Factor radio, to meet the USMC’s standing requirement for a new small tactical modular radio. System requirements include an eight-hour operating span off a single X90 lithium battery, while in support of “manportable and on-the-move capability”, according to the January RFI. Fielded MARA tactical radio systems will utilise a 3U VPX computing core, or a VNS+ variant, with a total operating load of 10 lb, the RFI stated. Once developed, the new MARA radios will support C2, communications, and fire-support missions carried out by USMC units at the operational and tactical levels. “The MARA will provide tactical edge communications as the radio frequency (RF) transport on tactical voice radio networks and tactical data networks”, service officials noted in the RFI. The MARA radio will be able to support secure, encrypted voice and data communications up to top secret classifications, the officials added. The MARA architecture standards on which the new small form factor radio will operate will mimic army’s Common Modular Open Suite of Standards (CMOSS) for electronic warfare (EW) and command, control, communications, computers, cyber, intelligence, surveillance, and reconnaissance (C5ISR) operations. (Source: Janes)
11 Feb 25. British Army pins communications upgrade hopes on new procurement model. The British Army is hoping to change its procurement processes in the digital space in the wake of problems with the Morpheus programme in order to take advantage of rapid technological developments that offer easily incorporated capability improvements. Speaking at the SAE Media Group’s Mobile Deployable Communications conference held in London in late January, Brigadier Jez Sharpe, head of the tactical system service executive, Defence Digital, said that the Digital Strategy for Defence had identified that the delivery of digital capability needs to be different. He noted the recent statement by the chief of the general staff of the need for an “any-to-any network” and highlighted the assumption that “data centricity is no longer an enabler but is the ‘vital ground’”. Brig Sharpe explained that the new service executive model (SEM) for procurement represented a shift of mindset, with constant reiteration through the life of a programme to maintain and improve capability. He said that the aim “is to leverage the technology environment in the digital space … so that capability is in the soldier’s hands earlier, and you keep iterating on that capability so it improves over time”. He contrasted that with the project approach, where capability tends to degrade from the moment of launch, and said that the aspiration is to achieve better capability over the life of equipment for equal budget and effort. (Source: Janes)
11 Feb 25. New UK sanctions target Russian cybercrime network. A key Russian cybercrime syndicate responsible for aiding merciless ransomware attacks around the world has been targeted by new UK sanctions.
- UK sanctions target Russian cyber entity, ZSERVERS responsible for facilitating crippling ransomware attacks globally
- targets also include 6 ZSERVERS members who are part of a prolific cybercrime supply chain, and their UK front company XHOST
- action on illicit Russian cybercrime syndicate is latest step to strengthen UK national security
Fresh sanctions are targeting ZSERVERS, a key component of the Russian cybercrime supply chain, and 6 of its members, as well as its UK front company, XHOST Internet Solutions LP. ZSERVERS provide vital infrastructure for cybercriminals as they plan and execute attacks against the UK.
The illicit supply chain protects, supports and conceals the operations of some of the world’s most ruthless ransomware gangs. Ransomware actors rely on these services to launch attacks, extort victims and store stolen data.
In the modern digital-first economy, cyber security is a non-negotiable cornerstone of business success. A secure digital economy is a less attractive target for cybercriminals and a more attractive home for investment, generating jobs and putting more money into hardworking people’s pockets, delivering on this government’s Plan for Change.
Foreign Secretary, David Lammy, said: “Putin has built a corrupt mafia state driven by greed and ruthlessness. It is no surprise that the most unscrupulous extortionists and cyber-criminals run rampant from within his borders. This government will continue to work with partners to constrain the Kremlin and the impact of Russia’s lawless cyber underworld. We must counter their actions at every opportunity to safeguard the UK’s national security and deliver on our Plan for Change.
Predatory ransomware groups pose a clear and persistent threat to national security, public services and privacy. These attacks threaten critical national infrastructure, disrupt essential services, compromise sensitive data and generated $1 bn from their victims globally in 2023 alone.”
Minister of State for Security, Dan Jarvis, said: “Ransomware attacks by Russian affiliated cybercrime gangs are some of the most harmful cyber threats we face today and the government is tackling them head on. Denying cybercriminals the tools of their trade weakens their capacity to do serious harm to the UK. We have already announced new world-first proposals to deter ransomware attacks and destroy their business model. With these targeted sanctions and the full weight of our law enforcement, we are countering the threats we face to protect our national security, a foundation of our Plan for Change, and our economy.
ZSERVERS explicitly advertise themselves to illicit actors as a Bulletproof Hosting (BPH) Provider. Some BPH are known to host hackers, misinformation, child exploitation material, spam and hate speech. BPH providers like ZSERVERS, protect and enable cybercriminals, offering a range of purchasable tools which mask their locations, identities, and activities. Targeting these providers can disrupt hundreds or thousands of criminals simultaneously. Today’s action is the latest in a series of coordinated steps alongside US and Australian partners, and comes off the back of recent sanctions against notorious ransomware groups LockBit and Evil Corp.”
