//
OFFLINE — VIEWING CACHED CONTENT
← Back to Archive

IC BRIEF

Current as of 1855 EDT (UTC-04), Thursday 09 April 2026

Contents

13 stories from 24 sources across 21 organizations


BOTTOM LINE UP FRONT

Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU) Unit 26165 is running two parallel cyber campaigns simultaneously — a global router-hijacking operation exposed by Government Communications Headquarters (GCHQ) and a spear-phishing campaign deploying novel PRISMEX malware against NATO logistics networks supporting Ukraine. The operational tempo suggests wartime tasking priorities and represents the most aggressive disclosed GRU cyber posture since the invasion of Ukraine.

CIA Deputy Director Michael Ellis announced the agency will integrate AI coworkers into analytic workflows and disclosed the first AI-generated intelligence report, while a federal appeals court denied Anthropic's bid to block its Pentagon blacklisting — splitting the Intelligence Community (IC)'s AI landscape between agencies that can and cannot access its models.

Ukrainian intelligence reported Russian military intelligence officers are now permanently stationed in Tehran coordinating satellite imagery transfers to Iranian forces, marking a structural escalation in Moscow's support for the Iran war from ad hoc sharing to embedded operational integration.


Allied Intelligence

UK Deploys Warships and Patrol Aircraft to Track Russian GUGI Submarines Near Undersea Cables

Britain deployed a frigate, support tanker, and maritime patrol aircraft after detecting an Akula-class attack submarine and two specialist vessels from Russia's Main Directorate for Deep Sea Research (GUGI) operating near undersea cables in the UK Exclusive Economic Zone for over a month. Norway coordinated with a P-8 aircraft and frigate. Defence Secretary John Healey warned Moscow directly: "We see your activity over our cables and our pipelines." No infrastructure damage was detected. British officials assessed Russia exploited the Middle East conflict as a distraction window for the covert reconnaissance.

Analyst Note: Russia's deployment of GUGI deep-sea research vessels — a unit specifically designed for undersea sabotage — alongside an attack submarine during the Middle East crisis window follows an established pattern of testing allied detection capabilities during periods of strategic distraction. The UK's decision to go public rather than quietly track suggests a deliberate deterrence message to Moscow.

Sources:

Germany Consults Five Eyes and European Partners on BND Reform to Enable Offensive Cyber Operations

German intelligence coordinator Philip Wolf met in London with British National Security Adviser Jonathan Powell and Joint Intelligence Committee (JIC) Chair Madeleine Alessandri to discuss expanding Bundesnachrichtendienst (Federal Intelligence Service) (BND) authorities for offensive cyber operations, currently barred under post-war legislation. Former BND officers have proposed restructuring the service along Secret Intelligence Service (MI6) or Direction Générale de la Sécurité Extérieure (DGSE) lines. The reform would move the BND from a collection-and-analysis mandate to operational capabilities matching allied services.

Analyst Note: Germany consulting MI6 and DGSE on offensive cyber models reflects a broader European shift toward operational intelligence capabilities. If enacted, this would be the most significant expansion of BND authorities since its founding, removing post-war restrictions that have limited it to collection and analysis for decades.

Sources:

Watch Items - Bundestag legislative action on BND offensive cyber authorities - Whether GUGI submarines return to UK EEZ during ceasefire period

Adversary Intelligence

GCHQ Exposes GRU Unit 26165 Campaign Hijacking Home Routers Across 120 Countries for Espionage

The UK National Cyber Security Centre, part of GCHQ, publicly attributed a broad router-hijacking campaign to GRU Unit 26165 (APT28/Fancy Bear) with its highest confidence rating. The operation compromised TP-Link and MikroTik routers across 120 countries by exploiting weak Simple Network Management Protocol (SNMP) configurations, enabling Domain Name System (DNS) hijacking and adversary-in-the-middle attacks to intercept credentials and authentication tokens. NSA and FBI co-sealed the advisory. The campaign was initially opportunistic—scanning widely for vulnerable devices—before narrowing to intelligence-priority targets in military, government, and critical infrastructure sectors.

Analyst Note: This is the second distinct APT28 campaign disclosed this week alongside PRISMEX, suggesting GRU Unit 26165 is running parallel operations across different target sets. The router campaign's shift from opportunistic scanning to intelligence-priority targeting mirrors the GRU's operational pattern of casting wide nets before narrowing to high-value collection. The FBI's active disruption via Operation Masquerade represents an increasingly aggressive U.S. counter-cyber posture.

Sources:

Prior Reporting - [Russian GRU exploited vulnerable routers worldwide to steal sensitive information, probe reveals](https://www.euronews.com/2026/04/08/russian-gru-exploited-vulnerable-routers-worldwide-to-steal-sensitive-information-probe-re) (2026-04-08) - [UK exposes Russian cyber unit hacking home routers to hijack internet traffic](https://therecord.media/uk-exposes-russian-cyber-unit-hacking-home-routers) (2026-04-07)

Six-Month DPRK Intelligence Operation Behind $285 Million Drift Protocol Cryptocurrency Theft Detailed

Forensic analysis revealed a six-month Democratic People's Republic of Korea (DPRK) state-sponsored intelligence operation behind the April 1 theft of $285 million from Drift Protocol, the largest Solana Decentralized Finance (DeFi) exploit in history. The operation, attributed to UNC4736 (AppleJeus/Citrine Sleet/Golden Chollima), used third-party intermediaries to approach Drift contributors at crypto conferences, build constructed professional identities, and deposit over $1 million to establish credibility. Attack vectors included weaponized VS Code projects and a fake Apple TestFlight wallet application. Fund flows and operational personas link the operation to the October 2024 Radiant Capital breach.

Analyst Note: The six-month preparation phase, constructed identities, and in-person conference approaches mark an escalation in DPRK tradecraft sophistication beyond previous crypto heists. UNC4736 is now investing operational resources comparable to traditional HUMINT recruitment cycles. The $285 million take likely exceeds North Korea's annual conventional arms export revenue, reinforcing cryptocurrency theft as a strategic funding stream.

Sources:

GRU Unit 26165 Deploys Previously Undocumented PRISMEX Malware Suite Against Ukraine and NATO Allies

GRU-linked APT28 (Forest Blizzard) launched a spear-phishing campaign deploying a previously undocumented malware suite dubbed PRISMEX against Ukraine and NATO logistics partners. The campaign, active since September 2025, targets Ukrainian government agencies, defense organizations, and rail/maritime logistics in Poland, Romania, Slovenia, Turkey, Slovakia, and the Czech Republic. PRISMEX uses steganography to conceal payloads in image files, Component Object Model (COM) hijacking, and legitimate cloud services for command-and-control. Attack chains exploit CVE-2026-21509 to force connections to attacker-controlled WebDAV servers without user interaction.

Analyst Note: The targeting of NATO logistics partners — rail in Poland, maritime in Romania and Turkey, ammunition support in Slovakia and Czech Republic — maps directly to Ukraine's supply lines. CVE-2026-21509 exploitation without user interaction lowers the barrier to mass compromise. Combined with the parallel router hijacking campaign, GRU Unit 26165 is operating at a tempo suggesting wartime tasking priorities.

Sources:

Ukraine Says Russian Military Intelligence Officers in Tehran Coordinating Satellite Imagery Transfers to Iran

Ukrainian intelligence reported that Russian military intelligence officers stationed in Tehran are facilitating satellite imagery transfers to Iranian forces through a permanent communications channel, enabling strikes against approximately 50-53 Israeli civilian energy infrastructure sites. President Zelensky said the targets have no military significance and could cause power grid collapse. Moscow has been sharing real-time satellite imagery and data on American warships and aircraft positions since March, while also providing parts to modify Shahed drones with improved communications and targeting. The intelligence cooperation represents the most direct Russian involvement in the Iran war to date.

Analyst Note: The permanent communications channel and embedded GRU officers in Tehran represent a qualitative shift from opportunistic intelligence sharing to structured operational integration. Targeting 50+ civilian energy sites for grid collapse moves this cooperation beyond battlefield support into strategic coercion. These claims rest on Ukrainian intelligence reporting; no Western service has independently confirmed permanent GRU personnel in Tehran, though U.S. officials confirmed the broader pattern of Russian satellite imagery sharing to Iran in March.

Sources:

Watch Items - Whether PRISMEX compromises extend to NATO ammunition supply chains - Additional DPRK crypto heist attempts reusing UNC4736 conference social engineering playbook - Independent verification of Russian GRU officers embedded in Tehran

Cyber Operations

Treasury Launches Cyber Threat Intelligence Sharing Program for Cryptocurrency Firms

Treasury's Office of Cybersecurity and Critical Infrastructure Protection launched a program extending to U.S. crypto firms the same threat intelligence already shared with traditional financial institutions. Deputy Assistant Secretary Cory Wilson cited the North Korean-linked $285 million Drift Protocol theft as evidence of growing attack sophistication. The program provides free access to early warnings, indicators of compromise, and tailored guidance for exchanges, wallet providers, and custodians.

Sources:

DOJ Requests $110.3 Million Increase for Zero-Trust Migration of Classified and National Security Systems

Department of Justice (DOJ) requested $149 million for its FY2027 Justice Information Sharing Technology fund, a $110.3 million increase over recent years to migrate 275,000 endpoints to zero-trust architecture. Of that, $66.1 million targets classified and national security systems. The build includes a central identity provider, cloud-based network broker replacing VPNs, and real-time endpoint detection. DOJ warned that without full funding, its systems remain exposed to the lateral movement techniques exploited in the SolarWinds intrusion.

Sources:

Watch Items - Additional Iranian ICS/SCADA compromises beyond the 75 initial devices - Treasury crypto intel sharing program uptake and first operational product

IC Technology

Appeals Court Denies Anthropic Bid to Block Pentagon Blacklisting as Small AI Rivals Fill Defense Gap

A federal appeals court denied Anthropic's request to temporarily block the Pentagon's supply chain risk designation, leaving the company excluded from DOD contracts while litigation continues. Anthropic can still work with other government agencies, including intelligence community customers evaluating its Claude Mythos model for cybersecurity. Small defense AI startups report fielding calls from generals and combatant commanders, with the Pentagon exploring shifts to Google, OpenAI, and xAI. The ruling deepens uncertainty over AI vendor access to classified military networks where Anthropic's Claude was the first AI system deployed.

Analyst Note: The split court decisions leave Anthropic excluded from DOD but accessible to other IC agencies — creating a two-track AI landscape where intelligence analysts may use Claude Mythos for cybersecurity while warfighters cannot. The rush toward smaller AI vendors introduces supply chain concentration risk that the Pentagon's own Anthropic designation was designed to prevent.

Sources:

Prior Reporting - [Appeals court rejects Anthropic's bid to block Pentagon blacklisting](https://siliconangle.com/2026/04/08/appeals-court-rejects-anthropics-bid-block-pentagon-blacklisting/) (2026-04-08) - [Anthropic loses bid to block Pentagon blacklisting in DC court](https://www.axios.com/2026/04/08/anthropic-loses-bid-to-block-pentagon-blacklisting) (2026-04-08) - [Appeals court rejects Anthropic's bid to temporarily halt Pentagon designation](https://thehill.com/policy/technology/5823132-appeals-court-rejects-anthropic-halt/) (2026-04-08)

CIA Deputy Director Outlines Plan for AI Coworkers and Autonomous Agent Teams

CIA Deputy Director Michael Ellis disclosed that agency officers will soon work alongside AI tools that assist with drafting intelligence assessments, editing for clarity, and comparing analytic products against tradecraft standards. Within a decade, Ellis said officers will manage teams of autonomous AI agents as hybrid operational partners. The agency currently has over 300 AI projects underway and recently completed its first AI-generated intelligence report. Technology-related foreign intelligence reporting has doubled as the CIA tracks adversary AI adoption.

Analyst Note: The first AI-generated intelligence report marks a threshold event for the analytic workforce. Ellis's 10-year timeline for autonomous agent teams aligns with the pace Office of the Director of National Intelligence (ODNI)'s 2.0 restructuring is already setting — fewer analysts, more machine augmentation. The doubling of technology-related foreign intelligence reporting signals the CIA is simultaneously racing to adopt AI and tracking adversary adoption, creating a dual pressure that will define tradecraft standards for the next decade.

Sources:

OpenAI National Security Lead Warns Pentagon AI Adoption Requires Workforce Transformation

OpenAI national security policy head Sasha Baker called for training analysts, service members, and Foreign Service officers to apply rigorous human judgment when operating AI systems in defense settings. Baker endorsed the Pentagon's "appropriate human judgment" standard and proposed embedding OpenAI engineers at Congress, the White House, and the Pentagon to educate policymakers. Her remarks came as the Pentagon seeks alternative AI vendors after blacklisting Anthropic.

Sources:

Watch Items - Whether other IC agencies follow CIA in adopting AI-generated analytic products - Pentagon timeline for selecting Anthropic replacement AI vendors for classified networks - First operational deployment of Claude Mythos for vulnerability detection under Project Glasswing

Counterintelligence

Former Army Special Operations Employee Charged Under Espionage Act for Leaking Classified Information

Courtney Williams, 40, a former operational support specialist at a Special Military Unit at Fort Bragg identified as Delta Force, was arrested and charged with willful transmission of national defense information under the Espionage Act. Williams held top-secret clearance from 2010 to 2016 and allegedly shared classified information with journalist Seth Harp between 2022 and 2025. The material appeared in Harp's 2025 book on unsolved murders at the special operations base. The FBI Charlotte Field Office is leading the investigation; Williams faces up to 10 years imprisonment.

Analyst Note: The seven-year gap between Williams leaving government (2016) and the alleged leaks (2022-2025) highlights the persistent insider threat from former clearance holders with retained knowledge. The prosecution under the Espionage Act rather than lesser unauthorized disclosure statutes signals DOJ intent to pursue maximum deterrence against media leaks from the special operations community.

Sources:

Prior Reporting - [Former Army employee charged with leaking classified information to journalist](https://www.militarytimes.com/news/your-military/2026/04/09/former-army-employee-charged-with-leaking-classified-information-to-journalist/) (2026-04-09) - [Former Army employee charged with leaking classified info to journalist](https://www.nbcnews.com/politics/national-security/former-army-employee-charged-leaking-classified-info-journalist-rcna267366) (2026-04-08) - [Former special operations support employee charged with leaking classified information](https://www.stripes.com/theaters/asia_pacific/2026-04-08/classified-information-leak-arrest-21321014.html) (2026-04-08)
Watch Items - Williams arraignment and whether additional charges follow - Whether DOJ pursues Harp under Espionage Act or just Williams

IC Oversight & Authorities

DCSA Launches $495 Million Background Check Support Solicitation as Vetting Caseload Drops 24 Percent

The Defense Counterintelligence and Security Agency launched a $494.7 million recompete for its Case Processing Operations Center, which processes approximately 2 million background investigations annually for 100 civilian and defense agencies and 10,000 cleared companies. The Case Processing Operations Center (CPOC) 2.0 contract covers case maintenance, application ingestion, and post-closing support, with a bid deadline of May 8. Defense Counterintelligence and Security Agency (DCSA)'s initial background investigation inventory has dropped 65 percent since early 2025, and over 3.8 million cleared personnel are now enrolled in continuous vetting under the Trusted Workforce 2.0 initiative.

Sources:

Watch Items - DCSA CPOC 2.0 bid deadline May 8 and vendor selection

COLLECTION GAPS

UNCLASSIFIED // OPEN SOURCE