• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

March 28, 2025 by

27 Mar 25. New UAS Radio Launched for Secure GPS-Denied Communications. Rampart Communications has launched the StrataWave™ UAS Radio, a GPS-independent system designed to ensure secure, resilient drone communications in contested and GPS-denied environments. Rampart Communications has unveiled the Rampart StrataWave™ UAS Radio, engineered to operate without GPS and safeguard transmissions from jamming technologies. Developed for both Group 3 and Group 2 uncrewed systems, the StrataWave UAS Radio overcomes traditional vulnerabilities by ensuring persistent, secure connectivity even in the most hostile environments. Unlike conventional radios, which rely on GPS and can be susceptible to jamming, StrataWave UAS radio prioritizes stealth, resilience, and survivability, allowing UAS operators to maintain unwavering command and control (C2) even under direct electronic attack.

Advantages of the StrataWave UAS Radio:

* GPS-Independent Communication: Immune to GPS jamming attacks, ensuring uninterrupted mission connectivity.

* Electronic Warfare (EW) Resilience: Low probability of detection (LPD) and anti-jam capabilities for enhanced survivability in contested environments.

* Proven Core Technology: Rampart’s physical layer technology is independently validated by over 10 technical and operational tests from top defense research institutions.

As the U.S. military and allied nations rapidly expand their drone operations, the StrataWave UAS Radio addresses a recognized need for resilient and secure battlefield communications. For defense leaders and warfighters, it is designed to maintain C2 even in GPS-jammed environments.

Matt Ball, Chief Executive Officer at Rampart Communications, commented, “Electronic Warfare is disarming battlefield drones at alarming rates, creating an urgent need for next-generation connectivity. StrataWave UAS is the first drone radio built to survive the most hostile electronic warfare—enabling mission-critical drones to stay connected and operational when adversaries attempt to disable them with sophisticated EW systems.” (Source: https://www.defenseadvancement.com/)

 

26 Mar 25.  New malware highlights heightened security, disruption risks to CNI sectors. On 25 March, the cyber security company Flashpoint reported that the pro-Iran hacktivist group ‘Cyber Av3ngers’ has been targeting critical national infrastructure (CNI) organisations with a new custom malware (‘IOCONTROL’) since at least December 2024. IOCONTROL copies itself onto a system’s memory after obtaining access to targeted systems to establish persistence and remain obfuscated. It then establishes communication with command-and-control (C2) infrastructure and subsequently deploys a backdoor component to exfiltrate sensitive data and ensure prolonged persistence. Cyber Av3ngers has used IOCONTROL to infiltrate Internet-of-Things (IoT) and operational technology (OT) devices within fuel management companies in Israel and the US amid the resumption of hostilities between Israel and Hamas.  We assess that there is a realistic possibility that the group will use the malware to temporarily disrupt the provision of key services and/or damage compromised equipment in the short-to-medium term. This highlights heightened security and disruption risks to national infrastructure stemming from hacktivist groups.  (Source: Sibylline)

 

25 Mar 14. Everfox, a leader in cross-domain technology solutions, today announced a strategic partnership with Palantir Technologies (NASDAQ: PLTR), a pioneer in data analytics and artificial intelligence (AI), aimed at supporting customers operating software solutions in classified network environments, including software solutions for joint and integrated command and control. Utilizing approved data transformation formats, this partnership—already tested and deployed with existing customers—will now extend to additional clients with complex network and operational environment needs. By applying Everfox’s robust cross-domain solutions to Palantir’s AI capabilities, warfighters can rapidly process, decide and react to real-time intelligence streamed from multiple sensors, platforms, and networks, providing a comprehensive and unified data environment across domains. Everfox will also utilize Palantir’s Mission Manager in conjunction with its own cross-domain solutions. This empowers customers to efficiently field, manage, and maintain their commercial, open source and government off-the-shelf software (GOTS) baselines across complex classified networks. Built on commercial industry best practices and government standards, Mission Manager offers a secure and automated software infrastructure, delivering rapid fielding and continuous integration/continuous delivery (CI/CD) support models to any tactical and classified network environment. This suite of capabilities heralds a new era of software agility and reliability, bringing commercial software best practices to customers operating within the most complex and secure classified network environments.

