• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

April 12, 2025 by

10 Apr 25. Careless Whispers. It is always good to check who is attending and participating in an online chat. A quick round-robin introduction can do the trick. Scrolling through the list of names should provide useful confirmation. Newcomers can be asked to identify themselves. Once all is tickety-boo, discussions can flow. Another good rule of thumb is to assume anything you say, or write, is being recorded and may live for eternity. By just obeying these simple rules, US vice president JD Vance, secretary of defence Pete Hegseth and the director of national intelligence Tulsi Gabbard would have saved themselves torrents of embarrassment. On 24th March it emerged that Jeffrey Goldberg, editor-in-chief of The Atlantic, had been added to a Signal group chat, which included the above, and several other government officials. Mr. Goldberg had been added erroneously by national security advisor Michael Waltz. Reports noted that, between 11th March and 15th March, the group discussed military operations directed against Houthi insurgents in Yemen. The discussions included significant disclosures of classified material. The affair has proven deeply embarrassing and possibly includes unlawful actions by the participants. Messaging software applications like Signal and WhatsApp have proven popular with some politicians in recent years. Former British Prime Minister Boris Johnson has been in hot water regarding messages he sent and received on WhatsApp concerning the Covid-19 pandemic during his tenure. Such software applications, convenient as they may be, are probably best avoided by politicians. Nothing is totally secure, but it is surely better to use bespoke, government systems designed for classified traffic? Perhaps that means carrying around an additional secure smartphone just for this traffic? Would that few extra seconds of due diligence to check chat group participants be such a slog? If in doubt, just refrain from sharing anything you think is classified during the conversation. These are all minor inconveniences, but they pale into insignificance vis-à-vis the scandal that erupts after a failure to follow basic due diligence. (Source: Armada)

 

07 Apr 25. New Operational Comms on the Horizon. The German Army will receive its TAWAN LBO tactical/operational level trunk communications systems over the next four years. TAWAN LBO will help connect the tactical SVFUA networking architecture to higher echelons. German land forces communications modernisation efforts continue a pace with the contract award for a new operational-level networking system. The Heer (German Army) is involved in a major communications modernisation effort. To date, much of this effort has focused on the Streitkräftegemeinsame verbundfähige Funkgeräteausstattung (SVFUA) initiative. SVFUA roughly translates as Joint Armed Forces Interconnectable Equipment and primarily focuses on rolling new tactical radios across the army’s manoeuvre force. As Armada has reported in the past, up to 30,000 new radios will be procured as part of the initiative. The principle transceiver fulfilling the requirement is Rohde & Schwarz’ Soveron-D Very/Ultra High Frequency (30 megahertz/MHz to three gigahertz/GHz) radio. Soveron-D will initially equip the German Army Krauss-Maffei Wegmann/Rheinmetall Puma tracked infantry fighting vehicles.

TAWAN LBO

The SVFUA radios will soon be complemented by the Heer’s new Tactical Wide Area Network for Land Based Operations, better known as TAWAN LBO. Whereas SVFUA enables tactical networking, TAWAN LBO will provide tactical/operational trunk communications. Rheinmetall won the contract to provide TAWAN LBO in February. According to a company press release, the programme could be worth several bn dollars over the next decade. The initial February order is worth circa $2 bn and will see TAWAN LBO equipping a single Heer division between 2026 and 2029.

Reports have noted that TAWAN LBO will be a vehicle-mounted system. General Dynamics’ Piranha-5 eight-wheel drive infantry fighting vehicle will form one of the platforms. A total batch of 256 TAWAN LBO-equipped Piranha-5s should be delivered to the Heer from 2026.

C-band SATCOM

In a written statement supplied to Armada, Rheinmetall said that the goal of the TAWAN LBO programme is to “provide an independent, tactically deployable, relocatable and interference-resistant transmission network.” To this end, the TAWAN LBO architecture will facilitate C-band (5.925GHz to 6.425GHz uplink/3.7GHz to 4.2GHz downlink) conduits, implying the system will be used for Satellite Communications (SATCOM). Interestingly, the Bundeswehr (German Armed Forces) possesses the SATCOMBw communications satellite constellation.

Constructed by Airbus’ defence and space subsidiary two satellites, COMSATBw-1 and COMSATBw-2, comprise the constellation. Both provide C-band and Ku-band (14GHz uplink/10.9GHz to12.75GHz downlink) connectivity. Open sources note that the Ku-band links are used for military communications within Germany while C-band links support expeditionary operations. Configuring TAWAN LBO to use C-band makes sense. German forces are deployed abroad to support North Atlantic Treaty Organisation (NATO) commitments and Germany already leads NATO’s multinational battlegroup in Lithuania. TAWAN LBO’s C-band connectivity would be vital should that battlegroup need to repel a Russian advance into the Baltic.

Route Planning

Rheinmetall stressed that the particulars regarding how TAWAN LBO would be deployed remain the responsibility of the Bundeswehr. The statement did say that communications routing can be planned with a software management system. Constituent TAWAN LBO components then deploy to their designated positions and the network is ready for use. While individual radio relays are static, communications routing can be organised and managed dynamically between these.

Once TAWAN LBO enters service in the coming four years, in cooperation with SVFUA, it will afford the Heer one of the most advanced communications architectures in Europe. This will be a welcome enhancement, not only for the Heer, but for allied European nations, as the threat from Russia intensifies. (Source: Armada)

 

08 Apr 25. Constellation Agnostic. The US Air Force’s DEUCSI programme envisages constellation-agnostic satellite communications terminals which can link with ease to disparate, commercial spacecraft to seamlessly send and receive traffic. In 2018, the US Air Force Research Laboratory launched its Defence Experimentation Using Commercial Space Internet (DEUCSI) programme, which has since achieved some major milestones. DEUCSI has a simple premise; to evaluate the capabilities of commercial Satellite Communications (SATCOM) constellations to improve military networking. Of particular interest, reports note, are commercial SATCOM constellations in geosynchronous, medium and Low Earth Orbits (LEO). In geosynchronous orbits, spacecraft largely remain over the same point on the planet. LEO satellites do not exceed orbits of 1,079 nautical miles/nm (2,000km). Medium Earth orbits occur at altitudes of between 1,079nm and 19,323nm (35,786km). Numerous companies have privately-owned SATCOM constellations using these orbits. DEUCSI is exploring the possibility of SATCOM terminals equipping military platforms using multiple constellations. In 2018, the year the project commenced, SpaceX won a DEUCSCI contract to evaluate that company’s Starlink network. The programme gained further momentum in 2023 when a host of companies won contracts to develop SATCOM terminals to perform accompanying tests and evaluations. A goal of the programme, as the reports continued, is for DEUCSI to be link agnostic. What this means in practice is that one terminal in one part of the world would communicate with ease with another somewhere else. This could be achieved without users needing to specify or designate a particular network to achieve this.

Commercial decisions

Dr. Brian Beal, DEUCSI’s head engineer, told Armada that the programme was realised “to start utilising the large commercial constellations that we saw coming down the horizon.” SpaceX is arguably the most famous, but others like Amazon’s Kuiper and EutelSat’s OneWeb are coming to the fore. Dr. Beal stresses that having the US Department of Defence (DOD) develop its own, similar, constellation, would have been expensive. Instead, DEUCSI develops the wherewithal to use these networks as and when they became available. Alongside Starlink, DEUCSI established contracts with Amazon to evaluate Kuiper and with Viasat to use the latter’s satellites. When the programme commenced, Dr Beal says that DEUCSI was focused on “relatively basic tests of the emerging constellations” with single vendor SATCOM terminals. Since then, the programme has evolved into looking at using “common hardware to communicate across many different constellations.” Alongside the companies mentioned above, Hughes has been involved in providing SATCOM terminal hardware and software in support of DEUCSI. Raghu Janardhan, vice president for Hughes’ defence and government systems division, told Armada that the company’s provisions “provide access to multiple commercial satellite constellations across the full scope of orbits. This means that interference or denial of access to one constellation does not inhibit the mission. The comms system simply switches to an alternate constellation and continues its work to stay connected. This switch is important as adversaries do not usually try to block all the available commercial options.”

Terminal building

Dr. Beal continued that DEUCSI is focusing on Ku-band (14 gigahertz/GHz uplink/10.9GHz to 12.75GHz downlink) and Ka-band (26.5GHz to 40GHz uplink/18GHz to 20GHz downlink) connectivity. This is “where the high capacity and proliferated constellations operate … We need to buy a service that is available, and (in those bandwidths is) really where it is available.” The primary focus of DEUCSI is to evaluate these constellations for the provision of wideband links with constellation-agnostic terminals. “We may add some narrow band links in the future, but that’s not currently something that we’re really working on.” Over the coming year, Dr. Beal expects to perform tests of multi-modem, multi-constellation capable SATCOM terminals developed via the programme. These tests will occur both on the ground and onboard aircraft. The DEUCSI programme should conclude by the first half of 2028 at the latest, says Dr. Beal. Beyond that, the multi-constellation, multi-modem terminals realised via the programme could evolve into architectures equipping current, and future, US military aircraft types.(Source: Armada)

 

09 Apr 25. Europe to the Rescue? Eutelsat’s constellation of low earth orbit communications satellites, a rendering of a constituent spacecraft is shown here, could provide Ka-band and Ku-band wideband communications in Ukraine as a supplement, or replacement, for the US Starlink system. European satellite communications providers could help to make up any future satellite communications shortfalls in Ukraine. The fallout from the disastrous meeting between Ukraine’s president Volodymyr Zelenskyy and his American counterpart Donald Trump on 28th February reverberated into March. Ukraine famously benefitted from access to SpaceX’s Starlink Satellite Communications (SATCOM) service in the immediate aftermath of Russia’s second invasion of the country on 24th February 2022. Starlink terminals began arriving in the country from 28th February. Since then, media reports note that thousands of terminals have been delivered. Ukraine’s government, military and civilian sectors are all using Starlink which provides wideband SATCOM links across Ku-band (14 gigahertz/GHz uplink/10.9GHz to 12.75GHz downlink) and Ka-band (26.5GHz to 40GHz uplink/18GHz to 20GHz downlink) channels. According to Starlink, users typically enjoy download speeds of between 25 megabits-per-second/mbps and 220mbps. Upload speeds of between five megabits-per-second and 20mbps are also achievable. Latency rates across the link range between 25 milliseconds/ms and up to 100ms. Starlink terminals are difficult to jam on account of their small antennas and narrow beams. Jammers must be relatively close to the terminal antenna, and pointing directly at it, to have a hope of success. Starlink has proven popular with the military. The link has been used to provide tactical and operational trunk communications. The low latency, high bandwidths and relatively resiliency of Starlink signals vis-à-vis jamming has also made the link attractive for Ukrainian Uninhabited Aerial Vehicle (UAV) operators.

Musk it always be like this?

Starlink’s provision has not been without controversy. In February 2023, SpaceX’s president Gwynne Shotwell complained about Ukrainian military use of Starlink arguing that it was “never meant to be weaponised.” She claimed that using the link to support Ukrainian UAV operations went beyond the scope of the agreement the company had with the Ukrainian government to use the network. Ms. Shotwell’s comments were reinforced by SpaceX founder Elon Musk that same month. Mr. Musk wrote on Twitter that “we will not enable escalation of conflict (sic) that may lead to World War Three.” Controversies have continued regarding the extent to which SpaceX denies coverage over Russian-occupied Crimea, in southern Ukraine. Claims have circulated that this is having a negative effect on Ukrainian military operations. In the wake of the meeting between Messrs. Trump and Zelenskyy, the former ordered a pause of all US military assistance to Ukraine on 4th March. Ostensibly, the move was intended to encourage the Ukrainian government to embark on peace negotiations. Reports on 11th March noted that this assistance would be resumed with immediate effect. The move followed Ukraine’s agreement to observe a 30-day ceasefire contingent on Russian agreement. As of the time of writing, in mid-March, the Russian government is yet to follow suit.