LockBit affiliates are known to have used ZSERVERS as a launch pad for targeting the UK, enabling ransomware attacks against various targets, including the non-profit sector.
Protecting the nation from threats both physical and digital sits at the foundation of the government’s Plan for Change. That is why we are moving through the entire ransomware pipeline step by step, cracking down on Russian cybercriminals that threaten the UK’s security, integrity, and prosperity.
Background
The full list of those sanctioned today:
- ZSERVERS
- XHOST Internet Solutions LP
- Aleksandr Bolshakov (employee)
- Aleksandr Mishin (employee)
- Ilya Sidorov (employee)
- Dmitriy Bolshakov (employee)
- Igor Odintsov (employee)
- Vladimir Ananev (employee)
Further information on how our actions align with the UK government’s overall strategy to disrupt cybercrime, and how these actors support the broader cybercrime ecosystem: Ransomware, extortion and the cyber crime ecosystem, NCSC.GOV.UK
An overview of Bulletproof Hosting (BPH) providers from our Australian partners: “Bulletproof” hosting providers, Cyber.gov.au (Source: https://www.gov.uk/)
10 Feb 25. The next battlefield is invisible and the fight for electromagnetic dominance has begun. The battlefield is changing, and the fight for dominance is shifting into a new, unseen realm. With the rapid evolution of drone warfare and electronic surveillance, the electromagnetic spectrum has become as critical as air, land, and sea.
Mastering electronic warfare (EW) is now essential – not just to jam enemy signals and intercept intelligence, but to defend systems from interference.
The rise of Pulsar
To meet this challenge, Anduril Industries has unveiled Pulsar, a modular system designed to adapt in real-time to emerging electronic threats. Using radio frequency machine learning (RFML), Pulsar can read and reconfigure itself in real-time against enemy EW systems. To put simply, it can read the electromagnetic room and reconfigure itself to counter enemy EW systems as they update themselves to try to shake the threat of detection or disruption. Traditional EW methods often struggle to keep pace with rapidly shifting signals, but Pulsar’s machine learning capabilities allow it to instantly counteract new threats.
A new era of warfare
The importance of EW is growing as modern armies become more reliant on interconnected systems. A new report from the Royal United Services Institute (RUSI) highlights the need for the British Army to prepare for this evolving threat landscape. The report warns that while not every soldier can be trained as an EW operator, all must become spectrum-aware. The increasing use of electronic devices in combat makes troops more vulnerable to jamming, hacking, and detection. In future conflicts, dominance won’t just be measured in firepower – it will be decided in the invisible battles of the electromagnetic spectrum. The question now is whether UK Armed Forces can adapt fast enough to keep up. (Source: forces.net)
10 Feb 25. Global: Surge in attacks targeting AI platforms underscores increased security, financial risks. On 8 February, international news outlets reported that a new cyber criminal business model is selling access to high-profile large language model (LLM) platforms for financial profit; it is reportedly doing so at an increasing rate. Threat actors allegedly use stolen credentials and/or exploit software vulnerabilities in third-party cloud storage platforms to infiltrate targeted LLM services. They then exploit legitimate OpenAI Reverse Proxies (ORP) servers to store application programming interface (API) keys before selling them on the dark web. This enables cyber criminals to sell unauthorised access to compromised platforms to users seeking to avoid high LLM service subscription fees. Earlier in February, cyber criminals also integrated the artificial intelligence (AI) platform DeepSeek into this model, showcasing their ability to capitalise on existing and emergent markets quickly. We assess this points to the increased security and financial risks for LLM entities in the short-to-medium term amid the increased commercialisation of cyber criminal enterprises. (Source: Sibylline)
10 Feb 25. Thales is taking part in the Artificial Intelligence Action Summit in Paris on 10th and 11th February 2025 to showcase its latest advances in the field of trusted AI for critical systems. At a time when much is expected of AI and its contribution to the security and sovereignty of nations, Thales offers a hybrid, explainable, cybersafe and frugal AI, which is already incorporated into more than 100 of its products. This technology is already delivering significant advances in the protection of infrastructure, optimisation of energy consumption and defence systems.
“Thales is a key player in the field of trusted AI: our experts have developed a hybrid AI, which offers transparency, cybersecurity, energy efficiency and an ethical approach — unlike many AI systems that rely exclusively on large amounts of data and are particularly energy-intensive. Thales offers an augmented intelligence, which is capable of changing society,” said Patrice Caine, Chairman and CEO of Thales.
Patrice Caine, Chairman and CEO of Thales, will take part in the dialogue between heads of state and government and business leaders at two roundtable sessions on AI and national security and on Europe’s AI champions.
