# Kinematic Threat Brief

**LRRK Watch / Open-Source Intelligence** — Five current signals across systems that sense, move, and act.

| Field | Value |
| --- | --- |
| Collection cutoff | 30 June 2010 |
| Platform | Quiet Systems |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Image rights require separate verification before publication. |

## Executive read

### BLUF

June’s public kinematic story is sanctions and centrifuges, not malware: the Security Council adopted resolution 1929 on Iran, while a Belarusian antivirus firm’s 17 June encounter with a new USB worm was not yet a public industrial-control event.

### Key judgments

1. **[Assessment — high confidence]** UNSCR 1929 (9 June 2010) is the month’s binding public Control Fabric on Iran’s enrichment and heavy-water work, as restated in the later IAEA report fetched for this archive.
2. **[Assessment — high confidence]** No June 2010 public primary fetched here describes a worm that reprograms Siemens PLCs; that story becomes public in July.
3. **[Inference — moderate confidence]** A June Watch desk would have been correct to intensify collection on Natanz physical operations and U.S. extra-theater UAV Act, and wrong to invent a cyber-physical campaign from silence.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. Security Council resolution 1929

*Event / publication dates: 9 June 2010*

**Verified record — [Fact — A1]** IAEA GOV/2010/46 records that on 9 June 2010 the Security Council adopted resolution 1929, affirming Iran’s failure to meet Board and prior Council requirements, affirming that Iran shall suspend enrichment-related and reprocessing activities and heavy-water-related work, reaffirming full cooperation with IAEA access demands, and deciding Iran shall comply fully with its Safeguards Agreement, including modified Code 3.1. Fetched: https://www.iaea.org/sites/default/files/documents/gov2010-46.pdf

**Threat landscape.** This is political-economy and legal Control Fabric around a physical enrichment plant. It is not a cyber operation. The physical consequence intended by the resolution is suspension; Iran’s subsequent IAEA-reported behavior is non-suspension.

**Intelligence assessment.** [Assessment — high confidence] 1929 raises the formal cost of continued centrifuge work. [Inference — moderate confidence] The resolution will be read later against any unexplained centrifuge trouble, but that reading is not available in June public sources. [Uncertainty] National implementation of 1929 export controls is not detailed in GOV/2010/46’s opening summary.

**Opportunity.** A June national-export-control notice naming frequency converters or PLC-related items would have been the supply-chain signal; none was fetched.

**LRRK relevance.** Control Fabric / Passport. File 1929 as the June legal parent of later Natanz physical reporting.

**Confidence.** High on adoption and operative themes as restated by IAEA.

## 02. Natanz remains an operating enrichment plant under IAEA accountancy

*Event / publication dates: continuing; May report GOV/2010/28; June Council action*

**Verified record — [Fact — A1]** GOV/2010/46, describing the period after May, still treats FEP and PFEP at Natanz as operating enrichment plants with IR-1 centrifuges in cascades, UF6 feed, and Agency containment and surveillance. That physical picture is the June public baseline. Fetched: https://www.iaea.org/sites/default/files/documents/gov2010-46.pdf

**Threat landscape.** Sense-Move-Act in the industrial sense: operators Sense cascade state, Move UF6, Act on rotors. Public verification is seals and cameras, not host-based ICS forensics.

**Intelligence assessment.** [Assessment — high confidence] Enrichment has not been publicly suspended. [Inference — moderate confidence] 1929 will not, by itself, stop feed. [Uncertainty] June intra-month cascade counts are not isolated in a June-only IAEA extract in this collection.

**Opportunity.** A June IAEA press note with a cascade snapshot would have been a cleaner monthly Fact.

**LRRK relevance.** Sense-Move-Act / Watch. Keep Natanz on the physical ledger.

**Confidence.** High on continued operation as the IAEA’s later report describes the period; moderate on June-only numbers.

## 03. A new USB worm exists inside one vendor — not yet a public ICS story

*Event / publication dates: 17 June 2010 internal find; public write-up in July*

**Verified record — [Fact — B1]** Brian Krebs’s 15 July 2010 post — the first widely read English-language account fetched here — states that VirusBlokAda said that on 17 June its specialists found two new malware samples able to infect a fully patched Windows 7 system if a user viewed an infected USB drive in Explorer, via shortcut-file handling, installing drivers mrxnet.sys and mrxcls.sys signed with a Realtek digital signature. Independent researcher Frank Boldewin told Krebs the samples appeared to look for Siemens WinCC SCADA systems. That public article is July; the vendor’s stated find date is 17 June. A June filing may record the date as later-reported, not as a June public signal. Fetched: https://krebsonsecurity.com/2010/07/experts-warn-of-new-windows-shortcut-flaw/

**Threat landscape.** If the July account is accurate, a USB-borne, signed-driver implant aimed at industrial-control engineering software already existed in June. The June public did not yet have that picture.