Enter Old Europe

The involvement of Mr. Musk and SpaceX in the ongoing conflict raises concerns. Starlink’s capabilities make it an indispensably useful system. However, Mr. Musk’s mercurial tendencies, and attraction to extreme right politics, raise questions as to the extent Starlink can be relied upon as a service. What if Mr. Musk decides once again to restrict, or end, the provision of Starlink to Ukraine? Such a decision could risk having a profoundly negative effect on Ukraine’s operational and tactical situation. Reports surfaced on 7th March that Eutelsat could increase its involvement in Ukraine, with the company saying that it could provide 40,000 civilian and military grade terminals into the country. Eutelsat continued that these terminals could be provided within a couple of months. The company’s shareholders include the French and UK governments, both staunch allies of Ukraine. In theory, this should make it harder for the company to threaten to terminate its services in Ukraine a la Mr. Musk. Sources close to Eutelsat confirmed to Armada that the company is already supplying low Earth orbit satellite connectivity in Ukraine. This connectivity is sold to Ukraine on a commercial basis via a distributor based in western Europe. In terms of capability, Eutelsat’s links have the same latency as those furnished by Starlink and provide similar geographical coverage. The source added that, whereas Starlink primarily sells on a business-to-consumer basis, Eutelsat provides business-to-business and business-to-government services. Like Starlink, Eutelsat’s constellation provides Ka-band and Ku-band links. Reports note that Eutelsat’s links support data rates of circa 150mbps. A deeper deployment of Eutelsat terminals and services in Ukraine could make up for any Starlink shortfall should the latter be restricted, or terminated, in the future: “We are actively collaborating with European institutions and business partners to enable the swift deployment of additional user terminals (in Ukraine) for critical missions and infrastructure,” the source shared. It seems highly likely that Eutelsat will increase its footprint in Ukraine in the coming months. This will also provide the company with a useful testing ground to evaluate the performance of its SATCOM links in a warzone. (Source: Armada)

 

10 Apr 25. April Radio Roundup. Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.

Post-Quantum Encryption

Himera’s G1 Pro handheld radio will benefit from post-quantum encryption techniques, and improved frequency-hopping performance, both of which will be delivered by a software upgrade.

News emerged in March that Himera’s G1 Pro handheld tactical radio will benefit from so-called post-quantum encryption. The company has partnered with Quantropi to deliver this capability via the company’s QEEP post-quantum encryption technology. Combining this encryption with the radio’s existing frequency-hopping spread spectrum protocols should further enhance its resilience to jamming. The radio uses ultra high frequency bands of 410 megahertz/MHz to 493MHz, and 700MHz to 900MHz. Jay Toth, Quantropi’s senior vice president for sales, told Armada that the development of post-quantum encryption is a response to the realisation of quantum computers that can potentially break current encryption schemes. Mr. Toth says that “to continue protecting important data, we need a new set of maths problems that are so difficult to solve that not even a future super powerful quantum computer can break them.” He adds that “post quantum encryption is based on new very difficult maths problems” that these computers will find challenging to solve. The quantum secure encryption that the G1 Pro radios will benefit from will be installed as a software upgrade. Mr. Toth continued that all existing and new G1 Pro users can benefit from these upgrades. In addition, Quantropi will enhance the radio’s frequency hopping performance to help mask the radio from detection. These new frequency-hopping algorithms will also be made available to G1 Pro users via a software update.

Taking PRRs into the Vehicle

Thales has developed its new Vehicle-Mounted SquadNet Radio from the company’s existing SquadNet personal role radio family. The new system has been designed to improve connectivity between a squad’s vehicle and its dismounted troops.

Thales has unveiled a vehicle-mounted version of its SquadNet Personal Role Radio (PRR). SquadNet radios are available in two variants: One uses using frequencies of 430 megahertz/MHz to 470MHz, and the other 865MHz to 880MHz wavebands, according to the company. Thales told Armada that the new Vehicle-Mounted SquadNet Radio (VMSR) is fully interoperable with SquadNet PRRs. The performance of the PRRs and VMSR is also identical. Nonetheless, the vehicle-mounted antenna of the latter “provides a significant range benefit.” The company is keen to emphasise that “the VSMR is not a substitute” for a standard vehicular radio. Instead, the new transceiver will “seamlessly link dismounted troops to the vehicle to enable better coordination during operations.” Troops using the PRR can share data and voice communications, and blue force tracking information. Communications and transmission security is provided using frequency hopping, and low probability of interception waveforms, Thales continued. Weighing around 500 grams (1.1 pounds) the VSMR “is designed to have a minimal impact on the vehicle installation.” VSMRs can equip standard military and commercial vehicles and can use the vehicle’s power supply. Moreover, the radio has dedicated audio and data connectors to ease integration with existing vehicle electronics. (Source: Armada)

 

10 Apr 25. Global: Activists face long-term surveillance, data-theft risks from Chinese state-sponsored actors. On 9 April, the UK’s National Cyber Security Centre (NCSC) published a joint alert warning that unnamed Chinese state-sponsored actors are targeting Falun Gong, Taiwanese, Tibetan and Uyghur activists in a surveillance operation. Threat actors distribute fraudulent mobile applications on legitimate application stores to infiltrate targeted iOS and Android devices. The applications contain two known spyware variants (‘BADBAZAAR’ and ‘MOONSHINE’) that exfiltrate sensitive information from compromised systems. Threat actors also use messaging and social media platforms to conduct social engineering attacks, tricking victims into downloading the spyware directly onto their systems. MOONSHINE has targeted Tibetan activist groups since at least 2019 while BADBAZAAR has been active since at least 2022. We assess that this underscores the longevity of China’s surveillance operations. China often targets perceived adversarial entities, including activists, in cyber surveillance operations to strengthen Beijing’s security posture. We assess that this report underscores the ongoing risks of long-term surveillance and information theft to activists. (Source: Sibylline)

 

09 Apr 25. Northrop Grumman developing new UAS multinode processor. Programme officials at Northrop Grumman are in the midst of testing and development of a new, multinode airborne processor for use aboard unmanned aircraft systems (UASs). The new processor is the latest variant under development for the company’s InSite family of battlefield edge processors, Rosa Salazar, program director of advanced communications at Northrop Grumman Mission Systems, said. The UAS-focused open architecture processor variant is currently in laboratory testing phase, with programme officials focused on hosting and integrating various modules, functions, and capabilities into the processor, Salazar told Janes during a March interview.

“We have not gotten to a point yet where we are integrating [capabilities] for flight,” she said, noting these efforts will likely take place later in 2025 or in early 2026.

The InSite family of processor variants runs the gamut in terms of capacity and form factor, ranging from the five-slot 3U OpenVPX chassis under development for UASs to a 22-slot chassis for large, fixed-wing aircraft, according to Salazar.

“Here is your 3U [electronic warfare (EW) card] and here is your 3U networking module” on top of all the cryptographic and messaging layer security (MLS) to allow data passback to higher command, she said. The reachback capability for InSite is focused on connecting these processors to the US Air Force’s (USAF’s) Battle Network, Salazar noted.

