Sponsored By Curtiss Wright
https://www.curtisswright.com/
—————————————————————————————————————-
12 Sep 25. Morpheus goes incremental. Sources close to BATTLESPACE at DSEI suggest that due to budgetary restrictions and the settlement of the extra funding with GDUK for the EVO project, that Morpheus will not be the big bang approach as originally envisaged. The data terminals will be sole sourced from Leonardo DSR and the radios competed on an incremental basis.
11 Sep 25. Take the Blame
‘Named and Shamed’, the editorial for the September edition of Armada’s Electronic Warfare Newsletter, our sister publication, discusses the recent unmasking of the alleged perpetrator responsible for the loss of Azerbaijan Airlines Flight 8243. On 25th December 2024 an Embraer 190 airliner crashed on approach to Aktau international airport, western Kazakhstan. The aircraft had been hit by a missile fired from a Russian Army Pantsir-S1 (NATO reporting name SA-22 Greyhound) short-range air defence system. The Pantsir-S1 has been deployed near Grozny, southern Russia. The identity of the Pantsir-S1 unit’s commander who ordered the shot has now been revealed. 67 passengers and crew were aboard the airliner, 38 of whom lost their lives.
Armada chronicled in our ‘Someone had Blundered’ article published on 6th February factors surrounding the shootdown. The piece articulated reports that the aircraft had experienced interference to its Global Navigation Satellite System (GNSS) receiver as it flew from Baku to Grozny that day. The interference was likely to have been caused by deliberate jamming and spoofing of Position, Navigation and Timing (PNT) signals transmitted from GNSS constellations by Russian military deployments near Grozny.
This is not the first time the Russian military, and by default the Russian government, have been accused of reckless, deliberate, PNT signal interference. Over the last decade, reports of GNSS jamming and spoofing blamed on Russia have increased in the Baltic and Black Sea regions. Russia is trying to protect key politico-military, industrial and urban targets from attack by GNSS-guided weapons and uninhabited aerial vehicles. It is deeply irresponsible for any state to deliberately interfere with GNSS reception. Moscow would doubtless argue it is protecting potential targets against Ukrainian GNSS-guided weapons, despite Russia being the initiator of her war with Ukraine. This is no excuse if such actions cause a loss of life for third parties not involved in the conflict.
In July, the International Civil Aviation Organisation (ICAO) called on Russia to cease and desist deliberate GNSS disruption. Moscow has 30 days to explain its actions, otherwise the ICAO assembly may consider these a violation of international law. Whether Russia will listen to the ICAO’s request is another matter. As of late August, it did not appear any response to the ICAO’s request has been received. The sad thing is that Russia will probably continue with the GNSS jamming, and that this will continue to disrupt air travel in the parts of the world where it is occurring. Fortunately, airliners have several navigation systems they can use to ensure safe flight. Technically, the loss of the GNSS signal should be manageable. Yet Azeri authorities investigating Flight 8243 have determined PNT disruption as a potential contributing factor. At the very least, losing the signal may have degraded cockpit situational awareness. The best course of action Russia could take is to stop all GNSS jamming with immediate effect. At the very least, this would help to reduce the likelihood that GNSS disruption becomes a factor in any future tragedy. (Source: Armada)
11 Sep 25. September Radio Roundup.
All Space Hydra-4 MAX satellite communications terminals will receive upgrades to their modems allowing them to use Telesat Government Solutions’ forthcoming Lightspeed low earth orbit satellite communications network.
Armada’s monthly roundup of all the latest news in the military communications product, programme and operational domains.
Globalstar secures CRADA
Globalstar has been awarded a Cooperative Research and Development Agreement (CRADA) from the US Army to evaluate the company’s satellite data solutions for military applications. The news was revealed in a company press release published on 16th July. Henry Orejuela, Globalstar’s head of government sales and business development, told Armada that this “partnership with the US Army is structured to provide direct access to emerging commercial satellite communications technologies for tactical and field-based applications”. Mr. Orejuela said that the army will evaluate Globalstar’s “low size, weight, power and cost satellites for IOT (Internet of Things) devices which are designed for long-duration deployment in austere environments without the need for regular maintenance and infrastructure support”. He added that the force will evaluate how these terminals perform in “real-world defence scenarios”. Such scenarios include asset tracking, CBRN (Chemical, Biological, Radiological and Nuclear) monitoring, unattended ground sensing and uninhabited system telemetry. The company’s devices have low probability of interception/detection attributes to help ensure protection against electronic attack. Globalstar also has a slice of the radio spectrum in the 11.5 megahertz terrestrial segment of the radio spectrum known as Band-53/N53. Band-53/N53 provides fifth generation (5G) cellular connectivity. Mr. Orejuela added that the army will evaluate how this band could support “pop-up 5G networks for tactical use” via the CRADA. The agreement is expected to last for three years concluding in 2027.
