← Back to Archive
IC BRIEF
Current as of 1725 EDT (UTC-04), Saturday 23 May 2026
Contents
9 stories from 40 sources across 37 organizations
KEY JUDGMENTS
The Islamic Revolutionary Guard Corps (IRGC)'s consolidation of authority under Ahmad Vahidi has restructured Iran's negotiating architecture, displacing the civilian diplomatic channels through which the April Pakistan ceasefire round was conducted. A public Vahidi appearance is unlikely before the end of August, leaving Washington without a verifiable counterpart capable of binding Tehran to terms. Separately, whether the White House's $9 billion intelligence chip acquisition plan and NSA-Anthropic classified contract finalize by September 30 is genuinely uncertain.
Convergent AP and regional reporting places Vahidi as the primary Iranian ceasefire contact after Parliament Speaker Ghalibaf faced internal criticism over the April round. A classified EU dossier independently names active IRGC officers posted under diplomatic cover across European capitals, corroborating Guards' dominance beyond the bilateral track. Moderate confidence rests on these independent streams. Unresolved disputes between the Pentagon and White House over AI use authority constrain the Anthropic procurement.
A verifiable Vahidi public appearance or an IRGC counterproposal routed through military channels would challenge the assessment that Guards' consolidation forecloses ceasefire progress. Congressional appropriation of the $9 billion chip request before August recess would resolve the IC's AI access timeline.
Adversary Intelligence
Classified Dossier Reveals IRGC Officers Operating in EU Under Diplomatic Cover
BLUF: Despite damning allegations, formal expulsion of any named Iranian attaché remains unlikely before year-end 2026, leaving IRGC officers entrenched under diplomatic cover while EU capitals prioritize fragile negotiating channels over enforcement.
A classified dossier seen by Euractiv alleges that Iranian military attachés posted across EU capitals are active IRGC officers operating under diplomatic cover 12, creating a direct contradiction with the EU's February 19, 2026 formal designation of the IRGC as a terrorist organization under Council Decision (CFSP) 2026/421. The document names Mohammad Naghizadeh, Iran's military attaché in Poland, as an active IRGC member and recommends sanctions and expulsions targeting Iranian attachés and diplomats linked to the organization 12. The dossier further alleges that IRGC commander Ahmad Vahidi now serves as Iran's de facto decision-maker following Khamenei's death, with the Guards controlling the security apparatus, parliament, and strategic negotiations with Washington 13. German Member of European Parliament (MEP) Hannah Neumann warned Wednesday that IRGC networks remain "up and running in some member states" 2.
Analyst Note: Formal expulsion of any named Iranian military attaché is unlikely before year-end 2026: several EU capitals have signaled reluctance to foreclose diplomatic channels, and structural incentives have shielded accredited Iranian military personnel from formal action. The concurrent claim that IRGC commander Vahidi now functions as Tehran's de facto decision-maker, if accurate, means nuclear negotiations and proxy posture reflect Guards priorities rather than foreign ministry pragmatism, compounding the stakes of EU inaction. Moderate confidence rests on a single classified document seen by one outlet, uncorroborated by signals intelligence or independent governmental confirmation. The dossier may instead reflect Iranian opposition-in-exile sourcing or a single allied service seeking to accelerate EU action. Should at least one expulsion occur, EU foreign ministers gain precedent for coordinated bloc-wide action; absent that, Tehran can credibly treat the February designation as a legal formality without operational consequence.
Sources:
1: Exclusive: Suspected IRGC operatives retain diplomatic cover in EU - Euractiv
2: Dossier: Suspected Terrorists Working in EU Under Diplomatic Cover - European Conservative
3: Suspected IRGC operatives retain diplomatic cover in EU - Maryland Coordination and Analysis Center (MCAC)
Russian SIGINT Ship Yuri Ivanov Tracks NATO Submarine Warfare Exercise in Norwegian Sea
BLUF: Moscow's pairing of SIGINT collection with strategic-force signaling reflects a maturing High North playbook that NATO's public call-outs document but cannot disrupt mid-collection.
NATO Maritime Command posted imagery on May 21 showing Portuguese frigate NRP Dom Francisco de Almeida and a Royal Navy Merlin Mk2 helicopter from HMS Prince of Wales monitoring Yuri Ivanov as it loitered near Exercise Dynamic Mongoose in the Norwegian Sea 12. The UK Defence Journal reported a UK Carrier Strike Group Type 45 destroyer also operating in close proximity, describing the combined effort as a joint operation with Standing NATO Maritime Group 1 3. Dynamic Mongoose, running through May 29 under NATO Maritime Command (MARCOM) and host-nation Norway, involves submarines, surface vessels, and maritime patrol aircraft from nine nations in anti-submarine warfare training 1. Russia concurrently concluded a three-day nuclear exercise with ballistic and cruise missile launches in the Barents Sea, per The Barents Observer and the UK Defence Journal 23.
Analyst Note: Russia's concurrent deployment of Yuri Ivanov alongside a three-day Barents ballistic and cruise missile exercise indicates a deliberate dual-track operation. The ship was positioned to harvest submarine acoustic signatures, communication procedures, and sensor employment data from nine NATO nations while Moscow staged a visible strategic-force demonstration. Norwegian Joint Headquarters' confirmation of daily surveillance flights over the Norwegian Sea earlier in May places this within an accelerating High North reconnaissance pattern. Confidence is constrained to what NATO chose to disclose, as all reporting traces to a single NATO MARCOM social media post with no independent government or signals-intelligence corroboration. The Barents exercise and Yuri Ivanov's patrol nonetheless fall within established Northern Fleet seasonal rhythms, consistent with coincident rather than orchestrated timing.
Sources:
1: Russian Surveillance Ship Spotted Near NATO Sub Drills - USNI News
2: Yuri is watching - The Barents Observer
3: British carrier group encounters Russian spy ship - UK Defence Journal
Royal Navy Monitors Russian Spy Ship Loitering Near NATO Exercise - The Maritime Executive
IRGC Chief Ahmad Vahidi, Former Quds Force Commander, Consolidates Power as Key Broker in Iran-US Ceasefire Talks
BLUF: Vahidi is unlikely to surface publicly before September 2026, leaving Washington negotiating ceasefire terms with an unseen IRGC interlocutor whose hardening line on Highly Enriched Uranium (HEU) retention forecloses foreign ministry compromise.
IRGC Commander Brig. Gen. Ahmad Vahidi has become the primary Iranian contact in ceasefire talks with the United States, a regional official with direct knowledge of the mediation told AP 123. April talks in Pakistan, led by Parliament Speaker Ghalibaf for Iran and Vice President Vance for the US, ended without a deal; Ghalibaf and Foreign Minister Araghchi returned home to internal criticism for excessive concessions 13. The Washington-based Institute for the Study of War assessed that Vahidi and his inner circle have "likely consolidated control" over Iran's military conduct and negotiations policy 134. Vahidi has not appeared publicly since February 8; Iranian media on Thursday carried contradictory reports on whether he met with Pakistan's interior minister in Tehran 132.
Analyst Note: Vahidi is unlikely to make a publicly verifiable appearance by the end of August 2026, and his concealment compounds U.S. difficulty in identifying an authoritative interlocutor. The IRGC's displacement of parliamentary and foreign ministry channels signals Tehran's red lines on HEU retention are hardening. If the EU classified dossier naming Vahidi as de facto post-Khamenei decision-maker is accurate, ceasefire terms require IRGC institutional buy-in that foreign ministry negotiation cannot deliver. Vahidi may instead shield a more diffuse decision-making body, his prominence a negotiating facade rather than binding authority. Moderate confidence rests on convergent reporting from credibly placed regional sources, limited to two primary reporting lines, with Vahidi's physical condition and command authority invisible to open-source collection. Whether he appears publicly determines whether U.S. negotiators have a binding counterpart at all.
