In the 2011 report to Congress on Foreign Spies Stealing U.S. Economic Secrets in Cyberspace, the Office of the National Counterintelligence Executive provided a baseline assessment of the many dangers facing the U.S. research, development, and manufacturing sectors when operating in cyberspace, the pervasive threats posed by foreign intelligence services and other threat actors, and the industries and technologies most likely at risk of espionage. The 2018 report provides additional insight into the most pervasive nation-state threats, and it includes a detailed breakout of the industrial sectors and technologies judged to be of highest interest to threat actors. It also discusses several potentially disruptive threat trends that warrant close attention.
Originating Organization: United States
- Department of Justice
- Office of the Director of National Intelligence
- California
- Department of Homeland Security
- Department of Defense
- New Jersey
- Delaware
- Florida
- Ohio
- Washington
- High Intensity Drug Trafficking Area
- Executive Office of the President of the United States
- Pennsylvania
- Nevada
- Maryland
- Mississippi
- Department of the Treasury
- Oregon
- Department of Energy
- Senate
- Department of State
- Department of Health and Human Services
- New York
- Supreme Court of the United States
- New Mexico
- House of Representatives
- Drug Enforcement Administration
- Federal Bureau of Investigation
- Office of Justice Programs
- Office of Community Oriented Policing Services
- El Paso Intelligence Center
- DEA Philadelphia Division
- Special Testing and Research Laboratory
- DEA Phoenix Division
- FBI Cyber Division
- Counterterrorism Division
- Office of Private Sector
- National Domestic Communications Assistance Center
- Behavioral Analysis Unit
- Counterintelligence Division
- Phoenix Field Office
- Criminal Justice Information Systems Division
- Bureau of Justice Assistance
- National Institute of Justice
- National Counterintelligence and Security Center
- National Counterterrorism Center
- Cyber Threat Intelligence Integration Center
- National Intelligence Council
- Orange County Intelligence Assessment Center
- Northern California Regional Intelligence Center
- California Cybersecurity Integration Center
- San Diego Law Enforcement Coordination Center
- Governor's Office of Emergency Services
- Intelligence Fusion Centers
- National Protection and Programs Directorate
- National Coordinating Center for Communications
- Office of Intelligence and Analysis
- Customs and Border Protection
- Immigration and Customs Enforcement
- U.S. Secret Service
- Transportation Security Administration
- Cybersecurity and Infrastructure Security Agency
- Federal Emergency Management Agency
- Office of Cyber and Infrastructure Analysis
- Office of Cybersecurity and Communications
- National Cybersecurity and Communications Integration Center
- Counterterrorism Mission Center
- Cyber Mission Center
- Office of Intelligence
- U.S. Border Patrol
- National Threat Assessment Center
- U.S. Army
- Defense Intelligence Agency
- Joint Chiefs of Staff
- Defense Personnel and Security Research Center
- Defense Forensics and Biometrics Agency
- U.S. Air Force
- U.S. Northern Command
- Office of the Secretary of Defense
- U.S. Marine Corps
- National Reconnaissance Office
- U.S. Army Training and Doctrine Command
- Asymmetric Warfare Group
- Training and Doctrine Command
- Center for Law and Military Operations
- Army Capabilities Integration Center
- Army Threat Inegration Center
- Office of Special Investigations
- U.S. Army North
- Office of Homeland Security and Preparedness
- Regional Operations and Intelligence Center
- Delaware Information and Analysis Center
- Central Florida Intelligence Exchange
- Northeast Ohio Regional Fusion Center
- Washington State Fusion Center
- Northwest High Intensity Drug Trafficking Area
- Michigan High Intensity Drug Trafficking Area
- Council of Economic Advisers
- Pennsylvania Criminal Intelligence Center
- Las Vegas Metropolitan Police Department
- Nevada High Intensity Drug Trafficking Area
- Johns Hopkins University
- Mississippi Analysis and Information Center
- Internal Revenue Service
- Oregon TITAN Fusion Center
- Senate Select Committee on Intelligence
- Senate Committee on Homeland Security and Governmental Affairs
- Overseas Security Advisory Council
- New York Police Department
- New Mexico All Source Intelligence Center
China, Federal Bureau of Investigation
FBI Cyber Bulletin: Identified Qakbot Malware Variant Found on Thumb Drive Manufactured in China
In March 2018, an identified financial services corporation received a thumb drive infected with the bank credential-stealing Qakbot malware variant, targeting information from networked computers and financial institution web sites. The financial services corporation purchased bulk thumb drives from a US online retailer of computer hardware. The thumb drives were originally manufactured in China. According to FBI forensic analysis, the Qakbot malware was on the infected thumb drive before the drive arrived in the United States. Qakbot is extremely persistent and requires removal of all malware from every device. Failure to remove even one node of malware may result in re-infecting previously sanitized systems possibly costing the victim hundreds of thousands of dollars in malware removal and system downtime.
Nevada
Las Vegas Metropolitan Police Department October 2017 Mass Shooting Final Report
As Engineer Schuck walked up the hallway of the 100 Wing, he observed Security Officer Campos poke his head out of an alcove. Engineer Schuck then heard rapid gunfire coming from the end of the 100 Wing hallway that lasted approximately 10 seconds. When the gunfire stopped, he heard Security Officer Campos tell him to take cover. Engineer Schuck stepped into an alcove and gunfire again erupted down the hallway coming from Room 32-135. The gunfire lasted a few seconds then stopped. The gunfire started again after a brief pause, but Engineer Schuck believed it was directed outside and not down the hallway. Meanwhile, inside the Las Vegas Village over 50 Las Vegas Metropolitan Police Department (LVMPD) personnel were on overtime assignments for the Route 91 Harvest music festival being held at the Las Vegas Village venue. The initial gunshots were heard on an officer’s body worn camera (BWC). As the suspect (Stephen Paddock) targeted the concertgoers with gunfire, officers quickly determined they were dealing with an active shooter and broadcast the information over the radio.
Department of Energy
Department of Energy Assessment of Electricity Disruption Incident Response Capabilities
Electricity is critical to every aspect of modern life. The United States’ national security, economy, and public health and safety rely on the North American electric grid every second of the day. These, and many other functions powered by the grid have likely experienced local outages caused by weather, accidents, or sometimes from tree branches falling on power lines. Larger power outages, however, are infrequent occurrences, due in part to an array of organizations that work tirelessly to ensure the grid remains reliable, resilient, and secure. Nonetheless, it is neither practical nor possible to prevent all disruptive events. Grid owners and operators balance risk, investment, and cost to customers when making investments in their systems.
Federal Bureau of Investigation
FBI Report: Active Shooter Incidents in the United States in 2016 and 2017
As with past FBI active shooter-related publications, this report does not encompass all gun-related situations. Rather, it focuses on a specific type of shooting situation. The FBI defines an active shooter as one or more individuals actively engaged in killing or attempting to kill people in a populated area. Implicit in this definition is the shooter’s use of one or more firearms. The active aspect of the definition inherently implies that both law enforcement personnel and citizens have the potential to affect the outcome of the event based upon their responses to the situation.
Department of Homeland Security
(U//FOUO) DHS Intelligence Note: Unidentified Cyber Actor Attacks State and Local Government Networks with GrandCrab Ransomware
An unidentified cyber actor in mid-March 2018 used GrandCrab Version 2 ransomware to attack a State of Connecticut municipality network and a state judicial branch network, according to DHS reporting derived from a state law enforcement official with direct and indirect access. The municipality did not pay the ransom, resulting in the encryption of multiple servers that affected some data backups and the loss of tax payment information and assessor data. The attack against the state judicial branch resulted in the infection of numerous computers, but minimal content encryption, according to the same DHS report.
Joint Chiefs of Staff
Joint Publication 3-12 Cyberspace Operations
Cyberspace operations (CO) is the employment of cyberspace capabilities where the primary purpose is to achieve objectives in or through cyberspace. This publication focuses on military operations in and through cyberspace; explains the relationships and responsibilities of the Joint Staff (JS), combatant commands (CCMDs), United States Cyber Command (USCYBERCOM), the Service cyberspace component (SCC) commands, and combat support agencies; and establishes a framework for the employment of cyberspace forces and capabilities.
Drug Enforcement Administration
DEA Drug Slang Code Words 2018
This Drug Enforcement Administration (DEA) Intelligence Report contains new and updated information on slang terms and code words from a variety of law enforcement and open sources, and serves as an updated version to the product entitled “Drug Slang Code Words” published by the DEA in May 2017. It is designed as a ready reference for law enforcement personnel who are confronted with hundreds of slang terms and code words used to identify a wide variety of controlled substances, designer drugs, synthetic compounds, measurements, locations, weapons, and other miscellaneous terms relevant to the drug trade. Although every effort was made to ensure the accuracy and completeness of the information presented, due to the dynamics of the ever-changing drug scene, subsequent additions, deletions, and corrections are inevitable. Future addendums and updates to this report will attempt to capture changed terminology to the furthest extent possible.
Federal Bureau of Investigation
FBI Report: E-mail Account Compromise Techniques Used to Steal Millions in Real Estate Settlement Funds
The Office of Private Sector, in coordination with the Criminal Investigative Division, is providing this LIR to inform private sector partners about the increasing use of e-mail account compromise (EAC) techniques in the US real estate settlement industry. Consumer borrowers, settlement/title companies, real estate agents, real estate attorneys, builders, and others are being targeted by criminal actors netting millions in illicit proceeds. These proceeds are often directed initially to US banks then re-directed via money service businesses and international accounts to Mexico, Nigeria, South Africa, China, Ghana, Turkey, and India. The increased use of EAC techniques, as well as, the evolving expansion into previously unidentified countries indicates this fraud scheme is not slowing and puts additional strain on industry participants to be vigilant with their e-mail communications and identity verification processes.
Federal Bureau of Investigation
FBI Cyber Bulletin: APT Actors Likely to Target US Cleared Defense Contractors
APT actors in the near future likely intend to target US Cleared Defense Contractors (CDC) via spear phishing campaigns or network infrastructure compromises, according to recent intelligence. Common spear phish targets may include individuals featured on internet-facing CDC Web sites and high-ranking CDC executives.
Department of Homeland Security
DHS Infrastructure Security Note: Unmanned Aircraft Systems Cybersecurity Risks
The Department of Homeland Security (DHS)/National Protection and Programs Directorate (NPPD)/Office of Cyber and Infrastructure Analysis (OCIA) assesses that unmanned aircraft systems (UASs) provide malicious actors an additional method of gaining undetected proximity to networks and equipment within critical infrastructure sectors. Malicious actors could use this increased proximity to exploit unsecured wireless systems and exfiltrate information. Malicious actors could also exploit vulnerabilities within UASs and UAS supply chains to compromise UASs belonging to critical infrastructure operators and disrupt or interfere with legitimate UAS operations.
Department of Defense
DoD Forensic Science Lexicon
The Department of Defense (DoD) performs forensic science in a collaborative environment which necessitates the clear communication of all activities and their results. A critical enabler of communication is the use of a clear, internally consistent vocabulary. The goal of the Department of Defense Forensics Lexicon is to provide an operational vocabulary to address Forensics. A shared vocabulary enables a common understanding of Forensics, enhances the fidelity and the utility of operational reporting, facilitates structured data sharing, and strengthens the decision making processes across the DoD.
Department of Homeland Security
Department of Homeland Security Cybersecurity Strategy 2018
The American people are increasingly dependent upon the Internet for daily conveniences, critical services, and economic prosperity. Substantial growth in Internet access and networked devices has facilitated widespread opportunities and innovation. This extraordinary level of connectivity, however, has also introduced progressively greater cyber risks for the United States. Long-standing threats are evolving as nation-states, terrorists, individual criminals, transnational criminal organizations, and other malicious actors move their activities into the digital world. Enabling the delivery of essential services—such as electricity, finance, transportation, water, and health care—through cyberspace also introduces new vulnerabilities and opens the door to potentially catastrophic consequences from cyber incidents. The growing number of Internet-connected devices and reliance on global supply chains further complicates the national and international risk picture.
Defense Intelligence Agency
(U//FOUO) DIA Study: Warp Drive, Dark Energy, and the Manipulation of Extra Dimensions
If one is to realistically entertain the notion of interstellar exploration in timeframes of а human lifespan, а dramatic shift in the traditional approach to spacecraft propulsion is necessary. It has been known and well tested since the time of Einstein that all matter is restricted to motion at sublight velocities ( << З х 10⁸ m/s, the speed of light, or с), and that as matter approaches, the speed of light, its mass asymptotically approaches infinity. This mass increase ensures that an infinite amount of energy would Ье necessary to travel at the speed of light, and, thus, this speed is impossible to reach and represent an absolute speed limit to all matter traveling through spacetime.
Defense Intelligence Agency
(U//FOUO) DIA Study: Advanced Space Propulsion Based оn Vacuum (Spacetime Metric) Engineering
А theme that has come to the fore in advanced рlаnniпg for long-range space exploration in the future is the соnсерt that empty space itself (the quantum vacuum, or spacetime metric) might bе engineered to provide energy/thrust for future space vehicles. Although far reaching, such а proposal is solidly grounded iп modern physical theory, аnd therefore the possibility that matter/vacuum iпteractions might bе engineered for spaceflight applications is nоt а priori ruled out.
Department of Homeland Security
(U//FOUO) DHS Final Decision on Removal of Kaspersky-Branded Products
BOD 17-01 requires all federal executive branch departments and agencies to (1) identify the use or presence of “Kaspersky-branded products” on all federal information systems within 30 days of BOD issuance (i.e., by October 13); (2) develop and provide to DHS a detailed plan of action to remove and discontinue present and future use of all Kaspersky-branded products within 60 days of BOD issuance (i.e., by November 12); and (3) begin to implement the plan of action at 90 days after BOD issuance (i.e., December 12), unless directed otherwise by DHS in light of new information obtained by DHS, including but not limited to new information submitted by Kaspersky.
Department of Homeland Security
(U//FOUO) DHS NCCIC Independent Assessment of Kaspersky-Branded Products
The Department of Homeland Security (DHS) National Cybersecurity and Communications Integration Center (NCCIC) reviewed the Independent Assessment, titled Information Security Risks of Anti-Virus Software (hereafter “BRG Assessment”), prepared by Berkeley Research Group, LLC (BRG), and dated November 10, 2017. Kaspersky Lab (hereafter “Kaspersky”) submitted the BRG Assessment to DHS as an exhibit to Kaspersky’s request for DHS to initiate a review of Binding Operational Directive (BOD) 17-01. The BRG Assessment, in part, responds to the NCCIC Information Security Risk Assessment (hereafter “NCCIC Assessment”) on commercial off-the-shelf (COTS) anti-virus software and Kaspersky-branded products, dated August 29, 2017. The NCCIC Assessment was attached as Exhibit 1 to an Information Memorandum from the Assistant Secreta1Y for DHS Cybersecurity and Communications (CS&C) to the Acting Secretary of DHS, dated September 1, 2017 (hereafter “Information Memorandum”). This document is a Supplemental Information Security Risk Assessment and will similarly be attached to an Information Memorandum from the Assistant Secretary for CS&C to the Acting Secretary of DHS.
Department of Homeland Security
(U//FOUO) DHS NCCIC Information Security Risk Assessment of Kaspersky-Branded Products
This assessment presents the inherent information security concerns and security ramifications associated with the use of any commercial-off-the-shelf (COTS) antivirus solution in devices with access to a federal network. It also addresses specific risks presented by Kaspersky-branded products, solutions, and services (collectively, “Kaspersky-branded products”).
Afghanistan, California, Intelligence Fusion Centers
(U//FOUO) San Diego Fusion Center Bulletin: Ambulance Used to Conceal Improvised Explosive Device in Afghanistan
On January 27, 2018 at approximately 12:15pm local time, a vehicle resembling an ambulance and laden with explosives detonated after it passed through a police checkpoint in Kabul, Afghanistan. The explosion killed more than 100 people and wounded approximately 235 others. According to the deputy spokesperson for the Afghanistan Interior Ministry, the vehicle was painted to resemble an ambulance and had successfully passed through a checkpoint after the attacker allegedly told police he was transporting a patient to a nearby hospital. While stopped at a second checkpoint farther inside the city limits, the attacker detonated the explosives concealed in the vehicle.
Drug Enforcement Administration
(U//FOUO) DEA Emerging Threats Reports 2017
The Special Testing and Research Laboratory’s Emerging Trends Program compiled the data for this report through a query of archived seizure and analysis information from drug evidence analyzed by the Drug Enforcement Administration’s laboratory system. This data is representative of drug evidence seized and analyzed in the date ranges annotated. This is not a comprehensive list of all new psychoactive substances and is not representative of all evidence analyzed by DEA. This data is a quarterly snapshot of the new psychoactive substance market in the United States.
U.S. Army
U.S. Army Threat Tactics Report: North Korea vs the United States
The Threat Tactics Report: North Korea versus the United States (US) and the other similar products serve to describe the foreign nation’s most common combat division with an order of battle, its offensive and defensive doctrine as articulated in its manuals or recent military actions, and an analysis of how this actor would fight if facing the US in the future.
Russia, U.S. Army
U.S. Army Threat Tactics Report: Russia
In the last seven years, Russia has reasserted itself as a military force in Eastern Europe and the Caucasus. With the 2008 military incursion into Georgia and the 2014 seizure of Crimea and support for pro-Russian separatists in Ukraine, Russia has assumed a more aggressive, interventionist stance in Europe. In the effort to influence events in Ukraine, the Russians have used what the US Army defines as “Hybrid Warfare” to infiltrate, isolate, and dominate eastern Ukraine and Crimea. This is all a part of the strategy of what can be called “Indirect Action”—the belief by the Russians that they reserve the right to protect ethnic Russians and interests in their former states from domination by Western powers and NATO.
Department of Homeland Security, Federal Bureau of Investigation, National Counterterrorism Center
(U//FOUO) DHS-FBI-NCTC Bulletin: Online Information May Provide Potential Roadmap for Crude Chemical-Biological Attacks
The late 2016 arrest of two California teenagers for allegedly planning a “mass casualty event” by carrying out a chemical attack at a local high school pep rally highlights how individuals can use online resources to plan crude chemical or biological attacks. Violent extremists continue to circulate often ineffective or misleading how-to instructions for producing and disseminating poisons, crude biological toxins, and toxic industrial chemicals that in many cases are commercially available and easy to obtain. While we have no indication the suspects in this case subscribed to or consumed material related to violent extremist ideologies, their activity highlights one path to conducting a potential chemical or biological attack.
Drug Enforcement Administration
(U//LES) DEA Bulletin: Expanding Fentanyl Threat in the United States
Fentanyl is a Schedule II synthetic opioid originally developed to serve as both an analgesic (painkiller) and an anesthetic; however, its strong opioid properties have made it an attractive drug of abuse in the United States. Fentanyl, in its licit form, is diverted from the market on a small scale for personal use or sale. Illicitly manufactured and trafficked fentanyl is responsible for the current domestic crisis. Fentanyl, fentanyl-related compounds, and the precursor chemicals needed to produce these substances originate in China and transit Mexico or Canada enroute to U.S. markets. It is believed that illicit fentanyl manufacturing is occurring in Mexico. Moreover, small-scale production facilities have been discovered in the United States and Canada.
White House
Council of Economic Advisers Report: The Cost of Malicious Cyber Activity to the U.S. Economy
This report examines the substantial economic costs that malicious cyber activity imposes on the U.S. economy. Cyber threats are ever-evolving and may come from sophisticated adversaries. Due to common vulnerabilities, instances of security breaches occur across firms and in patterns that are difficult to anticipate. Importantly, cyberattacks and cyber theft impose externalities that may lead to rational underinvestment in cybersecurity by the private sector relative to the socially optimal level of investment. Firms in critical infrastructure sectors may generate especially large negative spillover effects to the wider economy. Insufficient data may impair cybersecurity efforts. Successful protection against cyber threats requires cooperation across firms and between private and public sectors.