US indicts members of Russian spy cell for plotting assassinations on US, European soil

IndictmentTHE UNITED STATES DEPARTMENT of Justice unsealed last week charges against members of an alleged Russian intelligence network that planned a series of targeted assassinations in the United States and Europe. According to the indictment, the accused are part of a broad effort by the Russian state that amounts to a “global assassination network”—termed “intelligence services of the Russian Federation”, or “RIS”, network.

Three of the accused are believed to be senior members of the RIS network. They are: Yuri Khrameev, 63; his biological son, Kirill Khrameev, 27; and Oemis Romagoza Durruthy, 35. The elder Khrameev is a retired intelligence officer who claims to have reached the rank of colonel and has stated at least once that he worked alongside Russian President Vladimir Putin in the past. The younger Khrameev is believed to hold a mid-level rank in Russia’s Federal Security Service (FSB). The indictment describes Durruthy as a well-known member of the Cuban expatriate community in Russia, who has operated internationally as a member of the RIS network.

The fourth suspect is named as Yaidel Delgado Suarez (known as “the Viking”), who, like Durruthy, is a Cuban expatriate living in Russia. The remaining suspect is named as Angel Eduardo Castro, a 22-year-old Venezuelan. Notably all five suspects remain at large and are believed to reside in Russia. The Khrameevs and Durruthy are Russian citizens. Durruthy is also a Cuban national, as is Suarez—the latter’s status described in the indictment as that of “a Cuban national living in Russia”. Castro is referred to as a “Venezuelan national living in Russia”. It is therefore not known whether Suarez and Castro also hold Russian citizenship—though they most likely do.

According to the indictment, in the summer of 2026 Suarez and Castro recruited a Venezuelan citizen who was living in the New York area. The unnamed Venezuelan, who is referred to in the indictment as “Resident 1”, agreed to engage in reconnaissance activity in the vicinity of a house where the RIS network believed an exiled Russian dissident resided. In exchange for his services, “Resident 1” was promised between $1,000 and $1,500. The recruit was also offered $40,000 in exchange for assassinating the RIS network’s target, but appears to have declined the offer. Read more of this post

Germany charges businesswoman with espionage, expels her alleged Russian handler

Russian embassy in GermanyGERMAN FEDERAL PROSECUTORS HAVE formally charged a businesswoman with espionage on behalf of Russian intelligence, claiming she was tasked with gaining access to political and military circles in Germany. The woman, 56, officially identified only as Ilona W., is believed to hold German, Russian, and Ukrainian citizenship. She was arrested on January 21, 2026, and remains in pre-trial detention. The indictment was filed by Germany’s Federal Public Prosecutor’s Office on September 7, 2026.

The woman reportedly ran a consulting firm in Berlin and chaired a lobbying association. Through her role, she allegedly gained substantial access to elite political and military spheres across Germany. Prosecutors allege she had been in contact with a Russian intelligence officer stationed at the Russian Embassy in Berlin since October 2023. Throughout this time, it is alleged she provided her handler with intelligence on high-value political events. This information enabled him to attend some of these events under a false identity, with the aim of cultivating contacts for intelligence purposes.

The woman reportedly attended the events herself in order to identify and recruit potential contacts and targets—particularly from Germany’s Defense ministry and defense industry. Prosecutors claim she “compiled background information on participants in high-profile political events and gathered information on arms industry sites, drone tests and planned deliveries of drones to Ukraine”. The woman was also photographed at the December 2025 German-Ukrainian Economic Forum in Berlin, seated several rows behind Ukrainian President Volodymyr Zelenskyy and German Chancellor Friedrich Merz. It is also claimed the alleged spy cultivated a former head of the German Air Force’s 61st Test and Evaluation Center and a retired officer from Büchel Air Base, which stores United States nuclear weapons. Neither individual was detained and it remains unclear whether she obtained valuable intelligence from either of them.

The woman’s arrest triggered an immediate diplomatic confrontation between Berlin and Moscow. Within 72 hours of her detention, the German government expelled a Russian diplomat, identified as Andrei Mayorov, a colonel at the Main Directorate of the Russian Armed Forces’ General Staff—commonly known as GRU. Mayorov was serving as a deputy military attaché at the Russian Embassy in Berlin. He is accused of directing the alleged spy’s intelligence-gathering activities. His expulsion drew strong condemnation from Moscow, which vowed to retaliate.

This case reflects a broader pattern of Russian intelligence activity across Europe following the 2022 Russian invasion of Ukraine, which blurs the line between legitimate diplomatic activity and covert intelligence-gathering.

Author: Molly Jones | Date: 19 September 2026 | Permalink

Spanish NATO officer suspended from duty for dating Russian-born woman

Northwood Allied Maritime Command (MARCOM)A MILITARY OFFICER FROM Spain—a North Atlantic Treaty Organization (NATO) member—has been suspended from duty following an investigation into his relationship with a woman born in the former Soviet Union, amid fears she may have been spying for Moscow.

The unidentified Spanish naval commander, a married father of two, served at the Allied Maritime Command (MARCOM) at Northwood Headquarters in Hertfordshire, United Kingdom. MARCOM duties include the monitoring of Russian submarines, warships operating in United Kingdom waters and tracking sanctioned oil tankers from the Russian ‘shadow fleet’—a network of tankers used by the Russian state to clandestinely transport crude oil and evade international sanctions.

The Spaniard reportedly met Janina White, 49, on the online dating app Tinder in October 2024. White is believed to have been born in the Soviet Union but relocated to Poland and then to the United Kingdom as a teenager. She currently resides in Romford, London and holds joint Polish-British nationalities. Shortly prior to entering into a romantic relationship with the Spanish naval commander, White reportedly split from her British husband. The NATO commander is also believed to have separated from his wife shortly before starting a relationship with White.

Initial concerns were raised in December 2024 when, according to court documents, the couple attended a Christmas function at Northwood Headquarters. The following day, White reportedly accompanied her boyfriend to Oeiras, Portugal, while he attended an official meeting at Naval Striking and Support Forces NATO. The facility serves as NATO’s primary platform for integrating United States maritime forces into the Alliance’s operations. White maintains this was her only visit of substance to a NATO facility and insists she never entered classified areas. Read more of this post

German investigators uncover suspected Russian spy weapons cache near Berlin

Brandenburg an der HavelGERMAN INVESTIGATORS SUSPECT THAT a hidden weapons cache discovered in a forest near Berlin was intended to be used by Russian intelligence operatives to carry out assassinations on German soil. The discovery of the cache was reported late last week by several German news outlets, including the Süddeutsche Zeitung newspaper and the North German Broadcasting (NDR) and West German Broadcasting (WDR) public television stations.

According to the reports, the discovery of the weapons cache is linked to the arrest of a Russian intelligence operative in Romania in 2025. The operative, who is believed to have assembled and hidden the weapons cache, revealed its existence under interrogation. Acting on this information, authorities in Germany found the cache, which had been hidden in a wooded area located on the border between the city of Berlin and Brandenburg.

The cache consists of at least two handguns and is “professionally assembled”, according to reports. German authorities believe that the weapons were hidden for future use by agents of the Russian government intent on carrying out “kinetic operations” on German soil or in nearby European states. Upon discovering the weapons, German investigators disabled them and fitted them with geolocation devices in order to monitor them. They also placed the area around the hidden weapons cache under electronic surveillance.

After waiting for several months, they determined that the intended users of the weapons were unlikely to retrieve them—possibly because they were aware that their location had been breached. They therefore decided to terminate the surveillance operation and publicly announce the discovery of the weapons. The Office of the German Federal Prosecutor is now preparing to bring charges involving conspiracy to perpetrate serious criminal acts against the security of the state.

Author: Joseph Fitsanakis | Date: 24 August 2026 | Permalink

Iranian attacks on CIA facilities in Gulf prompts probe into Russian assistance

Iran UAV droneINTELLIGENCE ANALYSTS IN THE United States are looking into the possibility that Russia may have given Iranian targeters information about the location of secret Central Intelligence Agency (CIA) facilities in the Gulf. According to the Reuters news agency, Iran has managed to strike “several” CIA facilities in at least three countries in the Middle East in the past few months. Some of the strikes appear to have been surgically targeted at specific buildings, and even parts of buildings.

The CIA maintains official stations inside American embassy facilities throughout the Gulf. But the agency also manages an extensive network of offices, logistics hubs, safe houses, and surveillance or other operational facilities throughout the region. The location of these facilities is highly classified and compartmentalized even within the CIA itself. According to intelligence sources cited by Reuters, few nations other than Russia possess the necessary resources to map the precise locations of CIA facilities and the desire to share them with Tehran.

Citing “four people familiar with US intelligence”, Reuters said that Iran has managed to successfully target “more than one and fewer than a dozen” CIA facilities in the Gulf since March. Among them is a secret facility in Iraq, as well as the CIA station in Saudi Arabia, which is located inside the US embassy complex in Riyadh. According to reports, Tehran deployed an advanced version of its Shahed and Mohajer drones to demolish the exterior wall of the CIA station before another set of kamikaze drones burst into the interior of the facility. Some analysts believe that the kinetic capabilities of the drones used in the attack had been enhanced using Russian technical expertise.

The Reuters report added that Moscow has a longstanding intelligence-sharing relationship with Iran and has been known to provide Tehran with targeting information and other forms of support. This relationship only strengthened since the onset of the current war between the US, Israel, and Iran. However, the report states that intelligence officials have yet to draw firm conclusions about Russia’s precise role in the Iranian attacks on CIA facilities.

Author: Joseph Fitsanakis | Date: 23 July 2026 | Research credit: M.J. | Permalink

Russian spies hacked security cameras to monitor weapons shipments to Ukraine

CCTV cameraSTATE-SPONSORED RUSSIAN HACKERS compromised surveillance cameras in the Netherlands in an effort to monitor the transportation of weapons to Ukraine, according to a report issued by the Dutch government. The compromised cameras were located across routes used by North Atlantic Treaty Organization (NATO) forces to transport weapons to Kyiv, according to the report.

The revelation is contained in a joint communique issued by the two primary intelligence agencies of the Netherlands—the Military Intelligence and Security Service (MIVD) and the General Intelligence and Security Service (AIVD). It states that Russian hackers targeted security camera systems—most of them belonging to private businesses—located along transportation routes that are frequented by NATO military convoys heading to Ukraine.

Access to the camera feeds enabled Russian intelligence to identify the precise routes used by NATO military convoys and to monitor the types of equipment being transported to Ukraine. Ground-level security cameras also offered an important intelligence advantage over satellite and drone imagery by providing close-range views of vehicles and cargo, revealing operational details that overhead collection platforms often fail to capture.

The communiqué does not specify the exact number of compromised security cameras, noting only that it was “small”. Nor does it identify the specific transportation routes covered by the affected cameras. It does, however, confirm that the compromised systems were positioned along military logistics routes used to support NATO assistance to Ukraine. It further notes that the cameras were compromised as part of a “large-scale Russian operation” that aims to monitor, and if possible stop, NATO military assistance to Ukraine.

Author: Joseph Fitsanakis | Date: 14 Jul 2026 | Permalink

Investigation uncovers previously unknown Russian covert action unit

Valery GerasimovA JOINT PROJECT BY the German newsmagazine Der Spiegel and the investigative website The Insider has uncovered the existence and inner workings of a previously unknown Russian intelligence and cover action unit. The unit’s formal name is Military Unit 75127, but it is known within Russia’s intelligence establishment as Center 795. The Russian government reportedly created the unit in December 2022—less than a year following the Kremlin’s full military invasion of Ukraine.

By mid-2023, Center 795 was “fully staffed”, with its ≈500 officers coming mostly from the Main Directorate of the Russian Armed Forces’ General staff (known as GU or GRU). Other Center 795 officers came from ALPHA and VYMPEL—covert action units belonging to the Special Purpose Center of the Russian Federal Security Service (FSB). A smaller number of officers came from the Russian Armed Forces, the Federal Protective Service, and from the ALPHA Group of the Belarussian security service, known as KGB.

The structure of Center 795 features three directorates: Intelligence, Combat Support, and Assault Operations. The Directorate of Intelligence consists of nine distinct departments tasked with—among other things—collecting and analyzing intelligence from social media platforms, conducting reconnaissance using satellite networks and drones, carrying out signals intelligence, as well as executing human intelligence and covert operations, including assassinations and abductions.

The Directorate for Combat Support is staffed with explosive, air defense, armored warfare, and artillery operatives. It also maintains combat units that conduct technical maintenance, logistics, fortification, and other specialized tasks. The Assault Operations Directorate consists of four departments, which appear to conduct strictly compartmentalized functions that include airborne tasks.

Notably, unlike other special activities units in Russia’s intelligence arsenal, Center 795 does not appear to reside within the GRU. Instead, it appears to operate independently of military intelligence oversight and to report directly to General Valery Gerasimov (pictured), Chief of the Russian Armed Forces’ General Staff of and First Deputy Minister of Defense, or to one of his subordinate deputy defense ministers.

According to the investigative reports, the existence of Center 795 was revealed when one of its officers, Denis Alimov, used Google to translate a message sent to him by a Serbian operative living in the United States. This allowed the United States Federal Bureau of Investigation to use a Foreign Intelligence Surveillance Court (FISA) warrant and access the Google Translate transcripts. Alimov was eventually arrested in Bogotá, Colombia, on February 24, 2026, after arriving there on a Turkish Airlines flight from Istanbul, Turkey. He is currently awaiting extradition to New York.

Author: Joseph Fitsanakis | Date: 16 March 2026 | Permalink

Poland to probe alleged ties between Jeffrey Epstein and Russian intelligence

Donald Tusk

THE GOVERNMENT OF POLAND has announced plans to launch an investigation into the possibility that an international sex trafficking ring set up by the late financier and sex offender Jeffrey Epstein was a “honey trap” set up by Russian intelligence to entrap “the elites of the Western world,” according to Poland’s Prime Minister Donald Tusk.

Tusk announced the commencement of what he referred to as a “special investigation” at a press conference on Wednesday, following a senior-level government meeting. He told reporters that the investigation would be led by members of the Office of the Prime Minister in association with the Ministry of Justice and the Polish intelligence services.

In 2008 a Florida court convicted Epstein—a jet-setting financier with links to hundreds of prominent individuals in finance, politics, industry, and academia—for sex offences. The disgraced financier was found dead in his jail cell in 2019. Prosecutors in the United States say they have identified over 100 victims of Epstein’s sex-trafficking ring, but some estimates claim that as many as 1,000 other victims have yet to come forward.

At last week’s press conference, a stern-looking Tusk pointed to Epstein’s large fortune, describing it as “unexplained” and adding that it raised important questions about the late financier’s links with state actors. He reminded his audience that “a growing number of commentators and experts assume that it is highly probable that this pedophilia scandal was a premeditated operation by the Russian KGB”—a term still frequently used in Eastern European countries to refer to the post-Soviet intelligence community.

The operation may have been a “so-called ‘honey trap’, a sweet bait, a trap set for the elites of the Western world, primarily the United States,” Tusk said. The Polish prime minister then added: “I don’t need to tell you how serious the increasingly likely possibility that Russian intelligence services co-organized this operation is.” Among other things, it could “mean that they also possess compromising materials against many leaders still active today.” He added that investigators would systematically review and assess “every document currently available in the public domain.”

In a social media post later that day, Russian businessman Kirill Dimitriev, who last year was appointed by Russian President Vladimir Putin as Russia’s special presidential envoy on foreign investment and economic cooperation, dismissed the Polish government’s move. According to Dimitriev, all allegations about connections between Epstein and Russian intelligence are “lies” spread by “leftist elites.”

Author: Ian Allen | Date: 06 February | Permalink

Former deep-cover spy leads Kremlin’s efforts to woo Indian high-tech sector

Andrei Bezrukov A FORMER DEEP COVER Russian intelligence officer, whose cover was blown in 2010 when he was arrested in the United States, is spearheading efforts by the Kremlin to secure investments by India’s technology sector. The spy, Andrei Bezrukov, was recruited by the Soviet Committee for State Security (KGB) in the late 1970s or early 1980s—most likely alongside his wife, Elena Vavilova. For several years, the married couple lived in several countries, including Canada and France, before arriving in the United States in 1999 using fraudulently obtained Canadian passports.

Posing as Donald Heathfield and Tracey Foley, Bezrukov and Vavilova were among 10 Russian non-official-cover intelligence officers arrested by the Federal Bureau of Investigation (FBI) in June 2010. They were eventually swapped with Moscow for several Western spies held in Russian prisons. After returning to Russia, Bezrukov and Vavilova received the Order “For Merit to the Fatherland” 4th Class, which is Russia’s second-highest state decoration. They also entered state-sponsored employment, with Bezrukov advising the Rosneft Oil Company—Russia’s second-largest corporation—and teaching at the Moscow State Institute of International Relations.

In June 2025, Bezrukov apparently represented the Russian state at the 28th Saint Petersburg International Economic Forum (SPIEF)—often referred to as “Putin’s Davos”. According to the Washington Post, Bezrukov’s apparent role at SPIEF was to network with Forum representatives from India’s advanced technology sector, allegedly on direct orders by the administration of Russian President Vladimir Putin.

The event, which went under the tagline “Shared Values as a Foundation for Growth in a Multipolar World”, gathered nearly 20,000 delegates from 140 countries. The Kremlin touted it as evidence of the West’s failure to isolate Russia following its invasion of Ukraine. It also served as part of a set of broader efforts by the Kremlin to prevent the Russian economy from sliding into a recession by seeking to develop alternative energy markets and strengthening economic and political ties to the Global South.

India is by far the largest of a group of countries seen as “friendly” by Russia, which could potentially help revitalize the Russian economy, largely through the International North–South Transport Corridor (INSTC). The 14-year-old agreement aims to interconnect a transnational transportation network connecting Russia and India with import-export routes in Central Asia the Middle East, and Europe. Experts claim that the INSTC is the logistical backbone of Russia’s efforts to salvage its economy from the growing pressures of the war in Ukraine.

The Post reported that Bezrukov denied that he is still an employee of Russian intelligence agencies when approached and asked about his past by Western journalists.

Author: Joseph Fitsanakis | Date: 08 December 2025 | Permalink

France arrests members of humanitarian charity accused of being a Russian front

SOS DonbassFRENCH AUTHORITIES HAVE ARRESTED three individuals and placed a fourth person under supervision after scrutinizing the operations of a humanitarian organization suspected of being a front for Russian intelligence. The arrests were announced on Tuesday by the General Directorate for Internal Security (DGSI), France’s domestic security agency.

The organization in question was registered at the Pyrénées-Atlantiques prefecture of southwestern France in 2022 under the name “Sud Ouest Solidarité Donbass” (“Solidarity for South-West Donbass). This was abbreviated in the organization’s marketing material as “SOS Donbass”. Its expressed mission is to raise funds in support of civilians in Ukraine’s war-torn region of Donbass, most of which is currently under Russian military control.

The DGSI said it began monitoring the activities of SOS Donbass in early 2025. It claims that members of the organization used the cover of humanitarian work in order to spread Russian propaganda in France on the orders of Moscow. It also claims that they attempted to collect “economic information” from executives of French firms. At least one member of the group participated in a concerted campaign of putting up posters in downtown Paris, bearing the slogan “Russia is not my enemy” (pictured), according to the DGSI.

The director of SOS Donbass, identified in French media reports as “Anna N.”, 40, who was born in Russia but lives in France, was arrested by DGSI on November 17. Another Russian-born member of SOS Donbass, “Vyacheslav B.”, also 40, was arrested on the same day. A third individual, “Vensan B.”, 63, who is French-born and lives in Paris’ northern Seine-Saint-Denis suburb, was arrested the following day. A fourth individual, identified as “Bernard F.”, 58, has been placed under strict supervision and is required to report to the police weekly.

According to France’s Le Parisien newspaper, Anna N. and Vyacheslav B. have been formally charged with “colluding with a foreign power”, “conducting activities to gather information on the interests of the nation for a foreign power” and “actions likely to harm the fundamental interests of the nation”, which carry sentences of up to 10 years.

Author: Ian Allen | Date: 26 November 2025 | Permalink

Austrian prosecutors charge ex-intelligence officer accused of spying for Russia

Landesgericht für Strafsachen Wien Vienna Regional Court for Criminal MattersPROSECUTORS IN VIENNA HAVE charged a former intelligence officer with spying for Russia in a high-profile case that has had broad political ramifications in Austria and abroad. The criminal case centers on Egisto Ott, a former employee of Austria’s Federal Office for the Protection of the Constitution and Counterterrorism (BVT). The BVT operated as Austria’s primary domestic intelligence agency from 2002 until its dissolution in 2021.

Ott was first arrested in March 2021, but was soon released after Vienna’s state court ruled that the accused no longer had access to classified information, and was thus not a persistent threat to the state. Ott was arrested again in March 2024 on suspicion of having maintained contact with Russian intelligence officers even following his 2021 arrest and release, and of trying to sell classified information after his release. As intelNews reported a year ago, Ott was released again from pre-trial detention in June 2024, in a decision that raised eyebrows.

Now Ott is facing charges of colluding with an unidentified police officer to “support an intelligence agency” of a foreign country “to the detriment of Austria”, according to the public prosecutor. Ott is also accused of having engaged in bribery, misuse of his office, and of having broken Austria’s Official Secrets Act. Among several instances of engaging in espionage, Ott is accused of having given Russian intelligence an encrypted SINA-workstation laptop of the type used by government employees to access classified information remotely.

Ott and his lawyers have denied he was involved in espionage and have vowed to confront all charges against him in court.

Author: Joseph Fitsanakis | Date: 02 September 2025 | Permalink

Russian hacker group using Internet service providers to spy on foreign embassies

Hacking cyber - JFA HACKER GROUP LINKED to Russia’s Federal Security Service (FSB) has compromised Russia’s domestic internet infrastructure and is using it to target foreign diplomats stationed in Russia. According to a report, published last week by Microsoft Threat Intelligence, the hacker group behind this operation is Turla, also known as Snake, Venomous Bear, Group 88, Waterbug, and Secret Blizzard. Analysts have linked the group with “some of the most innovative hacking feats in the history of cyberespionage”.

Turla began its attempt to compromise a host of Russian internet service providers in February, according to Microsoft’s report. The group’s apparent goal has been to gain access to the software that enables Russian security agencies to legally intercept internet traffic, following the issuance of warrants by judges. This software is governed by Russia’s System for Operative Investigative Activities (SORM), which became law in 1995, under the presidency of Boris Yeltsin. All local, state, and federal government agencies in Russia use the SORM system to facilitate court-authorized telecommunications surveillance.

According to Microsoft, targeted Internet users receive an error message prompting them to update their browser’s cryptographic certificate. Consent by the user results in the targeted computer downloading and installing a malware. Termed ApolloShadow by Microsoft, the malware is disguised as a security update from Kaspersky, Russia’s most widely known antivirus software provider. Once installed the malware gives the hackers access to the content of the targeted user’s secure communications.

The Microsoft report states that, although Turla has been involved in prior attacks against diplomatic targets in Russia and abroad, this is the first time that the hacker group has been confirmed to have the capability to attack its targets at the Internet Service Provider (ISP) level. In doing so, Turla has been able to incorporate Russia’s domestic telecommunications infrastructure into its attack tool-kit, the report states. The report does not name the diplomatic facilities or the countries whose diplomats have been targeted by Turla hackers. But it warns that all “diplomatic personnel using local [internet service providers] or telecommunications services in Russia are highly likely targets” of the group.

Author: Joseph Fitsanakis | Date: 02 August 2025 | Permalink

Researchers uncover secretive Russian spy unit by studying its commemorative badges

FSB RussiaA GROUP OF RESEARCHERS in Finland have managed to outline the structure and geographic footprint of a highly secretive Russian signals intelligence (SIGINT) unit by studying commemorative badges issued by the Russian government. The research group, known as CheckFirst, specializes in open-source (OSINT) investigative reporting and works to combat online disinformation.

Earlier this month, CheckFirst published its latest report titled “OSINT & Phaleristics: Unveiling FSB’s 16th  Center SIGINT Capabilities”. The 36-page report focuses on the study of Russian government-issued commemorative badges—also known as challenge coins—relating to Center 16 (16-й Центр). Also known as  Military Unit 71330, Center 16 is a secretive SIGINT unit that houses most of the cyber espionage capabilities of Russia’s Federal Security Service (FSB).

Challenge coins are custom-made medallions given by military, intelligence, and government agencies to recognize service, commemorate achievements, or build morale. Originating in the United States military during World War I, and popularized during the Vietnam War, challenge coins are routinely exchanged in ceremonies or offered to personnel as tokens of camaraderie and loyalty within a specific unit or mission.

Often regarded as collectors’ items, challenge coins from various agencies are often resold on websites such as eBay, or displayed online on websites maintained by private collectors. CheckFirst researchers tracked down several versions of Center 16 challenge coins found on a variety of publicly available websites, as well as on the websites of Russian challenge coin manufacturers, such as GosZnak, SpetsZnak, or Breget.

Based on this OSINT methodology, CheckFirst researchers were able to identify 10 distinct directorates within Center 16, which specialize on various aspects of defensive and offensive cyber espionage. Previously only a single Center 16 directorate had been identified in the unclassified domain. Moreover, by examining geographic indicators found on several of challenge coins, such as maps or coordinates, CheckFirst researchers were able to partly map out the geographic structure of Center 16, locating nearly a dozen interception facilities throughout Russia.

Author: Joseph Fitsanakis | Date: 21 July 2025 | Permalink

Leaked counterintelligence document reveals Russian concerns about Chinese spying

FSB RussiaA LEAKED REPORT AUTHORED by Russia’s primary counterintelligence agency reveals deep concern in national security circles about the intensity of Chinese spying against Russian interests, according to The New York Times. The paper said last week that the leaked report, which was produced by Russia’s Federal Security Service (FSB) between 2023 and 2024, offers “the most detailed behind-the-scenes view” of Russia’s counterintelligence concerns about China.

Following the death of Soviet Premier Joseph Stalin, the two communist countries became sworn enemies and nearly went to all-out war against each other. But in recent years Moscow and Beijing put aside their differences, prompted by their mutual desire to challenge the geopolitical supremacy of the United States and bring about a multipolar world. Since 2022, when Moscow resumed its military invasion of Ukraine, Beijing has stood firmly by the Kremlin. China has become the largest importer of Russian energy and has provided the Russian military with much-needed advanced technology. The relationship between the two neighboring nations appears to be deeper than ever before.

But according to a recently leaked report, Russia’s national security establishment is deeply concerned about Chinese efforts to dominate its ally by spying against it. The eight-page report outlines “ENTENTE-4”, a counterintelligence program run by the 7th Service of the FSB’s Department for Counterintelligence Operations. The department is known by its Russian acronym, DKRO. The DKRO’s 7th Service is tasked with counterintelligence planning and operations against Asian countries, with China being its primary target.

According to The Times, the DKRO produced the report sometime between 2023 and 2024. The document appears to have been intended for distribution to the FSB’s field offices across Russia. It was acquired by ARES Leaks, a cyber criminal syndicate, which posted images of the document on the Telegram messenger application. The paper said it shared the leaked document with “six Western intelligence agencies”, all of which assessed it to be genuine. Read more of this post

Russian spies operated in Portugal using forged Brazilian papers, report claims

Porto PortugalTWO RUSSIAN SPIES USED forged documents acquired in Brazil in order to live in Portugal for years and use it as a base from where to conduct espionage, according to an investigation by Portuguese counterintelligence. The spies were husband-and-wife team Vladimir Aleksandrovich Danilov and Yekaterina Leonidovna Danilova, both in their 30s. According to The New York Times, they appeared in Portugal in 2018 using the names Manuel Francisco Steinbruck Pereira and Adriana Carolina Costa Silva Pereira.

Portuguese weekly newspaper Sol said on Saturday that Danilov used a Brazilian passport and supplied authorities with documentation showing his father was a Portuguese national. This allowed Danilov to eventually obtain Portuguese citizenship. Although Danilova did not apply for Portuguese citizenship, she was granted permanent residency by the European Union country. These credentials enabled the spies to move freely in the European Union’s 27 member-states without restriction.

In 2022 the Brazilian Federal Police, with the assistance of United States intelligence agencies, launched a lengthy investigation into the activities of several Russian spies who operated in Brazil in recent years. The spies appear to have used concocted Brazilian identities in order to operate around the world undetected. The investigation eventually incorporated counterintelligence services from as many as eight countries, including Portugal, according to Sol.

So far the Portuguese investigation has revealed that the Danilovs conducted a variety of espionage operations in the coastal city of Porto, which is Portugal’s second-largest urban center following the capital Lisbon. Using Porto as an operational base, the couple traveled extensively around the world using their Brazilian and Portuguese passports. Each time they were able to return to their home in Porto “without encountering any issues”, Sol reports. The two spies have vanished and their current whereabouts are unknown.

Author: Joseph Fitsanakis | Date: 26 May 2025 | Permalink