- On Tuesday 11th February, experts from cortAIx, Thales’s AI accelerator, will conduct exclusive demonstrations of the practical impacts of AI in 15 critical fields for official French and international delegations at the Thales Digital Factory. These AI-enabled solutions are designed to boost the performance of the most advanced systems and help humans make better decisions in crisis situations and high-stakes environments where data security and sovereignty are critical.
These solutions are already available and show how AI can reduce the environmental footprint of air traffic, protect airports and major events, protect maritime traffic and infrastructure, and, in the defence sector, increase the effectiveness of operational assets/resources and accelerate the OODA loop (observe, orient, decide, act).
Other events
- On Tuesday 11th February, Thales’s Friendly Hackers team will take part in the Cyber Crisis Management Exercise organised by ANSSI, France’s national agency for information system security, at the Cyber Campus in Paris.
- On Tuesday11th February, Thales will take part in two events:
o Empowering AI Ecosystems through Strategic Autonomy: Lessons from Finland and France at Finnish Embassy in Paris.
o Building Trust: Anticipating and Managing AI Risks, organised by the HEC Hub Digital and Axys in Paris.
- On Monday 10th February, Thales will take part in Military Talks, organised by the French Ministry of the Armed Forces and the Ministerial Agency for Defence AI (AMIAD), dedicated to AI for defence applications.
- As part of the Confiance.ai consortium, Thales is contributing to actions to expand the programme’s role internationally.
- On Sunday 8th February, Thales took part in the AI Luminate conference: Evolving AI Safety for Economic Growth in Uncertain Times, ML Commons, AI Verify, LNE and Prism, in Paris.
- On Thursday 6th February, Thales took part in the Presentation of AI Deliverables for Major French Groups, organised by French Tech Grand Paris and Wavestone in Paris.
- On Friday 24th January, Thales took part in the French-German AI Industry Executives Dialogue, organised by the French Embassy in Berlin. This event resulted in a Call for Action, which will be presented at the AI Action Summit.
- On Tuesday 21st January, ahead of the AI Action Summit, Thales organised a visit to its cortAIx research laboratory in Palaiseau with a presentation of its latest innovations for institutional stakeholders.
07 Feb 25. Cyber Update Key points.
- A spyware operation points to heightened surveillance risks for journalists and civil society.
- A malware operation against small-scale government and private organisations in Ukraine underscores security and information theft risks posed by a newly-identified zero-day vulnerability (CVE-2025-0411) (see Sibylline Cyber Daily Analytical Update – 4 February 2025).
- The Chinese state-sponsored group ‘Evasive Panda’ targeted global entities in a reconnaissance and information-theft operation, elevating long-term security risks.
- Highly sophisticated cryptocurrency theft campaign elevates security, financial risks to Android and iOS mobile users.
- Evolving tactics will sustain heightened security, information theft risks posed by the North Korean state-sponosred group ‘Kimsuky’ (see Sibylline Cyber Daily Analytical Update – 7 February 2025).
Technical analysis of weekly stories
Unnamed threat actors are targeting Android and iOS mobile users in a highly sophisticated cryptocurrency theft campaign (‘SparkCat’). Threat actors covertly infiltrated victims’ systems by infecting legitimate applications available on the Google Play Store and Apple App Store with malicious components. This includes a software development kit (SDK) known as ‘Spark’ that establishes communication with actors’ command-and-control (C2) infrastructure and decrypts and installs additional malicious payloads onto compromised devices. The main payload is a wrapper comprising several optical character recognition (OCR) stealers to extract sensitive information (such as credentials) from images and photo libraries. Namely, it contains a DictProcessor and a WordNumProcessor module to filter images by localised dictionaries and word length respectively, pointing to the sophistication of this operation. Spark then encrypts conforming images and sends them to the actors’ C2 servers, likely enabling threat actors to use stolen information to locate and hijack cryptocurrency wallets for financial profit. The modules specifically searched for terms in Chinese, Czech, English, French, Italian, Japanese, Korean, Polish and Portuguese, suggesting that the campaign’s targets may be primarily located in Europe and East Asia. However, there is also a realistic possibility that it may have also targeted entities in Indonesia, Kazakhstan, the UAE and Zimbabwe as some applications allowed users to sign up with phone numbers associated with these locations. Additionally, the infected applications boast more than 242,000 downloads from the Google Play Store, underscoring the scale and impact of this campaign. Threat actors often mimic legitimate services to communicate with C2 infrastructure and disguise malicious payloads as legitimate system packages, showcasing the sophistication of the actors’ obfuscation techniques to hinder analysis and reverse-engineering efforts. This operation marks an uncommon successful attempt at bypassing security restrictions in the Apple App Store to infect legitimate applications, elevating security and financial risks to both iOS and Android mobile users.
Some non-exhaustive recommendations to mitigate against these threats include:
- Monitor devices and networks for suspicious activity
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communication to malicious IP addresses associated with known malware
- Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
- Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering
(Source: Sibylline)

