LC-1 · Kinematic Threat Briefs
Kinematic Threat Brief
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# Kinematic Threat Brief **LRRK Watch / Open-Source Intelligence** — Five current signals across systems that sense, move, and act. | Field | Value | | --- | --- | | Collection cutoff | 30 June 2010 | | Platform | Quiet Systems | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Image rights require separate verification before publication. | ## Executive read ### BLUF June’s public kinematic story is sanctions and centrifuges, not malware: the Security Council adopted resolution 1929 on Iran, while a Belarusian antivirus firm’s 17 June encounter with a new USB worm was not yet a public industrial-control event. ### Key judgments 1. **[Assessment — high confidence]** UNSCR 1929 (9 June 2010) is the month’s binding public Control Fabric on Iran’s enrichment and heavy-water work, as restated in the later IAEA report fetched for this archive. 2. **[Assessment — high confidence]** No June 2010 public primary fetched here describes a worm that reprograms Siemens PLCs; that story becomes public in July. 3. **[Inference — moderate confidence]** A June Watch desk would have been correct to intensify collection on Natanz physical operations and U.S. extra-theater UAV Act, and wrong to invent a cyber-physical campaign from silence. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. Security Council resolution 1929 *Event / publication dates: 9 June 2010* **Verified record — [Fact — A1]** IAEA GOV/2010/46 records that on 9 June 2010 the Security Council adopted resolution 1929, affirming Iran’s failure to meet Board and prior Council requirements, affirming that Iran shall suspend enrichment-related and reprocessing activities and heavy-water-related work, reaffirming full cooperation with IAEA access demands, and deciding Iran shall comply fully with its Safeguards Agreement, including modified Code 3.1. Fetched: https://www.iaea.org/sites/default/files/documents/gov2010-46.pdf **Threat landscape.** This is political-economy and legal Control Fabric around a physical enrichment plant. It is not a cyber operation. The physical consequence intended by the resolution is suspension; Iran’s subsequent IAEA-reported behavior is non-suspension. **Intelligence assessment.** [Assessment — high confidence] 1929 raises the formal cost of continued centrifuge work. [Inference — moderate confidence] The resolution will be read later against any unexplained centrifuge trouble, but that reading is not available in June public sources. [Uncertainty] National implementation of 1929 export controls is not detailed in GOV/2010/46’s opening summary. **Opportunity.** A June national-export-control notice naming frequency converters or PLC-related items would have been the supply-chain signal; none was fetched. **LRRK relevance.** Control Fabric / Passport. File 1929 as the June legal parent of later Natanz physical reporting. **Confidence.** High on adoption and operative themes as restated by IAEA. ## 02. Natanz remains an operating enrichment plant under IAEA accountancy *Event / publication dates: continuing; May report GOV/2010/28; June Council action* **Verified record — [Fact — A1]** GOV/2010/46, describing the period after May, still treats FEP and PFEP at Natanz as operating enrichment plants with IR-1 centrifuges in cascades, UF6 feed, and Agency containment and surveillance. That physical picture is the June public baseline. Fetched: https://www.iaea.org/sites/default/files/documents/gov2010-46.pdf **Threat landscape.** Sense-Move-Act in the industrial sense: operators Sense cascade state, Move UF6, Act on rotors. Public verification is seals and cameras, not host-based ICS forensics. **Intelligence assessment.** [Assessment — high confidence] Enrichment has not been publicly suspended. [Inference — moderate confidence] 1929 will not, by itself, stop feed. [Uncertainty] June intra-month cascade counts are not isolated in a June-only IAEA extract in this collection. **Opportunity.** A June IAEA press note with a cascade snapshot would have been a cleaner monthly Fact. **LRRK relevance.** Sense-Move-Act / Watch. Keep Natanz on the physical ledger. **Confidence.** High on continued operation as the IAEA’s later report describes the period; moderate on June-only numbers. ## 03. A new USB worm exists inside one vendor — not yet a public ICS story *Event / publication dates: 17 June 2010 internal find; public write-up in July* **Verified record — [Fact — B1]** Brian Krebs’s 15 July 2010 post — the first widely read English-language account fetched here — states that VirusBlokAda said that on 17 June its specialists found two new malware samples able to infect a fully patched Windows 7 system if a user viewed an infected USB drive in Explorer, via shortcut-file handling, installing drivers mrxnet.sys and mrxcls.sys signed with a Realtek digital signature. Independent researcher Frank Boldewin told Krebs the samples appeared to look for Siemens WinCC SCADA systems. That public article is July; the vendor’s stated find date is 17 June. A June filing may record the date as later-reported, not as a June public signal. Fetched: https://krebsonsecurity.com/2010/07/experts-warn-of-new-windows-shortcut-flaw/ **Threat landscape.** If the July account is accurate, a USB-borne, signed-driver implant aimed at industrial-control engineering software already existed in June. The June public did not yet have that picture. **Intelligence assessment.** [Assessment — high confidence] June public sources fetched here do not treat this as a known ICS worm. [Inference — not used as a June operational conclusion] [Uncertainty] What VirusBlokAda told Microsoft in June, and what Microsoft had confirmed by 30 June, is not in a June primary in this collection. **Opportunity.** A 17–30 June public vendor advisory would have moved this from later-reported to contemporaneous. **LRRK relevance.** Lab / Watch. Passport tags 17 June as discovery date and July as public date — and does not reprint exploit steps. **Confidence.** High on the later-reported 17 June date; this signal is labeled as later-reported, not as a June open-source alert. ## 04. Extra-theater UAV Act continues without a new official legal theory *Event / publication dates: continuing; ACLU FOIA 13 January still the public demand* **Verified record — [Fact — B2]** No June 2010 official U.S. legal memorandum or strike table was fetched. The ACLU January request and the January Shane/Schmitt C2 description remain the public Control Fabric and C2 snapshots. Fetched: https://www.aclu.org/press-releases/aclu-requests-information-predator-drone-program ; https://www.nbcnews.com/id/wbna35027603 **Threat landscape.** Two Control Fabrics run in parallel: UN/IAEA on Iranian centrifuges, and an unreleased U.S. theory of remote killing. **Intelligence assessment.** [Assessment — moderate confidence] Continuity of both programs. [Uncertainty] June strike-level Facts not in hand. **Opportunity.** A June FOIA production or Glomar would have been the legal signal. **LRRK relevance.** Control Fabric. Dual-ledger month. **Confidence.** Moderate. ## 05. Domestic UAS access remains a process, not a consumer market *Event / publication dates: continuing FAA Certificate of Authorization practice; no civil small-UAS rule this month* **Verified record — [Fact — B2]** No June 2010 FAA final rule opening the National Airspace System to civil small unmanned aircraft was fetched. Later official testimony (13 September 2010) describes COAs as the public-operator path and states commercial UAS operations in the U.S. are not permitted. That September record is used here only to confirm that June was still a COA-and-restriction regime, not a consumer-drone market. Fetched (September primary, used as retrospective confirmation of the 2010 access regime): https://irp.fas.org/congress/2010_hr/uas.html **Threat landscape.** Military and CBP UAS exist; hobby-class COTS quadcopters as a mass Sense-Move-Act problem do not. Do not anachronize a 2013-era Phantom market into 2010. **Intelligence assessment.** [Assessment — high confidence] June 2010 is not a civil sUAS integration month. [Inference — moderate confidence] Training demand from QDR-era fleets will keep pushing FAA, but through COAs and restricted airspace. [Uncertainty] June COA counts were not published in a June primary fetched here. **Opportunity.** A June FAA COA statistical release would have been the domestic-access Fact. **LRRK relevance.** Control Fabric / Watch. Negative on COTS quadcopters; positive on COA as the only public civil path. **Confidence.** High on the absence of a civil rule; high that this brief will not invent a consumer-drone signal. ## Forward indicators Ranked watchlist as of the collection cutoff (what a 2001–2011 Watch desk would have monitored next). 1. National implementation notices for 1929 (export lists, banking). 2. Next IAEA Iran report after GOV/2010/28. 3. Any public antivirus or Microsoft advisory that names a Siemens-targeted worm. 4. ACLU FOIA responses. 5. FAA/DoD ExCom airspace-access products due later in 2010. > **Collection integrity.** 1929 and Natanz taken from IAEA GOV/2010/46. The 17 June VirusBlokAda date is recorded as later-reported from Krebs’s 15 July post, not as a June public alert. Did not describe exploit mechanics beyond Krebs’s high-level USB/.lnk/signed-driver/WinCC observations. Did not treat Stuxnet as publicly “discovered” in June. Did not invent a June CBP COA number. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C1</span></p>