← Back to Archive
IC BRIEF
Current as of 1806 EDT (UTC-04), Monday 25 May 2026
Contents
10 stories from 42 sources across 34 organizations
KEY JUDGMENTS
We assess that Western governments will likely issue no formal public attribution for either China-linked Webworm intrusions into five EU governments or the foreign-state compromise of Australian parliamentary communications before 30 September 2026. High confidence rests on the single-vendor evidentiary structure underlying both campaigns and the absence of Five Eyes coordination signals that have historically preceded named attributions. Additional vendor disclosures of state-aligned anti-forensic tradecraft are likely within three months, as actors across three adversary services have independently converged on memory-resident architectures.
Western investigators will almost certainly document active Russian-directed operations against Armenia's June parliamentary election before polls close, given leaked Social Design Agency (SDA) planning materials naming the interference outlet erevan.one. Israel will very likely conduct additional kinetic operations against Hamas leadership or Iranian-linked targets by September, with Israeli intelligence task force for October 7 accountability (NILI)'s continuation through the ceasefire confirming tempo independent of diplomatic constraints. Independent corroboration from a Spanish or Belgian national Computer Emergency Response Team (CERT), or a coordinated Five Eyes advisory naming Webworm, would shift the attribution assessment toward formal action.
Adversary Intelligence
Kazuar Malware Evolves Into Modular Espionage Ecosystem for FSB-Linked Secret Blizzard
BLUF: Kazuar's shift to a leadership-elected Peer-to-Peer (P2P) architecture neutralizes the perimeter-centric detection model most foreign ministries and defense agencies still rely on, handing Federal Security Service (Russia) (FSB) Center 16 sustained access to high-value diplomatic targets.
Microsoft researchers on May 14 documented Kazuar's rebuild as a three-module peer-to-peer botnet consisting of Kernel, Bridge, and Worker components, a finding independently confirmed by PolySwarm analysts writing for Cyber Security News 12. The Kernel module runs an autonomous leadership election so only one infected host handles Command and Control (C2) communications while the others enter silent mode, reducing the network footprint defenders can observe 12. The Bridge module serves as the C2 relay, routing encrypted traffic between the elected Kernel leader and remote infrastructure via HTTP, WebSockets, or Exchange Web Services (EWS)-based email channels 12. Worker modules perform keylogging, screenshot capture, file harvesting, and MAPI email collection, and the framework's roughly 150 configuration options include Antimalware Scan Interface (AMSI), Event Tracing for Windows (ETW), and Windows Lockdown Policy (WLDP) security bypasses 12. Cybersecurity and Infrastructure Security Agency (CISA) attributes Secret Blizzard to Center 16 of Russia's FSB; the group targets foreign ministries, embassies, and defense organizations across Europe, Central Asia, and Ukraine 2.
Analyst Note: The leadership-election model compresses Kazuar's footprint to a single host's outbound traffic, defeating the perimeter volume thresholds defenders use to triage alerts. With roughly 150 configuration options and native AMSI, ETW, and WLDP bypasses, operators can tailor the framework to defeat signature-based and behavioral detection simultaneously, shifting the detection problem to correlating fragmented Inter-Process Communication (IPC) activity across multiple compromised hosts. Read alongside the same-week disclosure of Lazarus's RemotePE, the pattern confirms that state-aligned actors across multiple services have independently settled on anti-forensic, memory-resident architectures, though Microsoft is the sole primary source, with secondary amplification only. The modular rebuild may instead reflect internal engineering priorities rather than a deliberate effort to compress the detection surface.
Sources:
1: Russian hackers turn Kazuar backdoor into modular P2P botnet - BleepingComputer
2: Kazuar Malware Evolves Into Modular Espionage Ecosystem for Secret Blizzard Operations - Cyber Security News
Kazuar: Anatomy of a nation-state botnet - Microsoft Security Blog
China-Aligned Webworm APT Deploys EchoCreep and GraphWorm Backdoors Against EU Governments
BLUF: Formal public attribution by any named EU member state remains unlikely by 30 November 2026, given the single-vendor evidentiary base and Webworm's reliance on commodity platforms that muddy the threshold for naming Beijing.