Sources:
1: This hard-line Iranian general is a major player in talks with US over war - Associated Press (via ABC News)
2: IRGC chief Ahmad Vahidi emerges as key power broker as Iran-US talks hang in balance - Shabtab News
3: IRGC chief Ahmad Vahidi emerges as key power broker as Iran-US talks hang in balance - Al Arabiya English
4: U.S. Think Tank: Ahmad Vahidi, Key Figure Behind Iran's Hardline Stance in Negotiations - IranWire
Lumen Black Lotus Labs Exposes Chinese Showboat Malware Family Targeting Middle East Telecom Providers Since 2022
BLUF: Three years of undetected access to regional telecom backbones gives Beijing a pre-positioned espionage platform whose true victim count almost certainly exceeds the handful confirmed so far.
Lumen Black Lotus Labs on May 21 disclosed
Showboat, a previously unreported Linux malware framework targeting telecommunications providers since at least mid-2022, with remote shell access, file transfer, and Socket Secure version 5 (SOCKS5) proxy capabilities; the malware registered zero detections on VirusTotal when first submitted and reportedly remained undetected through April 2026
12. Black Lotus correlated C2 nodes to Chengdu-geolocated IP addresses, including one resolving to China Unicom, and attributed the tooling to at least one, and likely several, PRC-aligned clusters observed sharing the tool across dissimilar targets; The Hacker News and BleepingComputer identify Calypso, also tracked as Red Lamassu and assessed as likely operating out of Sichuan Province, as one such actor
123. Confirmed victims include an Afghanistan-based ISP and an Azerbaijani entity, with secondary C2 analysis surfacing possible compromises in the United States and Ukraine
12. PwC Threat Intelligence, in a coordinated release with Black Lotus, documented a companion Windows implant called JFMBackdoor deployed via Dynamic Link Library (DLL) side-loading against telecommunications targets in Afghanistan, with capabilities including remote shell, file system operations, network proxying, screenshot capture, and self-removal
234.
Analyst Note: Telecom operators across Central Asia and the Middle East are running infrastructure that PRC-aligned actors have weaponized as lateral movement platforms for at least three years. SOCKS5 and portmapping capabilities turn a single infected host into a pivot into internal network segments, leaving downstream customers and peering partners with inherited exposure invisible to their own teams. A Chengdu-geolocated C2 resolving to China Unicom and coordinated deployment of Windows implant JFMBackdoor point to deliberate dual-platform tradecraft. With no independent corroboration of Black Lotus's findings, Showboat may be a contracted or underground-market framework independently adopted by multiple actors rather than a state-directed capability with unified tasking. Secondary C2 analysis places suspected compromises in the United States and Ukraine.
Sources:
1: Introducing Showboat: A new malware family taunts defenses and targets international telecom firms - Lumen Black Lotus Labs
2: Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor - The Hacker News
3: Chinese hackers target telcos with new Linux, Windows malware - BleepingComputer
4: New 'Showboat' malware tied to China-linked telecom espionage - CyberNews
Belarus-Linked Ghostwriter Group Launches OysterFresh Campaign Against Ukrainian Government Using Prometheus Platform Lures
BLUF: Belarus is investing in durable espionage access inside Ukrainian government networks, with the dual lures and geo-filtered delivery signaling a deliberate effort to outpace Computer Emergency Response Team of Ukraine (CERT-UA)'s detection and remediation.
CERT-UA reported this week that Ghostwriter (UAC-0057, UNC1151) has been phishing Ukrainian government organizations since spring 2026, using emails from compromised accounts that impersonate Prometheus, a Ukrainian online learning platform used by government employees 123. The emails deliver PDF attachments linking to a ZIP archive containing OYSTERFRESH, a JavaScript file that drops an obfuscated payload (OYSTERBLUES) into the Windows Registry and loads a decoder component (OYSTERSHUCK) 12. OYSTERBLUES harvests system fingerprint data and transmits it to Cloudflare-shielded C2 servers on .icu domains, with CERT-UA assessing Cobalt Strike as the final payload 13. ESET Research separately documented FrostyNeighbor activity from March 2026 using a Ukrtelecom-themed lure and a JavaScript PicassoLoader variant, with server-side IP validation delivering the malicious archive only to Ukrainian-geolocated systems 4. ESET further identified concurrent FrostyNeighbor targeting of Poland and Lithuania, where victimology extends beyond military and government to industrial, manufacturing, healthcare, pharmaceuticals, and logistics sectors 4.
Analyst Note: The convergence of two Ghostwriter chains on Cobalt Strike indicates Belarus state intelligence pursuing persistent access inside Ukrainian government networks rather than episodic disruption. The Prometheus lure exploits a platform government employees genuinely use, raising click rates above generic phishing, while FrostyNeighbor's server-side IP geo-filtering defeats sandbox detonation and slows detection timelines. CERT-UA's wscript.exe restriction addresses the OYSTERFRESH delivery chain but leaves the FrostyNeighbor RAR-delivered JavaScript variant requiring separate detection logic. The overlap could equally reflect two independent Belarusian collection cells updating existing toolkits rather than centrally directed intensification. ESET Research is the sole primary source; secondary outlets amplify without independent collection.
Sources:
1: Ghostwriter Is Back, Using a Ukrainian Learning Platform as Bait to Hit Government Targets - Security Affairs
2: Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware - The Hacker News
3: Belarus-linked hackers use fake training certificates to target Ukrainian officials - The Record from Recorded Future News
4: Belarus-aligned FrostyNeighbor attacks Ukrainian government, again — ESET Research discovers
Точковий сплеск активності UAC-0057 (CERT-UA#10340)
FrostyNeighbor: Fresh mischief and digital shenanigans - ESET Research (WeLiveSecurity)
IC Technology & Surveillance
Pentagon and AARO Release Second PURSUE Tranche with Declassified Lake Huron 2023 UAP Shootdown Footage Assessed as Likely Balloon
BLUF: All-domain Anomaly Resolution Office (AARO)'s acknowledgment that responsive records lack substantiated chain of custody, not the routine balloon identification, is the disclosure most likely to erode congressional confidence in the Presidential Unsealing and Reporting System for Unidentified Anomalous Phenomena (UAP) Encounters (PURSUE) archive's integrity.
The Department of War on May 22 released a 46-second infrared video of the February 12, 2023 Lake Huron shootdown as part of the second PURSUE tranche 123. AARO describes the object as roughly spherical with cable-like material beneath it that fragments on impact in a radial displacement pattern consistent with balloon behavior; official documentation retains its unidentified status 123. The footage was retrieved from a classified network following a March 6, 2026 request from eight House members for 51 UAP-related records, with AARO noting that many items in the collection lack a substantiated chain of custody 23. Canadian authorities associated March 2023 shoreline debris with commercial weather-monitoring equipment; a redacted Royal Canadian Air Force (RCAF) report obtained by CTV News separately suggested a National Weather Service balloon from Michigan as the probable source 2.
Analyst Note: Convergent physical indicators, including radial fragmentation, spherical profile, dangling cable structure, and shoreline debris linked to commercial weather-monitoring equipment, place the Lake Huron object firmly in the benign-balloon category. The infrared footage is the first visual confirmation of pilot assessments made at the time of engagement, with broad outlet corroboration grounded in the single PURSUE release. AARO's admission that materials in the responsive collection lack a substantiated chain of custody is the more consequential disclosure, raising questions about the archive's integrity and its credibility with Congress. That caveat also leaves open the possibility that the footage is not authenticated as the Lake Huron engagement at all.
Sources:
1: Pentagon Releases Declassified Lake Huron Footage Suggesting 2023 UAP Shootdown Target Was Likely a Balloon - The Defense News
2: We Finally See The Mysterious Object Shot Down By F-16s Over Lake Huron - The War Zone
3: Pentagon Finally Releases Footage Of Unidentified Object Shot Down By F-16 Over Lake Huron - The Aviationist
Presidential Unsealing and Reporting System for UAP Encounters (PURSUE) - Department of Defense / PURSUE Portal
UFO Files: Department of Defense Releases Second Batch of Records - Newsweek
White House Backs Nine Billion Dollar Chip Plan and Anthropic Deal to Keep CIA and NSA at AI Frontier
BLUF: By prioritizing AI speed over procurement security, the White House has cleared bureaucratic hurdles, but a formally executed NSA-Anthropic contract by September 30, 2026 remains genuinely uncertain given unresolved use-authority and data disputes.
The New York Times, citing current and former U.S. officials, reported May 22 that the White House approved a secret $9 billion request to acquire Nvidia Grace Blackwell chips for intelligence agencies while reprogramming $800 million for near-term computing, pending congressional approval 12. White House Chief of Staff Susie Wiles separately authorized the NSA to continue using Anthropic's AI despite the Pentagon's designation of the company as a supply chain threat 12. The government and Anthropic are finalizing a classified contract for NSA access to Anthropic's Mythos model 123. The contract will include a carve-out barring use on Americans' data and will omit the Defense Department's earlier demand for authority to employ the technology for "any lawful use" 12.
Analyst Note: The White House has traded procurement security discipline for operational AI speed, but a formally executed NSA-Anthropic contract by September 30, 2026 is genuinely uncertain. Wiles's override cleared a bureaucratic barrier, but unresolved disputes over use authority and data restrictions impose structural constraints that classified acquisition timelines routinely extend. Analytic confidence is moderate, grounded in direct official sourcing via The New York Times and The Information, though finalization depends on deliberations outside the open-source record. The Pentagon's supply chain designation may reflect a substantive counterintelligence concern rather than bureaucratic friction, making the override a trade of near-term capability for uncharacterized supply-chain risk. A closed contract would establish a template the White House intends to replicate with other vendors and pull forward a parallel NSA-OpenAI negotiation. Failure leaves intelligence agencies capacity-constrained through the next fiscal planning cycle.
Sources:
1: White House Approves $9 Billion for Spy Agencies to Catch Up on AI - GV Wire
2: White House clears $9B for spy agencies' AI chips - Arkansas Democrat-Gazette
3: White House, Anthropic Near Deal For Spy Agencies to Use AI - The Information
White House Approves $9 Billion for Spy Agencies to Catch Up on A.I. - The New York Times
White House backs $9 billion chip plan and Anthropic deal to keep spy agencies at AI frontier - Crypto Briefing
Operations & Tradecraft
CIA Director Ratcliffe Brought Maduro Capture Operative to Cuba Meeting as Warning to Regime
BLUF: Ratcliffe's naming of the Maduro operative escalates pressure beyond rhetoric, but whether Havana yields a verifiable concession by year-end 2026 remains genuinely uncertain given Cuba's demonstrated tolerance for coercive signaling.
CIA Director John Ratcliffe brought a paramilitary operative involved in the January Maduro capture to his meeting with senior Cuban officials in Havana the week of May 14, multiple sources told CBS News 12. Ratcliffe introduced the operative as "the one who killed your people in Venezuela," those sources said; Cuba has reported 32 of its military and police officers died in the Maduro operation 12. Cuban attendees included Interior Minister Lázaro Álvarez Casas, the head of Cuba's intelligence services, and Raúl Rodríguez Castro ("Raulito"), grandson of former President Raúl Castro, according to NBC News and Cuba Headlines 32. A CIA official told CBS News that Ratcliffe delivered Trump's message that the U.S. would engage on economic and security issues "only if Cuba makes fundamental changes," while Cuba, facing an energy crisis after Maduro's capture severed Venezuelan oil supplies, countered that it poses no national security threat and should be removed from the U.S. state sponsors of terrorism list 13.
Analyst Note: Introducing the Maduro operative by name converts the meeting from diplomatic overture to coercive demonstration the regime cannot dismiss as rhetoric. The Raúl Castro indictment unsealing within days of the Havana session indicates the pressure sequence was coordinated, and Cuba's confirmed fuel exhaustion narrows external maneuver space even as Havana's public posture remains defiant. Whether Cuba produces a verifiable concession by year-end 2026 is genuinely uncertain; the regime has historically absorbed intensive coercive signaling without altering core policy commitments. The introduction may instead have been calibrated to open negotiating space, demonstrating capability while leaving Havana a visible off-ramp. Analytic confidence is low: the account rests on unidentified sources describing closed-room dynamics, and no Cuban internal signal corroborates a shift in regime deliberation. A sustained NO forces State and NSC to determine whether the coercive track has exhausted its non-military options.
Sources:
1: CIA director brought paramilitary leader involved in Maduro capture to Cuba meeting, sources say - CBS News
2: Paramilitary Involved in Maduro's Capture Attended CIA Meeting in Cuba, CBS News Reports - Cuba Headlines
3: CIA Director Ratcliffe meets with Cuban officials in Havana - NBC News
New Report Reveals CIA Director John Ratcliffe Dropped One Heck of a Boss Move on Cuban Regime - RedState
IC Oversight & Authorities
Gabbard Plans Weekly Intelligence Declassification Releases on COVID Origins, Havana Syndrome, Crossfire Hurricane Before June 30 Departure
BLUF: Whether Office of the Director of National Intelligence (ODNI) executes the promised weekly declassifications before Gabbard's June 30 departure is genuinely uncertain, as her proven appetite for bulk releases collides with mandatory interagency legal reviews and a five-week window.
Director of National Intelligence (DNI) Tulsi Gabbard met with President Trump in the Oval Office on May 22 to submit her resignation, citing her husband Abraham Williams' rare bone cancer diagnosis, with her departure set for June 30 12. Officials familiar with the matter told The Daily Wire that ODNI plans weekly releases of declassified materials throughout June covering COVID-19 origins, Havana Syndrome, Crossfire Hurricane, and the 2017 Intelligence Community Assessment on Russian election interference 13. CNN, citing multiple sources, reported that Gabbard was routinely excluded from major foreign policy deliberations during her tenure, including on Iran and Venezuela, while her office concentrated on election-related and "deep state" investigations at Trump's direction 2. Principal Deputy DNI Aaron Lukas is expected to assume acting director duties after June 30 pending a permanent appointment 1.
Analyst Note: Whether ODNI delivers weekly declassified releases before June 30 is genuinely uncertain. Gabbard's Director's Initiatives Group record argues for at least partial execution, but a compressed five-week window, mandatory interagency legal reviews, and her documented exclusion from core national security deliberations each constrain delivery. Low confidence reflects a single anonymous sourcing channel with no corroboration from ODNI itself. The releases may instead be legacy framing: Gabbard's team managing an exit narrative rather than reflecting institutional readiness to publish before June 30. Congressional oversight staff and allied counterpart services must decide whether to prepare substantive responses before June 30 or hold for acting DNI Aaron Lukas, who inherits any undelivered commitment.
Sources:
1: Tulsi Gabbard to Release High-Profile Intelligence Reports Before Leaving DNI Post on June 30 - The Defense News
2: Sidelined on Iran and Venezuela, Gabbard instead pursued Trump's Deep State grievances amid her own suspicions - CNN
3: Before resigning, Tulsi Gabbard, the head of the US National Intelligence Service, intends to disclose data on the results of a number of high-profile internal investigations, including the COVID-19 pandemic, the Havana syndrome and the presidential elections - Pravda USA
Here's What Tulsi Gabbard Plans To Reveal Before Leaving Office - The Daily Wire
COLLECTION GAPS
- Five Eyes intelligence cooperation and allied service restructuring, particularly coordination pressures from concurrent European, Middle Eastern, and Indo-Pacific operations.
- FISA Section 702 reauthorization status and any modifications to surveillance authorities under the current administration.
- Active U.S. counterintelligence investigations, including espionage prosecutions or insider threat cases.
- NRO and space-based intelligence collection developments, including changes to overhead reconnaissance programs or commercial imagery partnerships.
- IC Inspector General investigations concurrent with ODNI leadership transition and the declassification initiative.