Sponsored By Curtiss Wright
https://www.curtisswright.com/
———————————————————————————————————————————————————————————————————————————————————————————————————————————————-
10 Jul 25. Europe: India-linked actors will raise cyber espionage, security risks to diplomatic entities. On 8 July, the cyber security company Trellix reported that the India-linked advanced persistent threat (APT) group ‘DoNot APT’ has conducted a suspected cyber espionage operation against an unnamed European foreign affairs ministry. DoNot APT distributed phishing emails to trick users into clicking on a Google Drive link that triggered the download of a .RAR archive. The archive then deployed a custom remote access trojan (RAT) called ‘LoptikMod’ to establish communication with command-and-control (C2) infrastructure, execute commands, download additional malicious payloads and exfiltrate data. LopTikMod also displays anti-virtual machine techniques to prevent the malware from executing in multiple environments and hinder analysis, highlighting the sophistication of its detection evasion capabilities. The adoption of LopTikMod showcases a likely shift in the group’s tactics to include more targeted and premeditated operations against diplomatic entities across Europe. This will therefore raise security and cyber espionage risks in the medium-to-long term amid shifting geopolitical relations. (Source: Sibylline)
10 Jul 25. Mergers and Acquisitions. As these words were being written in late June, it was no exaggeration to say the Islamic Republic of Iran’s Integrated Air Defence System (IADS) and Ground-Based Air Defences (GBAD) were no longer a threat. Israel commenced her attacks against Iranian Weapons of Mass Destruction (WMD), and politico-military targets, on 13th June. The goal of the attacks being to destroy Iran’s ability to develop and deploy nuclear weapons. The United States joined the fray on 21st June, hitting three targets associated with Iran’s WMD ambitions. So far, it appears Israel and US warplanes have suffered no losses. Israel declared air superiority over Tehran on 15th June. It seems likely the Israeli Air Force now has air superiority, or even air supremacy, over much of northwestern Iran. That the Iranian IADS and GBAD folded so quickly has come as a surprise, but the clues may have already been there. Surface-to-Air Missile (SAM) batteries Iran secured from Russia in recent years were unable to protect the country from the aerial onslaught. Iran’s home-grown systems, much vaunted in kitsch propaganda videos, fared little better. Tell-tale clues of the ramshackle nature of Iran’s air defences came to light in mid-May: An analysis performed by the James Martin Centre for Non-proliferation Studies indicated that Iranian air defence radar may lack robust networking. It could be argued that the strength of an IADS can be measured by the extent to which its constituent fighters, SAMs, radars and Command and Control (C2) centres are connected. Air combat occurs at high speed across large areas. It is axiomatic that IADS federate these assets to provide as detailed picture of as large a slice of airspace as possible in real time. Radar pictures are merged at tactical and operational levels to provide a detailed Recognised Air Picture (RAP) of local airspace and air approaches. These individual RAPs converge at the national level to provide a ‘Super RAP’ of a country, or an operational theatre’s airspace and its environs. This lack of networking was inadvertently revealed by Iranian air defenders in a video showing the defences around the Natanz WMD site in central Iran. A two-second clip showed four separate radar screens and their imagery. Researchers determined that each radar screen represented a separate system. The radar screens also inadvertently revealed the position of each radar relative to the Natanz facility. At a stroke, the Iranians had accidentally revealed exactly where the radars were located, and where the accompanying SAM batteries these radars served were positioned. What was also surprising was that the RAPs generated by each of these radars were not merged on a single screen. The deeper their situational awareness, the better chance air defenders have of engaging and defeating hostile aircraft. Four radar operators, looking at four different radar screens will struggle to enjoy the same level of awareness, as four operators looking at a merged radar image, the latter having the tactical advantage. Why the radar pictures were not merged is unclear. Perhaps Iranian engineers had not developed software to translate the presumably different radar output languages and merge the disparate imagery into a single RAP? We may never know the reasons why a key tenet of air defence theory appears not to have been followed by Iran’s air defenders. What we do know is that despite the decades of bombastic bluster about the superior capabilities of Iranian air defence technology, bns of dollars spent protecting Iranian skies has been wasted. Like the facility in Natanz, which was attacked by US warplanes on 222nd June, Iran’s air defences are in ruins. (Source: Armada)
08 Jul 25. Is this a DIGAR I see before me? Underscoring the problem of GNSS jamming and spoofing around the world, the flightradar24 website publishes a daily map of GNSS disruption concentrations. The red areas are where jamming and spoofing is particularly acute. Efforts to mitigate the threat of satellite navigation signal spoofing and jamming through technological innovation are deepening in the United States. The June/July edition of Armada International includes an article that examines recent incidences of United States military aircraft experiencing Global Navigation Satellite System (GNSS) signal disruption. Worrying reports emerged this April: GNSS Position, Navigation and Timing (PNT) signal receivers equipping US Air Force (USAF) aircraft flying over the Persian Gulf had experienced jamming. Evidence was provided via the flightradar24 website. The website showed a USAF Boeing C-17A Globemaster-III turbofan airlifter appearing to follow an erratic flightpath. It seems that the incoming PNT signal received by the Globemaster’s GNSS system may have been corrupted. This then affected the outward Automatic Dependent System-Broadcast (ADS-B) transmission by the aircraft which was then depicted by flightradar24. The website relies on ADS-B data to show the location, identity and other characteristics of flights. ADS-B in turn relies on a PNT signal to display an aircraft’s position. If the incoming PNT signal is disrupted, so will the outgoing ADS-B transmission. Mindful of the dangers of GNSS PNT signal disruption, deliberate or otherwise, the United States Department of Defence (DOD) has embarked on several efforts to mitigate or eliminate this. Many of these efforts focus on improving the capabilities of GNSS receivers or investing in alternative PNT technologies. One example of these efforts is the Digital Global Positioning System Anti-Jam Receiver (DIGAR) programme. DIGAR is being rolled out across various USAF aircraft types by the US Air Force Life Cycle Management Centre (AFLMC). In 2018, Rockwell Collins (now Collins Aerospace) was selected by the AFLMC to provide its DIGAR technology to equip US Air National Guard and US Air Force Reserve General Dynamics/Lockheed Martin F-16 series combat aircraft. In 2022, BAE Systems won a contract to provide DIGAR technology for USAF McDonnell Douglas/Boeing F-15E Strike Eagle jets.
Architecture
Dhiraj Raghwani, BAE Systems’ director of airborne programme management, told Armada that the company’s approach to GNSS jamming/spoofing mitigation uses an innovative beamforming approach. BAE Systems’ literature says its DIGAR products use up to 24 simultaneous beams to enhance jamming immunity. What this means in practice is that “each channel in the (GNSS) receiver gets assigned to a beam dedicated to one unique satellite that it is tracking” says Mr. Raghwani. This combination of the individual satellite, and that satellite’s incoming PNT signal, “forms a unique antenna pattern that is optimised for a single satellite.” What this means in practice is that the DIGAR system is continually looking at this antenna pattern, as opposed to looking at the whole sky, for incoming PNT signals. GNSS jamming relies on seemingly genuine PNT jamming and/or spoofing signals being received by the GNSS system. These counterfeit signals are often more powerful than the comparatively weak incoming PNT signals which have lost much of their power after the long journey from space to Earth. Once received by the GNSS system, the counterfeit signals start to do damage. By only monitoring the unique antenna pattern, a DIGAR system ignores all GNSS signals, real or otherwise, that do not match this.
DIGAR works with a host of GNSS signals, notably those transmitted by the US DOD’s Global Positioning System (GPS). Signals include the dedicated military P(Y)-Code transmitted on the GPS constellation’s L1 and L2 channels which use frequencies of 1.57542 Gigahertz/GHz and 1.22760GHz respectively. The US DOD’s new military M-Code GPS PNT signal also uses the L1/L2 channels. The principal difference between civilian C/A-Code (Coarse Acquisition Code) and P(Y)-Code is precision and encryption: C/A code will afford around four-metres (13-feet) of accuracy while P(Y)-Code provides under three-metres’ (ten-feet’) accuracy. Both P(Y)-Code and M-Code are encrypted. Logically, a GNSS system which can detect P(Y)-Code and M-Code should ignore all incoming PNT signals lacking the requisite encryption. However, one key difference between P(Y)-Code and M-Code is that the former must initially acquire a C/A-Code signal before the receiver can begin obtaining the P(Y)-Code. The receiver might not necessarily obtain the P(Y)-Code if the C/A-Code PNT signal is already being disrupted. This is not the case for the M-Code signal which does not require this initial ‘handshake’.
DIGAR variants
BAE Systems’ DIGAR series comprises three distinct systems: DIGAR-300 is a Line Replaceable Unit (LRU) comprising hardware and software which needs a 28-volt direct current power supply. DIGAR-200 has a similar design but needs a 115-volt alternating current power supply. The DIGAR-200S includes an internal GPS module to provide position, velocity and time information to a host computer. All DIGAR systems can be used with an array of Controlled Reception Pattern Antennas (CRPAs) equipping “airborne, maritime and/or land platforms” says Mr. Raghwani. CRPA antennas can be used to ‘null’ directions from where jamming and/or spoofing has been identified to improve GNSS receiver resilience. Mr. Raghwani adds that the next-generation “DIGAR will be offered as an LRU including hardware and embedded software, with and without an internal M-code GPS module to provide position, velocity and timing (information) to the host computer.” While M-Code and P(Y)-Code provides resistance to GNSS jamming and/or spoofing, DIGAR takes this protection further. That the system has been installed on the USAF F-15E and F-16 fleets indicates the seriousness with which the DOD is tackling the PNT jamming/spoofing menace. Other US and allied platforms look set to receive this technology in the future as the GNSS threat proliferates. (Source: Armada)
09 Jul 25. Building the Integrated Force. In the second of two articles Armada examines what the United Kingdom’s Strategic Defence Review, published on 3rd June, will mean for British military communications. The UK’s Ministry of Defence (MOD) published the country’s Strategic Defence Review (SDR) in early June. The document outlines the United Kingdom’s strategic priorities, the defence policies to meet those priorities and the capabilities required therein. Tellingly, the United Kingdom is moving towards becoming what the SDR calls an Integrated Force by completing “the journey from ‘joint’ to ‘integrated’”, according to the review. The UK has already embraced the North Atlantic Treaty Organisation’s (NATO’s) commitment to Multi-Domain Operations (MDO). NATO defines MDO as “the push for NATO to orchestrate military activities across all operating domains and environments.” The alliance adds that “(t)hese actions are synchronised with non-military activities and enable (NATO) to create desired outcomes at the right time and place.” Put another way, MDO emphasises the intra- and interforce connectivity of all military assets at all levels of war for synchronous operations across the spectrum of conflict. The aim of MDO is to promote better quality decision-making at a more rapid pace than one’s adversaries to seize and maintain initiative across the battlespace. The UK’s Integrated Force will have no fixed force design. Instead, force structures will evolve and develop as threats and technologies change and emerge. The Integrated Force will be under the command of a new Military Strategic Headquarters (MSHQ). The MSHQ will be under the command of the Chief of the Defence Staff and their subordinate service chiefs. Furthermore, the Integrated Force will be able to operate unilaterally, or multilaterally, as circumstances dictate.
Digital Targeting Web
The SDR emphasises that the Integrated Force must be “underpinned by a common digital foundation and shared data”. This common digital foundation will be enabled by a “Digital Targeting Web” (DTW). The review states that the SDW is to be delivered by 2027. This targeting web will connect sensors, deciders and effectors to create “choice and speed in deciding how to degrade or destroy an identified target across domains and in a contested cyber and electromagnetic domain.” In common with the UK’s erstwhile Multi Domain Integration approach, now superseded by the Integrated Force, the latter will take a whole-of-government approach. What this means in practice is that the military will integrate other stakeholders, like the nation’s intelligence services, as and when necessary during crisis, contingency and/or combat operations. Delivering the Integrated Force requires “resilient and secure communications networks (and) an assured data fabric”. The data fabric is described by the review as a “sophisticated system that enables the efficient management and integration of large amounts of data across multiple sources”. Another technology vital for the Integrated Force is the Secret Cloud. This is described by the review as a “secure and scalable platform for storing and sharing information classified at Secret (level).” Plans call for the Digital Targeting Web capability to be available to the UK military from 2027, with the complementary Secret Cloud to be available one year earlier. An MOD spokesperson told Armada that the UK government plans to invest up to $1.4 bn by 2027 “to support faster identification and lethal response to threats across land, sea, air and space”. It is hoped that this investment will “give the UK a decisive advantage on the battlefield through greater integration and communication between our armed forces.”
Questions remain
Much remains unknown regarding the DTW architecture: What links, and communications hardware and software, will the digital targeting web use? How will existing MOD military communications initiatives like LETACCIS (Land Environment Tactical Communications and Information Systems) work with the DTW? What are the long term prospects for the troubled Project Morpheus land forces tactical communications and command and control programme? The Digital Targeting Web is an ambitious, and potentially expensive, undertaking. The UK’s and NATO’s commitment to multi-domain operations means that it cannot be allowed to fail. The future of the United Kingdom’s Integrated Force depends on it. (Source: Armada)
10 Jul 25. Devices and Desires. Army’s Next Generation Command and Control system were put through their paces at the force’s recent Project Capstone Convergence effort which took place between March and April in California. The US Army has taken an important step towards implementing an ambitious new command and control architecture for its manoeuvre force that takes a novel approach to communications links and devices. In April the United States Army’s Next Generation Command and Control (NGC2) system became a formal programme of record. In the army’s own words, the NGC2 will fundamentally change how its manoeuvre force performs command and control. The initiative is led by the army’s Programme Executive Office for Command, Control, Communications and Networks (PEO C3N). From an architecture perspective, the NGC2 comprises an array of networks, existing and planned, software and hardware. According to the PEO C3N, the army has been taking NGC2 technology through its paces during annual Project Convergence Capstone events. The events are joint and multinational initiatives “to transform and ensure future war-fighting readiness”, according to the US Department of Defence (US DOD). The DOD is the event’s sponsor. The most recent PCC took place in March and April this year at Fort Irwin, California. The PCC initiative plays a key role in examining technologies applicable to the US DOD’s Multi-Domain Operations (MDO) philosophy. The inter- and intra-force connectivity integral to MDO will be facilitated by the Combined Joint All-Domain Command and Control (CJADC2) system. The Next Generation Command and Control initiative commence in 2024 as an army-directed experiment under leadership of the Army Futures Command. Put simply, the command ensures the army remains at the leading edge of technological innovation for the benefit of the manoeuvre force. A key design feature of the NGC2 is that it will use open and modular architectures “comprised of command and control data, software systems and applications, as well as the underlying network, transport and infrastructure solutions” Colonel Christopher Anderson, the NGC2’s programme manager at the PEO C3N, told Armada. This open and modular approach will “refine and swap out capabilities in response to changing operational needs, emerging technologies, and deliver solutions that are modular and configurable for commanders.”
End user devices
The NGC2 architecture will overhaul the command and control architectures used by the army’s manoeuvre forces at tactical (battalion and brigade) through to division and corps (operational) levels. At the latest PCC event NGC2 technologies, notably “applications, data infrastructure, software, and hardware such as tablets, end user devices, and mobile communications equipment” was trialled with an armoured battalion, and a brigade and division headquarters. Col. Anderson added that PCC events “provide positive operational feedback on NGC2 to build upon technical insights from earlier experimentation efforts.” These efforts will enable the army “to now move forward with equipping a prototype division” with NGC2 capabilities. From a hardware perspective new devices incorporating edge computing will be delivered as part of the NGC2 suite of capabilities. New edge computing devices and communications will see some dismounted and mounted tactical radios being replaced, where appropriate, with alternatives. However, Col. Anderson emphasises that “(t)he army is not doing away with tactical radios altogether, as we continue to anticipate the need for high assurance (and) assured voice communications at echelon.” One of the alternatives being explored is to employ end user devices like smartphones. These devices can use links like fifth-generation (5G) networking and wifi “to send and receive data, assuming the infrastructure exists to support those capabilities”, Col. Anderson notes.
Hybrid procurement
Plans are afoot to deliver the architecture using initial contracts what will take a hybrid approach “to enable competition for best-of-breed solutions throughout the NGC2 ‘technology stack’ with continuous opportunities for competition,” Col. Anderson stated. The hybrid procurement approach “will allow the government to on-ramp and off-ramp capabilities for best of breed capability (for) the NGC2 ecosystem.” Crucially, the procurement approach being taken vis-à-vis NGC2 will look beyond the traditional defence supplier base to acquire civilian, or dual use, technology applicable to the architecture. The approach will also eliminate the use of single-vendor, multi-year contracts Col. Anderson continues: “No one company can provide a complete solution for NGC2, and the government intends to continue to competitively onboard vendor teams for additional components and architecture layers that will be available after the initial prototyping awards.” NGC2 capabilities will be delivered as they are acquired with operational units. There is unlikely to be a ‘big bang’ moment when NGC2 will reach an initial/full operational capability. Instead, capabilities will be introduced in an iterative fashion. (Source: Armada)
10 Jul 25. July Radio Roundup. The Colombian Navy’s new Plataforma Estratégica de Superficie (Strategic Surface Platform) frigates will be outfitted with EID’s OeanNEX command and control system, and the company’s ICCS7 communications architecture. Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.
New Colombian Navy Communications
In May EID announced that it had won a contract to equip surface combatants of the Armada Nacional de la República de Colombia (Colombian Navy) with the company’s communications, and Command and Control (C2) systems. The Colombian Navy is acquiring five Plataforma Estratégica de Superficie (Strategic Surface Platform) frigates. Gregory Flippes, EID’s commercial and marketing director, told Armada that the first of these vessels should enter Colombian naval service in 2030. The core of EID’s provision is built around the company’s OceaNEX C2 and ICCS7 communications systems. The systems “will be adapted to meet the specific requirements of the Colombian Navy.” He continued that “the latest generation of the (ICCS7) allows for seamless communication across all onboard and external systems, with strong resilience and maintainability.” Design features include advanced cybersecurity, and a full internet protocol architecture, “using standard, open technologies for integration and interoperability.” Both systems are reconfigurable and employ modular, scalable designs Mr. Flippes continued.
Magnetic Personality
Leidos has revealed that its MagNav navigation system is currently undergoing flight testing. MagNav uses quantum sensing to provide a navigation alternative to Global Navigation Satellite System (GNSS) Position, Navigation and Timing (PNT) reliance. The company told Armada that the goal of the programme is to “demonstrate a prototype MagNav solution on a variety of platforms by the end of a (two-year) period of performance.” Leidos’ statement continued that the MagNav architecture uses “commercial advances in COTS (Commercial Off-The-Shelf) quantum magnetometers.” Leidos expects that the commercialisation of MagNav, and its integral sensor technology, “will take additional time since different applications have different requirements.” MagNav depends on an accurate magnetometer and dedicated software. The system’s hardware includes the sensor head, support electronics and a computer to host the MagNav software. It is this software that produces position, velocity and altitude outputs. These components can be installed within a platform in such a fashion as to meet size, weight, power and magnetic isolation requirements. Potential applications for the technology include inhabited and uninhabited aircraft and munitions. Furthermore, the “technology is well suited for any (military and/or civilian) flight platforms that may be vulnerable to (GNSS) outages.”
NSA Certification for Wave Relay
In June Persistent Systems announced that its Wave Relay tactical communications products have been approved by the United States National Security Agency (NSA) as IP SEC VPN (Internet Protocol Security Virtual Private Network) and MAC SEC (Media Access Control Security) components, according to a press release. When integrated with NSA-approved capability packages, this approval lets the systems handle classified information. This process of approval provides an alternative to the NSA’s Type-1 encryption standard and ensures that Persistent Systems’ products are on the NSA’s Commercial Solutions for Classified (CSFC) component list. The CSFC process complements, and does not replace, NSA Type-1 certification. The company told Armada, via a written statement, that “Wave Relay devices are (now) approved commercial components to protect our nation’s most sensitive data when integrated in accordance with NSA guidelines.” Software modifications to these devices were integral to realising this approval. The statement continued that “(t)he approval applies to actively fielded fifth-generation Wave Relay devices with a no cost software-based upgrade.” (Source: Armada)
09 Jul 25. Cuashub.com said today that Silvus strengthens drone comms resilience in EW environments. Silvus Technologies has released a new software update to its StreamCaster radios, introducing enhanced electronic warfare (EW) defense features under the name Spectrum Dominance 2.0. The update is intended to improve the performance of Silvus’ mobile ad hoc networking (MANET) radios in contested and congested radio frequency environments. The upgrade builds on the company’s existing MN-MIMO waveform by introducing two new capabilities: Wake on Wireless and Dual Frequency Link. These join a suite of existing features aimed at Low Probability of Intercept/Detection (LPI/LPD), anti-jam protection and threat mitigation. According to the company, the new version is available via firmware update for existing StreamCaster AN/PRC-169 radios, enabling previously deployed systems to receive the enhancements without new hardware. The radios are used in handheld, vehicle-mounted and OEM-integrated configurations by U.S. and allied forces. Silvus describes the update as a “layered EW defense” system, offering modular options that can be activated individually or as part of a broader spectrum defense configuration. This approach is designed to maintain secure, high-throughput communications during attempts to disrupt radio signals, such as jamming or spoofing. While no operational or customer data was provided, the company emphasized that the release continues its focus on scalable, field-upgradable tactical communication systems capable of operating in high-threat environments. Silvus is a U.S.-based company that develops tactical wireless communication systems, including mesh networking technologies used in military, public safety and industrial applications. https://cuashub.com/en/content/silvus-strengthens-drone-comms-resilience-in-ew-environments/ (Source: https://cuashub.com/)
08 Jul 25. Savox and Insta Launch Collaboration – Aiming to Develop Integrated Audio and Vehicle Solutions. Savox Communications and Insta and have signed an agreement to combine their top-tier technologies and expertise in developing and delivering advanced defence and security solutions. The collaboration will be officially announced at the international DSEI 2025 exhibition in London, taking place from 9-12 September. The collaboration leverages Savox’s position as a leading provider of mission-critical communication solutions and technology company Insta’s strong capabilities in networked defence solutions and system integration. Together, the companies aim to develop more comprehensive, integrated, and interoperable solutions tailored for the demanding needs of defence and public safety operators – with a particular focus on integrated audio and vehicle environments, where real-time situational awareness, connectivity, and compatibility are critical.
– Collaborating with Insta supports our strategy to strengthen our offering with holistic solutions that enhance operational effectiveness and situational awareness in challenging conditions, says Jerry Kettunen, CEO of Savox Communications.
– Savox’s technological know-how perfectly complements Insta’s system development capabilities. As experts in the state-of-the-art technology, we highly value collaboration to provide purposeful products and solutions. We see strong growth potential both in Finland and on the international market, says Ville Kettula, Vice President of Insta ILS Oy.
The joint solution will be showcased at the DSEI 2025 exhibition in London this September.
For more information about Savox, visit: www.savox.com
About Savox:
Savox Communications designs and manufactures advanced, rugged and robust hearing protection and communication solutions for the most demanding conditions. Headquartered in Finland, our worldwide network, distributors and agents deliver mission-critical systems for defense, fire and rescue, law enforcement, and industrial sectors across global markets. Over 40 years of experience in the industry and our agile and highly advanced R&D and engineering capability have earned Savox a reputation for superior quality. Our 300 co-workers around the world pride themselves on ensuring the safety and enhancing the operational capability of teams and individuals in challenging conditions where seamless access to voice and information is vital.
About Insta:
Decisive defence technology for the future
Insta is a diversified technology company with in-depth expertise to enable secure and customer-focused solutions for the needs of industry, defence, software development, and cyber security. We are a reliable partner that develops future security and decisive performance in an ever more rapidly changing, networked world. Insta is also a strategic partner of the Finnish Defence Forces. Advanced technology allows you to see further, react earlier, and influence more efficiently – on land, sea, and in the air. We use our strong know-how to build defence by integrating systems, developing and maintaining capabilities, enhancing command and control, and creating the real-time situational picture to support decisions.
Continuous movement, experience and responsibility are at the core of our safety culture. In 2024, the net sales of our growing family business was 176,2 m euros and we employed approximately 1,200 people. Insta – Decisive Impact. Further information: www.insta.fi
04 Jul 25. Cyber Update Key points.
- A new wave of ransomware attacks has underscored the elevated security risks facing the transport and aviation sectors stemming from the ransomware group ‘Scattered Spider.’
- A ransomware attack against a third-party provider for the Swiss government highlights the long-term security and supply-chain risks facing data-rich sectors (see Sibylline Cyber Daily Analytical Update – 1 July 2025).
- The increasing overlap between cyber criminal and state-sponsored groups points to the heightened security risks facing global businesses.
- The likely co-operation between cyber threat groups underscores the increasing security and financial risks facing Latin American financial institutions.
- New malware (‘NimDoor’) has underscored the security and financial risks facing Web3 and cryptocurrency platforms stemming from North Korean state-sponsored actors (see Sibylline Cyber Daily Analytical Update – 4 July 2025).
Technical analysis of weekly stories
Cyber criminal and state-sponsored cyber threat actor activity is increasingly overlapping. In February, the cyber security company Proofpoint detected several cyber espionage operations that it attributed to the financially motivated threat group ‘TA829’. While it is unclear whether TA829 has any connections to the Russian state, the group has conducted cyber espionage operations against Ukraine since the onset of the war in that country in February 2022. However, TA829 reportedly acquires services and infrastructure from the cyber criminal underworld and typically employs tactics associated with cyber criminal activity, which likely enhances detection evasion and complicates attribution efforts. The group uses compromised MikroTik routers to relay malicious traffic via mail providers and to distribute phishing emails. These emails aim to trick victims into clicking on a malicious link embedded in the email and/or a PDF attachment. The link redirects users to a fake online storage platform emulating Google Drive and/or OneDrive and contains an executable that (if downloaded) initiates the infection chain. This deploys two malware loaders (‘RustyClaw’ and ‘MeltingClaw’) and subsequently two backdoors (‘DustyHammock’ and ‘SingleCamper’).
DustyHammock was previously employed in campaigns solely for cyber criminal purposes, while SingleCamper was used as an espionage-first tool. However, TA829 has started employing the payloads interchangeably in cyber criminal and espionage operations, further exacerbating attribution difficulties. Both malware variants are likely managed via a unified control panel and enable remote command execution as well as system monitoring. In the same month, Proofpoint also uncovered another activity cluster (‘UNK_GreenSec’) that employed similar tactics to TA829 to target organisations in North America (while using different infrastructure and deployment methods). UNK_GreenSec also installed a different backdoor (‘TransferLoader’) to maintain persistence within compromised systems and, in some cases, deploy ransomware. We assess this further showcases the complications stemming from the increasing convergence between cyber criminal operations and state-sponsored activity.
Non-exhaustive recommendations to mitigate against these threats include:
- Monitor devices and networks for suspicious activity
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
- Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
- Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering
Our cyber word(s) of the week: Binary file (Source: Sibylline)
————————————————————————————————————————————————————————————————————————————————————————————————————————————–
Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.
We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.
Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.
————————————————————————————————————————————————————————————————————————————————————————————————————————————–