European software and cybersecurity company (ESET) Research on May 20 reported that Webworm targeted government entities in Belgium, Italy, Poland, Serbia, and Spain in 2025, and also compromised a local university in South Africa 123. The group's two new backdoors are EchoCreep, which uses Discord for C2, and GraphWorm, which uses Microsoft Graph API and OneDrive endpoints exclusively 132. ESET decrypted 433 Discord messages from EchoCreep's C2 channel, finding commands sent to more than 50 targets beginning March 21, 2024, and traced attribution to Webworm via a GitHub repository containing a SoftEther VPN configuration file matching a known Webworm IP 132. ESET has not identified the initial access vector, but observed the custom proxy tool WormFrp retrieving configurations from a compromised AWS S3 bucket that operators used to exfiltrate files from a Spanish government entity between December 2025 and January 2026 12.
Analyst Note: Formal EU attribution to China over the Webworm campaign is unlikely by 30 November 2026. Moderate confidence rests on a single ESET vendor report with no corroboration from national intelligence services and an attribution chain anchored to one IP inside a SoftEther VPN configuration file. European governments have made formal attributions to China only when diplomatic preparations were underway and national intelligence independently corroborated vendor findings; neither precondition is currently observable. Reliance on commodity infrastructure, including Discord, Microsoft Graph, and Amazon S3, further blurs the evidentiary threshold governments must clear before accusing Beijing. Toolset overlap with multiple China-nexus clusters sharing open-source RATs also leaves open the possibility that this reflects contractor or affiliate activity rather than a unified state-directed operation. Attribution would open a coordinated EU diplomatic response and accelerate sanctions deliberations; absent that outcome, affected governments manage exposure through technical defenses alone.
Sources:
1: ESET uncovers the expanded arsenal of China-aligned Webworm; European governments targeted - ESET / GlobeNewswire
2: China's Webworm Uses Discord, Microsoft Graphs to Hack EU Govts - Dark Reading
3: Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API - The Hacker News
ESET uncovers the expanded arsenal of China-aligned Webworm; European governments targeted - ESET / GlobeNewswire
Webworm: New burrowing techniques - ESET / WeLiveSecurity
China Webworm Uses Discord Microsoft Graphs to Hack EU Governments - Dark Reading
Iran Claims Shootdown of Israeli Orbiter Surveillance Drone Over Hormozgan Province
BLUF: Israeli confirmation of the Orbiter loss is very unlikely within 31 days, leaving Tehran's narrative uncontested and handing Iran a propaganda win as nuclear talks close.
Iran's Mehr news agency reported Sunday that Iranian air defense forces shot down an Israeli Orbiter surveillance drone over Hormozgan province 123. Press TV, citing southeastern air defense command sources in Bandar Abbas, said the drone was intercepted by a specialized system capable of detecting radar-evading UAVs, and that wreckage was subsequently recovered by maritime border police units operating in the province 3. The incident occurred one day after U.S. President Trump publicly stated that a deal with Iran to reopen the Strait of Hormuz was "largely negotiated" and nearing announcement. The Times of Israel reported that the IDF said it was "not familiar with the incident" 4.
Analyst Note: Israeli confirmation of the Hormozgan drone loss is very unlikely within the next 31 days. Jerusalem has never acknowledged sensitive ISR missions over Iranian territory, and doing so would validate Tehran's air defense narrative as Washington presses to close a nuclear framework. The claim's timing, released as that framework nears completion, signals deliberate deterrence projection and domestic prestige management, though the incident may instead be fabricated with no drone actually intercepted. If the wreckage recovery is authentic, Iranian forces obtained technical intelligence on Israeli collection parameters over a priority maritime corridor. Moderate confidence reflects single-source Iranian state-media reporting with no independent corroboration; ISR planners can only revise Persian Gulf routing assessments if Israeli silence breaks.
Sources:
1: Iran shoots down Israeli spy drone in countrys south: Report - Middle East Monitor
2: Iran shoots down an Israeli surveillance drone, news agency says - Al Arabiya English
3: Iran shoots down Israeli spy drone over Hormozgan province - Press TV
4: May 24: Iran claims it downed an Israeli surveillance drone; IDF says not familiar with incident - The Times of Israel
Fox-IT Exposes Lazarus Groups Memory-Only RemotePE RAT Targeting Financial and Crypto Organizations
BLUF: Environmental keying paired with in-memory execution and userland Endpoint Detection and Response (EDR) blinding gives this Lazarus subgroup a tradecraft edge that will frustrate post-incident attribution and prolong dwell time in crypto and financial targets.
Fox-IT researchers Yun Zheng Hu and Mick Koomen on May 22 published a technical breakdown of a three-stage, memory-only toolset deployed by a Lazarus subgroup, linked to Citrine Sleet and UNC4736, against financial and cryptocurrency organizations
12. DPAPILoader, the first stage, masquerades as Windows' Internet Authentication Service and applies Data Protection Application Programming Interface (DPAPI)-based environmental keying, binding each payload cryptographically to the victim host and, as Fox-IT notes, rendering off-system analysis infeasible without the victim's OS credentials
12. RemotePELoader disables userland EDR hooks via Hell's Gate syscall unhooking and neutralizes ETW telemetry before retrieving RemotePE from an operator-controlled C2 server; RemotePE then executes entirely in memory and writes nothing to disk
13. Fox-IT obtained four RemotePE samples with compilation timestamps spanning July 2023 to mid-2024 and confirmed neither RemotePELoader nor RemotePE appeared on VirusTotal before the May 22 publication
13.
Analyst Note: Based on Fox-IT's original research with no independent corroboration, DPAPI environmental keying is the crux: any captured payload is forensically inert without the victim's OS credentials, collapsing the reverse-engineering workflow that enables rapid threat characterization. Zero VirusTotal presence before May 22 and actor-in-the-loop delivery confirm deliberate reservation for high-value targets, with four samples spanning July 2023 to mid-2024 marking roughly one year of development. Hell's Gate unhooking and ETW patching systematically blind userland EDR, raising the likelihood of undetected long-dwell intrusions in financial and crypto environments lacking kernel-level telemetry. The restricted distribution may indicate Lazarus holds pre-positioned accesses well beyond current incident response visibility.
Sources:
1: RemotePE: The Lazarus RAT that lives in memory - Fox-IT
2: RemotePE: The Lazarus RAT that lives in memory - Malware News
3: Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms - The Hacker News
Lazarus Deploys RemotePE Memory-Only RAT for Financial and Crypto Companies - Fyself News
Hackers Breach Russias Social Design Agency Exposing Active Disinformation Operations Across Six Countries
BLUF: Formal Armenian citation of erevan.one as a Russian interference vector before the June vote is unlikely, leaving Western governments with attribution evidence but no procedural lever to act on it pre-election.
Hackers leaked internal Social Design Agency documents to Delfi Estonia reporters, who shared the files with Organized Crime and Corruption Reporting Project (OCCRP) and partners; the materials detail influence operations across Armenia, France, Ukraine, Germany, Moldova, and Norway 12. Per an internal spreadsheet in the same cache, the leaked chats belong to EU-sanctioned Russian Presidential Administration official Sofia Zakharova, whose messages reference awaiting approval from first deputy chief of staff Sergei Kiriyenko 1. Documented operations include the September 2025 Paris mosque pig-head attacks, pig heads marked with 'Macron' placed at nine mosques, for which Serbian courts convicted three men citing Russian intelligence direction, and false-flag vandalism campaigns in France and Germany 1. The files also name local collaborators including a retired US general and a former Bundestag member, and outline an election interference plan targeting Armenia's June 7 parliamentary vote through erevan.one, with an internal document titled 'Programme for work in the anti-Pashinyan direction for 2026' aiming to frame the vote as a referendum against the prime minister personally 12. The UK government independently sanctioned 49 SDA employees on May 11, 2026 over the Armenia interference operation, corroborating the leaked documents' account of Kremlin direction.
Analyst Note: Erevan.one is unlikely to receive formal citation from Armenian electoral authorities or an Organization for Security and Co-operation in Europe (OSCE)/Office for Democratic Institutions and Human Rights (ODIHR) observer mission before end of June, constraining pre-election action against a named interference vector. Low confidence reflects the single OCCRP investigative source chain and absence of independent official corroboration. The leak advances Western governments' evidentiary position on Kremlin direction, naming Armenia as the SDA's near-term electoral target. The cache could represent a selective release by a competing intelligence service, surfacing authentic material to accelerate European pressure before the June 7 vote. A formal citation before that date would give EU and US policymakers standing for pre-election sanctions or takedown requests against erevan.one. Without one, coordinated action defers to post-election observer reports by which point the operation will have run its course.
Sources:
1: Leaked Documents Reveal Russian 'Cognitive Strikes' Against the West — Including Islamophobic 'Pig Head' Attacks in Paris - OCCRP
2: Risky Bulletin: Mythos found thousands of critical bugs - Risky Biz
Allied Intelligence
Israel Compiles Secret Kill-or-Capture List of Thousands of Oct 7 Attackers Using Shin Bet and Military Intelligence
BLUF: NILI's survival through the ceasefire converts October 7 accountability into a permanent extraterritorial targeting apparatus that will shadow every future negotiation and reshape Hamas's command bench faster than it can regenerate.
The Wall Street Journal reported on May 21 that Israel's Shin Bet and military intelligence formed a task force called NILI holding thousands of October 7 participants on a kill-or-capture target list 12. Targets are added once two independent pieces of evidence place an individual at the scene, using facial recognition run against terrorist-posted video, intercepted communications, cellphone location data, and detainee interrogations 312. Israeli officials told the Journal that hundreds of names have been crossed off, including Hamas Gaza chief Izz al-Din al-Haddad last week and Nukhba Force commander Ali Sami Muhammad Shakra last month 32. The campaign has continued through the Gaza ceasefire, with NILI reduced to a smaller contingent passing target data to field commanders, the Journal reported 12.
Analyst Note: NILI's continuity through the ceasefire establishes it as a permanent Israeli state instrument whose shadow falls across every future Gaza negotiation. The two-source evidentiary threshold provides procedural standing inside Israeli legal frameworks, but International Humanitarian Law (IHL) exposure deepens when targeting rationale shifts from imminent threat to historical status, an argument Hamas will press at every multilateral forum. Systematic removal of Nukhba-level commanders forces the organization to elevate undertrained replacements faster than its training pipelines allow. Sourced exclusively to the Wall Street Journal without independent corroboration, the disclosure may itself be deliberate deterrence messaging, with operational details selectively surfaced to maximize psychological effect on regional actors rather than document actual program scope.
Sources:
1: Israel reportedly established elite task force to locate October 7 terrorists - The Jerusalem Post
2: Report: Israel Formed Secret Unit to Kill or Capture Every Oct. 7 Attacker - Breitbart
3: Israel has list of all Oct. 7 participants, aims to kill or arrest each one -- WSJ - The Times of Israel
Inside Israel's Campaign to Kill Every Oct. 7 Attacker - The Wall Street Journal
Israel hunts every Oct. 7 attacker on secret kill-or-capture list - JNS
Australian Signals Directorate Investigates Foreign State Hack of Federal MP WhatsApp Accounts
BLUF: Public attribution to a named state actor by 30 September 2026 is unlikely, leaving the four compromised accounts as an unresolved counterintelligence exposure of indeterminate collection duration.
A Senate Estimates hearing on Monday disclosed that a federal parliamentarian and three staffers had their WhatsApp accounts compromised on March 6, after attackers tricked victims into sharing verification codes to gain full account access 123. Department of Parliamentary Services (Australia) (DPS) chief information officer Mike Webb told the hearing that current evidence points to a foreign state actor, citing comparable state-sponsored phishing warnings from Germany, the Netherlands, the United States, and the United Kingdom 12. DPS notified the Australian Signals Directorate and blocked parliamentary web access to WhatsApp from March 9 through the following Sunday 23. DPS officials separately reported 46 malware instances, approximately 20,000 phishing attempts, and roughly 1,458 cyber alerts across parliamentary systems between July 1, 2025 and March 31 13.
Analyst Note: The takeover granted an adversary trusted-principal access to ongoing parliamentary correspondence for a duration DPS has not bounded. Public attribution to a named state actor by 30 September 2026 is unlikely. Australia has confined formal cyber attributions to cases with prior allied consensus, and DPS grounded its assessment in behavioral pattern-matching to known campaigns rather than actor-specific technical indicators. Analytic confidence is moderate, reflecting open-source behavioral comparison absent Australian Signals Directorate (ASD)'s classified technical assessment, with all coverage drawn from a single report and no independent technical corroboration. The attacker may instead be a sophisticated criminal organization mimicking state TTPs, as no independent evidence links verification-code phishing to a named group. Attribution would give DFAT a diplomatic signaling tool aligned with allied governments and grounds to mandate platform restrictions. Without it, Australia cannot join formal coalitions targeting the broader campaign.
Sources:
1: MPs messaging account hacked by foreign state actor - Michael West Media
2: Federal MP's WhatsApp account hacked by state actor - Information Age (ACS)
3: WhatsApp hack on politician revealed, amid onslaught of attempted cyber attacks - SBS News
Turkish MIT and Syrian Intelligence Capture 10 Daesh Suspects Including Figure Linked to 2015 Ankara Bombing
BLUF: Capturing Daesh's assessed Turkey intelligence chief alongside a 2015 Ankara bombing suspect removes the connective tissue between the group's Syrian remnant and its domestic attack planning, while validating Ankara-Damascus security cooperation as an operational instrument.
Turkish National Intelligence Organization (Turkey) (MIT) and Syrian intelligence captured 10 Daesh suspects in Syria on May 23 and transferred them to Türkiye, where nine were formally arrested and one held in extended detention, Turkish security sources told Daily Sabah 12. All ten held Interpol Red Notices and were identified as Turkish nationals who had joined Daesh in Syria in prior years 13. Among those seized was Ömer Deniz Dündar, linked by security sources to the 2015 Ankara twin bombings that killed 109, on the basis of fingerprint evidence recovered from suicide bomber explosive devices in 2017 14. Ali Bora, identified by the same sources as Daesh's intelligence chief for Turkey operations, was said to have joined the group in 2014 and participated in planning attacks against Turkish military forces 123.
Analyst Note: Daesh loses its assessed Turkey intelligence chief and a figure fingerprint-linked to the 2015 Ankara bombings, degrading Syria-resident nodes bridging its residual structure to domestic attack planning, though individual role attributions and evidentiary claims rest on unverified Turkish security sources. The MIT-Damascus operation confirms al-Sharaa-era cooperation has crossed into field-actionable coordination, closing the Syrian haven that shielded Turkish Daesh fugitives. Interrogation reporting on attack instructions, training pipelines, and propaganda networks suggests further network disruption will accelerate. Türkiye's pace of over a thousand arrests in 2026 marks a sustained dismantlement campaign, though the selection of these ten for their 2015 Ankara symbolic resonance may mask a network retaining operational depth this profile does not capture.
Sources:
1: Turkiyes MIT captures 10 Daesh suspects in joint Syria operation - Daily Sabah
2: Turkish and Syrian officials detain 10 individuals with alleged ISIL ties - Al Jazeera
3: Türkiye captures 10 ISIL suspects in Syria - Hurriyet Daily News
4: Ten ISIS terrorists captured in joint Turkey-Syria operation - The Jerusalem Post
Counterintelligence & Tradecraft
SBU Detains Russian Agent Who Directed May 24 Missile Attack on Kyiv
BLUF: Russia has operationalized a low-tradecraft, Telegram-based recruitment pipeline that converts Kyiv civilians into real-time strike spotters, collapsing the window between impact and targeting refinement for follow-on attacks.
The Security Service of Ukraine (SBU) on May 25 arrested an 18-year-old Kyiv resident near a Ministry of Defense facility while he conducted post-strike reconnaissance the morning after the mass Russian attack, according to the SBU press center and Prosecutor General Ruslan Kravchenko 12. The SBU said the suspect was recruited via Telegram in mid-May, first tasked with mapping Ukrainian military transport routes in suburban Kyiv, then directed on May 24 to photograph strike damage and transmit results to a Russian handler in real time 32. Officers seized a smartphone containing prepared intelligence reports, geolocated imagery, and handler correspondence 13. Kravchenko confirmed investigators charged him with high treason under martial law and a court remanded him in custody without bail, with the charge carrying a potential life sentence 21.
Analyst Note: The seized handler correspondence confirms Russian intelligence coordinated damage documentation by angle and address during the May 24 strike cycle itself, requiring no tradecraft beyond a Telegram account. All sourcing, however, traces to a single SBU official statement republished by Ukrainian state media without independent corroboration, which limits analytic confidence in the specific claim that his imagery fed active targeting adjustments rather than post-strike battle damage assessment. The graduated recruitment model, benign commercial tasking preceding military reconnaissance, reduces Russian intelligence exposure while exploiting economic vulnerability among young urban Ukrainians at scale. Defence Intelligence of Ukraine (GUR) involvement alongside the SBU signals Ukrainian military intelligence assessed the network as extending beyond a single opportunistic recruit.
Sources:
1: SBU detains Russian agent who directed attack on Kyiv on May 24 - Ukrinform
2: Coordinated Russian strikes on Kyiv during the massive attack on May 24: Kravchenko announced the detention of an 18-year-old Russian agent - Ukrainian News Network (UNN)
3: SBU detains Russian agent who adjusted enemy attack on Kyiv on May 24 – source - Interfax Ukraine
SBU official statement on detention of Russian agent who adjusted May 24 Kyiv attack - Security Service of Ukraine (SSU/SBU)
SBU Detains Russian Agent, Kills Infiltrator in Donetsk Raid - Kyiv Post
IC Oversight & Authorities
Citizen Lab Warns Canada Bill C-22 Could Give FBI Real-Time Surveillance Powers on Canadian Soil via CLOUD Act
BLUF: Concluding a Canada-US Clarifying Lawful Overseas Use of Data Act (CLOUD Act) executive agreement by year-end 2026 is very unlikely, but Republican pressure on Ottawa signals Washington intends to extract real-time surveillance access regardless of Canadian judicial safeguards.
Citizen Lab's Kate Robertson, writing in The Walrus, reports that
Bill C-22 would create the legal prerequisites for a CLOUD Act agreement granting US agencies real-time surveillance authority in Canada absent Canadian judicial oversight
12. Republican House Judiciary and Foreign Affairs committee chairs wrote to Public Safety Minister Anandasangaree this month confirming CLOUD Act talks remain "ongoing," directing Canada toward "prompt collaboration," and warning that the bill threatens US national security
23. Geist reports Signal, Windscribe, Apple, and Meta have each threatened exit or raised public objections, while Robertson notes Ottawa has not explained the US pressure or signaled reluctance to conclude a deal
312.
Analyst Note: A signed Canada-US CLOUD Act executive agreement by year-end 2026 is very unlikely. Bill C-22 remains in parliamentary committee with no amendment pathway, and passage would still compress four years of stalled negotiation into months. Republican committee chairs' directive signals American urgency, not Canadian readiness, and documented DOJ misconduct patterns sharpen the sovereignty cost Ottawa would absorb. Moderate confidence rests on convergent technical and legal reporting from a single investigative foundation, though the negotiating text and Ottawa's internal posture are not publicly available. The pressure may instead be political cover for surveillance expansion Ottawa independently wants, with CLOUD Act framing absorbing domestic civil-liberties opposition. A missed deadline preserves current protocols; a concluded agreement immediately obligates Canadian privacy commissioners to audit whether existing US data-access arrangements survive under the oversight-waived framework.
Sources:
1: Trump Wants to Tap Your Phone. Ottawa Might Let Him. - Citizen Lab
2: Trump Wants to Tap Your Phone. Ottawa Might Let Him - The Walrus
3: The Lawful Access Two-Headed Surveillance Monster: How Bill C-22 Went Off the Rails - Michael Geist
COLLECTION GAPS
- FISA Section 702 reauthorization implementation status and any DOJ compliance reporting since the April 2026 renewal
- NSA or ODNI workforce attrition and hiring freeze impacts following Q2 2026 budget sequestration
- BND or DGSE operational assessments of Russian intelligence reconstitution after officer expulsions
- AUKUS Pillar II advanced capabilities integration milestones and associated intelligence-sharing arrangements
- Five Eyes coordination on attribution standards for single-vendor-sourced state-aligned campaigns