US President Donald Trump has signed a national security memo that will allow US companies to conduct cyber attacks against criminal groups and foreign adversaries.

The National Security Presidential Memorandum directs President Trump’s administration to "leverage the capability and innovation of the private sector to help conduct these cyber operations under the direction, control, and authority of the US government”, the White House said.

“The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States,” the directive states.

“By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens.”

In a fact sheet about the memo, the White House cited ransomware attacks, financial frauds and other crimes run by foreign-based criminal organizations, referred to in the memo as "transnational criminal organizations."

The memo creates a framework that encourages private sector companies to enter into agreements with other private entities, as well as federal, state, local, tribal, and territorial agencies to gather threat information on transnational criminal organizations and propose cyber operations to address those threats, the White House added.

The memo directs the Department of Homeland Security, through the Homeland Security Task Force's National Coordination Center, to create a program "to conduct specific cyber operations that disrupt foreign TCOs" that will be overseen by DHS and the Department of Justice.

Under the supervision of the federal government, participating companies, once vetted, will conduct "cyber surveillance operations" and "cyber effects operations" against specified targets, according to the memo.

"Cyber effects includes the potential manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon," according to the memo.

Participating companies will have to maintain a bond or escrow of at least $1 million, according to the memo.

The idea of private sector firms participating in cyber operations against criminal and other targets is not new, and has been controversial in the past, for fears of escalation, inadvertent consequences, and inter-agency coordination issues.

Successive administrations have increasingly relied on the private sector to bolster its cyber security capabilities, though authorising companies to carry out government-directed operations marks a significant expansion of that relationship.

The White House did not immediately respond to requests for additional information about the directive.

Additional reporting from agencies.