RE: https://infosec.exchange/@metacurity/117087219784433516
So I've been breaking down this memo for the past hour or so, and there is a part of it, Section 4(c), that determines whether a target is eligible for private companies to conduct operations against foreign cyber-enabled transnational criminal organizations.
Section 4(c) says a foreign group is presumed to be a non-state actor unless the government already possesses "clear intelligence" proving otherwise.
For clear, independent criminal gangs such as Scattered Spider, this makes sense.
But for criminal gangs in Russia, China, Iran, and North Korea, where criminal actors are staffed alongside a hostile state's security services, the presumption is least reliable and could result in inadvertent escalation to global geopolitical levels, no?
In other words, the real risk isn't a participating company hitting the wrong criminal server — it's hitting infrastructure with an undisclosed link to a hostile intelligence service and turning a law-enforcement operation into a state-to-state incident.