“Joint command and control are crucial for the U.S. to keep pace with the volume and complexity of data in modern warfare. Access to this data is often the difference between mission success and failure,” said Sean Berg, CEO of Everfox. “Working with Palantir Technologies, we can better support our customers through innovative and highly secure cross-domain technology solutions.”

“We’re proud to partner with Everfox to enhance the warfighter mission,” said Akash Jain, President of Palantir USG. “Our combined efforts will provide our customers with transformative operational efficiency, ensuring they remain at the forefront of technological advancements in defense.”

Everfox and Palantir Technologies underscore a shared commitment to advancing national security through innovation. By combining their respective strengths, the two companies will deliver transformative solutions that will empower the warfighters with the necessary tools to maintain a strategic advantage on the battlefield. To learn more about Everfox, its collaboration with Palantir and work supporting command and control capabilities, visit www.everfox.com. (Source: BUSINESS WIRE)

 

24 Mar 25. British Army’s Project Asgard network enhancements revealed. Further details have emerged of the communications element of Project Asgard, the British Army’s programme to enhance the command-and-control (C2) capability of the force committed to the defence of Estonia, including the Forward Land Force (FLF) battlegroup from the 4th Armoured Brigade Combat Team (4 Armd Bde CT) that is deployed in theatre. Speaking at SAE Media’s Future Soldier Technology conference in London in March, Colonel Pete Brunton, programme manager for Land Environment Tactical Command Information Systems (LE TacCIS), said Project Asgard had resulted from the Chief of the General Staff’s directive that the FLF required a recce/strike complex and needed to be able to “see further, strike harder and cheaper, and decide much quicker”. Col Brunton said Project Asgard was providing enhanced intelligence, surveillance, target acquisition, and reconnaissance (ISTAR); one-way effectors; and networks. Focusing on the networks, Col Brunton said the project had been in progress since the fourth quarter of 2024. Equipment is being delivered, training is under way in the United Kingdom, and delivery into theatre will take place later in 2025. He explained that the networks effort had addressed three areas: range extension, dismounted communications, and national and international interoperability. New masts, higher than the existing 12 m equipment and with longer low-loss co-axial cables, have been procured to break the tree canopy for range extension without radio rebroadcast. DarkSky radio frequency reflectors from Phoenix C4i, which can be attached to the antennas, are intended to enhance directional gain and screen the antenna from advanced electronic warfare (EW) sensors. (Source: Janes)

 

25 Mar 25. Asia-Pacific: Covert operation points to raised espionage risks from Chinese state-sponsored groups. On 24 March, the cyber security company Sygnia reported that the Chinese state-sponsored group ‘Weaver Ant’ had been conducting a stealthy cyber espionage operation against an unnamed high-profile telecommunications company in the Asia-Pacific region since at least 2021. The group reportedly used an operational relay box (ORB) network (made up of several compromised Zyxel home routers) to infiltrate the company’s systems and to obfuscate infrastructure. Weaver Ant also combined several web shells to maintain access to compromised systems while bypassing security restrictions. It then used port mirroring to exfiltrate sensitive data and to enhance detection evasion at the same time. The group was able to steal information for at least four years before detection, showcasing the stealth and longevity of its operation. This campaign follows an uptick in the number of reports concerning cyber espionage operations conducted by Chinese state-sponsored groups against the telecommunications sector in the Asia-Pacific region, as well as in Europe and the US. We therefore assess that it highlights the long-term elevated cyber security and espionage risks amid ongoing geopolitical tensions. (Source: Sibylline)

 

21 Mar 25. Cyber Update Key points

* A spike in state-sponsored cyber attacks underscores the long-term security, cyber espionage and disruption risks facing the European telecommunications sector.

* A new remote access trojan (‘StilachiRAT’) has highlighted the elevated security and financial risks facing global cryptocurrency users.

* The use of fake artificial intelligence (AI) installers to distribute malware underscores the elevated security and financial risks stemming from cyber criminals. The Ukrainian military and defence sectors are facing increased security and cyber espionage risks from the cyber threat group ‘UAC-0200.’

* A cyber operation targeting Taiwanese national infrastructure will sustain long-term security and information-theft risks from the threat group ‘UAT-5918’.

Technical analysis of weekly stories

Cyber criminals are using fake software installers for the AI platform ‘DeepSeek’ to distribute malware in an ongoing financially motivated campaign. Threat actors typically use search engine optimisation (SEO) poisoning to direct traffic to threat actor-made malicious websites; the websites’ URL and general appearance emulate legitimate AI services to trick users into downloading fake DeepSeek installers. This covertly executes several malware strains onto victims’ systems to steal credentials and/or sensitive financial information. In some instances, threat actors re-created fake CAPTCHA challenges to feign legitimacy before infecting victims’ systems with information-stealing malware. This likely allows threat actors to hijack user accounts and initiate fraudulent money transfers. Alternatively, threat actors can download a Powershell script through process-injection techniques after establishing communication with command-and-control (C2) servers; this enables them to deploy crypto-mining software (‘XMRig’) while remaining obfuscated by hiding the crypto-miner within legitimate processes. Another iteration of the campaign covertly installs third-party software in a bid to increase the volume of downloads and to garner illicit profit as part of affiliate marketing programmes. This campaign highlights cyber criminals’ ability to capitalise quickly on evolving market trends. The cyber threat group UAT-5918 has targeted critical national infrastructure (CNI) organisations in Taiwan in an information-theft operation since at least 2023. The group typically exploits known software vulnerabilities on unpatched internet-facing servers to infiltrate targeted organisations; it then disables the security protections put in place by the cyber security service Microsoft Defender before conducting initial network reconnaissance to gather system information. UAT-5918 subsequently deploys several web shells to establish persistence within compromised systems, to escalate privileges and to execute remote commands. The threat actors likely create administrative-level user accounts to enhance persistence. The group also installs information-stealing malware (such as ‘Mimikatz’, ‘LaZagne’ and ‘BrowserDataLite’) to exfiltrate login details and browser information, enumerating local and shared files to identify data of interest. Additionally, UAT-5918 consistently conducts network reconnaissance throughout its operations to identify and infect additional devices, highlighting the prolonged nature of this campaign. The group uses reverse proxies to establish and obfuscate C2 communication, underscoring its detection-evasion capabilities.

Non-exhaustive recommendations to mitigate against these threats include:

* Monitor devices and networks for suspicious activity

* Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware

* Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise

* Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

Our cyber word(s) of the week: Reverse proxy (Source: Sibylline)

 

24 Mar 25. New RaaS variant points to financial, disruption risks for businesses in short-to-medium term. On 23 March, the technology company Check Point reported that a new Ransomware-as-a-Service (RaaS) operation (‘VanHelsing’) has targeted global entities since at least 7 March. VanHelsing identifies and deletes all backup files to hinder system recovery before encrypting a system’s files. Threat actors then demand a ransom payment of up to USD 500,000, warning that the use of third-party decryption software will result in permanent data loss to coerce victims into paying the ransom. VanHelsing supports multiple commands to attune the encryption process to victims’ systems, underscoring its sophistication. Additionally, VanHelsing affiliates cannot target members of the Commonwealth of Independent States (CIS), suggesting the threat actors are possibly of Russian origin. The ransomware has successfully targeted three known victims since its inception and has developed a second (more advanced) version, highlighting its rapid development and possible impact. We assess this points to the elevated security, financial and disruption risks facing global entities in the short-to-medium term. (Source: Sibylline)

 

