//
OFFLINE — VIEWING CACHED CONTENT
← Back to Archive

IC BRIEF

Current as of 0318 EDT (UTC-04), Saturday 15 August 2026

Contents

9 stories from 47 sources across 38 organizations


KEY JUDGMENTS

Russian and Chinese intelligence operations escalated against allied targets this cycle, with Moscow extending operational reach from Ukraine's interior to a US-citizen assassination plot on NATO territory and Beijing sustaining espionage across diplomatic, physical-proximity, and cyber vectors spanning Five Eyes partners. Another NATO state will very likely disclose disruption of a Russian intelligence operation on allied territory within 90 days, driven by the sustained European counterintelligence disclosure tempo and domestic incentives to publicize Russian operational failures.

At least one Five Eyes government other than New Zealand will very likely publicly attribute a Peoples Republic of China (PRC)-linked espionage or cyber operation within 60 days, following New Zealand Security Intelligence Service (NZSIS)'s decision to name Purple Mountain Observatory publicly. Congressional inquiry into PRC-linked property acquisitions near sensitive US facilities is likely within 90 days, assuming the investigation generates broader media attention. Moderate confidence on the congressional track rests on consistent response patterns to comparable China-threat disclosures.

The Post's disclosure of a covert CIA drone program behind Ecuadorian fishing-boat strikes, combined with the Warsaw assassination exposure, will likely prompt at least one congressional committee to examine covert lethal authorities within 90 days. Low confidence reflects the absence of a scheduled hearing or formal referral; announcement of either would be the leading indicator that inquiry is imminent.


Adversary Intelligence

New Zealand Names China No. 1 Espionage Threat as NZSIS Report Reveals Scale of PRC Intelligence Operations

BLUF: Wellington's shift from generalized warnings to naming a specific PRC-linked entity signals Five Eyes convergence toward granular attribution that narrows Beijing's room to dismiss espionage allegations as political overreach.

The New Zealand Security Intelligence Service's Security Threat Environment 2026 assessment, released Thursday, named China as the only country detected conducting espionage in New Zealand "at scale," per Director General Andrew Hampton 12. The report said NZSIS disrupted an attempt by Purple Mountain Observatory, a China-based organization with close government ties, to install ground-based space-tracking infrastructure through a local company it assessed was likely unaware the equipment could collect military-value intelligence 12. Hampton described the threat environment as "the most challenging of recent times" and said espionage activity is expected to increase over the next 12 months 13. The Chinese Embassy in Wellington rejected the report as "rife with Cold War thinking" and a product of "foreign interference," calling the claims fabricated and warning against actions that would harm the bilateral relationship 34.

Analyst Note: Naming Purple Mountain Observatory publicly shifts NZSIS from generalized warnings to specific attribution, raising the diplomatic cost of routine PRC-linked technical activity and setting a template other Five Eyes partners may follow. Sourcing converges across independently reporting outlets: Reuters' wire account and Global Times' direct embassy statement, corroborated by EurAsian Times and the South China Morning Post, with no single-source dependency on the core finding. Release roughly three months before Wellington's November election puts foreign interference on the campaign agenda and sharpens scrutiny of candidates' contacts with unofficial Chinese intermediaries. Beijing's denial tracks its 2025 response nearly point for point, suggesting the annual disclosure-and-denial exchange has become a fixed ritual. The rhetoric may instead be primarily domestic election-year positioning rather than a genuine new security disclosure.

Sources:

1: Chinese state-linked observatory sought NZ site, spy agency says - The Japan Times (Reuters)

2: China Named No.1 Espionage Threat in New Zealand Report — Embassy Fires Back, Says Rife with Cold War Thinking - EurAsian Times

3: China claims New Zealand's spy report is product of foreign interference - South China Morning Post

4: Chinese Embassy firmly rejects NZ intelligence report hyping 'Chinese interference,' says claims rife with Cold War thinking - Global Times

SSU Dismantles FSB Agent Network Guiding Russian Airstrikes Across Three Ukrainian Regions

BLUF: Dismantling four isolated informants leaves the Federal Security Service of the Russian Federation (FSB) handler's Telegram-based recruitment pipeline intact, ensuring replacement agents can be sourced from the same open funnel at minimal cost.

The Security Service of Ukraine (SSU) counterintelligence department detained four FSB informants simultaneously in the Donetsk, Dnipropetrovsk and Kirovohrad regions following a multi-stage operation, with the suspects acting independently but sharing a common Russian handler 1234. According to the SSU, the network targeted logistics depots holding weapons and ammunition, air defense positions, and areas with concentrations of Ukrainian personnel and equipment 14. The detainees include a former machine-building plant employee from Kramatorsk who tracked airfield and fortification locations, two agents in Dnipropetrovsk region (a municipal utility worker from Kamianske and a deserter from Pavlohrad) who passed military-facility coordinates, and an unemployed man from Znamianka in Kirovohrad region who surveyed the town for Defense Forces sites 1234. The SSU states the men came to Russian intelligence attention after posting anti-Ukrainian comments in Telegram chats and communicated via anonymous messenger chats they deleted after each session; all four have been notified of suspicion under Article 111.2 of Ukraine's Criminal Code (high treason under martial law) and face life imprisonment with confiscation of property 124.

Analyst Note: The network's structure, four operationally isolated recruits reporting to one Russian handler, points to a centralized FSB tasking cell running parallel low-cost human sources rather than a single compromised cell; disruption of this group leaves the handler's broader recruitment pipeline intact. Telegram comment threads functioned as an open recruitment funnel, screening for pro-Russian sentiment before contact, a vector Ukrainian counterintelligence cannot close without restricting the platform itself. The targeting set, logistics depots, air defense positions, and troop concentrations, mirrors strike-planning requirements rather than generic surveillance, indicating the tasking originated from units directly supporting airstrike execution against the Defense Forces.

Sources:

1: SSU dismantles FSB intelligence network spying in three regions of Ukraine simultaneously - GlobalSecurity.org

2: СБУ викрила групу коригувальників ворожих атак по Силах оборони у трьох областях - Ukrinform

3: СБУ: викрито агентурну мережу, яка шпигувала в трьох областях за логістичними складами з озброєнням - Interfax-Ukraine

4: Four agents were detained for passing data on military facilities in three regions of Ukraine to the FSB - UNN

СБУ викрила агентурну мережу фсб, яка коригувала удари рф по Донеччині, Дніпропетровщині та Кіровоградщині - Security Service of Ukraine (SSU) press service

СБУ викрила агентурну мережу фсб, яка коригувала удари рф по Донеччині, Дніпропетровщині та Кіровоградщині - Security Service of Ukraine (SSU) press service

Poland Thwarts FSB-Ordered Assassination Plot Against US-Ukrainian Citizen in Warsaw in First Such Case on NATO Territory

BLUF: FSB willingness to order a kill against a US citizen on NATO soil marks an operational escalation that will compel allied services to widen protective coverage well beyond traditional Russian dissident targets.

Polish Prime Minister Donald Tusk announced that the Internal Security Agency (ABW), assisted by police, detained a Russian national on August 7 who had been recruited by Russian intelligence services to kill a US-Ukrainian dual citizen in Warsaw 12. Tusk said the plot was foiled "at the last minute" and called it the first known case of a Russia-directed attack on a US citizen inside NATO territory 13. Minister Tomasz Siemoniak confirmed the operation was carried out in cooperation with US services and described the target as a US citizen "of Ukrainian origin" 13. Warsaw police said the 29-year-old suspect was charged with planning a murder and accepting a paid contract to carry it out, and has been ordered held in pretrial detention for three months 13. Tusk did not disclose the suspect's or target's identity, saying only that the victim was someone "inconvenient" to the Putin government 12.

Analyst Note: Poland's disclosure marks a threshold shift: FSB targeting now extends to dual-national US citizens on NATO soil, not just Russian exiles or Ukrainian officials, and will push US and allied services to reassess protective postures for similarly exposed figures across Europe. Confirmed ABW-US operational cooperation indicates real-time intelligence sharing on Russian recruitment networks inside Poland is functioning and will shape how future plots surface publicly. Coming the same week as the SSU's dismantlement of an FSB airstrike-correction network across three Ukrainian regions, the case shows FSB operational reach extending from Ukraine's interior to NATO territory. Sourcing converges on a single origin, Tusk's press conference, with Western and Polish outlets echoing official statements rather than independently corroborating details, and the disclosed specifics may serve Warsaw's deterrence messaging toward Moscow as much as investigative necessity.

Sources:

1: Poland detains Russian seeking to assassinate US-Ukrainian citizen in Warsaw - Notes from Poland

2: Rosjanin miał dokonać egzekucji w Warszawie. Donald Tusk ujawnił szczegóły - Gazeta Prawna

3: Poland says it thwarted Russian plot to kill US citizen in Warsaw - CNN

Miał zlikwidować obcokrajowca w Warszawie. Polskie służby zatrzymały Rosjanina - PAP (Polska Agencja Prasowa)

Poland says it thwarted Russian assassination attempt on U.S. citizen in Warsaw - The Washington Post

CCP Intelligence Official With MPS UFWD and MSS Ties Buys Building 650 Feet From White House Complex

BLUF: Absent a counterintelligence review or forced divestment, this acquisition gives a figure embedded in China's security apparatus a permanent collection platform overlooking the White House complex.

A Daily Caller News Foundation investigation found that Philip Qiu, known in Chinese as Qiu Feili, purchased the century-old Securities Building at 729 15th Street NW, roughly 650 feet northeast of the White House grounds, through the Philip Qiu and Family Foundation for $8.4 million on July 21 12. Daily Caller News Foundation (DCNF) reporting, citing university records and translated Chinese government announcements, documented Qiu's prior work as a Shanghai Public Security Bureau detective, special-forces and sniper training at Shanghai Jiaotong University, and at least three United Front Work Department-linked posts including chairmanship of the Shanghai Overseas Chinese Foundation 12. DCNF reported that Shanghai Overseas Chinese Foundation (SOCF)'s secretary general has also directed an organization identified by former Australian Strategic Policy Institute analyst Alex Joske as a Ministry of State Security front 12. DCNF further found the Philip Qiu and Family Foundation's headquarters is a separate historic property roughly half a mile north of the White House, an address shared with several Qiu-controlled entities including the Chinese American Museum in Washington, which Qiu co-founded in 2017, and that Chinese government entities co-sponsored at least eight museum programs, four of them backed by United Front Work Department-controlled organizations 12. Townhall, PJ Media and World Tribune each relayed the DCNF findings, with Townhall and PJ Media additionally citing former CIA officer Bryan Dean Wright and China analyst Gordon Chang on the property's potential surveillance uses 345. Qiu did not respond to DCNF's requests for comment 12.

Analyst Note: Qiu's trajectory, from Shanghai criminal-investigation and special-forces training into chairmanship of a United Front charity whose secretary general also runs an identified Ministry of State Security (China) (MSS) front, reads as service inside China's security and influence apparatus rather than private philanthropy, and his ownership of a building 650 feet from the White House creates a persistent physical and signals-collection vantage point over executive facilities that no disclosed federal review currently addresses. The finding rests on a single Daily Caller News Foundation investigation; Townhall, PJ Media, and World Tribune amplified but did not independently corroborate it, leaving the story single-source despite multi-outlet pickup. Qiu's United Front Work Department (UFWD) posts may instead reflect ordinary co-optation of a prominent overseas Chinese community figure rather than a directed tasking to acquire property near the White House, and absent any announced divestment or counterintelligence response the access vector persists unaddressed.

Sources:

1: Exclusive: CCP Intelligence Official Buys Building Steps From White House - Daily Caller News Foundation

2: EXCLUSIVE: CCP Intelligence Official Buys Building Steps From White House - Daily Caller News Foundation

3: CCP Intelligence Official — Trained As a Sniper — Buys Building 650 Feet From White House - Townhall

4: Senior Chinese Communist Intelligence Official Buys Historic Building Close to the White House - PJ Media

5: CCP intelligence official buys historic building 650 feet northeast of White House - World Tribune

Allied Intelligence

Israeli Intelligence Officials Shocked by Speed of Iran Military Recovery as Missile Production Approaches Pre-War Levels

BLUF: Iran's faster-than-expected missile reconstitution likely compels Israel to strike reconstituted production sites before year-end 2026, repeating a cycle of underestimation that has failed to achieve lasting degradation.

The Jerusalem Post reported that Israeli defense and intelligence officials, including from the Israel Defense Forces (IDF) and Mossad, have been surprised by the pace of Iran's military recovery four months after the war's main phase ended in April, with the turnaround extending across multiple areas including the ballistic missile threat 1. Israeli officials assess Iran has adopted a targeted reconstruction approach prioritizing missile production over broader industrial rebuilding, and Iran has used bulldozers to reopen roughly 50 of 69 tunnel entrances at 18 underground missile facilities, potentially restoring access to an estimated 1,000 ballistic missiles 2. The Post reported it independently confirmed Iranian officials' claims of accelerated weapons production, and estimated that manufacturing 100 to 300 missiles per month would restore Iran's arsenal to roughly June 2025 levels by early-to-mid 2027 12. Iran's estimated missile stockpile grew from roughly 1,300 in June 2025 to about 2,500 by February 2026, and the Post assessed Iran could become a prohibitive threat by 2028 if that production pace holds 1. The IDF, responding to the Post, said it has "substantially harmed" Iran's military capabilities and continues tracking rehabilitation efforts but declined to specify production estimates, citing intelligence sources and methods 1.

Analyst Note: Israel's admission that Iran has reopened access to roughly 1,000 stored missiles and resumed production marks a third consecutive failure of Israeli battle-damage assessment following identical false confidence after the October 2024 and June 2025 strikes. Absent a fourth strike campaign, Iran's arsenal likely returns to pre-war strength by early-to-mid 2027, driven by tunnel-clearing at 18 facilities and monthly output in the 100-300 missile range. Moderate confidence rests on the Jerusalem Post's independently confirmed production data, though no corroborating intelligence estimates from allied services have surfaced. This recurring underestimation pattern will likely push Israeli planners toward considering renewed strikes on reconstituted production sites before year-end 2026, independent of Strait of Hormuz or nuclear-track negotiations.

Sources:

1: Iran rapidly rebuilding ballistic missile arsenal after war, stunning Israel - The Jerusalem Post

2: Israel shocked by speed of Iran recovery as missile stockpile rapidly growing - The Jewish Chronicle

Israel stunned by Iran's rapid military recovery — newspaper - TASS

Israel shocked by pace of Iran's military recovery – media - RT

Prior Reporting - [The Iranian Threat Was Viewed as Psychological Warfare: Officials Admit Major Intel Failures](https://www.jfeed.com/middleeast/israeli-intelligence-failures-iran) (2026-06-08) - [The Biggest Intelligence Failure of the Iran War](https://www.aei.org/op-eds/the-biggest-intelligence-failure-of-the-iran-war/) (2026-04-07) - [Did Israel miscalculate Iranian military capabilities?](https://www.aljazeera.com/news/2026/3/22/did-israel-miscalculate-iranian-military-capabilities) (2026-03-22)

Australia Deploys MC-55A Peregrine SIGINT and Electronic Warfare Aircraft to South China Sea for First Overseas Mission

BLUF: Clark-based Peregrine rotations give the Five Eyes alliance a persistent SIGINT collection layer over the South China Sea that Canberra can sustain without publicly acknowledging mission specifics.

Aircraft A51-004, the Royal Australian Air Force's first operational MC-55A Peregrine SIGINT/electronic-warfare aircraft, flew from Royal Australian Air Force (RAAF) Base Edinburgh to Clark Air Base in the Philippines on July 28, marking the type's first overseas deployment 12. Flight-tracking data compiled by Flightradar24 shows the aircraft flew six to seven missions of four to nine hours between July 30 and August 7, mostly over or near Philippine airspace around Mindoro and Palawan 123. On four of those missions its transponder went dark for three to four hours while it turned west into the South China Sea, consistent with transit toward the Spratly Islands or Scarborough Shoal, though Australian officials did not confirm specific tracks 123. An Australian Defence spokesperson confirmed the deployment to Australian Defence Magazine only as part of Australia's "longstanding engagements in the Indo-Pacific region," declining to detail mission types or areas of operation 2. Defence Security Asia additionally reported that the deployment coincided with intensified Chinese naval-air activity near Scarborough Shoal, including Type 052D and Type 054A surface combatants, Z-20 helicopters, and H-6K bombers carrying YJ-12 anti-ship missiles 3.

Analyst Note: The deployment likely establishes Clark as a recurring rather than one-off SIGINT/Electronic Warfare (EW) forward base through the remainder of 2026, given the four-strong Peregrine fleet, No. 10 Squadron's stated Indo-Pacific posture, and continuity with prior P-8A and AP-3C rotations from the same base, at moderate confidence given consistent flight-tracking data across three independently converging secondary outlets but no confirmed mission tasking or geolocation of the transponder gaps. Those gaps may instead reflect routine flight-tracking coverage limits over open ocean rather than deliberate deactivation for covert collection. Canberra's refusal to detail mission types or areas signals continued reliance on ambiguity as an operational-security tool rather than a policy shift. If the pattern holds, Philippine and allied planners commit infrastructure and access agreements to sustain recurring ISREW sorties, whereas a one-off evaluation leaves P-8A patrols as the primary surveillance tool.

Sources:

1: Australia MC-55 Electronic Warfare Jet Has Entered The South China Sea - The War Zone

2: Peregrine leaves the nest - Australian Defence Magazine

3: Australia Sends MC-55A Spy Plane Near China's South China Sea Flashpoints - Defence Security Asia

IC Technology

AUKUS Leaders Advance First Pillar II Signature Project for Autonomous Undersea Intelligence Collection and Surveillance

BLUF: Leader-level affirmation keeps Australia-United Kingdom-United States Security Partnership (AUKUS) politically intact, but the unnamed Pillar II project's value hinges on unresolved IP-sharing and manufacturing arrangements that no public statement has addressed.

Australian Prime Minister Anthony Albanese said Donald Trump reaffirmed AUKUS as "full steam ahead" in a phone call, with the two leaders reviewing progress on the partnership's first signature Pillar II project 123. Albanese said the project centers on joint development of advanced payloads and enabling systems for uncrewed undersea vehicles, and he briefed Trump on Australian technologies including the Ghost Shark undersea vehicle and Ghost Bat combat aircraft 4. Albanese said Trump agreed AUKUS would continue to benefit Australia, the US, and the UK 4. The leaders also discussed the critical-minerals agreement, with Albanese citing more than $3.5 billion in projects underway, including an Alcoa gallium project projected to supply about 10 percent of global demand and a $400 million US investment in the Sunrise Energy Metals project near Dubbo 4.

Analyst Note: Leader-level endorsement moves AUKUS Pillar II toward a named workstream on joint payloads and enabling systems for uncrewed undersea vehicles, but the real test shifts to IP-sharing, manufacturing location, and contract awards rather than political statements, and all reporting traces to a single Reuters wire or Albanese's own press-conference remarks with no independent confirmation from Washington or London on the call's substance. The critical-minerals figures Albanese cites signal Canberra angling to be framed as a supplier rather than customer within the partnership. The public messaging may serve domestic political needs, reassuring Australian industry and voters that AUKUS survives scrutiny under the Trump administration, more than reflecting a substantive programmatic shift among the other two partners.

Sources:

1: Australia's Albanese Says AUKUS Remains 'Full Steam Ahead' After Trump Call - US News (Reuters)

2: Australia's Albanese says AUKUS remains 'full steam ahead' after Trump call - The Jakarta Post (Reuters)

3: Trump, Albanese reaffirm AUKUS in 'warm' phone call - The Leader (AAP)

4: AUKUS Full Steam Ahead as Autonomous Undersea Project Advances - Defence Matters

IC Operations

Washington Post Reveals Covert CIA Drone Program Behind Mysterious Strikes on Ecuadorian Fishing Boats Near Galápagos

BLUF: Washington's silence on the Galápagos strikes will very likely hold through year-end 2026, and the murder of Ecuador's investigating prosecutor eliminates the sole remaining pathway to accountability.

The Washington Post reported that a covert CIA program, run separately from the Pentagon's Southern Spear boat-strike campaign, was behind attacks on Ecuadorian fishing vessels near the Galápagos Islands in January and March 1. The fishing boat Fiorella disappeared on January 20 with eight crew members aboard, who are presumed dead by the United Nations; before it vanished, its captain sent daily satellite messages describing sustained surveillance by aircraft, patrol boats and drones bearing US markings 1. Survivors of the March 17 and 26 strikes said they were abducted, hooded, cuffed and flown to El Salvador before being returned to Ecuador without explanation 123. Ahead of each attack, a surveillance plane registered to a nonexistent company and unlisted with the Federal Aviation Administration (FAA) departed El Salvador's Ilopango airport and flew toward the Galápagos, the Post reported, a pattern it said points to CIA involvement 2. No US agency has claimed responsibility, and the Pentagon has not produced evidence tying the vessels to drug trafficking 13; Ecuador's prosecutor investigating the strikes was shot and killed in June, according to Truthout 2.

Analyst Note: US agencies will very likely maintain public silence on responsibility through year-end 2026, a pattern already evident in the unmarked surveillance aircraft, the absent FAA registration, and the Pentagon's failure to substantiate drug-trafficking claims. Confidence is low, given single-source disclosure of the CIA link and no independent corroboration of tradecraft details like the Ilopango flight pattern; Common Dreams, Truthout, Democracy Now!, and Newsmax merely republish the Post's original reporting. The strikes could instead reflect an authorized but compartmented extension of Southern Spear, with secrecy stemming from operational classification rather than concealment of an unlawful campaign. Continued silence, compounded by the June killing of the Ecuadorian prosecutor investigating the strikes, leaves the Fiorella disappearance and March abductions without accountability and pushes congressional oversight toward closed-door intelligence committee review rather than public Pentagon scrutiny.

Sources:

1: Covert CIA program said to be behind mysterious attacks on Galápagos boats - Washington Post

2: CIA Involved in Covert Strikes on Ecuadorian Boats, Report Says - Truthout

3: CIA Carried Out Drone Strikes, Disappearances and Torture Near Ecuador's Coast - Democracy Now!

Mysterious Attacks on Ecuadoran Fishing Boats Carried Out by Covert CIA Operation: Report - Common Dreams

Report: CIA Ran Covert Strikes on Ecuador Fishing Boats - Newsmax

IC Technology & Cyber

Symantec Exposes Jewelbug APT China-Based Group Running Parallel Government Espionage and Cryptocurrency Fraud From Shared Infrastructure

BLUF: Jewelbug's shared infrastructure between state espionage and cryptocurrency fraud gives financial-crime authorities a rare lateral entry point to disrupt PRC intelligence collection through commercial enforcement actions.

Symantec's Threat Hunter Team reported that Jewelbug, a China-based hackers-for-hire group tracked elsewhere as Earth Alux, REF7707, and CL-STA-0049, runs espionage against governments and militaries in the Middle East, Southeast Asia, and South Asia alongside a for-profit cryptocurrency fraud business from a single control panel called XG-Web 12. Symantec tied at least one operator to a registered company in Hunan Province, identifying a legal representative from government-issued identity documents who operated under the Telegram handle "paopaodada" (Bubble Boss) as admin contact for an SEO business 1. The group's primary implant, a malicious "PDF Viewer" browser extension, requests broad permissions to harvest credentials and cookies. The Antino backdoor uses the Microsoft Graph API for command-and-control, and the Rust-based ClientKing implant targets Linux servers and routers 123. In its largest operation, the group compromised a Middle Eastern state telecom's shared hosting platform to plant a watering-hole script across more than 15 government webmail tenants 12, and its victim database logged over one million implant check-ins, 580,000 stolen cookies, several thousand credentials, and more than 2,300 exfiltrated email bodies in under three months 123.

Analyst Note: Symantec's exposure collapses the line defenders use to triage nation-state versus criminal intrusions: identical infrastructure, personnel, and victim database run PRC-linked state espionage and commodity cryptocurrency fraud in parallel, though the dual model may equally reflect an underfunded contractor monetizing idle infrastructure between state taskings rather than a deliberate intelligence-crime fusion. Because the fraud arm is the more tractable target for financial-crime enforcement, disrupting XG-Web's commercial side could simultaneously degrade the group's espionage tooling, an unusual joint disruption vector for cyber and financial investigators. The named legal representative tied to a Hunan-registered company gives investigators a rare handle for sanctions or indictment against an otherwise anonymous hack-for-hire operator, while the single compromise hitting 15-plus government webmail tenants through shared hosting flags supply-chain footholds regional administrators should audit. Reporting rests on Symantec's single primary account, with other outlets offering amplification rather than independent verification.

Sources:

1: Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side - Symantec (Security.com)

2: China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud - The Hacker News

3: 'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft - Dark Reading

Jewelbug APT: China-based group runs espionage and crypto fraud - CyberMaterial

COLLECTION GAPS

UNCLASSIFIED // OPEN SOURCE