In December 2024 programme officials held an internal demonstration of an InSite multifunction airborne processor, featuring a 12-slot chassis, according to Salazar. The 12-slot version demonstrated also represented the minimum viable product (MVP) for the InSite programme. (Source: Janes)

 

09 Apr 25. Rohde & Schwarz Leads the Way in Secure Military Communications With SATURN. Rohde & Schwarz, leveraging its expertise in secure military communications, is poised to support the transition to SATURN, a NATO-designated, highly secure, and interoperable waveform technology, with a proven track record of deploying thousands of SATURN radios across various global platforms. Rohde & Schwarz today highlighted its pivotal role in being one of the first to implement the Second-Generation Anti-Jam Tactical UHF Radio for NATO (SATURN) standard. As NATO’s standard UHF coalition waveform, SATURN is offering highly reliable transmission of voice and data. It is expected to replace the legacy HAVE QUICK waveform in operational use. Rohde & Schwarz has extensive expertise in secure military communications, garnered from decades of developing cutting-edge waveforms. With the company’s commitment to delivering innovative, secure solutions for the world’s most critical communications, it has successfully supplied and commissioned thousands of SATURN radios and embedded solutions for NATO and allied partners. With SATURN/HAVE QUICK already installed and operational in thousands of radios across NATO, the company reaffirms its position as the European market leader in secure communications. SATURN has earned the distinction of being designated as a NATO Minimum Military Requirement (MMR) for maritime and air operations interoperability, ensuring seamless connectivity across allied forces. Its advanced fast frequency-hopping waveform provides superior jamming resistance, safeguarding critical military communications against evolving threats. Compliance with NATO STANAG 4372 facilitates SATURN’s integration across various platforms, including naval, air, and ground stations.

“As a trusted partner in secure communications and software-defined radios, we’re thrilled to support the transition from HAVE QUICK to SATURN, enhancing security and interoperability for our NATO and allied partners,” said Markus Dolfen, Vice President, Secure Communications, Rohde & Schwarz. (Source: ASD Network)

 

08 Apr 25. Compass Call electronic-attack plane makers eye overseas market. BAE Systems and L3Harris are halfway through delivery of the Air Force’s planned fleet of 10 EA-37B Compass Call planes and expect to deliver the final five in 2027 and 2028. The firms — co-prime contractors to create the next generation of electronic warfare aircraft — expect the market for Compass Calls to continue growing in years to come. In a Monday call with reporters, BAE and L3 officials said they see growing potential to sell Compass Calls to international customers and that the Air Force could increase its purchase of the planes. The EA-37B is a heavily adapted Gulfstream G550 business jet loaded with electronic warfare equipment. It is designed to jam enemy communications, radar and navigation signals and allow airmen to defuse roadside bombs wirelessly. It will also block the ability of enemy air defenses to transmit information between sensors, control networks and weapons, allowing U.S. and partner aircraft to get closer to their targets. It is replacing the Vietnam-era EC-130H Compass Calls, which were heavily used during the wars in Iraq and Afghanistan and are now being retired. The Air Force had 15 EC-130Hs in 2017, but that fell to four in 2024 and is set to keep dropping. The new Compass Call is projected to fly 40% faster than the EC-130H and cover twice the range, and have a top altitude that is nearly 15,000 feet higher than the older aircraft, L3Harris said. The growing sophistication of the potential adversaries the U.S. and its allies might fight requires an electronic attack aircraft like the Compass Call, which is capable of countering multiple threats, L3 and BAE officials said.

“The [potential battlefield] environment is getting more and more complex every day,” Dave Harrold, vice president and general manager for countermeasure and electronic attack solutions at BAE, said. “When you think about countering enemy kill webs, it’s no longer a one-versus-one thing — it’s about being to persecute a variety of threats simultaneously.”

The State Department in October 2024 approved a $680 m sale of Compass Call planes to Italy. Harrold pointed to that foreign military sale as a sign of the plane’s expanding market.

“This isn’t just an important United States Air Force platform,” Harrold said. “It’s an ideal platform for our important allies as well. … We see the opportunity for that to be even more prolific internationally.”

Jason Lambert, L3Harris’s president of intelligence, surveillance and reconnaissance, said other unnamed international partners have expressed interest in buying their own Compass Calls. This would help improve interoperability between the U.S. and NATO fleets, he said.

However, the government’s studies have shown the planned fleet of 10 Compass Calls may not be enough to counter the projected future threats facing the Air Force, L3 and BAE officials said, and may need to be doubled to 20.

“The common message that we’re hearing, regardless of the study or regardless of the customer organization we speak with, 10 is not enough,” Lambert said.

BAE, L3Harris and Gulfstream proposed adding four new Compass Calls to the planned fleet, with the first two of those included in the Air Force’s unfunded priorities list in 2026. Using the G550 business jet as the foundation of the Compass Call will make it easier to sustain and keep jets ready to fly, Lambert said. There are more than 600 G550s fielded worldwide, he said, and a well-established sustainment and spare parts network that can service planes in under 30 hours. He predicted this would result in aircraft availability in the high 90% range. BAE builds the electronic attack components for the new aircraft. L3Harris focuses on converting the G550 jets into Compass Calls and integrates the equipment at its Waco, Texas, facility. The final five Compass Calls are now having their outer mold lines modified to make room for the electronic attack equipment at Gulfstream’s Savannah, Georgia, facility, according to Lambert. The sixth Compass Call is expected to move to L3Harris’s Waco facility for further work in the second quarter of 2025. Aircraft six, seven and eight are projected for delivery to the Air Force in 2027, and the final two are on track for a 2028 delivery, Lambert said. The first two EA-37Bs that were delivered to the Air Force are now undergoing testing, according to Harrold. The third arrived at Davis-Monthan Air Force Base in Arizona — the new fleet’s future home — in August 2024, and airmen are now conducting pilot training with it. The fourth Compass Call is also now at Davis-Monthan, Harrold said. The fifth Compass Call has been delivered to the Air Force, Lambert said, but is now receiving an upgrade. (Source: Defense News Early Bird/Defense News)

 

09 Apr 25. Global: Spike in cyber attacks underscores heightened security risks from botnet infrastructure. On 7 April, the security company GreyNose reported that cyber attacks against TVT DVR video recording devices have spiked since at least the beginning of March. Threat actors exploit a known security flaw to bypass authentication and security measures to infiltrate targeted devices. The vulnerability provides threat actors with administrative-level privileges, allowing them to conduct malicious activity (including cryptocurrency mining and distributed denial-of-service (DDoS) attacks). The vulnerability was reportedly patched in May 2024, underscoring the importance of timely patch management policies to prevent compromises. The attacks originated from at least 6,600 IP addresses, highlighting the scale of this operation. The attacks also include the deployment of Mirai-based malware, suggesting that threat actors likely intend to incorporate infected devices into existing Mirai botnet infrastructure. This report underscores the heightened security, financial and disruption risks stemming from botnets following an uptick in botnet-related activity since at least the end of 2024. (Source: Sibylline)

 

08 Apr 25. Global: Distribution of highly sophisticated AI tool will increase long-term security risks. On 7 April, the cyber security company SlashNext reported that unnamed threat actors are distributing a sophisticated, multi-model artificial intelligence (AI) cyber attack automation tool (‘Xanthorox AI’) on the dark web. Xantharox AI contains several highly advanced data exfiltration capabilities including voice and image analysis modules. It can also automate command and control (C2) communication, highlighting Xantharox AI’s extensive capabilities. Additionally, the tool can autonomously generate malicious code, thereby enabling low-skilled threat actors to conduct sophisticated cyber attacks. Xantharox AI is composed of five custom-built large language models (LLMs). It is also stored within private actor-controlled infrastructure to enhance defence evasion, further showcasing the developers’ skillsets and knowledge. Threat actors are increasingly incorporating AI into cyber attacks to boost success rates, enhance sophistication and facilitate attack automation. As such, we assess that this report points to the long-term security risks posed by AI tools amid a broader increase in AI-led cyber attacks. (Source: Sibylline)

 

04 Apr 25. Global: Exploitation of vulnerable third-party tools points to elevated risks from Chinese threat actor. On 3 April, the technology company Google Mandiant reported that the Chinese-nexus cyber threat actor ‘UNC5221’ has been exploiting a critical software vulnerability as part of a likely cyber espionage operation since mid-March. The software vulnerability (CVE-2025-22457) impacts Ivanti Connect Secure virtual private network (VPN) applications and allows threat actors to execute code remotely. UNC5221 deploys to newly observed malware strains (‘TRAILBLAZE’ and ‘BRUSHFIRE’) to establish prolonged connection to actor-controlled infrastructure. The use of new malware through the employment of typical tactics by UNC5221 points to the group’s ongoing development. UNC5221 consistently abuses zero-day and existing software vulnerabilities to move laterally into targeted systems and to execute code remotely. CVE-2025-22457 is equipped with a patch that was released in February, underscoring the necessity for robust patch-management policies to prevent unnecessary exploitation. Threat actors often exploit vulnerable third-party tools to gain access to strategic networks, highlighting what we assess to be long-term security risks. (Source: Sibylline)

 

04 Apr 25. Cyber Update Key points

  • A new malware (‘Crocodilus’) is targeting Android users in Spain and Turkey to steal cryptocurrency wallet keys, elevating financial risks to users (see Sibylline Cyber Daily Analytical Update – 31 March 2025 and our Technical analysis below).
  • A wide-scale phishing operation will increase financial and information-theft risks to individuals (see Sibylline Cyber Daily Analytical Update – 1 April 2025 and our Technical analysis below).
  • A long-term operation injecting ‘fake workers’ into European businesses underscores a rise in espionage and information-theft risks.
  • A new backdoor (‘Anubis’) is being distributed by the cyber criminal group ‘FIN7’, underscoring heightened financial and security risks across the globe.
  • The Chinese-nexus group ‘UNC5221’ is exploiting a software vulnerability in a likely cyber espionage operation, raising third-party security risks.

Technical analysis of weekly stories

Crocodilus is a new mobile banking trojan containing highly sophisticated techniques to steal data and garner illicit funds. The malware is installed via a proprietary malware dropper that bypasses Android security restrictions and then enables Accessibility Services on the device. Once this is enabled, the malware connects to a command-and-control (C2) server to receive instructions such as the list of targeted applications and the fake login pages to overlay over legitimate pages to steal cryptocurrency wallet credentials. The malware will initially overlay a fake alert message on the user’s screen claiming that users must back up their cryptocurrency wallet within 12 hours or they will lose access to their wallet. If users move on to the next stage, the malware will then capture their login credentials and wallet keys to garner profit. By abusing accessibility services, Crocodilus can monitor all accessibility events and log anything displayed on the device, effectively becoming a keylogger. However, the trojan is also capable of overlay attacks, remote access and remote control to complete fraudulent transactions, underscoring the notable sophistication of this banking trojan. Additionally, Crocodilus can hide its remote access activity by overlaying blank screens on top of the activity, obfuscating its malicious behaviour.

‘Lucid’ is a sophisticated Phishing-as-a-Service (PhaaS) platform operated by a Chinese-speaking threat actor, ‘XinXin Group’, targeting 169 entities across 88 countries globally. It operates as a scalable, subscription-based service that allows cyber criminals to conduct large-scale phishing operations to harvest credit card credentials to directly exploit or sell on dark web marketplaces for profit. The phishing operations use text messages to lure victims into clicking malicious links; the phishing messages often contain payment and/or shipping themes to trick users into clicking links. The link will then redirect a user to a phishing webpage that appears to be a legitimate payment portal. Lucid will distribute the malicious text messages using Apple’s iMessage or Android’s Rich Communication Services (RCS) to bypass traditional text messaging spam detection mechanisms as these messaging services use end-to-end encryption and cannot be read by traditional spam tools. To enhance the operation’s detection evasion, the PhaaS platform will then block connections from IP addresses outside targeted regions or if users attempt to access malicious domains directly instead of clicking on the link in the phishing message. Additionally, a credit card verifying tool runs immediately following card details being entered to ensure that the offered details are legitimate.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

Our cyber word(s) of the week: Rich Communication Services (RCS) (Source: Sibylline)

 

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT