US Navy
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor is publicly referenced under the alias “US Navy” and is associated with the United States of America. It operates as a component of the U.S. Department of the Navy, with its actions attributed to Navy prosecutors involved in a specific legal case. The actor’s affiliation with a state military organization establishes a clear government nexus rather than a criminal or commercial entity.
Targeting observed in the sole publicly reported incident focused on U.S. military legal personnel and journalists covering a war crimes trial. The actors sought to compromise the devices of Air Force lawyers defending a Navy SEAL and to reach editors of military publications that had published detailed trial coverage. The geographic scope of the activity was confined to the United States, with no indication of overseas targets or broader sectoral interests. Strategic objectives appeared centered on espionage, specifically the identification of potential document leaks and the monitoring of communications related to the ongoing court case, rather than financial gain or disruptive effects.
The reported tactics involved the delivery of custom malware via email, which was designed to grant full access to a victim’s computer and to function as tracking software. The malware included capabilities to extract network IP addresses and exfiltrate that information to a server located in San Diego. Initial access relied on social engineering through seemingly legitimate correspondence, and the tooling style reflected a bespoke approach tailored to surveillance and data collection rather than the use of widely known malware families or exploit kits. No evidence points to the employment of zero‑day vulnerabilities, ransomware, or distributed denial‑of‑service techniques in this operation.
The most notable campaign associated with this actor occurred in May 2019, when the U.S. Air Force investigated a malware infection on the devices of its legal counsel and on the computer networks. The incident to Navy prosecutors, according to the Air Force, phone, and related systems of an Air Force lawyer and on the systems of a military publication editor. The incident was attributed to Navy prosecutors attempting to uncover sources of alleged leaks concerning a war crimes trial, and it resulted in the seizure of the affected devices for forensic review. This case remains the only publicly documented operation that links the actor to a specific malware deployment and objective. The actor’s activities, as currently known, are limited to this targeted espionage effort within the U.S. military and media environment.
Incidents
Attributed incidents are available to members.
1 incident