• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

April 18, 2025 by

17 Apr 25. Europe: New backdoor underscores long-term security, espionage risks from China-nexus groups. On 15 April, the security company NVISO reported that the China-nexus threat group ‘UNC5221’ has been targeting European organisations in a suspected cyber espionage operation since at least 2022. The group has reportedly been employing a new version of the custom backdoor ‘BRICKSTORM’ to target Windows environments. BRICKSTORM was originally developed to target Linux servers; this suggests that UNC5221 has modified its tools in order to expand its victim pool. The new variant facilitates lateral movement and obfuscation within compromised systems via file-management and network-tunnelling capabilities. UNC5221 then exploits legitimate network protocols to execute commands and conduct additional malicious activity. Several different cloud providers host BRICKSTORM’s command-and-control (C2) infrastructure; the group also uses common protocols for communication. We assess this showcases the sophistication of the group’s detection-evasion capabilities. As such, the operation underscores the security and cyber espionage risks facing European entities from China-nexus groups amid currently elevated geopolitical tensions. (Source: Sibylline)

 

15 Apr 25. Portugal and Brazil to jointly develop a new C-390 Millennium variant for strategic intelligence gathering. On April 1, 2025, during the LAAD Defense & Security exhibition in Rio de Janeiro, the Portuguese Air Force officially announced its decision to join Embraer and the Brazilian Air Force (FAB) in joint studies aimed at adapting the C-390 Millennium multi-mission transport aircraft to perform Intelligence, Surveillance, and Reconnaissance (ISR) missions. The announcement was made at a formal ceremony attended by General João Cartaxo Alves, Commander of the Portuguese Air Force; Lieutenant-Brigadier Marcelo Kanitz Damasceno, Commander of the Brazilian Air Force; Francisco Gomes Neto, President and CEO of Embraer; and Bosco da Costa Junior, President and CEO of Embraer Defense & Security. A concept image was presented showing the roll-on/roll-off modular ISR mission system currently under development. This system is designed to enable ISR capabilities while retaining the aircraft’s existing multi-mission functions. The ISR-capable version of the aircraft is officially designated as the C-390 IVR. This variant is part of an effort led by the Brazilian Air Force and Embraer to integrate ISR capabilities such as synthetic aperture radar, electro-optical and infrared sensors, advanced communication systems, and two hardpoints for external payloads. The development is intended to maintain compatibility with current operational and logistical systems. Structured studies are ongoing to evaluate potential adaptations of the C-390 platform, particularly for maritime patrol and ISR tasks. According to Lieutenant-Brigadier Damasceno, these studies are being conducted efficiently and systematically. Bosco da Costa Junior stated that the initiative is aligned with an ongoing partnership to extend the aircraft’s operational scope.

The announcement by Portugal builds on developments from December 3, 2024, when Embraer and the FAB signed agreements at the Mostra BID National Defense and Security Fair in Brasília to develop ISR and maritime patrol capabilities for the aircraft. These efforts are focused on increasing surveillance coverage across multiple operational environments, including coastal zones and national airspace. The concept of a roll-on/roll-off ISR mission system supports rapid reconfiguration for different missions, including those involving monitoring of territorial waters, Exclusive Economic Zones, and national infrastructure. The Portuguese Air Force’s participation adds operational experience and contributes to technical evaluation processes for the ISR configuration. The C-390 IVR development aligns with increased global demand for ISR platforms. The ISR aircraft and drones market was valued at $13.37 bn in 2023 and is projected to reach $22.1 bn by 2033. ISR systems are used to monitor large areas for security, environmental, or resource-related purposes. Brazil’s maritime geography and offshore interests are cited as drivers behind the decision to adapt the C-390 to ISR and maritime patrol missions. Similar needs exist in other regions such as Southeast Asia, the Middle East, and Eastern Europe. Countries already operating the C-390 Millennium, including South Korea and Sweden, may assess the ISR variant’s relevance for their maritime or border surveillance requirements. The C-390 Millennium was developed by Embraer beginning in the mid-2000s with financial support from the Brazilian government and Air Force. It was designed as a twin-engine, jet-powered alternative to turboprop tactical transports such as the C-130. The project received a $1.5bn development contract in April 2009, and the aircraft’s first flight occurred on February 3, 2015. The aircraft entered service with the Brazilian Air Force in 2019. By June 2022, the C-390 fleet had flown over 8,200 hours across 6,000 flights. According to Embraer and the FAB, the platform achieved a technical availability rate of approximately 80% and a mission completion rate of 99.5%. The aircraft has been used in various missions, including pandemic response in Manaus, humanitarian aid to Lebanon and Haiti, joint exercises in the United States, Antarctic supply flights, and repatriation efforts during the Russia–Ukraine conflict. Portugal has been part of the C-390 program since 2010. It ordered five aircraft in 2019 to replace its C-130 fleet. The first C-390 was delivered in October 2022, reached full operational status in October 2023, and has since completed transatlantic missions and international exercises. Portugal’s OGMA company is involved in the industrial production of the aircraft, including structural components and systems. On April 25, 2023, Brazilian President Luiz Inácio Lula da Silva and Portuguese Prime Minister António Costa announced that the KC-390 could be assembled at OGMA for European customers. The Portuguese Air Force’s involvement in ISR studies reflects its existing operational use of the aircraft and participation in the industrial base. (Source: Google/armyrecognition.com)

 

16 Apr 25. The USAF is demonstrating its commitment to joint warfighting capabilities, integrating airpower into a vast network of sensors and shooters during Project Convergence Capstone 5, a large-scale military modernization experiment held amidst the desolate California desert, the Shadow Operations Center-Nellis Air Force Base, Nevada, and other locations February through April. Project Convergence Capstone 5, hosted by Army Futures Command, serves as a vital experimentation ground for the future of warfare. It focuses on the continued integration of joint and multi-national layered air and missile defense systems. The Air Force Futures Directorate is the primary organization responsible for the Air Force contributions to the Army’s large force experiment. The event brings together forces from the Air Force, Space Force, Air National Guard, Army, Navy, Marine Corps and coalition partners from the United Kingdom, Australia, Canada, New Zealand, France and Japan.

“We are in the middle of a generational evolution when it comes to developing operational concepts, fielding technologies, and pursuing new levels of force integration,” said Lt. Gen. Dave Harris, deputy chief of staff for Air Force Futures. “These events are critical as we develop and deliver capabilities for the joint force that provide decision advantages that keep the U.S. well ahead of the threat.”

A key program for the experiment is the continued development of the Tactical Operations Center-Light Major Release 1, a program managed by the Department of the Air Force Program Executive Office for Command, Control, Communications and Battle Management. Airmen used the system to refine integration with joint force systems, including Palantir’s AI-driven Maven Smart System and the System-of Systems Technology Integration Tool Chain.

“PC-C5 brings multiple agencies together, allowing us to integrate diverse software and applications into a unified operating picture and troubleshoot systems like the TOC-L,” said Tech. Sgt. Timothy Keefer, a weapons and tactics flight chief for the 752nd Operations Support Squadron, and acting as the advanced Joint Interface Control Center operator for the experiment. “Legacy systems offer some mobility, but not agility. The TOC-L moves us toward both, which is essential for future battlefields.”

PC-C5 serves as a crucial operational venue for data-gathering, providing valuable insights into the effectiveness of these programs within the DAF BATTLE NETWORK, the Air Force’s contribution to Combined Joint All Domain Command and Control. Air Force Futures creates the Air Force’s strategy across multiple time epochs, develops the corresponding force design, and advocates for the necessary requirements to ensure the Air Force possesses the capabilities to deter, and if required, defeat strategic competitors. Their Advanced Battle Management System Cross Functional Team is leading the planning, management and execution of Air Force support to PC-C5.

The Air Force Operational Test and Evaluation Center is leading the Air Force’s campaign of learning during the experiment.

“We’re focused on delivering valuable data to senior leaders – data about both the systems and their human operators,” said Kristopher Looney, AFOTEC’s Experimentation Directorate director. “System data reveals precisely how operators and technology interact, highlighting successes and failures. Directly interviewing operators provides crucial context, helping us understand why things worked or didn’t.”

The shift from traditional, siloed testing to collaborative development in a real-world environment is central to the Air Force’s modernization strategy. Project Convergence embodies this approach, allowing for rapid iteration and feedback loops that accelerate the development and refinement of tactics, techniques and procedures for multi-domain operations.

“We use mission threads focused on shortening the kill chain,” said Tech. Sgt. Jeylend Kitchen, lead non-commissioned officer in charge of group evaluations for the 552nd Air Control Group and acting as the weapons director for the experiment. “Current mission threads involve extensive communication to verify information, which can create delays. We aim to automate this process, enhancing decision advantage. AI-enabled software like STITCHES and MSS helps ensure operators have accurate, readily available information based on established TTPs.”

PC-C5 demonstrated the TOC-L MR1’s interoperability with Army command and control systems and other joint assets, a key aspect of the DAF BATTLE NETWORK, the systems-of-systems that provides resilient decision advantage.

“This experiment continues to show us the critical importance of human-machine teaming within the CJADC2 structure,” said Army Chief Warrant Officer 3 Matthew Middlebrooks, a member of the Army’s cross functional team for the 108th Air Defense Artillery Brigade and acting as a JICC operator for the experiment. “While we’ve made strides in system integration, we must equally prioritize training and procedures that optimize human-machine teaming. This experiment allows us to observe our procedures in action, identifying areas for refinement and gain a clear understanding of the joint air and ground defense picture.”

The lessons learned from PC-C5 will directly inform future readiness and modernization activities, ensuring the Air Force and its joint and coalition partners are equipped to address emerging threats. By analyzing data, refining TTPs, and identifying areas for improvement in technology, training and doctrine, the Air Force continues to evolve its capabilities to maintain its competitive edge in an increasingly complex global security environment. (Source: ASD Network)

 

11 Apr 25. ESSOR to enter stage 4. The European Secure Software Defined Radio (ESSOR) programme will enter stage 4 in July, a Rohde & Schwarz (R&S) spokesperson told Janes on 10 April. The stage 4 of the programme will involve the fielding of a high data-rate waveform (HDRWF) and development of a narrowband waveform (NBWF) with the aim of ensuring native interoperability among different types of radios for NATO and its Federated Mission Networking (FMN) capability. Andreas Boyd Buchin, operations director at the Alliance for ESSOR (a4ESSOR) joint venture, told journalists including from Janes visiting R&S at the beginning of April that the ESSOR programme seeks to enable interoperability of mission-critical radio connectivity assets for all domains by co-developing and standardising waveforms and the supporting infrastructure. It aims to develop pan-European software-defined radio (SDR) technology to improve the interoperability of armed forces participating in coalition operations. The participating countries are Germany, Finland, France, Italy, Poland, and Spain. The Bonn-based Organisation for Joint Armament Cooperation (Organisation Conjointe de Coopération en matière d’Armement: OCCAR) is the ESSOR programme office, which has contracted a4ESSOR made up of Bittium, Indra, Leonardo, Radmor, R&S, and Thales. The programme cost is EUR290m (USD323.7m) for 2008–25. ESSOR is the design authority and customer focal point tasked with the management, co-ordination, and control of the design and development of ESSOR products. In addition to the HDRWF and NBWF, these products include the ESSOR 3-Dimensional Waveform (3DWF) and ESSOR Satellite communication Waveform. There will be NATO Standardization Agreements (STANAGs) for all four waveforms. (Source: Janes)

 

16 Apr 25. US Navy adds Persistent Systems to FoS USV IDIQ contract. Company’s mobile ad hoc network (MANET) technology to support Navy’s vision of integrating manned and unmanned formations. Persistent Systems, LLC (“Persistent”), a leader in mobile ad hoc networking (MANET), announced today the U.S. Navy has selected the company as one of 88 participants for a $982.1 m, indefinite delivery/indefinite quantity (IDIQ) contract to support current and future data links for unmanned surface vessels (USVs). The USV Family of Systems (FoS) contract, first awarded in 2020, now includes 88 contractors supporting the Navy’s effort to integrate USVs into its fleet. Building on its experience working with the Unmanned Systems divisions of Naval Surface Warfare Centers and Naval Information Warfare Centers, Persistent Systems will supply its MANET solutions to Naval Sea Systems Command (NAVSEA) to enable secure, resilient data links for RDT&E efforts in support of the Navy’s USV program.

“As a leading provider of MANET solutions for this contract, we will serve as the critical data link for maritime unmanned reconnaissance vehicles, supporting numerous mission sets, including maritime domain awareness, sea control/sea denial, and swarming operations,” said Ed Leopold, Director of Business Development at Persistent Systems. “This is essential for maintaining real-time situational awareness for expeditionary forces and supporting collaborative autonomy of unmanned systems.”

The company’s MPU5 networking devices leverage their highly scalable Wave Relay® MANET to seamlessly connect users in a true peer-to-peer fashion, allowing for the high-throughput transfer of voice, video, text, sensor data, and GPS information without needing external infrastructure.

“As the U.S. Navy emphasizes the need for manned and unmanned formations, we are seeing the shift from pilot programs and proof of concepts towards the implementation of validated USV upgrades as part of their Unmanned Maritime Autonomy Architecture (UMAA),” says Leopold.