Lightspeed SATCOM Partnership
Telesat Government Solutions and All Space have concluded a Memorandum of Understanding (MOU) that will see the latter’s terminals integrated with the former’s Low Earth Orbit (LEO) network. Armada was told via a written statement that the MOU will see both companies collaborating “on joint customer use-case evaluations and field demonstrations”. This work will ensure that All Space’s Hydra-2 MAX and Hydra-4 MAX military Satellite Communications (SATCOM) terminals have type certification. The effort will also ensure the terminals are ready for when Telesat’s Lightspeed SATCOM services commence. All Space terminals are in operational use with the United States Army and US Navy, the statement added. Armada understands that the terminals will be made ready for Lightspeed via an upgrade to the terminal’s modems. This upgrade is currently under development. Telesat Lightspeed satellites will be launched from late 2026 with global SATCOM services commencing in 2027. Type approval should occur that same year once several of the Lightspeed LEO satellites are in orbit and terminal testing can begin. (Source: Armada)
11 Sep 25. Kahootz, the leading British provider of secure online collaboration platforms, announced the launch of Kahootz in a Box, a game-changing deployable solution designed for organisations that demand the highest levels of security and data sovereignty. Delivered in partnership with Nightball Technologies, the platform combines Kahootz’s proven secure collaboration expertise with Nightball’s CRIW® Cyber Resilient platform to create a fully autonomous system that can be deployed in even the most demanding operational environments without the common assurance challenges.
Kahootz in a Box allows organisations to stand up a complete collaborative environment interoperable with their own infrastructure entirely independent of external cloud services and designed to be deployed across multiple classification levels. From air-gapped networks to rapid field deployments, it integrates seamlessly with existing security protocols and architectures. For government agencies, defence firms, and other critical enterprises, this means total operational sovereignty and control over sensitive data, whilst retaining the full collaborative capabilities trusted by the UK’s most critical programmes.
Luca Leone, CEO of Kahootz, said: “Kahootz in a Box gives our clients the freedom to deploy secure collaboration wherever and whenever it is needed. It combines rapid deployment with the uncompromising security and functionality our customers expect, ensuring teams can work effectively even in the most sensitive environments.”
The launch marks another step in Kahootz’s continued growth in the secure collaboration market, with recent contract awards from the MOD, and international partnerships with major defence and security providers, and new government deployments.
Polly O’Meara, Managing Director of Nightball Technologies, said: “Nightball Technologies are proud to work closely with Kahootz, bringing together our experience of deploying secure solutions with Kahootz’s secure collaboration expertise. It is vital our customers have a secure way of collaborating, even in the most complex of environments.”
04 Sep 25. YEO Messaging, the British leader in AI-powered secure communications with continuous biometric authentication, has announced it has signed an agreement with CS Comms, a specialist provider in delivering secure, robust communications to defence organisations operating in some of the world’s most austere, and tightly controlled military environments.
In the collaboration agreement, CS Comms will use the YEO Messaging for Business app as the encrypted messaging backbone behind its Phantom Signal solution, to give UK defence and government personnel operating discreetly on the ground, a combined bespoke specialised global SIM service with a fully encrypted, continually facial recognition verified, geo-fenced messaging platform.
Founded by military veteran Craig Sykes, CS Comms first emerged from years of service within the highest levels of UK Defence, and has subsequently evolved into a trusted provider of bespoke, defence-ready SIM technology and more. Phantom Signal now integrates SIM-level protection with YEO Messaging’s continuous biometric authentication; end-to-end encryption to secure messages; and voice and video calls. Together, the combined solution ensures that sensitive operational communications remain private, controlled, and compliant, even in high-threat environments.
“In the environments we operate, secure communications are the foundation of survival. By integrating YEO Messaging for Business into our Phantom Signal platform, we’ve added a layer of identity-verified encryption that matches the strength of our SIM technology.” Noted Craig Sykes, Founder of CS Comms. “Together, this gives defence teams complete confidence that their communications are secure, private, and under their control, no matter where they are in the world.”
“CS Comms takes YEO Messaging into some of the most demanding and sensitive environments imaginable. Pairing our identity-verified, end-to-end encrypted platform with their Phantom Signal infrastructure creates a uniquely secure communications channel that’s not only resistant to interception, but also simple for personnel to use in the field.” Said Christo Conidaris, CRO of YEO Messaging. “It’s a powerful example of how the right technology partnership can directly enhance the operational safety of our armed forces.”
12 Sep 25. Savox Communications Oy Ab (Ltd) (Savox) and Nokia Solutions and Networks Oy (Nokia) today announced a Memorandum of Understanding (MoU) to explore the development of joint solutions in the defense communications space. By combining their technical expertise, Savox and Nokia aim to create innovative solutions for tactical communications that provide unmatched connectivity, speed, and reliability for mission-critical operations. Under the agreement, this collaboration will explore:
- Enhanced Connectivity: Leveraging 5G and 6G networks to provide seamless and ultra-fast communication channels for tactical operations, ensuring real-time data exchange and improved situational awareness.
- Advanced Solutions: Developing innovative solutions that combine the strengths of both companies, such as secure communication devices, advanced encryption technologies, and robust network infrastructure.
- Global Reach: Expanding the reach of tactical communication solutions to global markets, enabling defense and security forces worldwide to benefit from state-of-the-art technology and enhanced operational capabilities.
“By integrating Savox mission-critical audio, command and control solutions with Nokia´s advanced networks, we will deliver reliable, scalable communications tailored for the most demanding operations,” said Jerry Kettunen, CEO at Savox.
“Nokia is committed to innovation and excellence in communications technology,” said Giuseppe Targia, Head of Space and Defense, Nokia. “We look forward to working with Savox to create new and innovative solutions that will benefit our customers and the industry as a whole.”
12 Sep 25. AARONIA AG showcased its AARTOS Drone Detection & Defense System (DDS) and demonstrated live how state-of-the-art CUAV capabilities are key to enhancing the agility and resilience of tomorrow’s armed forces – fully aligned with this year’s motto, “Preparing the Future Force.”
Programmable 360° Smart Jammer – Full Spectrum Control
The new AARTOS 360° Smart Jammer redefines electronic countermeasures, setting an entirely new benchmark. Instead of relying on rigid presets, operators – or the software itself, if desired – can mark and suppress any signal in real time within the 400 MHz to 6 GHz range (expandable upon request).
Whether targeting individual channels, multiple frequency bands, or the entire spectrum, the Smart Jammer enables surgical precision interventions. Equipped with 4 to 8 sector antennas, its effects can be directed with pinpoint accuracy into one or multiple directions simultaneously, achieving ranges of up to 10 km and an output power of up to 800 W CW (up to 5000 W EIRP).
It is currently the only system worldwide that combines frequency programmability, 360° coverage, sector-based steering, and real-time operator intervention. For electronic warfare specialists, this means maximum flexibility, instant responsiveness, and a system that adapts seamlessly to any tactical scenario.
Modularity, Precision, Speed
In addition to the Smart Jammer, AARONIA highlighted the modular architecture of AARTOS:
Ultra-compact, agile systems for flexible deployments
Mobile turnkey solutions such as the Mercedes Zetros 6×6 with integrated AARTOS X9
Wide-area protection networks covering entire operational zones
All systems deliver precise direction finding, reliable geolocation, and ultra-fast sweep rates to provide a resilient real-time operational picture. Hardware capabilities are enhanced by the RTSA-Suite PRO software, which analyzes broadband data streams, integrates multiple receivers, and supports decoders as well as pattern recognition for rapid, reliable decision-making.
Targeted Demand at DSEI
“The conversations at the exhibition made it clear: decision-makers today seek not broad information but precise, tailored solutions to specific operational scenarios,” said Stephan Kraschansky, CEO of Aaronia Austria. “With AARTOS, we can meet these requirements – through modular hardware, precise localization, rapid analysis, and the programmable 360° Smart Jammer as the centerpiece of modern electronic warfare.”
Proven Protection – Ready for the Future
AARTOS is deployed in over 650 installations worldwide and has proven itself in highly critical scenarios – from summit and large-event security to 24/7 military operations. It combines cutting-edge sensors, powerful effectors, an integrated C2 system, and programmable jamming – available in a variety of turnkey solutions ranging from shelters to military and civilian vehicles, as well as large-scale infrastructures. This provides armed forces with maximum flexibility and resilience against future threats.
With its presence at DSEI 2025, AARONIA has underscored how the programmable 360° Smart Jammer, in combination with the modular AARTOS systems, is setting new benchmarks in electronic warfare – and making a vital contribution to building the Future Force.
12 Sep 25. AI-related campaign underscores elevated security risks to businesses. On 11 September, the cyber security company Trend Micro reported that unnamed threat actors are leveraging fake artificial intelligence (AI) tools to infiltrate targeted organisations. Threat actors reportedly create and distribute fake AI applications on newly registered websites purporting to provide authorised software downloads. The applications then covertly execute malicious code during the download process that deploys malware onto compromised systems (‘EvilAI’). The applications can simultaneously carry out advertised functionalities to enhance legitimacy, highlighting the actors’ sophistication and detection evasion capabilities. EvilAI primarily acts as a backdoor to maintain persistence within compromised systems and deploy additional payloads. However, the campaign’s main objectives remain unclear. EvilAI compromised multiple different sectors across several countries before its detection, underscoring the scale of this campaign. We assess that this report highlights the elevated security risks facing global businesses as threat actors continue to incorporate AI into malicious cyber activity. (Source: Sibylline)
12 Sep 25. Cyber Update.
Key points
- A new phishing technique has highlighted increased security and social engineering risks facing entities in Colombia (see Sibylline Cyber Daily Analytical Update – 8 September 2025).
- A Chinese state-sponsored cyber operation has underscored sustained security and cyber espionage risks facing key sectors in the US (see Sibylline Cyber Daily Analytical Update – 9 September 2025).
- The exploitation of the legitimate IT application Docker in malicious activity has highlighted increased security risks to global businesses (see Sibylline Cyber Daily Analytical Update – 10 September 2025 and our Technical analysis below).
- Military and key sectors in the Philippines face elevated security and cyber espionage risks from a Chinese advanced persistent threat (APT) group (see Sibylline Cyber Daily Analytical Update – 11 September 2025 and our Technical analysis below).
- A cyber campaign related to artificial intelligence (AI) has underscored heightened security risks to global businesses (see Sibylline Cyber Daily Analytical Update – 12 September 2025).
Technical analysis of weekly stories
A Chinese APT group targeted a military company in the Philippines in a cyber espionage operation. While the operation’s initial attack vector remains unclear, the group reportedly used a new multi-stage malware toolkit to penetrate the system. The attack’s first stage comprised the deployment of two malware loaders (‘EggStremeFuel’ and ‘EggStremeLoader’) to prepare the environment for later stages, gather initial system information and establish persistent communication with command-and-control (C2) infrastructure. EggStremeLoader was ultimately responsible for executing the main backdoor (‘EggStremeAgent’) into the system’s memory to remain obfuscated. EggStremeAgent uses the remote procedure call (gRPC) protocol for encrypted C2 communication and possesses 58 distinct commands. These include system fingerprinting, resource enumeration, privilege escalation, command execution, data exfiltration, process injection and file directory manipulation. The group also deployed an additional backdoor (‘EggStremeWizard’) to ensure persistence, showcasing the toolkit’s complexity. We assess that this also suggests that the group likely values long-term access, as well as espionage.
Unnamed threat actors are exploiting exposed application programming interfaces (APIs) from the container application Docker to infiltrate targeted organisations. Threat actors send container creation requests to exposed APIs for initial access. This causes existing containers to execute embedded code that establishes communication with C2 infrastructure and subsequently executes a second-stage script. Threat actors use the Tor network for C2 communication to guarantee anonymity and modify secure shell (SSH) configurations to ensure persistence, highlighting their capabilities and sophistication. The script then enables threat actors to maintain prolonged access, block any future external attempts to access the same API and deploy additional payloads, showcasing the actors’ sophistication and knowledge of modern IT infrastructure. The script also installs additional tools (including ‘masscan’, ‘zstd’, ‘libpcap’ and ‘torsocks’) to evade detection and support replication efforts, such as scanning and propagation. The infection strain continues to create containers to spread the infection, while masscan also checks for other exposed ports. This suggests that threat actors may be in the initial stages of attempting to create a large-scale botnet network, pointing to long-term operational and infection risks.
Non-exhaustive recommendations to mitigate against these threats include:
- Monitor devices and networks for suspicious activity.
- Add available Indicators-of-Compromise (IoCs) to your organisation’s security systems to detect potentially malicious samples on the network; configure firewalls to block outbound communications to malicious IP addresses associated with any known malware.
- Adopt behaviour-based end-point detection and response (EDR) solutions, prioritising the detection of the initial stages of a compromise.
- Conduct cyber hygiene awareness courses for users, enabling them to recognise and report phishing and other types of social engineering.
Our cyber word of the week: Containers (Source: Sibylline)
10 Sep 25. Thales and Autonomous Devices team up to develop drone-based electronic warfare solution for naval and land forces
- At DSEI 2025, Thales and the UK company Autonomous Devices announced an agreement to jointly develop a versatile, modular, turnkey drone-based electronic warfare solution for naval and land forces.
- Thales draws on its electronic warfare expertise to develop a payload capable of performing both electronic support, to detect, identify and locate threats, and electronic attack, i.e. jamming, roles. Autonomous Devices is responsible for designing a new-generation drone with high manoeuvrability and long endurance capabilities.
- This drone-based electronic warfare solution is currently undergoing initial testing, which will continue throughout the year.
Thales and the UK company Autonomous Devices will co-develop the EW-UAS1 in the latest of a series of joint projects by the two partners.
This turnkey solution will benefit from Thales’ expertise in electronic warfare command-and-control system integration and certifications needed for drones to fly in civil and military airspace.
Recent conflicts have confirmed the growing importance of both defensive and offensive electronic warfare in all domains of military operations. The armed forces need to rely on agile and long-endurance platforms, easy to recover and re-use, to deploy their electronic warfare systems. The combination of the drone from Autonomous Devices and the payload from Thales will meet these requirements, providing a high-performance drone-based electronic warfare solution tailored to the challenges of modern warfare.
“The drone-based electronic warfare solution developed by Thales and Autonomous Devices is a technological game-changer for the armed forces, providing a reliable passive capability to counter modern threats while ensuring long- range protection around their strategic assets,” said Marie Gayrel, Vice-President in charge of the Intelligence, Surveillance and Reconnaissance activities, Thales.
“The integration of these technologies in a turnkey solution promises to unlock EW capabilities well beyond the state of the art, providing an effective counter to rapidly-evolving threats, and this agreement represents a significant step en route to delivering these capabilities to the warfighter,” said Ken Wahren, CEO, Autonomous Devices
EW-UAS has a key role to play in defending ships from new and emerging threats. Thanks to its speed, agility and endurance, this drone can be quickly deployed to detect anti-ship missiles and initiate electronic countermeasures (soft kill), thereby improving ship survivability while minimising ordnance.
EW-UAS will also provide proactive protection for sensitive military assets engaged in land and naval operations, conducting complementary jamming missions to disrupt the adversary’s radar surveillance and targeting capabilities and bolster electronic defences in the theatre of operations. The drone can also be used for passive detection and surveillance, to anticipate threats by extending detection coverage. It can reposition itself quickly to enable the electronic warfare payload to detect enemy radar emissions (weapon guidance, targeting and surveillance), then jam or manipulate these signals to create an alternative radar reality. These deception tactics confuse radar operators, send missiles off-course and ensure that sensitive assets are not detected.
——————————————————————————————————————
Curtiss-Wright Corporation (NYSE: CW) has a long history with its roots dating back to Orville and Wilbur Wright’s first flight in 1903, and Mr. Glenn Curtiss, the father of naval aviation. In 1929, the companies founded by these three great aviation pioneers, the Curtiss Aeroplane and Motor Company and Wright Aeronautical Corporation, merged to form the largest aircraft company at the time, Curtiss-Wright Corporation.
We have continued on the path of innovation and advanced engineering, and have applied that expertise to a number of critical applications in high-performance markets. Our success has resulted in a world-renowned reputation for performance, long-standing customer relationships and significant growth and profitability in the markets in which we compete.
Today, we are a global, integrated provider of highly engineered, technologically advanced products and services. Our revenues are generated by providing our critical solutions through three segments: Aerospace & Industrial, Defense Electronics and Naval & Power, which support several of the largest, most vital industries in the world.
————————————————————————————————————————–

