LC-1 · Kinematic Threat Briefs
Kinematic Threat Brief
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# Kinematic Threat Brief **LRRK Watch / Open-Source Intelligence** — Five current signals across systems that sense, move, and act. | Field | Value | | --- | --- | | Collection cutoff | 31 July 2010 | | Platform | Quiet Systems | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Image rights require separate verification before publication. | ## Executive read ### BLUF July is the month a USB-borne, digitally signed Windows implant aimed at Siemens industrial software became a public Sense-to-Act story — and the month WikiLeaks dumped the Afghan War Diary, putting field-level lethal-action records, including unmanned references where they exist in the files, into open collection. ### Key judgments 1. **[Assessment — high confidence]** By mid-July, VirusBlokAda’s samples and Brian Krebs’s 15 July account established a new public malware family that spreads via USB shortcut files, uses Realtek-signed drivers, and appears to seek Siemens WinCC systems. 2. **[Assessment — high confidence]** On 25 July WikiLeaks released over 91,000 U.S. military reports from Afghanistan (2004–2010), a primary archive of lethal actions and intelligence notes. 3. **[Inference — moderate confidence]** The industrial-control worm and the war-diary dump are different sources, but both puncture the same type of trust: operators assumed the public would not see the internals of Act — whether PLC logic or field SIGACTs. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. Public discovery of the USB/.lnk industrial worm (later named Stuxnet) *Event / publication dates: VirusBlokAda find dated 17 June; Krebs 15 July 2010; Microsoft advisory 16 July 2010* **Verified record — [Fact — B1]** Krebs reported that VirusBlokAda said that on 17 June it found malware that executes when a user merely opens an infected USB drive in Windows Explorer, via shortcut (.lnk) handling rather than Autorun. Sergey Ulasen described installation of mrxnet.sys and mrxcls.sys, both signed with a Realtek Semiconductor Corp. digital signature. Microsoft’s Jerry Bryant said the company was investigating. A 16 July update on the same Krebs post said Microsoft had released an advisory on a Windows Shell vulnerability present in every supported version of Windows, with mitigations. Frank Boldewin told Krebs the samples appeared made for Siemens WinCC SCADA — “Looks like this malware was made for espionage.” This filing does not reproduce exploit steps. Fetched: https://krebsonsecurity.com/2010/07/experts-warn-of-new-windows-shortcut-flaw/ **Threat landscape.** A signed-driver implant that can reach air-gapped industrial engineering machines via USB is a Sense-and-Act trust failure: Windows treats the signature as a passport; the USB is the move; WinCC is the possible act surface. Physical consequence is still unproven in July public sources. **Intelligence assessment.** [Assessment — high confidence] The worm and the .lnk issue are real public technical facts by 15–16 July. [Inference — moderate confidence] WinCC targeting, if Boldewin is right, points at industrial process control rather than ordinary IT espionage. [Uncertainty] July public sources fetched here do not yet prove a specific plant or a sabotage payload. **Opportunity.** A Siemens or asset-owner July statement of whether WinCC hosts were actually altered would have moved this from “looks like” to verified Act. **LRRK relevance.** Lab / Sense-Move-Act / Passport. A July Passport would have recorded signed-driver theft/abuse as a supply-chain passport failure and USB as the last-hop Move — without publishing a how-to. **Confidence.** High on Krebs/VirusBlokAda/Microsoft advisory chain; moderate on WinCC purpose; low on physical damage. ## 02. Symantec and Siemens enter the public investigation *Event / publication dates: mid-to-late July 2010 as later compiled in Symantec’s dossier* **Verified record — [Fact — B1]** Symantec’s November 2010 W32.Stuxnet Dossier timeline, fetched as a primary compilation of the firm’s own July work, lists: 13 July, Symantec adds detection as W32.Temphid; 16 July, Microsoft advisory and Verisign revocation of the Realtek certificate; 17 July, ESET identifies a driver signed with a JMicron Technology Corp. certificate; 19 July, Siemens reports it is investigating malware infecting Siemens WinCC SCADA systems and Symantec renames detection to W32.Stuxnet; 20 July, Symantec monitors command-and-control traffic; 22 July, Verisign revokes the JMicron certificate. Fetched: https://www.cs.unh.edu/~it666/reading_list/ZeroDay/w32_stuxnet_dossier.pdf **Threat landscape.** Two stolen or abused code-signing passports (Realtek, then JMicron) and a named industrial vendor (Siemens) make this a supply-chain and ICS event, not a generic worm story. C2 monitoring means some infected hosts still had outbound paths. **Intelligence assessment.** [Assessment — high confidence] By 19–20 July the antivirus industry and Siemens are treating this as a WinCC-relevant threat named Stuxnet. [Inference — moderate confidence] Certificate revocation is a partial Passport response; it does not remove already-installed drivers. [Uncertainty] July C2 content is not described in operational detail in the dossier’s timeline table, and this brief will not reconstruct C2 tradecraft. **Opportunity.** A Siemens July customer advisory stating which product versions and whether PLCs were in scope would have been the manufacturer primary. **LRRK relevance.** Passport / Lab / Control Fabric. Record certificate revocation dates and the Siemens investigation notice as the July integrity actions. **Confidence.** High on the dated Symantec/Siemens/Verisign sequence as Symantec later compiled it; the compilation is November, the events are July. ## 03. Afghan War Diary: field records of lethal action, 2004–2010 *Event / publication dates: 25 July 2010, 5:00 PM EST* **Verified record — [Fact — A1]** WikiLeaks’ own release page states that on 25 July 2010 it released the Afghan War Diary, “an extraordinary compendium of over 91,000 reports covering the war in Afghanistan from 2004 to 2010,” written by soldiers and intelligence officers, mainly describing lethal U.S. military actions, plus intelligence and political-meeting notes. About 15,000 reports were withheld for harm minimization. Formats included HTML, CSV, SQL, and KML. Coverage excludes most U.S. Special Forces activity, top-secret operations, and most European/other ISAF operations. Fetched: https://www.wikileaks.org/wiki/Afghan_War_Diary,_2004-2010 **Threat landscape.** This is a Control Fabric leak of the Army’s own Sense-and-report system (SIGACTs and related). Where those reports mention unmanned aircraft, they become public documentation of UAV use — but this filing does not invent a drone-strike tally from the dump without a contemporaneous counted primary. **Intelligence assessment.** [Assessment — high confidence] The diary is a large, dated U.S. military reporting archive now in public hands. [Inference — moderate confidence] Researchers will mine it for civilian-casualty and ISR patterns, including UAV mentions. [Uncertainty] This collection did not independently tabulate UAV-tagged entries. **Opportunity.** A DoD authenticity statement and a public UAV-filtered extract would have reduced reliance on third-party counts. **LRRK relevance.** Watch / Passport. Treat the diary as a primary reservoir, grade individual rows, do not treat the dump as a finished UAV study. **Confidence.** High on release date and stated scope; low on uncounted UAV subset. ## 04. CRS frames domestic Predator B border surveillance *Event / publication dates: 8 July 2010 (CRS RS21698)* **Verified record — [Fact — A1]** The Congressional Research Service product RS21698, “Homeland Security: Unmanned Aerial Vehicles and Border Surveillance,” by Chad C. Haddal and Jeremiah Gertler, has a listed publication date of 8 July 2010 on the Library of Congress CRS product page. Fetched: https://www.congress.gov/crs-product/RS21698 **Threat landscape.** Domestic UAS Sense (CBP Predator B / Guardian path) is now a dated congressional research object in the same month as an ICS worm and a war-diary leak. Three different Control Fabrics — homeland COA, wartime SIGACT, industrial malware — are simultaneously public. **Intelligence assessment.** [Assessment — high confidence] Congress has an updated UAV-border primer this month. [Inference — moderate confidence] Domestic access fights will cite this paper. [Uncertainty] This filing did not successfully retrieve the PDF body; fleet counts inside the report are therefore not quoted. **Opportunity.** Fetching the 8 July PDF would have allowed CBP inventory Facts without secondary paraphrase. **LRRK relevance.** Control Fabric / Watch. Index RS21698 as the July domestic-UAS congressional record; do not invent its tables. **Confidence.** High on title, authors, and date; low on unread tables. ## 05. Extra-theater UAV Act is not paused by the new public stories *Event / publication dates: continuing Pakistan campaign; January 2010 still the last detailed fetched C2 snapshot* **Verified record — [Fact — B2]** No July official U.S. statement ending the Pakistan drone campaign was fetched. The January C2 description (Virginia satellite control, Pakistani launch base, Reaper growth) remains the last detailed official-adjacent snapshot in this collection. Fetched: https://www.nbcnews.com/id/wbna35027603 **Threat landscape.** Public attention this month is malware and WikiLeaks; the remote-kill program continues as a separate Act ledger. **Intelligence assessment.** [Assessment — moderate confidence] Continuity. [Uncertainty] July strike-level Facts not fetched. **Opportunity.** An official July tempo note would have updated the ledger. **LRRK relevance.** Kestrel. Do not let Stuxnet and the diary erase Waziristan. **Confidence.** Moderate on continuity; low on July counts. ## Forward indicators Ranked watchlist as of the collection cutoff (what a 2001–2011 Watch desk would have monitored next). 1. Siemens/Microsoft/Symantec papers that state whether PLCs, not only WinCC PCs, are modified. 2. Any IAEA or Iranian statement linking centrifuge trouble to malware (none exists yet in this collection). 3. Media mining of the Afghan War Diary for UAV lines. 4. Next WikiLeaks tranche (Iraq or cables). 5. Certificate-authority and code-signing audits after Realtek/JMicron revocations. > **Collection integrity.** Stuxnet public story taken from Krebs (15–16 July) and Symantec’s later dossier timeline for Siemens/rename/C2-monitor dates. No exploit recipe, payload frequency table, or reproduction procedure is included. Afghan War Diary taken from WikiLeaks’ own release page; no unverified drone-kill count extracted. CRS cited for bibliographic Fact only because the PDF body was not retrieved. VirusBlokAda’s own English page was not independently fetched. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C1</span></p>