This IDIQ contract builds on Persistent’s ongoing work with the Navy. Over the past few months, the company has supported several naval efforts: In July, the U.S. Naval Information Warfare Center Pacific awarded Persistent a contract to network USVs, individual operators, ships, and ground control stations; Persistent Systems supported networking efforts during Valiant Shield, a joint exercise conducted every two years across the INDOPACOM Area of Responsibility and; During the Paris Olympics, the French navy used Persistent’s MANET technology on vessels and shore infrastructure to secure a sailing competition.

“We look forward to building on these relationships, and this selection reinforces our position as a trusted supplier for the U.S. Navy,” Leopold concluded. (Source: ASD Network)

 

11 Apr 25. Cyber Update Key points.

  • A large-scale, multi-pronged phishing campaign (‘PoisonSeed’) points to heightened financial risks for cryptocurrency users and our Technical analysis below).
  • The distribution of a highly sophisticated artificial intelligence (AI) cyber attack automation tool will increase long-term security risks facing global entities.
  • A spike in cyber attacks against Internet-of-Things (IoT) devices underscores heightened security risks stemming from botnet infrastructure.
  • Activist groups face long-term surveillance and data-theft risks from Chinese state-sponsored actors (see Sibylline Cyber Daily Analytical Update – 10 April 2025).
  • A cyber operation by the Russia-nexus group ‘Gamaredon’ highlights the prolonged security and espionage risks for Ukraine-based Western military entities and our Technical analysis below).

Technical analysis of weekly stories

Unidentified threat actors are targeting global cryptocurrency users in a multi-pronged financially motivated campaign (PoisonSeed). The campaign starts with the creation of fake login pages emulating high-profile email marketing providers; threat actors then distribute the fake pages via spoofed email domains, tricking victims into entering their credentials to hijack targeted user accounts. Threat actors then export existing marketing mailing lists from the compromised systems to identify potential targets. Subsequently, the actors disseminate mass cryptocurrency-related phishing emails, using compromised and spoofed email domains to appear legitimate and bypass security mechanisms. They also generate a new application programming interface (API) key to maintain prolonged access within compromised systems in the event of a credential reset, underscoring the actors’ moderate capabilities. The phishing emails contain a fake cryptocurrency seed phrase which is typically used to restore access to cryptocurrency wallets in instances where users lose access. The emails also contain a warning about a fake wallet migration to coerce victims into transferring funds into an actor-controlled wallet highlighting the actors’ social engineering skills. Threat actors can then use the fake seed phrases to steal funds by transferring them to an external account.  The Russia-nexus group Gamaredon has been targeting the military mission of an unnamed Western country in Ukraine in a cyber espionage operation since at least February. Gamaredon reportedly used external removable drives to infiltrate targeted systems and run an obfuscated .LNK file. The file contained a script that executed two files to establish command-and-control (C2) communication and deploy an information-stealing malware (‘GammaSteel’). Gamaredon implemented multiple new, advanced detection evasion techniques throughout the campaign, showcasing the development of its capabilities. This included the adoption of legitimate tools to initiate C2 communication as well as the migration to PowerShell-based tools to enhance detection evasion. Gamaredon used a PowerShell script before executing GammaSteel to gather information on the targeted system’s security protections and to facilitate detection evasion. Subsequently, GammaSteel then employed a PowerShell-based web request to exfiltrate sensitive documents from compromised systems.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security detection systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

Our cyber word(s) of the week: PowerShell. (Source: Sibylline)

 

14 Apr 25. Global: New, stealthy phishing kit variant underscores long-term security, financial risks. On 12 April, international news outlets reported that threat actors are using a new, more advanced version of the Phishing-as-a-Service (PhaaS) kit ‘Tycoon2FA’. The kit primarily targets Microsoft365 and Gmail users and has been active since at least October 2023. This variant features enhanced capabilities to evade detection and bypass endpoint security protections, enabling the theft of user credentials and the hijacking of user accounts for financial gain. The new version of Tycoon2FA reportedly uses a new character encoding standard to conceal malicious code. It also contains a JavaScript that detects browser automation tools to hinder analysis, underscoring the development of Tycoon2FA’s detection evasion capabilities. Additionally, the new kit hosts a CAPTCHA challenge on actor-controlled infrastructure to further enhance obfuscation, highlighting the actors’ sophistication and resources. We assess that this report displays the long-term security and financial risks posed by the continuous innovation of cyber criminal tools and enterprises. (Source: Sibylline)

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT