Sponsored By Curtiss Wright
https://www.curtisswright.com/
——————————————————————————————————————————————————————————————————————————————————————————————————————————————-
18 Jul 25. Statement of condemnation by the North Atlantic Council concerning Russian malicious cyber activities
- We strongly condemn Russia’s malicious cyber activities, which constitute a threat to Allied security. We stand in solidarity and recognise that Estonia, France, the United Kingdom and the United States have recently attributed malicious cyber activity targeting several NATO Allies and Ukraine to Russia’s military intelligence service (GRU). We recall that in 2024, Germany and the Czech Republic individually attributed activity to APT 28, which is sponsored by the GRU. We also note with concern that the same threat actor targeted other national governmental entities, critical infrastructure operators and other entities across the Alliance, including in Romania. These attributions and the continuous targeting of our critical infrastructure, with the harmful impacts caused across several sectors, illustrate the extent to which cyber and wider hybrid threats have become important tools in Russia’s ongoing campaign to destabilise NATO Allies and in Russia’s brutal and unprovoked war of aggression against Ukraine.
- We call on Russia to stop its destabilising cyber and hybrid activities. These activities demonstrate Russia’s disregard for the United Nations framework for responsible state behaviour in cyberspace, which Russia claims to uphold. Russia’s actions will not deter Allies’ support to Ukraine, including cyber assistance through the Tallinn Mechanism and IT capability coalition. We will continue to use the lessons learned from the war against Ukraine in countering Russian malicious cyber activity.
- NATO stands for a free, open, peaceful and secure cyberspace. We call on all States, including Russia, to uphold their international obligations, also when acting in cyberspace, and to act consistently with the framework for responsible state behaviour in cyberspace as affirmed by all members of the United Nations.
- We remain united in our determination to counter, constrain, and contest Russian malicious cyber activities and are investing in our defences; including through the establishment of the NATO Integrated Cyber Defence Centre and upholding our Cyber Defence Pledge commitments as well as through the commitments made in the Hague Summit Declaration.
- We are determined to employ the full range of capabilities in order to deter, defend against and counter the full spectrum of cyber threats. We will respond to these at a time and in a manner of our choosing, in accordance with international law, and in coordination with our international partners including the EU.
18 Jul 25. Bittium Corporation’s Subsidiary Bittium Wireless Ltd. and Indra Group to Sign a Letter of Intent for Strategic Cooperation on Tactical Radio Communications Solution. Bittium Corporation’s subsidiary Bittium Wireless Ltd and Indra Group have today signed a Letter of Intent to establish strategic cooperation in the development of Software Defined Radio (SDR) solution – a key technology in defense modernization – at the Ministry of Defense in Madrid, Spain. The intent of the cooperation is to explore a technology transfer from Bittium regarding Software Defined Radios for tactical communications, with Indra contributing its extensive experience in the field of Software Defined Radio and waveforms and performing the necessary evolution for the implementation in Spain of the required technological and industrial capabilities to develop a European fully proprietary solution thus meeting Spanish and Allied Armed Forces requirements. Bittium has long experience in tactical communication solutions, including modern, high performance tactical IP network system and next generation Software Defined Radios supplied in various countries, such as Finland, Estonia, Croatia, and Austria. Indra Group develops and produces radios for critical and military communications and has supplied its solutions to various countries, including US and Canada.
“We are excited to provide our technology to Indra as a critical asset for the use for the military programs in jointly agreed market areas. Bittium will continue to be a global supplier of tactical communications and SDR radios in the future. With over 40 years of experience, Bittium has been positioned as a forerunner in advanced next generation tactical communication solutions and Software Defined Radios for the modernization of military tactical communications. Together with Indra, we are stronger to meet the requirements in the agreed market areas”, says Petri Toljamo, CEO of Bittium Corporation.
“With this agreement, we want to take another step forward in Indra’s extensive track record in developing proprietary technologies and experience over the past 15 years in the field of SDR technology and waveforms, which has positioned us as a national leader in this area,” said Ángel Escribano, president of Indra Group.
Both Indra Group, in coordination with Spanish authorities, and Bittium are among the founding members of the a4ESSOR joint venture, which brings together the most advanced companies in Europe working on the development of waveforms specifically designed to enable armed forces to interoperate more securely and efficiently. Two years ago, NATO adopted one of the high-speed data waveforms developed by this joint venture and approved its use for tactical communications on radio platforms. Bittium announced earlier on 11 July 2025 that the Spanish Ministry of Defense plans to launch a project to acquire new national software-based tactical radios. Bittium and Indra will work together to provide Bittium’s technology to the jointly agreed market areas. The negotiations are still in the early stages, and it is too early to estimate the size of the financial potential of this cooperation to Bittium, nor to estimate the size of the potential deals.
18 Jul 25. US: Chinese actors will sustain long-term security, espionage risks to defence, government entities. On 17 July, international news outlets reported that the Chinese state-sponsored group ‘Salt Typhoon’ targeted a US Army National Guard network in a cyber espionage operation between March and December 2024. The attack reportedly resulted in the exfiltration of administrator credentials, configuration files, network diagrams and the personal information of service members. Between 2023 and 2024, Salt Typhoon stole approximately 1462 network diagrams associated with around 70 US government and critical national infrastructure (CNI) entities, showcasing the scale of the group’s operations. It later used the stolen diagrams to compromise at least one US government agency, suggesting that the group will likely attempt to use stolen documents from the National Guard for follow-on operations. Salt Typhoon routinely targets critical sectors in the US to obtain sensitive information and maintain prolonged persistence for potential future disruption. We assess that this development underscores sustained long-term security and cyber espionage risks amid ongoing geopolitical tensions. (Source: Sibylline)
17 Jul 25. QinetiQ launches ‘Droneworks’ and plans complex UAS jamming testing. QinetiQ has revealed to Janes its new test and evaluation (T&E) framework, which it calls ‘Droneworks’, to help companies developing unmanned air systems (UASs) solve complex engineering problems and provide specialist assessment. Droneworks is provided through QinetiQ’s Long Term Partnering Agreement (LTPA) with the UK Ministry of Defence (MoD). On 22 May 2025 QinetiQ announced a five-year, GBP1.54 bn (USD2.06 bn) extension to the 25-year LTPA, originally signed in 2003. The MoD said the LTPA investment supports an extensive supply chain of 825 companies, including 590 small-to-medium enterprises (SMEs). Droneworks was established by QinetiQ under the LTPA extension’s Innovation Gateway, designed to make LTPA services more accessible to SMEs. Evolving out of the Air Test and Evaluation Centre (ATEC) construct between QinetiQ and the MoD, Droneworks provides a UAS test and evaluation hub for the RAF’s Air and Space Warfare Centre (ASWC), the RAF’s Rapid Capabilities Office (RCO), QinetiQ, 744 Naval Air Squadron (which in 2024 transitioned to the Joint Uncrewed Air System Test and Evaluation Squadron (JUAS TES)), and various companies, from major defence primes to small and medium enterprises. The UK’s 2025 Strategic Defence Review (SDR), published on 2 June, called for “an initial operating capability for a new Defence Uncrewed Systems Centre established by February 2026”. Commonly referred to as a ‘Drone Centre of Excellence’, Peter Barnfield, senior business development manager at QinetiQ, told Janes. (Source: Janes)
16 Jul 25. Global: Cyber operation will sustain security risks to Android mobile users. On 15 July, the security company BforeAI reported that unnamed threat actors are conducting a cyber operation against global Android mobile users. Threat actors reportedly distribute links and/or QR codes to trick victims into visiting a malicious website and downloading a fake version of the messaging application Telegram. The campaign boasts approximately 607 malicious domains and targets Android visitors with a download banner, highlighting the sophistication and potential scale of this operation. Threat actors also exploited an Android vulnerability (affecting all versions between 5.0 and 8.0) to insert malicious code into the application without changing its signature. This allows it to bypass standard security detection methods. Upon deployment, the application performs legitimate tasks to evade detection while covertly granting threat actors remote execution permissions. However, the campaign’s objective remains unclear. We assess that this report demonstrates sustained elevated security risks to Android mobile users amid the continued development of cyber capabilities. (Source: Sibylline)
16 Jul 25. Four US companies to help accelerate DoD adoption of advanced AI. Anthropic, Google, OpenAI, and xAI are each positioned to receive a maximum of $200m in under the contract. Pentagon’s Chief Digital and Artificial Intelligence Office (CDAO) has awarded contracts to four major US-based AI companies to expedite the military’s integration of advanced AI via the US Department of Defense (DoD). Each of the four companies, namely Anthropic, Google, OpenAI, and xAI, will receive awards with a ceiling of $200m. The DoD will harness the expertise and innovation of these companies to create generative AI-driven workflows for various national security missions. This initiative is expected to expand DoD’s engagement with AI capabilities and facilitate a deeper understanding among these tech companies of the national security requirements that their AI solutions can address. DoD chief digital and AI officer Dr Doug Matty said: “The adoption of AI is transforming the Department’s ability to support our warfighters and maintain strategic advantage over our adversaries.
“Leveraging commercially available solutions into an integrated capabilities approach will accelerate the use of advanced AI as part of our Joint mission essential tasks in our warfighting domain as well as intelligence, business, and enterprise information systems.”
The DoD is pursuing a “commercial-first” strategy to fast-track the implementation of AI. The awards are part of this initiative, bringing advanced US-based AI expertise to bear on specific DoD challenges. Additionally, the CDAO is facilitating access to some of the most recent generative AI models for general use by various defence entities through platforms like the Army’s Enterprise Large Language Model Workspace powered by Ask Sage. This access extends to broader enterprise applications via embedded AI models in data and AI platforms such as Advancing Analytics (Advana), Maven Smart System, and Edge Data Mesh nodes. These platforms are designed to integrate AI directly into data environment workflows. In an effort to consolidate federal efforts around AI technology procurement and utilisation, the DoD is also collaborating with the General Services Administration (GSA). This partnership aims to harness government-wide purchasing power for AI production and computational resources, ensuring that federal agencies have access to premier AI technologies. In December 2024, CDAO initiated a new programme to expedite the deployment of advanced AI technologies within the US DoD. (Source: naval-technology.com)
14 Jul 25. Global: New attack technique highlights heightened security risks stemming from AI tools. On 13 July, international news outlets reported that the artificial intelligence (AI) platform Gemini can be exploited to conduct a new multi-stage social engineering attack. The first stage of the attack involves the creation of an email containing malicious instructions that are written in white, zero-size font to render them invisible. If the email recipient uses Gemini to obtain a summary of the email’s content, the tool follows the embedded instructions and warns users that their password has been compromised. This tricks users into calling a phone number to reset their password, enabling threat actors to steal user credentials. While this technique has reportedly not yet been exploited by threat actors, it highlights the potential exploitation of legitimate AI tools for malicious cyber activity. We assess that this technique highlights heightened security and social engineering risks to global businesses amid the increased adoption of AI tools. (Source: Sibylline)
11 Jul 25. Cyber Update Key points.
- A cyber operation by the China-linked threat group ‘UNC5174’ has underscored the security risks facing critical national infrastructure (CNI) in France (see Sibylline Cyber Daily Analytical Update – 7 July 2025).
- A long-term cyber campaign has underscored the security and cyber espionage risks facing government entities in the Middle East and North Africa region from the Iranian state-sponsored group ‘BladedFeline’ (see Sibylline Cyber Daily Analytical Update – 8 July 2025).
- Activity by a mobile malware variant (‘Anatsa’) will sustain the long-term security and financial risks facing US-based Android mobile users (see Sibylline Cyber Daily Analytical Update – 9 July 2025 and our Technical analysis below).
- Activity by the India-linked advanced persistent threat (APT) group ‘DoNot APT’ has elevated the security and cyber espionage risks facing diplomatic entities in Europe (see Sibylline Cyber Daily Analytical Update – 10 July 2025 and our Technical analysis below).
- Activity by an Iranian Ransomware-as-a-Service (RaaS) group, ‘Pay2Key’, will sustain the security and disruption risks facing Israeli and US entities (see Sibylline Cyber Daily Analytical Update – 11 July 2025).
Technical analysis of weekly stories
Unnamed threat actors are using a banking trojan (Anatsa) to conduct a financially motivated operation against US-based Android mobile users. The trojan is hidden within a fake actor-made PDF reader application that is distributed via the Google Play Store. Threat actors reportedly released the malicious version of the application after six weeks of advertising a clean version to gain popularity and enhance legitimacy. The clean version ranked among the ‘top free tools’ on the app store while the malicious version amassed approximately 50,000 downloads before its removal, underscoring the scale of the operation. Upon deployment, the application overlays a maintenance message whenever users open their banking application to conceal malicious activity, allowing threat actors to hijack accounts covertly and initiate fraudulent money transfers. Anatsa can also perform credential theft prior to conducting overlay attacks depending on the target. The trojan can target a wide range of banking institutions, which can be dynamically selected via command-and-control (C2) communication, further showcasing its sophistication. The operation was carried out in June; activity by previous iterations was observed since February 2024, highlighting the longevity of this threat.
The India-linked APT group DoNot APT has conducted a suspected cyber espionage operation against an unnamed European foreign affairs ministry. DoNot APT distributed phishing emails discussing a diplomatic visit between Italy and Bangladesh to trick users into clicking on an embedded Google Drive link. The HyperText Markup Language (HTML) included special characters in the email text in order to enhance legitimacy, highlighting the group’s detection-evasion capabilities. The link triggered the download of a .RAR archive, as well as a malicious executable that mimicked a legitimate PDF document and ultimately deployed a custom remote access trojan (RAT) called ‘LopTikMod’. Upon deployment, LopTikMod establishes communication with C2 infrastructure to enable command execution and deploy additional malicious payloads, as well as to exfiltrate data. DoNot APT obfuscated crucial parts of the malware’s code and used American Standard Code for Information Interchange (ASCII) characters to decode malware elements upon deployment. The group also employs anti-virtual machine techniques and creates a mutex to prevent LopTikMod from executing in multiple environments, further showcasing the sophistication of the group’s capabilities. The malware also uses scheduled tasks to maintain persistence.
Non-exhaustive recommendations to mitigate against these threats include:
- Monitor devices and networks for suspicious activity
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware
- Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise
- Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering
Our cyber word(s) of the week: Virtual machine (VM) (Source: Sibylline)
———————————————————————————————————————————————————————————————————————————————————————————————————————————————-
Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.
We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.
Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.
—————————————————————————————————————————————————————————————————————————————————————————————————————————————