21 Mar 25. Persistent Systems Supports CJADC2 Operations at Project Convergence-Capstone 5 Experiment. Company demonstrates the maturity of its networking capability in line with U.S. military.  Persistent Systems, LLC (“Persistent”), a global leader in mobile ad hoc network (MANET) technology, announced today that its secure, highly scalable network successfully supported Project Convergence-Capstone Five (PC-C5), a Combined Joint All-Domain Command-and-Control (C-JADC2) experiment. Hosted by U.S. Army Futures Command, PC-C5 brought together all branches of the U.S. Armed Forces—along with foreign military partners from Australia, Canada, France, Japan, and New Zealand—for an operationally relevant, two-phase experiment at locations around the West Coast and the INDOPACOM theater.

“Over three days, we successfully integrated our transport-agnostic global communications fabric – the Wave Relay® MANET – into the Army’s existing Mission Command applications architecture, uniting decision-makers, tactical teams, and systems,” said Brian Spurlock, Vice President of Growth and Strategy at Persistent. “At PC-C5, Persistent networked a wide range of units and platforms—from Army armored vehicles to the Air Force’s Tactical Operations Center-Light (TOC-L) and high-altitude balloons – bringing the vision of C-JADC2 to life.”

For the Army component of PC-C5, Persistent Systems provided the Wave Relay® MANET connectivity for tactical combat formations executing one of the most challenging military operations – a combined arms breach of a mined wire obstacle. This marked the first time Persistent’s MANET connected M1A1 tanks and Bradley Fighting Vehicles with dismounted soldiers, enhancing the Army’s ability to execute complex combat maneuvers.

“In combined arms breaches, rapid mobility and large-scale communication can be a challenge,” Spurlock said. “At PC-C5, the Wave Relay® MANET provided a highly mobile, scalable communication fabric – from the edge to the enterprise.”

Accelerating Decision Making

Persistent also provided networking support to the Futures Directorate of Air Force Combat Command. The company integrated its MANET-Cloud High Mobility Radio (MCHMR) – previously validated in June at Valiant Shield – with the new Air Force battle management system, TOC-L.

“By combining MCHMR with the TOC-L, the Air Force was able to move radar and high-bandwidth sensor data to Army shooters in seconds,” said Adrien Robenhymer, VP of Air Force and Intelligence programs at Persistent. “This marks a dramatic shift from large, fixed, and expensive legacy systems.”

Additional Testing and Integration

Beyond core experiments, Persistent engaged in additional networking opportunities at PC-C5:

* Collaboration with the Joint Chiefs of Staff’s J6 Directorate, using the event as a technology risk-reduction opportunity ahead of Northern Edge.

* Transmitting data from high-altitude balloons back to Fort Irwin, demonstrating Persistent’s ability to link distributed assets across large operational areas.

“At PC-C5, Persistent showed that its robust, secure, scalable networking technology can meet U.S. military CJADC2 requirements today,” Spurlock said. (Source: ASD Network)

 

20 Mar 25. Taiwan: Cyber operation underscores long-term security, information-theft risks facing CNI. On 20 March, the technology company Cisco reported that the cyber threat group ‘UAT-5918’ has targeted critical national infrastructure (CNI) organisations in Taiwan in an information-theft operation since at least 2023. The group typically exploits known software vulnerabilities on unpatched internet-facing servers to infiltrate targeted organisations; it then disables security protections before conducting initial network reconnaissance. UAT-5918 subsequently deploys multiple web shells to establish persistence within compromised systems, as well as to escalate privileges and execute commands remotely. It also installs credential-stealing malware to obtain sensitive information, and consistently conducts network reconnaissance to infect additional systems, highlighting the long-term nature of its campaign. UAT-5918’s modus operandi and choice of targets overlap with those of several Chinese state-sponsored groups, suggesting this operation is possibly aligned with China’s strategic objectives. We assess the operation will sustain long-term security and information-theft risks for Taiwanese CNI sectors amid ongoing regional tensions. (Source: Sibylline)

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT