//
OFFLINE — VIEWING CACHED CONTENT
← Back to Archive

IC BRIEF

Current as of 1813 EDT (UTC-04), Thursday 14 May 2026

Contents

13 stories from 43 sources across 39 organizations


KEY JUDGMENTS

Congressional oversight is converging on IC accountability across three fronts: CIA's removal of JFK/MKUltra files from Office of the Director of National Intelligence (ODNI), House Permanent Select Committee on Intelligence (HPSCI)'s COVID-19 analytic integrity investigation, and the collapsed FISA 702 extension vote. Whether this produces substantive changes to IC authorities or operations within six months is genuinely uncertain. Classification reflexes and institutional resistance favor absorption over reform, but bipartisan scope and whistleblower testimony narrow the space for delay. HPSCI's release of unclassified findings would signal accountability over spectacle.

Iran will likely reconstitute missile capability sufficient to threaten Strait of Hormuz shipping within 12 months. Confidence is moderate, grounded in assessments showing 70 percent prewar stockpile retention and 30 of 33 coastal sites restored. Chinese arms transfer discussions via African intermediaries add supply-chain risk, though confirmed deliveries are unlikely within six months. Formal expansion of Israel-Gulf intelligence cooperation beyond the United Arab Emirates (UAE) is unlikely by November.

Russian-aligned services are running concurrent cyber campaigns, with Sandworm holding active footholds in Operational Technology (OT) environments across seven countries. Whether an adversary Advanced Persistent Threat (APT) executes a destructive attack on NATO critical infrastructure within 12 months is genuinely uncertain. US law enforcement will likely announce at least three additional People's Republic of China (PRC) espionage arrests within six months.


Adversary Intelligence

Russian Government Hackers Targeted Spyware Investigator in Signal Hijacking Campaign

Donncha Ó Cearbhaill, head of Amnesty International's Security Lab, told TechCrunch he was one of more than 13,500 targets in a campaign that impersonated Signal support to trick users into submitting verification codes, linking their accounts to attacker-controlled devices. Ó Cearbhaill identified the automation tool as "ApocalypseZ" and found its codebase, interface, and victim chat translations all in Russian. Cybersecurity and Infrastructure Security Agency (CISA), the UK's National Cyber Security Centre (NCSC), and Dutch intelligence have attributed the same impersonation technique to Russian government actors; Der Spiegel separately reported that the hackers compromised several individuals inside Germany, including high-profile politicians. Netzpolitik.org reported in January that dozens of investigative journalists, including from Die Zeit and Correctiv, along with lawyers and civil society members, were also targeted.

Analyst Note: The targeting pattern, covering spyware investigators, investigative journalists, lawyers, and civil society, marks this almost certainly as a Russian intelligence collection operation focused on those who expose Kremlin-linked actors, corroborated across CISA, the UK NCSC, and Dutch intelligence. ApocalypseZ's Russian-language architecture reflects deliberate investment in durable tradecraft: its "snowball" mechanism harvests each compromised account's contact lists to identify the next target tier without fresh operator input, building structural self-expansion into the campaign's design. The 13,500-target figure is a floor; campaign activity continued through May 14 and total exposure is materially larger. A criminal or hacktivist actor using Russian-language tooling for attribution confusion remains a competing read, though convergent government attribution substantially undercuts it.

Sources:

Sandworm Shifts Tactics to Target Pre-Compromised OT Environments After Detection

Nozomi Networks analyzed 5.5 million alerts from 10 industrial organizations across seven countries between July 2025 and January 2026, confirming 29 Sandworm intrusion events and finding the group exploited already-compromised networks via legacy tooling, including EternalBlue, WannaCry, Cobalt Strike, and Log4Shell, rather than zero-day exploits. Every infected system had produced high-confidence warning alerts for between 20 and 155 days before Sandworm activity began, averaging 43 days. Across the dataset, 17 infected machines targeted 923 unique internal systems, with one host probing 405 machines individually. In each affected environment, Sandworm escalated after detection, expanding tooling and shifting focus toward engineering workstations, HMIs, PLCs, and RTUs rather than withdrawing.

Analyst Note: Sandworm's operational model is parasitic rather than pioneering, per Nozomi Networks' single-source telemetry. The group exploited already-compromised OT networks using legacy tooling, with every infected host having generated high-confidence alerts an average of 43 days before intrusion activity, shifting culpability squarely to defender inaction. Post-detection behavior inverts standard incident response assumptions: the group escalated across multiple dimensions, pivoting toward engineering workstations, HMIs, PLCs, and RTUs rather than withdrawing. The escalation pattern may instead reflect automated kill-chain progression rather than deliberate operator-directed decisions. A destructive Industrial Control Systems (ICS) attack outside Ukraine is unlikely within approximately 12 months, but active footholds confirmed across seven countries make the remediation question immediate for NATO OT-ICS defenders.

Sources:

Ghostwriter APT Targets Ukrainian Government With Geofenced PDF Phishing and Cobalt Strike

ESET Research on May 14 attributed new FrostyNeighbor activity since March 2026 to spear-phishing campaigns delivering malicious PDFs that impersonate Ukrainian telecommunications provider Ukrtelecom and target government, military, and defense organizations in Ukraine. The lure PDFs link to an attacker-controlled server that performs a geofencing check, returning a benign decoy to non-Ukrainian connections while delivering a RAR archive containing a JavaScript PicassoLoader downloader to Ukrainian-sourced requests. PicassoLoader fingerprints the compromised host and beacons system data to Command and Control (C2) infrastructure every ten minutes; ESET assessed that operators likely decide manually whether to push a third-stage Cobalt Strike payload based on that data. The Hacker News and Dark Reading corroborated the findings and identified Poland and Lithuania as additional targets with broader sectoral scope.

Analyst Note: Operator-gated Cobalt Strike delivery, held pending manual PicassoLoader fingerprint review, signals FrostyNeighbor is treating Ukrainian government network access as operationally scarce (ESET Research, corroborated by two secondary outlets). That discipline may instead reflect a small team managing its own triage burden rather than elevated targeting doctrine. FrostyNeighbor will likely conduct additional cyberattacks against Ukrainian government entities within the next six months, backed by active Cloudflare-masked C2 and a new PicassoLoader variant. Ukraine operations track a narrow intelligence-collection mandate while Poland and Lithuania campaigns span healthcare, logistics, and manufacturing, a distinct access-accumulation objective. Whether Computer Emergency Response Team (CERT)-UA sustains threat-hunting against the live C2 or reallocates to competing threats turns on which reading holds.

Sources:

Former FSB Colonel Reveals Escape From Russia Hidden in Dead Cow Carcass After Exposing Corruption

Dmitry Senin, a former Federal Security Service of the Russian Federation (FSB) colonel, told The Telegraph on May 14 he escaped Russia in September 2022 inside a dead cow carcass, wrapped in foil to defeat thermal cameras, relying on smugglers to dump the carcass across the Kazakhstan border. Senin says his 2017 flight followed a tip he passed that led to Interior Ministry Colonel Dmitry Zakharchenko's arrest, in which investigators recovered over $120 million in cash; Russian courts convicted him in absentia to nine years in 2023. Austrian judicial records reviewed by The Telegraph tie former intelligence officer Egisto Ott to database searches tracking Senin across Europe; Montenegro refused Russia's extradition request in February 2023, citing political persecution.

Analyst Note: Austrian judicial records corroborate Ott's database searches on Senin across Europe, placing this case, per a single Telegraph interview, inside the Ott-Marsalek network, already tied to surveillance of Christo Grozev and German Gorbuntsov. The coordinated timing of a Monaco Interpol warrant, a false death report, and Ott's 2024 Vienna trial points to active measures: Russia treating European institutions as operational assets, not constraints. Montenegro's extradition refusal shows formal pressure can be resisted, but a GPS tracker on his wife's vehicle confirms Russia operates below that threshold. His claim of no material transfer is unverified; if false, above-top-secret access likely explains the eight-year pursuit, though he may instead be a Western instrument using this account to expose Russian networks.

Sources:

US Intelligence Finds Chinese Companies Discussing Weapons Transfers to Iran Through Intermediaries

Unnamed US officials told the New York Times that US intelligence has gathered information showing Chinese companies and Iranian officials discussed arms transfers, with plans to route shipments through third countries to mask their origin. At least one transit country is in Africa, those officials said; they disagree on whether any weapons have already reached it. The officials added that the discussions were unlikely to have occurred without Chinese government knowledge, though Beijing has not formally approved any transfers. No Chinese weapons appear to have been used against US or Israeli forces since the conflict began in late February.

Analyst Note: Per a single New York Times report on anonymous US officials, China's posture toward Iran has shifted toward structured transfer architecture, with corporate intermediaries and African transit routing built to frustrate attribution. Confirmed Chinese deliveries are unlikely to be publicly reported within 6 months: the obfuscation layer resists attribution, and no Chinese-origin weapons have appeared since late February. Trump officials have signaled reluctance to surface complicating intelligence during the Beijing summit, reinforcing Xi's deniability through corporate-government separation that allows discussions without policy accountability. The discussions may instead reflect commercial positioning: Chinese firms securing leverage without government authorization. Public confirmation would force Treasury and State to impose Iran secondary sanctions on specific Chinese entities, a step withheld to preserve the diplomatic reset.

Sources:

Counterintelligence & Tradecraft

Jury Convicts Lu Jianwang for Operating Secret Chinese Police Outpost in Manhattan

A federal jury in Brooklyn convicted Lu Jianwang, 64, on May 13 of acting as an unauthorized agent of the Chinese government and obstruction of justice. Jurors acquitted him on a related conspiracy count after sending several notes questioning the charge's meaning during roughly eight hours of deliberation. Prosecutors presented text messages between Lu and a Ministry of Public Security handler showing Lu helping to identify U.S.-based dissidents; Lu deleted those messages after the FBI raided his Chinatown office on October 3, 2022. He remains free on bail pending sentencing; his attorney, John Carman, announced plans to appeal and cited what he called multiple trial issues.

Analyst Note: The conviction confirms Ministry of Public Security of the People's Republic of China (MPS) embedded a surveillance node inside a US diaspora organization, assigning dissident-identification tasks from Beijing via WeChat. The split verdict, guilty on agent and obstruction but not conspiracy, narrows the prosecutorial template for network-framing cases and gives the defense a credible appellate foothold. Jurors' conspiracy acquittal reflects the competing view that Lu's office was a mundane operation prosecuted opportunistically. Beijing has strong incentive to deepen concealment now that the trial record is public. Whether law enforcement identifies a second undeclared PRC station within six months is uncertain. If one surfaces, DHS and the FBI face pressure to formalize a detection program; if none does, the administration loses leverage on pending transnational repression legislation.

Sources:

Allied Intelligence

Mossad Chief Held Secret UAE Meetings to Expand Intelligence Sharing During Iran War

The Wall Street Journal, citing Arab officials and a person familiar with the matter, reported Wednesday that Mossad chief David Barnea made at least two covert visits to the UAE in March and April to coordinate with senior Emirati officials on intelligence sharing and missile defense integration during the Iran conflict. Kan News additionally reported that Shin Bet chief David Zini also traveled to the UAE in recent weeks for intelligence and security coordination; neither government confirmed either visit. U.S. Ambassador Mike Huckabee confirmed this week that Israel deployed an Iron Dome battery and operating personnel to the UAE during the conflict to intercept Iranian missiles and drones targeting Emirati territory.

Analyst Note: The Iron Dome deployment, the first overseas use of the system with Israeli operating personnel on foreign soil, alongside covert visits by both intelligence chiefs, reported secondhand across multiple outlets, marks the Israel-UAE relationship as a full operational alliance that no other Abraham Accords state has matched. Riyadh's undisclosed retaliatory strikes show Gulf willingness to act against Tehran, but Saudi deniability exposes the structural gap between ad hoc military action and institutionalized intelligence partnership. Formal expansion to at least one additional Gulf state is unlikely by November 2026. Cooperation may instead prove contingent on Iranian military pressure rather than durable by design, a distinction that determines whether CENTCOM can plan collective regional air defense as unified architecture or must manage costlier bilateral channels.

Sources:

France Investigates Israeli Firm BlackCore for Disinformation Campaign Targeting Municipal Elections

French intelligence agencies are investigating whether BlackCore, an obscure influence firm, ran a disinformation campaign against three France Unbowed candidates ahead of March's elections and who commissioned it, three sources told Reuters. The campaign used deceptive websites, fake social media accounts alleging criminal conduct, and disparaging ads targeting Sébastien Delogu in Marseille, François Piquemal in Toulouse, and David Guiraud in Roubaix. Meta removed the associated account network for "coordinated inauthentic behavior," told Reuters the activity originated in Israel, and linked it to a BlackCore-claimed operation conducted for an African government. Reuters could not locate BlackCore in Israeli corporate records, and the firm's website and LinkedIn page went offline after journalists made inquiries.

Analyst Note: Per a single Reuters report without independent corroboration, French investigators can name BlackCore as executor but have nothing on whoever commissioned the campaign. BlackCore's erasure from registries and the internet removes the clearest investigative path. Meta's Israel-origin linkage establishes geographic provenance, not legal culpability, and is equally consistent with a non-Israeli actor routing the operation through Israeli infrastructure to complicate attribution. France is unlikely to file charges against any individual linked to BlackCore by November 2026, given an unidentified commissioning party and no verifiable legal entity. Whether identifiable defendants emerge before 2027 presidential campaigning begins will determine how urgently Viginum and French legislators expand foreign-interference law.

Sources:

IC Oversight & Authorities

CIA Reportedly Seized JFK and MKUltra Declassification Files From DNI Gabbard Office

CIA whistleblower James Erdmann III testified before the Senate Homeland Security Committee on May 13 that the agency removed 40 boxes of JFK and MKUltra files from ODNI during Gabbard's declassification review and illegally monitored her investigators' communications. NewsNation reported, citing an intelligence official, that the removal occurred last year from the National Reconnaissance Office during the government shutdown and the documents have not been returned. Rep. Anna Paulina Luna (R-FL) gave the CIA 24 hours to return the files or face a subpoena and traveled to CIA headquarters on May 14 with Rep. Eric Burlison (R-MO) to inspect them. A DNI spokeswoman denied a raid had occurred; CIA spokeswoman Liz Lyons dismissed the hearing as "dishonest political theater."

Analyst Note: The removal occurred last year during a government shutdown at the National Reconnaissance Office (NRO), months before Gabbard's review attracted sustained political attention, positioning CIA's move as a pre-existing custody claim, not a response to executive pressure. The agency dismissed sworn Senate testimony as "dishonest political theater" without addressing the substance, per a single Daily Caller report amplified by an ideologically aligned outlet cluster. Congress has invoked subpoena authority, though enforcement against an intelligence agency is unlikely to resolve within the 24-hour window lawmakers set. Whether the 40 boxes contain unreleased records or material CIA considers routine administrative custody remains unknown. The "seizure" framing may reflect legislators seeking institutional leverage rather than evidence of deliberate suppression.

Sources:

Senate FISA Section 702 Three-Year Extension Cloture Motion Withdrawn

The Senate withdrew a cloture motion on the motion to proceed for S.4344, a bill to extend FISA Section 702 surveillance authorities for three years. Section 702, which became Public Law 119-87 on April 30 via S.4465, remains the subject of ongoing legislative activity around the scope of reauthorization and oversight mechanisms.

Analyst Note: The withdrawal, confirmed in three independent official records but uncorroborated by legislative or civil liberties reporting, reflects leadership's failure to secure sixty votes for cloture, compounded by diminished urgency after S.4465 became law on April 30. Leadership may have pulled the motion tactically to negotiate amendment terms before re-filing, leaving S.4344 viable for a later floor attempt. Still, S.4344 passing the Senate by end of August 2026 is unlikely: no public scheduling commitment exists, and the emergency that drove S.4465 is gone. PL 119-87 now governs. A successful reauthorization push would reopen debate on 702's scope and duration before that law expires.

Sources:

HPSCI Chairman Crawford Cites IC Analytic Integrity Failures on COVID-19 Origins

The Senate Homeland Security and Governmental Affairs Committee convened a whistleblower hearing on May 13 on an alleged multi-agency cover-up of COVID-19 origins and gain-of-function research, with Chairman Paul delivering opening remarks. HPSCI Chairman Crawford issued a statement the same day citing a key allegation raised at the hearing: that the CIA refused to comply with ODNI efforts to restore analytic integrity on COVID-19 origins assessments. Crawford said HPSCI has been conducting classified investigations into IC analytic integrity failures and expects to release unclassified findings during this Congress. He also announced ongoing reform work to establish the IC Inspector General as an independent agency separate from the elements it oversees.

Analyst Note: The CIA-ODNI friction Crawford cites constitutes intra-IC insubordination at the most consequential level of the component-agency relationship. Grouping COVID-19 origins with anomalous health incident and Russia cases signals a systemic analytic culture indictment, not isolated reviews. The IC IG reform, reportedly nearing legislative text after a year in development, addresses a conflict of interest whistleblowers cite as the barrier to cooperation and is likely to advance to a bill. Crawford may instead be leveraging unverified whistleblower testimony to generate pressure for reforms already in development. Whether unclassified findings materialize before this Congress expires, with both sources being official committee statements without independent corroboration, tests whether this campaign produces public accountability or stays sequestered.

Sources:

US Intelligence Assesses Iran Retains 70 Percent of Missile Arsenal Despite Administration Claims of Destruction

Classified US intelligence assessments from early May, reported by The New York Times on May 13, show Iran has regained operational access to 30 of its 33 Strait of Hormuz missile sites. Those assessments put Iran's retention of its prewar missile stockpile and mobile launchers at roughly 70 percent and rate 90 percent of its underground launch facilities as partially or fully operational. The Washington Post separately reported consistent figures from US officials; CNN reported Iran can sustain the blockade for up to four months. Gen. Dan Caine declined to confirm or deny the findings in Senate testimony on May 13, citing classification, while Democratic Sen. Chris Murphy stated that private briefings contradict the administration's public claims.

Analyst Note: US commanders, conserving bunker-busters for Asia contingencies, chose to seal facility entrances rather than destroy sites, producing limited degradation at substantial munitions cost, per classified assessments reported by a single primary source and amplified across three outlets. Raw inventory figures may overstate operational readiness if command networks and trained crews are more degraded than stockpile counts suggest. Iran is likely to reconstitute its ballistic missile stockpile to pre-strike levels within 12 months. Blockade endurance projected at four months extends coercive leverage through September, while depleted Tomahawk, Patriot, and precision-strike inventories requiring years to replenish place munitions replenishment ahead of any renewed strike authorization.

Sources:

IC Technology & Surveillance

US Dramatically Increases Intelligence Surveillance Flights Near Cuba Amid Maximum Pressure Campaign

A CNN analysis of FlightRadar24 data shows the US Navy and Air Force have conducted at least 25 intelligence-gathering flights off Cuba since February 4, some within 40 miles of Havana and Santiago de Cuba. The flights used P-8A Poseidon patrol planes, RC-135V Rivet Joint signals-intelligence aircraft, and MQ-4C Triton drones; CNN notes such flights were exceedingly rare off the island before February. Washington imposed additional sanctions on Havana last Thursday; Cuba's foreign minister characterized the measures as "collective punishment of a genocidal nature." Trump said publicly on Friday that an aircraft carrier returning from Iran could be stationed offshore Cuba, while Axios reported that Brazil's President Lula told reporters Trump privately said he has no intention of invading the island.

Analyst Note: The surveillance surge, drawn from open-source flight-tracking data with no independent corroboration, functions as coercive signaling: aircraft capable of masking transponders are flying them hot, making the message the mission. Washington is pairing sanctions and an oil blockade with visible military presence in a dual-track campaign, with Cuban Independence Day on May 20 flagged as the nearest pressure point. Lula's report that Trump privately ruled out invasion sits in unresolved tension with Trump's public carrier-positioning remarks, a gap that likely reflects deliberate strategic ambiguity. The flights may instead reflect opportunistic repositioning from the Iran theater, with public rhetoric serving domestic audiences rather than signaling operational intent.

Sources:

COLLECTION GAPS

UNCLASSIFIED // OPEN SOURCE