Sponsored By Curtiss Wright
https://www.curtisswright.com/
———————————————————————————————————————————————————————————————————————————————————————————————————————————————
27 Jun 25. Thales and KONGSBERG to establish new major Defence communications joint venture in Norway.
- Thales, a global high-tech leader, and Kongsberg Defence & Aerospace, part of the Kongsberg group and a premier supplier of defence products and systems, have signed an agreement to set up a joint venture company in secure communications.
- The new company will consolidate Thales’ crypto and secure communications business in Norway and KONGSBERG’s communications business, which includes software-defined military radios. This collaboration aims to better address the current and future needs of armed forces in Norway, NATO and internationally, employing approximatively 350 people.
- The merger will create a new key player with a strong and comprehensive secure communications portfolio, particularly relevant in the context of accelerating defence spending across Europe.
Thales and Kongsberg Defence & Aerospace have agreed to combine two of their businesses – KONGSBERG’s secure communications unit and Thales’ crypto and secure communications business in Norway – in a joint venture designed to meet the growing connectivity needs of defence forces in Norway, NATO countries and other nations. This new company is a response to European armed forces’ call for greater interoperability, sovereignty, and the urgent need for large-scale equipment delivery. The new company will be jointly owned 50/50 by Thales and Kongsberg Defence & Aerospace with approximatively 350 strong workforce based across Oslo, Trondheim and Asker, Norway. These two businesses had combined revenues of about NOK 1.5bn (130m euros) in 2024. The venture anticipates continued growth, projecting that the combined businesses will achieve NOK 3bn (254m euros) in revenue by end of the decade driven by substantial market opportunities and product synergies. It will have a broader product mix with powerful and advanced systems. Thales in Norway provides high-grade crypto networks and voice communication systems to NATO and other nations. KONGSBERG delivers tactical radio systems for the land domain (combat vehicles and soldiers) and tactical networks for many systems, including NASAMS air defence. Both companies have a strong history in their respective domestic defence and secure communications markets, with significant export potential.
“By consolidating KONGSBERG’s secure communications and Thales’ crypto expertise, we will create a comprehensive, robust communications offering and be better positioned to deliver and develop current and future technologies and services to the armed forces,” said Eirik Lie, President of Kongsberg Defence & Aerospace. “Together, we can develop and sustain a broader and stronger product portfolio and domain expertise to create a solid partner for the Norwegian customer, while also gaining access to better market channels internationally, particularly with the support of Thales’ global distribution network,” said Lie. “Through this jointly owned company, we will be able to strengthen collaboration and leverage synergies between KONGSBERG and Thales, creating a new key player in secure communications that supports bilateral cooperation between Norway and France. The new company will be also particularly well-positioned to address markets where there are complementarities between Thales and KONGSBERG’s portfolio and geographical footprint,” said Christophe Salomon, Executive Vice President of Thales, Secure Communications & Information Systems.
The completion of the transaction is subject to customary regulatory approvals.
26 Jun 25. Bittium launches a comprehensive portfolio of life cycle services to maximize the operational life and performance of tactical communications solutions and to enable local servicing and repair capabilities for the customers in the defense sector. The services are offered for all life cycle stages of the products and systems to support their deployment, use, and eventually transition into a new generation of solutions. The life cycle services support the operational activities of the customers and are adapted to their needs flexibly. Core of the life cycle services is a comprehensive entity of support and maintenance services that entails technical support by Bittium and local partners as well as maintenance of both hardware and software over their entire life cycle. Bittium’s products and systems for tactical communications are designed for extremely demanding use over decades, requiring active management of hardware component life cycles. In systems based on software-defined radio technology, also software maintenance and updates play a particularly significant role. The support and maintenance services entity covers software maintenance and updates and ensuring software compatibility with other elements of the system as well as third-party elements integrated with the system. In addition to the support and maintenance services, Bittium provides several additional services such as training and on-site support according to customer needs. Especially in military crises, customers have a need for localized servicing and repair measures. Bittium enables it by offering different levels of services that can be trained and transferred as part of the customer’s organization. The localized servicing and repair capabilities empower customer sovereignty and maximize operational availability, reducing dependence on Bittium’s support.
“We have formed our life cycle services as a comprehensive entity that meet the requirements of our customers and support their operational activities flexibly. Due to the shift in the state of the world, the need for localized services has grown, and it is important to consider when offering the services. The implementation of life cycle services as complete solutions also helps our customers budget annual expenses and ensure service availability,” said Tommi Kangas, Senior Vice President of Bittium’s Defense & Security business segment.
Life cycle services are an important part of the overall offering of Bittium’s Defense & Security business segment. By developing the offering of life cycle services, Bittium responds to growing customer needs, which also supports Bittium’s growth objectives.
More information on Bittium’s life cycle services: https://www.bittium.com/defense-security/life-cycle-services/
27 Jun 25. Global: New ransomware group points to sustained operational, financial risks facing global firms. On 24 June, the cyber security company Trustwave reported that a new ransomware group (‘Dire Wolf’) has targeted at least 16 global entities since its emergence in May. The group has primarily targeted organisations in the technology and manufacturing sectors, highlighting the elevated operational and financial risks facing these sectors. The group’s victims are global in nature; targets in the US and Thailand have reported the highest number of attacks by Dire Wolf since May. Dire Wolf uses UPX (an executable file compressor tool), which is a common method employed by cyber threat actors to obfuscate malware code so as to inhibit static analysis, pointing to the group’s moderate sophistication. While Dire Wolf’s current arsenal is relatively standard for ransomware groups, we assess that the continuous emergence of new ransomware groups along with the uptick in ransomware operations in 2025 will sustain operational and financial risks facing global firms. (Source: Sibylline)
26 Jun 25. US-East Asia: Long-term intrusion campaign highlights security risks from Chinese threat actors. On 23 June, the cyber security company SecurityScorecard reported that unnamed China-linked threat actors have conducted multiple intrusion campaigns to infect devices across the US and East Asia since at least September 2023. The assailants typically integrate targeted devices – including small and home office (SOHO) routers, Internet-of-Things (IoT) devices, virtual servers and IP cameras – into an operational relay box (ORB) network (‘LapDogs’) to conduct stealthy cyber activity. LapDogs typically infects no more than 60 devices at a time and comprises at least 162 intrusion sets, highlighting the scale and targeted nature of these operations. China-linked threat actors use ORBs to conceal the origins of malicious traffic, likely in a bid to enhance stealth. The report follows an uptick in the number of instances concerning Chinese intrusions into organisations operating across the aforementioned regions. Consequently, we assess this highlights the elevated security risks stemming from China-linked actors amid ongoing geopolitical tensions. (Source: Sibylline)
25 Jun 25. Senior Official Promotes Bolstering DOD Cyber Workforce. During a cybersecurity workforce showcase in Washington yesterday, a senior-level Defense Department official spoke to members of Congress and representatives from the academic and cyber communities about the need to increase the department’s cybersecurity workforce.
Mark Gorak, director of DOD’s Cyber Academic Engagement Office, said there is currently a shortage of over 20,000 cyber professionals departmentwide, including 7,000 essential positions. “We’re at a critical point; cyber talent is a national security imperative,” he told the group, adding that the need for skilled cyber professionals has never been greater amid a constantly changing digital landscape filled with relentless adversaries.
To meet that challenge, Gorak highlighted the work being done through “CyberSkills2Work.”
That program, he said, focuses on drawing in veterans, transitioning service members, first responders and current federal employees, and then providing them with the skills needed to work in the cybersecurity field.
“These individuals understand service, often hold security clearances, possess mission-focused experience and are eager to continue contributing to our national defense,” Gorak said. “Through tailored coursework, industry-aligned certifications and support networks, the program equips participants to transition into cybersecurity roles quickly and effectively to serve the nation,” he added.
In highlighting the progress made thus far, Gorak said the program has already prepared approximately 3,500 cybersecurity professionals, providing more than $10,000 in education and training. Noting the program is “just one piece of a larger puzzle,” Gorak said a “comprehensive, multipronged approach” is needed to strengthen the cyber workforce. To that end, he said DOD’s chief information officer is pursuing five key initiatives to develop a “world-class” cyber workforce:
- Qualifying personnel;
- Mature, skills-based hiring;
- Increasing certification and training opportunities;
- Enhancing cyber workforce initiatives and pay flexibilities; and
- Recognizing and addressing resource limitations.
Gorak said the CIO is increasingly relying on data to make better decisions about the cyber workforce and that a newly developed workforce health report is providing leaders with a clearer understanding of their cyber team by showing individual skill sets and the jobs the team is working on.
“This report pulls together information from across the department, helping leaders see where we have gaps in our workforce and how we can better recruit and keep talented people,” he said, adding that the report helps the department gauge the overall health of its cyber team.
Gorak concluded by emphasizing the role government plays in supporting the department, stating that — by supporting the Cyber Academic Engagement Office — Congress can expect improved cyber workforce development, enhanced national security readiness, streamlined points of contact for congressional inquiries, reduced redundancy and improved return on investment, and a one-stop shop for academia, partners and students.
“To the congressional members who support this program, to the educators who deliver this training and education, and to the learners, thank you,” Gorak said. “Let’s keep building the cyber workforce our nation needs into the 21st century and beyond.” (Source: U.S. DoD)
24 Jun 25. Turkish Air Force inducts F-16 EDPOD into operation. The EDPOD system is fully designed and developed using local resources. The Turkish Air Force has integrated a domestically produced electronic warfare system, the F-16 Electronic Support Pod (EDPOD), into its inventory. The system, created by the TUBITAK Informatics and Information Security Research Center (BILGEM), completed tests flight against actual radar systems, Türkiye Industry and Technology Minister Mehmet Fatih Kacir said in a post on X. Fully designed and developed from local resources, the EDPOD system can identify, categorise, document, and pinpoint radar signals from various enemy radars involved in target detection, tracking, missile guidance, and illumination, according to local newspaper Türkiye Today. This indigenous development aims to decrease Türkiye’s reliance on international defence technology.
“Developed to reduce our country’s dependence on foreign defence technologies, EDPOD has provided a strategic contribution to our electronic warfare capabilities,” Kacir said.
The EDPOD is equipped with both narrowband and wideband receivers, enabling it to detect multiple threats concurrently. The system’s analytical capabilities allow for comprehensive signal parameter assessment, facilitating the creation of an electronic order of battle for electronic warfare operation planning, the newspaper added. Additionally, EDPOD can archive extensive raw signal data for detailed post-mission analysis and facilitate real-time threat data sharing through Link-16 with ground forces and other airborne systems. This significantly improves situational awareness for F-16 pilots and aids in synchronized electronic warfare strategies.
“I congratulate all our colleagues who contributed to this effort and thank the Ministry of National Defense and the Presidency of Defense Industries for paving the way for the development of national systems,” Kacir added. (Source: airforce-technology.com)
25 Jun 25. Global: Botnet expansion underscores increased security, financial risks facing businesses. On 22 June, the security company CloudSEK reported that threat actors have been exploiting legitimate servers to expand the ‘Androxgh0st’ infrastructure. The perpetrators have employed a wider range of initial attack vectors since a previous report was issued in 2024, which has resulted in an approximately 50% expansion of the botnet’s arsenal. This includes the exploitation of software vulnerabilities in internet-facing servers used by prominent academic institutions. The threat actors then establish communication with command-and-control (C2) infrastructure before installing web shells to maintain persistence. Androxgh0st operators also typically exploit additional software vulnerabilities to execute commands remotely; they subsequently steal sensitive information and ‘mine’ for cryptocurrency. The botnets allow the threat actors to propagate cyber attacks via a network of infected devices, underscoring the potential scale and impact of Androxgh0st’s activity. We assess this will increase security, disruption and financial risks facing global entities amid a spike in botnet-related operations since the beginning of 2025. (Source: Sibylline)
24 Jun 25. US: Cyber campaign underscores heightened security risks facing academics, Russia critics. On 21 June, international news outlets reported that the suspected Russian state-sponsored group ‘UNC6293’ has been targeting prominent academics and critics of Russia in the US via a social engineering campaign since at least April. The group distributes spear phishing emails impersonating the US State Department as an initial attack vector. The emails trick victims into creating and sharing an app-specific password to log in to a threat actor-made online meeting platform. UNC6293 then steals the password to hijack victims’ Gmail accounts, likely to monitor user activity and exfiltrate sensitive data. The group often exchanges several emails with victims before coercing them into creating the password, showcasing the premeditated and prolonged nature of this campaign. The attack also requires pre-obtained knowledge of the victims’ systems, highlighting the group’s sophistication and resources. As such, we assess this campaign underscores the heightened security, social engineering and data theft risks facing the aforementioned entities amid current geopolitical instability. (Source: Sibylline)
20 Jun 25. Cyber Update Key points
- A cyber surveillance operation underscores heightened security risks posed to European journalists by the spyware ‘Graphite’.
- The new wiper feature for the Ransomware-as-a-Service (RaaS) operation ‘Anubis’ will increase security, disruption and destruction risks to global businesses.
- Increased cyber activity highlights elevated financial, operational and security risks to operators in Israel and Iran amid the escalating war.
- A deepfake-enhanced cyber campaign raises security risks from the North Korean state-sponsored group ‘BlueNoroff’ (see Sibylline Cyber Daily Analytical Update – 19 June 2025 and our Technical analysis below).
- A cyber espionage operation against a US-based telecommunications provider highlights long-term national security risks posed by the Chinese state-sponsored group ‘Salt Typhoon’ (see Sibylline Cyber Daily Analytical Update – 20 June 2025).
Technical analysis of weekly stories
The Anubis RaaS operation has been responsible for destructive cyber attacks against global businesses (including the construction engineering and healthcare sectors) since at least December 2024. Anubis can be purchased on several cyber criminal forums and enables affiliates to choose from different monetisation avenues, underscoring the continuous evolution of RaaS operations and cyber criminal revenue streams. Threat actors reportedly distribute Anubis via spear phishing emails that trick victims into opening a malicious attachment. The attachment then executes the main ransomware payload before escalating privileges and deleting all backup system files to hinder recovery efforts. Threat actors subsequently identify and encrypt all system files via the Elliptic Curve Integrated Encryption Scheme (ECIES), exfiltrate sensitive data for double extortion and issue a ransom demand for file decryption. The ransomware also contains a wiper component (/WIPEMODE) that can permanently delete all encrypted files regardless of whether the ransom is paid. This feature marks a departure from typical ransomware variants that focus on temporary disruption for financial gain. The North Korean state-sponsored group BlueNoroff is using artificial intelligence (AI)-generated deepfakes to conduct a cryptocurrency-theft campaign against macOS systems. In one incident, the group contacted an employee at an unnamed cryptocurrency company via the messaging platform Telegram to trick them into joining an online meeting. The online session used a fake domain for the virtual meeting platform Zoom and displayed several deepfakes that impersonated members of the company’s leadership as well as external participants. This highlights the continued incorporation of deepfakes into cyber operations to enhance credibility. During the meeting, the actors also faked a microphone issue to coerce the employee into downloading a fake Zoom extension that contained a malicious payload and script. The malicious code then executes an implant (‘Telegram 2’) to establish command-and-control (C2) communication and download additional payloads. This included a backdoor and a remote access trojan (RAT) to maintain persistence within compromised systems and enable remote code execution, as well as a keylogger and a cryptocurrency-focused information stealer to steal user credentials for financial profit. BlueNoroff also exploited several macOS edge cases to inject code into existing processes, highlighting the group’s sophistication.
Non-exhaustive recommendations to mitigate against these threats include:
- Monitor devices and networks for suspicious activity
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
- Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
- Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering
Our cyber word(s) of the week: Deepfake (Source: Sibylline)
20 Jun 25. Silvus Technologies StreamCaster LITE 5200 Added to DIU Blue UAS Framework. Silvus Technologies, Inc., a global leader in advanced wireless networking communication systems, announced that the U.S. Department of Defense (DoD), Defense Innovation Unit (DIU), has officially added Silvus’ StreamCaster LITE 5200 (SL5200) OEM Module to the Blue UAS Framework. Delivering powerful MANET radio performance for today’s leading-edge unmanned systems, the SL5200 unifies C2, sensor and telemetry data with communications relay capabilities in an easy to integrate, ultra-low SWaP OEM module form factor. After undergoing the Blue UAS program’s rigorous evaluation, this certification validates the SL5200 compliance with DoD standards for cybersecurity, supply chain integrity and operational reliability. Interoperable and NDAA compliant, the SL5200 has been approved for use in conjunction with Blue UAS platforms. The SL5200 joins the StreamCaster SC4200EP and StreamCaster LITE SL4200 MANET radios on the Blue UAS Framework – exemplifying Silvus’ commitment to delivering robust, secure, and reliable C2 and mesh networked communications solutions for unmanned operations across any domain.
“Silvus continues to push the boundaries of mesh networking for mission-critical unmanned systems applications,” said Jimi Henderson, VP of Sales, Silvus Technologies. “With all three of our latest StreamCaster MANET radios now on the Blue UAS Framework – we’re proud to lead the way in secure, resilient communications technology for unmanned systems developers.”
SL5200: Blue UAS Framework Certified. The Power To Perform
Compact and powerfully versatile, the SL5200 delivers class-leading power, range, and tactical mobility with up to 2 Watts output power (4W effective power, thanks to TX Eigen-Beamforming), and 100 Mbps data rate for bi-directional C2, video, sensor and telemetry data communications in one self-contained OEM Module.
Featuring an ultra-low SWaP profile (52g), with multiple I/O interface options (Ethernet, USB, RS232), the SL5200 is designed for seamless integration into leading-edge unmanned systems, loitering munitions, and other SWaP constrained embedded applications. Systems operators can now experience Group 2 UAV level radio performance in a compact form factor engineered for Group 1 sized platforms.
At the heart of every StreamCaster MANET radio is Silvus’ battle-proven MN-MIMO waveform, that creates a self-forming and adaptive mesh network – capable of linking hundreds of nodes with unmatched range, throughput, EW resiliency and scalability. With the SL5200, operators can connect multiple UAVs, UGVs, USVs, sensors, personnel, and manned/unmanned platforms, to actualize a common operating picture through one massively scalable mesh network. The SL5200 is seamlessly compatible with 4000-series StreamCaster MANET radios, ensuring interoperability across a diverse range of applications. In addition to AES256 and FIPS 140-3 encryption for secure operations, the SL5200 provides available access to Silvus’ Spectrum Dominance – an expansive suite of LPI/LPD and Anti-Jamming resiliency capabilities. Silvus is the only tactical MANET radio provider that delivers Spectrum Dominance secure and protected communications in complex, congested and contested environments, without sacrificing performance. (Source: UAS VISION)
——————————————————————————————————————————————————————————————————————————————————————————————————————————————-
Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.
We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.
Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.
————————————————————————————————————————————————————————————————————————————————————————————————————————————-

