• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • SPECTRA banner
  • Curtiss-Wright banner

BATTLESPACE Updates

   +44 (0)77689 54766
   

  • Home
  • Features
  • News Updates
  • Defence Engage
  • Company Directory
  • About
  • Contact

C2, TACTICAL COMMUNICATIONS, AI, CYBER, EW, CLOUD COMPUTING AND HOMELAND SECURITY UPDATE

May 30, 2025 by

Sponsored By Curtiss Wright

 

 

https://www.curtisswright.com/

 

———————————————————————————————————————————————————————————————————————————————————————————————————————————–

28 May 25. Europe-North America: Russian state-sponsored group will elevate security risks for defence sector. On 27 May, the technology company Microsoft reported that a new Russian state-sponsored group (‘Void Blizzard’) has targeted government and defence sectors across Europe and North America in a cyber espionage operation since at least 2024. Void Blizzard typically purchases stolen user credentials on the dark web to hijack user accounts via password spraying attacks, highlighting the low-resource and low-cost nature of these attacks. More recently, the group has also started using spoofed login pages resembling those for the identity management service ‘Microsoft Entra’ to steal authentication data, showcasing the rapid evolution of Void Blizzard’s skillset. The group has reportedly extracted emails, files and chats throughout its campaign, likely in a bid to collect strategic information pertaining to the war in Ukraine and the security posture of Ukraine’s allies. We assess this underscores the elevated security risks facing the aforementioned sectors amid the continued expansion of Russia’s cyber strategy. (Source: Sibylline)

 

28 May 25. Nokia and blackned to create next-generation deployable tactical networks for the defense sector. Companies sign agreement to provide advanced, deployable mobile communication systems for military battlefield operation

Tailored for Germany’s defense requirements, with adaptability for international use

Leverages Nokia’s cutting-edge 5G technology and blackned’s expertise in defense digitalization to enable high performance, scalability and strategic advantage

Nokia and blackned GmbH, in which the Düsseldorf-based technology group Rheinmetall holds a 51% stake, have entered into a memorandum of understanding to create advanced deployable tactical networks for the defense sector, the companies announced today. The partnership brings together Nokia’s 5G technology and blackned’s expertise in defense digitalization to develop high-performance, next-generation tactical communications solutions that provide secure and reliable connectivity for military operations in the field. Under the agreement, the companies will integrate their respective product and solution portfolios to design a unique, deployable communication system tailored to Germany’s defense needs and adaptable for use in other countries. This collaboration will leverage Nokia’s 5G tactical communications technology and blackned’s software-based defense solutions, creating an ideally integrated platform for the Rheinmetall Battlesuite. Deployable tactical networks are cutting-edge, mobile solutions designed for quick deployment and extended reach. Built for various battlefield environments, these systems provide reliable, uninterrupted connectivity and high data rates for military teams supporting the Software Defined Defense paradigm. These deployable tactical networks enhance situational awareness, speed up decision making and improve asset co-ordination

“blackned is dedicated to advancing innovation in defense digitalization, and our agreement with Nokia represents an important milestone in that mission. Together, we will provide powerful, flexible and future-ready tactical network solutions built for the realities of modern defense, said” Timo Zaiser, CTO at blackned GmbH.

“In a rapidly evolving tactical environment, speed, mobility and adaptability are paramount. Through the partnership with blackned, our 5G technology will empower defense forces to deploy robust communication capabilities swiftly and share intelligence more effectively, providing our customers with a decisive advantage on the battlefield,” added Giuseppe Targia, Head of Space and Defense at Nokia.

 

27 May 25. US: Evolving social engineering tactics underscore heightened security risks facing legal sector. Earlier on 27 May, international news outlets reported that the cyber criminal group ‘Luna Moth’ has targeted US law firms in a cyber extortion campaign since at least 2023. Luna Moth uses phishing or telephone-oriented attack delivery (TOAD) techniques to trick victims into calling a customer support phone number embedded in a phishing email. During the phone call, victims receive a link that covertly installs a remote access programme, providing threat actors with prolonged access to compromised systems. Luna Moth started shifting its tactics in March. Threat actors are known to impersonate IT personnel so as to trick victims into enabling remote access sessions to facilitate covert data exfiltration. The group then exfiltrates sensitive data and sends an extortion note to victims, threatening to leak the stolen data unless a payment is made. The report underscores the heightened security, social engineering and financial risks facing the legal sector amid the continuous evolution of cyber criminal tactics. (Source: Sibylline)

 

23 May 25. Cyber Update Key points.

  • A new backdoor (‘Skitnet’) will elevate the security risks facing global entities from ransomware groups (see Sibylline Cyber Daily Analytical Update – 19 May 2025 and our Technical analysis below).
  • State-sponsored cyber attacks showcase the ongoing security risks facing perceived adversarial entities as geopolitical tensions continue to strain (see Sibylline Cyber Daily Analytical Update – 20 May 2025).
  • A series of ransomware attacks by the threat group ‘Scattered Spider’ point to the elevated security risks facing global businesses in the medium term (see Sibylline Cyber Daily Analytical Update – 21 May 2025).
  • A long-term cyber espionage operation by the Russian state-sponsored group ‘APT28’ underscores the heightened security risks facing European and US entities.
  • The exploitation of a zero-day software vulnerability underscores the heightened security, supply chain and pre-positioning risks from the Chinese-speaking group ‘UAT-6382.’

Technical analysis of weekly stories

Ransomware groups are increasingly deploying a new backdoor (Skitnet) to conduct stealthy post-exploitation activities. Threat actors typically use a first-stage malware-loader to decrypt and execute Skitnet within a compromised system’s memory upon infiltrating said system. Skitnet then establishes communication with threat actor-controlled infrastructure and initiates three separate channels of communication (for command execution, data exfiltration and monitoring activities), showcasing its sophistication. The backdoor relies on a domain name system (DNS) and the hypertext transfer protocol (HTTP) for command-and-control (C2) communication to assimilate with legitimate traffic and enhance Skitnet’s stealth. Skitnet can download remote access tools for remote command execution, take screenshots, enumerate active security software and perform persistence tasks. It can also execute PowerShell scripts for enhanced attack customisation, allowing threat actors to retain prolonged control over compromised systems. Skitnet is available for purchase on dark web forums; this likely enables ransomware groups to upscale and streamline cyber operations quickly.

The Chinese language-speaking group UAT-6382 has been exploiting a zero-day vulnerability (CVE-2025-0994) to penetrate targeted systems since at least January. The vulnerability affects an asset management platform (Trimble Cityworks) that is widely used by local governing bodies across the US; it enables authenticated users to execute code remotely on compromised systems. UAT-6382 infiltrated the platform before exploiting CVE-2025-0994 to conduct initial system reconnaissance and to deploy malware. This included the deployment of several web shells (‘AntSword’, ‘chinatso’ and ‘Behinder’), backdoors, ‘Cobalt Strike’ beacons and a ‘VShell’ stager to maintain prolonged access to compromised systems and execute additional malicious code. The group also used the web shells to facilitate data exfiltration after enumerating multiple directories and files of interest. Furthermore, UAT-6382 used a malware loader (‘TetraLoader’) to deploy the beacons and stager into legitimate system processes so as to enhance detection evasion. The group then pivoted into customer environments (particularly those involved in utility and public asset management), likely in an effort to monitor systems and conduct pre-positioning activities.

Non-exhaustive recommendations to mitigate against these threats include:

  • Monitor devices and networks for suspicious activity
  • Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
  • Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
  • Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering

Our cyber word(s) of the week: Beacons. (Source: Sibylline)

 

23 May 25. US: Vulnerability exploitation points to security risks from Chinese-speaking threat actors. On 22 May, the cyber security company Cisco Talos reported that the Chinese language-speaking group ‘UAT-6382’ has been exploiting a zero-day vulnerability (CVE-2025-0994) to penetrate targeted systems since at least January. CVE-2025-0994 affects an asset management platform (Trimble Cityworks) that is widely used by local governing bodies across the US. UAT-6382 infiltrated the platform before exploiting the vulnerability to execute malicious code on compromised servers. This enabled the group to conduct initial system reconnaissance, and subsequently to deploy malware to prolong access. UAT-6382 then pivoted into customer environments (particularly those involved in utility and public asset management) in a likely bid to monitor systems and conduct pre-positioning activities. Trimble released a patch for this vulnerability in February, showcasing the importance of timely patch-management policies. China-linked threat actors routinely target and establish persistence within US national infrastructure; we assess this underscores the heightened security, supply chain and pre-positioning risks facing the aforementioned sectors. (Source: Sibylline)

 

20 May 25. Network Innovations today announced the launch of Argus, a software-defined platform that transforms how organizations deploy, secure, and scale communications across terrestrial, wireless, and satellite environments. This includes Network Innovations’ own VSAT network, third-party satellite networks (Starlink, OneWeb), 5G/LTE, private LTE, and terrestrial transport. Argus is a mission-ready overlay framework that bridges multi-path connectivity, security, and operational complexity by unifying disparate technologies under a single cohesive platform. The result is simplified deployment with strengthened network security and operational efficiency for customers in the government, enterprise and maritime sectors, among others.

“Argus was developed with the understanding that lives, missions, and outcomes depend on unfailing, agile, and secure connectivity in an increasingly complex environment,” said Derek Dawson, CEO of Network Innovations. “This solution serves as an invisible backbone to bring these technologies into one cohesive framework, so organizations have visibility, control, security, and resilience to focus on what matters, when and where it matters, without worrying about their network.”

 

26 May 25. Switzerland to expand EU defense ties with new cyber-defense role. Switzerland has received the European Union’s approval to join a multinational military cybersecurity project, the EU’s Council announced this week. The decision allows Switzerland to become part of the Estonian-led Cyber Ranges Federations project under the EU’s Permanent Structured Cooperation (PESCO) framework, marking a notable advance in Swiss–EU military cooperation. This comes despite Bern’s famously longstanding policy of strict military neutrality. Switzerland had applied to join the project in October of last year, shortly after submitting an application for another joint project focused on military mobility. Two formalities remain before becoming a full project member: Estonia must invite Switzerland to the cooperation, and Bern needs a so-called administrative arrangement with the EU governing formalities such a data exchange and other parameters. The Swiss government welcomed this week’s EU decision, saying that the country “will take part in the European PESCO project.” Switzerland has beefed up its own cyber defense capabilities in recent years with its Swiss Cyber Training Range and a Cyber-Defence Campus. The EU’s Cyber Ranges Federations initiative seeks to centralize capacity, pool unique services and automate processes across member states, reducing manual workload during exercises and accelerating the development of advanced cybersecurity technologies. Austria, Belgium, Bulgaria, Finland, France, Italy and Luxembourg are already members of the project, in addition to Estonia. Under PESCO’s third-state participation rules established in 2020, non-EU countries may join individual projects if they share EU values and pose no threat to member states’ security interests. The Council confirmed that Switzerland meets the required political, legal and substantive criteria and will bring “substantial added value and mutual benefit” to the federation, it said in a press release. The Council retains oversight of third-state involvement and may adjust conditions should security considerations evolve, ensuring alignment with the EU’s collective defense objectives. Swiss defense planners have balanced these new engagements with Bern’s policy of armed neutrality, with federal officials calling cooperation in PESCO initiatives “ad hoc collaboration on specific projects which are thematically in the interest of both parties and which do not create critical dependencies for neutrality.” Participation in the cyber project enables Switzerland to contribute – and benefit from – expertise and infrastructure without entangling the country too deeply in broader EU defense commitments, from Bern’s point of view. The Swiss government said that “participation will take place selectively and on a needs-oriented basis.” The latest project represents part of Switzerland’s broader strategic approach to selective participation in PESCO projects that align with its defense interests while maintaining neutrality. It’s not Switzerland’s first brush with EU defense initiatives. In January, the government received the green light to join an EU-led military mobility project, which it applied for in September 2024. The Military Mobility project aims to simplify and standardize national cross-border military transport procedures, enabling swift movement of military personnel and assets throughout the EU via road, rail, sea, or air. Other non-EU countries, such as the UK, Northway, the USA and Canada are also part of this project. In addition to deepening engagement with the EU, Switzerland has also been a member of NATO’s partnership for peace since the 1990s, as has its neutral eastern neighbor, Austria. Hardline neutrality defenders have long taken issue with Swiss engagement on military projects beyond its own borders. Their criticism received new urgency in the aftermath of Russia’s attack on Ukraine in 2022. Last year, a civil movement garnered more 130,000 certified signatures to organize a national referendum on strengthening Switzerland’s international neutrality. The referendum organizers specifically want to prevent what they see as a gradual erosion of Switzerland’s traditional neutrality through strengthened international defense cooperation. (Source: Defense News)

——————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.

We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.

Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.

————————————————————————————————————————————————————————————————————————————————————————————————————————————-

Primary Sidebar

Advertisers

  • Pythia
  • Teledyne
  • Exensor
  • Visit the Oxley website
  • Blighter
  • SPECTRA
  • Britbots logo
  • Faun Trackway
  • Systematic
  • CISION logo
  • ProTEK logo
  • ProTEK logo
  • ssafa logo
  • IEE
  • EXFOR logo
  • sibylline logo
  • Team Thunder logo
  • Comtech logo
  • GoExporting logo
  • ECHODYNE logo
  • Supercat logo
  • Galvion logo
  • Leonardo DRS logo
  • MTC logo
  • IDC logo
  • DSEI logo
  • DVD2024 logo
  • SDSC logo
  • TELEDYNE FLIR logo
  • VeteranUK logo
  • Matrix Space logo
  • ST Engineering logo
  • EWS logo
  • sentinel photonics logo
  • capua logo
  • Curtiss-Wright logo
  • Brave1 logo
  • Drone Evolution logo
  • AEI Systems logo
  • EOS logo
  • NMSUK logo
  • Openworks logo
  • Sandown Park logo
Hilux UKDSE AARTOS ST Engineering Future Artillery

Contact Us

BATTLESPACE Publications
41 St Georges Drive
London SW1V 4DG

+44 (0)77689 54766

BATTLESPACE Technologies

An international defence electronics news service providing our readers with up to date developments in the defence electronics industry.

Recent News

  • Protek Selected By Dutch Armed Forces

    May 2, 2026
    Read more
  • PARLIAMENTARY QUESTIONS

    May 1, 2026
    Read more
  • MANAGEMENT ON THE MOVE

    May 1, 2026
    Read more

Copyright BATTLESPACE Publications © 2002–2026.

This website uses cookies to improve your experience. If you continue to use the website, we'll assume you're ok with this.   Read More  Accept
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT