← Back to Archive
IC BRIEF
Current as of 1634 EDT (UTC-04), Tuesday 19 May 2026
Contents
8 stories from 32 sources across 29 organizations
KEY JUDGMENTS
Iran and Russia are sustaining multi-domain operations against NATO allies and Western interests that enforcement disrupts at the node level but does not suppress structurally. Western authorities will very likely disclose at least one additional Islamic Revolutionary Guard Corps (IRGC) or proxy operation by year-end 2026. High confidence reflects a monthly-to-quarterly disclosure cadence across Western enforcement agencies. The Europol takedown and Al-Saadi prosecution removed specific operators, but hosting across jurisdictions, cryptocurrency financing, and proxy amplification indicate structural resilience.
Russian intelligence will very likely fabricate additional claims that a Baltic or Nordic NATO member is enabling Ukrainian strikes by year-end 2026. Poland's withdrawal from Signal after Russian Advanced Persistent Threat (APT) campaigns targeted officials' accounts illustrates the parallel cyber track. At least one additional allied government will likely restrict a commercial platform citing state-linked threats in the same period. Moderate confidence reflects uncertainty whether such directives will emerge publicly.
Israeli Attorney General Baharav-Miara will likely retain her office through year-end 2026, preserving prosecution authority over both the Gotliv Shin Bet identity-disclosure case and the Gofman's Mossad appointment. Coalition efforts to bifurcate or vacate her role have stalled on judicial and procedural grounds. An indicator: passage of AG-bifurcation legislation with an immediate-effect clause.
Allied Intelligence
Affidavit Undercuts Legal Challenge to Incoming Mossad Chief Gofman, Paving Way for June Appointment
BLUF: Despite the committee remand delaying a June transition, Gofman will likely take the Mossad's helm by late July, as the affidavit guts the false-testimony allegation underpinning any reversal.
A declassified affidavit from Brig. Gen. "G" states that when he questioned Gofman in May 2022, neither man knew Elmakayes's identity and the name never came up in the conversation 12. According to the filing, "G" asked only whether anyone in Gofman's division had transferred classified material to Telegram channels; Gofman denied it and stated the division's influence work relied solely on open-source material 2. The High Court on Monday ordered Attorney General Baharav-Miara to share the document with Netanyahu and Gofman; Netanyahu then asked the court to dismiss the petitions, citing "no blemish" in Gofman's conduct 13. In an interim ruling on Tuesday, the court found the advisory committee's examination "lacking" and directed it to hear directly from Elmakayes and "G" and submit updated findings by May 26 4.
Analyst Note: Corroborated across Jerusalem Post, Times of Israel, and Yeshiva World, the affidavit removes the evidentiary foundation for any blocking reversal, and the High Court's parallel rejection of Shin Bet petitions provides direct precedent. The court's finding that the committee's examination was lacking bounds procedural risk to the May 26 hearing, the ruling that pushed the timeline past June 2. Testimony from Elmakayes and "G" could still produce a record that materially alters what Gofman knew, sustaining the petitions. Gofman is likely to lead the Mossad by July 31, 2026, requiring intelligence partners to plan for a liaison transition extending into July rather than a clean handover under Barnea this month.
Sources:
1: Gofman likely to helm Mossad after affidavit appears to undercut claims against him - Times of Israel
2: Declassified affidavit says Gofman denied approving intel. material transfer to Telegram channels - The Jerusalem Post
3: Major Blow to Attorney General: Contents of Secret Affidavit in Mossad Appointment Battle Revealed - The Yeshiva World
4: Mossad appointment controversy: Court orders advisory c'tee reconvene, missed critical information - The Jerusalem Post
Israel Indicts Likud MK Gotliv for Disclosing Shin Bet Officers Identity in Violation of Security Service Law
BLUF: Whether the House Committee recommends immunity for Gotliv by end of 2026 is genuinely uncertain, but a coalition vote to shield her would sharpen the government's institutional confrontation with the attorney general.
Attorney General Gali Baharav-Miara filed the indictment Tuesday, charging Gotliv under the Shin Bet Law's prohibition on revealing service employees' identities 12. The Jerusalem Post's account of the filing states that on January 24, 2024, Gotliv posted on X a screenshot naming protest leader Shikma Bressler's partner as a Shin Bet employee; the post drew over 400,000 views and was never removed 3. Defense Minister Israel Katz signed the required confidentiality certificate earlier this month; JFeed, citing Israeli broadcast reports, said Katz acted after the Shin Bet warned that withholding it could harm national security 4. The indictment was forwarded under parliamentary procedure to Speaker Amir Ohana and the House Committee, and Education Minister Yoav Kisch along with coalition MKs publicly called for immunity to be granted before criminal proceedings can continue 23.
Analyst Note: With the indictment forwarded to the House Committee, the coalition majority is now the decisive variable. Whether it recommends immunity by end of 2026 is genuinely uncertain; coalition intent is visible in public calls from Kisch and others, corroborated across ideologically opposed outlets. Granting immunity deepens the confrontation with the attorney general and compounds pressure from concurrent judicial reform; that assessment carries moderate confidence. The case's coincidence with legislation bifurcating Baharav-Miara's role suggests she may be accelerating sensitive proceedings to constrain her potential successor before reform takes effect. An immunity vote forces coalition managers to decide how broadly to extend parliamentary protection; denial accelerates movement on her removal.
Sources:
1: Israel Indicts Likud Lawmaker Gotliv for Disclosing Shin Bet Officer's Identity - Haaretz
2: AG announces indictment against MK Tally Gotliv - Israel National News (Arutz Sheva)
3: A-G files indictment against MK Gotliv over alleged disclosure of Shin Bet employees identity - The Jerusalem Post
4: Shin Bet Case Against Tali Gottlieb Moves Forward - JFeed
Poland Orders Officials Off Signal After Russian APT Groups Target Government Accounts
BLUF: Poland's retreat to sovereign platforms signals other NATO members will likely follow, trading the security assurance of audited commercial encryption for state-controlled account provisioning whenever Russian intelligence targets officials directly.
Poland's Government Plenipotentiary for Cybersecurity on May 14, under Deputy Prime Minister Krzysztof Gawkowski's signature, directed National Cybersecurity System entities to abandon Signal for two domestic platforms: mSzyfr, managed by Research and Academic Computer Network - National Research Institute (Poland) (NASK-PIB), and SKR-Z for classified communications 12. National Computer Security Incident Response Team (CSIRT) teams identified active phishing campaigns by APT groups the advisory attributes to hostile foreign intelligence services, targeting politicians, military personnel, and government employees 12; Security Affairs reported officials specifically tie the campaigns to Russian-backed actors 3. The advisory states Signal's encryption was not broken; attackers impersonated support staff to harvest verification codes and PINs, or deployed malicious QR codes to silently link attacker-controlled devices to victim accounts 23. mSzyfr replaces Threema, Poland's recommended platform since 2022, and operates entirely within Polish jurisdiction 32.
Analyst Note: The attack vector exploited account-management features, specifically credential harvesting via impersonated support staff and malicious QR codes that silently linked attacker devices, not cryptographic weakness in Signal. Per official Polish Ministry of Digitization publications, mSzyfr's closed-enrollment, Polish-hosted model transfers account-provisioning and revocation authority to Warsaw in ways Signal's architecture cannot provide, reflecting a broader European preference for sovereign infrastructure over audit transparency. Replacing Threema marks the operational ceiling of official tolerance for commercially managed platforms under active state-linked targeting. Warsaw's institutional drive for sovereign communications may predate the APT campaigns, with the advisory furnishing political leverage rather than generating a new operational trigger.
Sources:
1: Recommendation of the Government Plenipotentiary for Cybersecurity regarding the Signal messenger - Polish Ministry of Digitization (gov.pl)
2: Poland urges officials to ditch Signal for state-run messaging apps - CyberInsider
3: Poland shifts away from Signal following cyberattacks on officials accounts - Security Affairs
Adversary Intelligence
Russias SVR Claims Ukraine Deploying Drone Units to Five Latvian Military Bases, Threatens Retribution Against NATO Ally
BLUF: Independent corroboration of the Foreign Intelligence Service of Russia (SVR)'s Latvian basing claim is very unlikely before 19 August 2026, marking this as a Russian pretext-building operation to pre-justify strikes against NATO territory.
Russia's SVR on Tuesday alleged that Ukrainian Unmanned Systems Forces have already deployed to five Latvian military bases, naming Adazi, Selija, Lielvarde, Daugavpils, and Jekabpils 1234. The agency's statement claimed Ukraine persuaded Latvia to agree by falsely arguing that drone launch sites could not be pinpointed with precision, while warning that Latvia's NATO membership "will not protect the accomplices of terrorists from just retribution" 2314. Latvian Foreign Minister Baiba Braže rejected the claim as "a disinformation campaign," President Edgars Rinkevics denied that Latvia had permitted its airspace or territory to be used for strikes against Russia, and Prime Minister Evika Siliņa stated Riga had "never given Ukraine permission to use its territory or airspace for defensive strikes against Russia or any other country" 314. Ukraine's Defense Ministry spokesman Georgy Tikhy separately dismissed the SVR statement as "false" 1.
Analyst Note: Independent corroboration of the Latvian basing claim is very unlikely before 19 August 2026. The allegation originates solely from the SVR Press Bureau, amplified by four secondary outlets without original reporting, and no allied, NGO, or signals source has placed Ukrainian drone operators in Latvia. Naming specific bases lends surface plausibility to a documented Russian pattern of manufacturing NATO complicity narratives to pre-justify retaliatory action. The claim more plausibly functions as escalation signaling calibrated to pressure Latvia into restricting Ukrainian military access to Baltic infrastructure than as a disclosure of genuine basing intelligence. Should it gain allied traction, NATO defense ministers face immediate pressure to restrict that access; current force posture holds only while allied intelligence silence persists.
Sources:
1: Ukraine preparing strikes on Russia from Latvian territory – Moscow - RT
2: Russias Spy Agency Claims Ukraine Plans to Launch Drone Attacks From Latvia - The Moscow Times
3: Russia's Foreign Intelligence Service claims Ukraine is planning to launch drones from Latvian territory. 'Russia lies again,' Riga responds. - Meduza
4: Russia's spy agency accuses Latvia of aiding Ukrainian drone strikes amid rising Baltic tensions - WION
Russia to respond to aggression as Kiev plans to launch drones from Latvia — intel agency - TASS
Europol-Led Operation Dismantles IRGC Online Propaganda Network Across 19 Countries, Removes 14,200 Links
BLUF: Europol's takedown removed visible nodes but left the IRGC's resilient architecture intact, since Russian-hosted infrastructure and AI-generated content let the network outpace referral-based suppression that depends on voluntary platform cooperation.
Europol's EU Internet Referral Unit ran a 19-country operation from February 13 to April 28, referring approximately 14,200 IRGC-linked posts, accounts, and links for removal from social media platforms, streaming services, and standalone websites 12. The operation also secured restriction of the IRGC's primary X account, which had accumulated over 150,000 followers, following the EU's February 19 terrorist designation of the group 2. Removed content spanned six languages and included AI-generated videos glorifying the IRGC, and investigators traced the network's reach into proxy groups including Hezbollah and Hamas 1. Europol found the network relied on hosting providers across multiple jurisdictions, including Russia and the United States, and used cryptocurrency transactions to sustain its online operations 12.
Analyst Note: The structural ceiling on this operation is Russian-hosted infrastructure that EU legal process cannot compel, with cryptocurrency financing evading sanctions monitoring and proxy amplification through Hezbollah and Hamas routing around platform-level enforcement. Voluntary cooperation from platforms operating under EU jurisdiction is the binding constraint on sustained suppression. AI-generated production can replenish removed material faster than referral operations clear it. Per a single Europol press release with no independent corroboration, the 14,200 referrals and X account restriction may represent a designation-timed enforcement signal calibrated for European publics rather than a capability sufficient to degrade IRGC online reach in any durable way. The network architecture persists.
Sources:
1: Europol dismantles IRGC-linked online propaganda network, removes 14,200 links across digital platforms - Industrial Cyber
2: Europol disrupts thousands of IRGC online accounts across 19 countries - Euronews
EU targets Iran's Revolutionary Guard propaganda ecosystem in an online crackdown – Investigators identified 14 200 links tied to IRGC activity - Europol
North Korean Kimsuky Group Targets Defense Officials and Recruiters in Four Spear-Phishing Campaigns
BLUF: By routing Command and Control (C2) through GitHub, Visual Studio Code (VSCode) tunnels, and Microsoft's CDN, Kimsuky has effectively neutralized reputation-based defenses, forcing South Korean defense organizations toward behavioral detection or accepting sustained, targeted intelligence loss.
Logpresso's May 15 report identified four Kimsuky spear-phishing campaigns in Q1 2026, each with distinct lures targeting South Korean defense officials, foreign military attachés, cryptocurrency developers, corporate recruiters, and public sector employees
12. Three campaigns embedded payloads in oversized Windows shortcut file format (LNK) files disguised as PDFs; the fourth delivered JavaScript Encoded file (JSE) scripts that decoded a reconnaissance DLL via certutil and rundll32, then established remote access by downloading a Microsoft-signed VSCode binary and tunneling through GitHub OAuth
12. Campaign 2 hosted payloads and received exfiltrated system data through a GitHub repository, and Campaign 3 generated Media Access Control (MAC)-address-keyed payloads from 103.67.196.25, restricting final-stage code delivery to pre-identified machines
12. Lure documents varied by campaign: Campaign 1 used resumes, business cards, and medical forms; Campaign 2 mimicked fake Solana security tool documentation; Campaign 3 used military competition materials; and Campaign 4 disguised payloads as graduate school training documents
2. Post-compromise C2 traffic was additionally routed through nelark[.]icu and yespp[.]co[.]kr alongside the GitHub and VSCode tunnel infrastructure
2.
Analyst Note: Per Logpresso alone with no independent corroboration, GitHub repositories, VSCode OAuth tunnels, and Microsoft CDN channels generate C2 traffic indistinguishable from routine developer activity, voiding the reputation-based perimeter controls most South Korean defense organizations deploy. Campaign 3's MAC-address-keyed payload delivery confirms pre-operational reconnaissance against named individuals, including foreign military attachés: deliberate intelligence collection, not opportunistic credential harvesting. Rapid infrastructure rotation across all four campaigns renders Indicator of Compromise (IOC)-based blocking insufficient, requiring defenders to shift to behavioral detection centered on process relationships and scheduled task anomalies. Separate DPRK units sharing a common toolkit would equally explain the divergent C2 infrastructure and absent cross-campaign IOC overlap.
Sources:
1: 2026년 1분기 DPRK Operation Kimsuky 분석 (2026 Q1 DPRK Operation Kimsuky Analysis) - Logpresso
2: Kimsuky Uses LNK, JSE Lures to Target Recruiters, Crypto Users, Defense Officials - GBHackers
Counterintelligence & Tradecraft
US Charges Kataib Hezbollah Commander with Directing 18 Attacks on Jewish Targets Across Europe, Plotting NYC Synagogue Attack
BLUF: Despite the strong case, Turkey is unlikely to formalize Al-Saadi's handover via extradition within the year, exposing the prosecution to jurisdictional challenges while the surviving Islamic Revolutionary Guard Corps-Quds Force (IRGC-Quds Force (QF)) architecture continues directing attacks on Western Jewish targets.
Federal prosecutors in Manhattan on Friday charged Iraqi national Mohammad Baqer Saad Dawood Al-Saadi with directing at least 18 attacks on Jewish and American targets across Europe and Canada and coordinating a US campaign targeting a New York City synagogue and Jewish centers in Los Angeles and Scottsdale, Arizona 12. The complaint alleges he ran both operations through a Kataib Hezbollah front called Harakat Ashab al-Yamin al-Islamiya 12. Al-Saadi faces six counts including conspiracy to provide material support to Kataib Hezbollah and the IRGC and conspiracy to bomb a place of public use 12. The complaint further alleges Al-Saadi agreed to pay an undercover officer posing as a Mexican cartel member $10,000 to set all three US sites ablaze simultaneously, advancing approximately $3,000 in cryptocurrency before his arrest in Turkey 12. Prosecutors also allege he maintained close ties to senior IRGC-Quds Force commanders, including the late Qasem Soleimani and current QF leader Esmail Qaani 12.
Analyst Note: Turkey is unlikely to ratify the informal handover through extradition within the next year; informal transfers are not retroactively formalized, and Ankara has little incentive to revisit what it already achieved, leaving prosecution exposed to jurisdictional challenges defense has signaled it will press. The filings, grounded in a single Department of Justice (DOJ) complaint with secondary outlets corroborating rather than independently collecting, confirm Al-Saadi directed parallel US homeland plots and advanced cryptocurrency payment before arrest, a delta from prior Europe- and Canada-focused reporting. His ties to Qaani indicate the IRGC-QF external operations architecture survives intact. IRGC-QF may have treated him as expendable, having replaced his operational function before the arrest could unravel the network.
Sources:
1: The Iran-Backed Militia Behind a Terror Plot Against American Jews - Time
2: Iraqi militant leader 'directed and urged' attacks on Americans and Jews over Iran war, feds say - CNN
Iraqi National Arrested and Charged with Providing Material Support to Iranian-Backed Terrorist Organizations and Directing Attacks Targeting U.S. Citizens and Interests - U.S. Department of Justice, Office of Public Affairs
IC Technology & Surveillance
DARPA Solicits DISCORD Program to Build AI-Native Tactical Decision Engine for Commanders
BLUF: Whether Defense Advanced Research Projects Agency (DARPA) awards a Disruption through Intelligent Strategies, Counter Options, and Resilient Defenses (DISCORD) contract by year-end 2026 is genuinely uncertain, but the solicitation already forces defense AI firms to commit proposal resources or surrender competitive position.
DARPA posted the DISCORD solicitation on May 15, seeking proposals to develop an AI-native decision engine that generates diverse tactical strategy portfolios for commanders from live sensor data and high-fidelity simulation 12. The solicitation specifies explainability as a design requirement, enabling human operators to validate AI-generated options 1. The 24-month program runs two 12-month phases; a Proposers Day under Special Notice DARPA-SN-26-60 closed April 28, and full proposals are due July 9 123. DISCORD implements Ender's Foundry, one of the Department of War's warfighting Pace-Setting Projects, drawing on AI-driven edge-compute simulation, model-predictive control, and game theory 12.
Analyst Note: A year-end 2026 DISCORD award is genuinely uncertain: DARPA's evaluation-to-selection typically runs three to six months past the July 9 deadline, and explainability requirements narrow the viable performer pool even as the Pace-Setting designation presses for faster selection. Per the single originating SAM.gov solicitation, trade outlets repackage rather than independently report. DARPA may be building a capability-maturity baseline rather than a near-term fielded system, given requirements spanning game theory, edge-compute simulation, and real-time sensor fusion. A year-end award gives winning firms early-mover advantage in Phase 2; absent one, program advocates must defend DISCORD's pace against competing AI acquisition priorities in the next budget cycle.
Sources:
1: DARPA releases DISCORD solicitation - Intelligence Community News
2: Disruption through Intelligent Strategies, Counter Options, and Resilient Defenses (DISCORD) - SAM.gov (official US government)
3: Disruption through Intelligent Strategies Counter Options and Resilient Defenses (DISCORD) - HigherGov
Proposers Day: DISCORD - DARPA.mil
DARPA AI-Native Tactics Engine and Simulation Development - DARPA-SN-26-60 - G2Xchange
COLLECTION GAPS
- Chinese intelligence operations, including MSS cyber espionage campaigns and technology-transfer recruitment targeting Western firms.
- FISA Section 702 reauthorization status and broader surveillance authority developments during active congressional debate.
- Five Eyes and European partner service reorganizations, personnel changes, and intelligence-sharing agreements.
- US IC workforce developments, including clearance backlogs, hiring freezes, and personnel attrition from ongoing federal restructuring.
- NRO, NGA, and NSA acquisition programs and technology procurement developments beyond DARPA.