**Intelligence assessment.** [Assessment — high confidence] June public sources fetched here do not treat this as a known ICS worm. [Inference — not used as a June operational conclusion] [Uncertainty] What VirusBlokAda told Microsoft in June, and what Microsoft had confirmed by 30 June, is not in a June primary in this collection.

**Opportunity.** A 17–30 June public vendor advisory would have moved this from later-reported to contemporaneous.

**LRRK relevance.** Lab / Watch. Passport tags 17 June as discovery date and July as public date — and does not reprint exploit steps.

**Confidence.** High on the later-reported 17 June date; this signal is labeled as later-reported, not as a June open-source alert.

## 04. Extra-theater UAV Act continues without a new official legal theory

*Event / publication dates: continuing; ACLU FOIA 13 January still the public demand*

**Verified record — [Fact — B2]** No June 2010 official U.S. legal memorandum or strike table was fetched. The ACLU January request and the January Shane/Schmitt C2 description remain the public Control Fabric and C2 snapshots. Fetched: https://www.aclu.org/press-releases/aclu-requests-information-predator-drone-program ; https://www.nbcnews.com/id/wbna35027603

**Threat landscape.** Two Control Fabrics run in parallel: UN/IAEA on Iranian centrifuges, and an unreleased U.S. theory of remote killing.

**Intelligence assessment.** [Assessment — moderate confidence] Continuity of both programs. [Uncertainty] June strike-level Facts not in hand.

**Opportunity.** A June FOIA production or Glomar would have been the legal signal.

**LRRK relevance.** Control Fabric. Dual-ledger month.

**Confidence.** Moderate.

## 05. Domestic UAS access remains a process, not a consumer market

*Event / publication dates: continuing FAA Certificate of Authorization practice; no civil small-UAS rule this month*

**Verified record — [Fact — B2]** No June 2010 FAA final rule opening the National Airspace System to civil small unmanned aircraft was fetched. Later official testimony (13 September 2010) describes COAs as the public-operator path and states commercial UAS operations in the U.S. are not permitted. That September record is used here only to confirm that June was still a COA-and-restriction regime, not a consumer-drone market. Fetched (September primary, used as retrospective confirmation of the 2010 access regime): https://irp.fas.org/congress/2010_hr/uas.html

**Threat landscape.** Military and CBP UAS exist; hobby-class COTS quadcopters as a mass Sense-Move-Act problem do not. Do not anachronize a 2013-era Phantom market into 2010.

**Intelligence assessment.** [Assessment — high confidence] June 2010 is not a civil sUAS integration month. [Inference — moderate confidence] Training demand from QDR-era fleets will keep pushing FAA, but through COAs and restricted airspace. [Uncertainty] June COA counts were not published in a June primary fetched here.

**Opportunity.** A June FAA COA statistical release would have been the domestic-access Fact.

**LRRK relevance.** Control Fabric / Watch. Negative on COTS quadcopters; positive on COA as the only public civil path.

**Confidence.** High on the absence of a civil rule; high that this brief will not invent a consumer-drone signal.

## Forward indicators

Ranked watchlist as of the collection cutoff (what a 2001–2011 Watch desk would have monitored next).

1. National implementation notices for 1929 (export lists, banking).
2. Next IAEA Iran report after GOV/2010/28.
3. Any public antivirus or Microsoft advisory that names a Siemens-targeted worm.
4. ACLU FOIA responses.
5. FAA/DoD ExCom airspace-access products due later in 2010.

> **Collection integrity.** 1929 and Natanz taken from IAEA GOV/2010/46. The 17 June VirusBlokAda date is recorded as later-reported from Krebs’s 15 July post, not as a June public alert. Did not describe exploit mechanics beyond Krebs’s high-level USB/.lnk/signed-driver/WinCC observations. Did not treat Stuxnet as publicly “discovered” in June. Did not invent a June CBP COA number.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C1</span></p>
