Author: Incident Response Team

Russia Bombs Maternity Ward & Children’s Hospital in Mariupol As Part of Siege

A medical complex in the southern city of Mariupol, Ukraine, has been destroyed in a reported airstrike on 9 March 2022, social media videos show. It is virtually certain that…

A medical complex in the southern city of Mariupol, Ukraine, has been destroyed in a reported airstrike on 9 March 2022, social media videos show. It is virtually certain that Russia has conducted the attack. Russian forces have encircled the city since 1 March, uniting advancing forces from Crimea with those in Donetsk oblast, and enjoy local air superiority. Since the pincer move was completed, Russian troops have resorted to unrestricted, punitive strikes to force the Ukrainian soldiers and population in Mariupol to surrender.

THE ATTACK 

Eyewitnesses report that the strike was carried out by aircraft. The blast carved a giant crater in the middle of the medical complex, which the New York Times estimates to be 10 feet deep. If the attack was air-launched, Russia likely employed a FAB-series air-dropped bomb, likely FAB 500 (the numbers indicate its mass in kilograms). Russia has already used FAB 500 bombs in Chernihiv, including against residential areas. The possibility of a surface to surface attack also exists, however, one single artillery shell is unlikely to have caused this impact mark. No weapon debris has been documented so far. 


A regional official told Ukrainian media that 17 people were injured, including staff and patients. No deaths have been reported so far, according to Pavlo Kyrylenko, the head of the Donetsk regional administration, as quoted by Interfax

FACILITY AND LOCATION

Geolocation confirms that the building complex seen in the footage is indeed a medical facility, appearing as Dytyacha Konsul’tatyvno-DIahnostychna Poliklinika (translates in Children’s Consulting and Diagnostic Polyclinic) on Google Maps, located in Mariupol. As photos and open source information indicate, a maternity ward is also part of the medical complex. 

It is possible that Russia deliberately targeted this facility as part of its siege tactics. As extensively seen during Russia’s siege operations in Syria, Russian forces purposely target medical facilities to deprive the local population and defenders of healthcare and other key services. Such attacks also serve a psychological purpose: to terrorize the population into submission. Thrown into a humanitarian disaster, an attrited population and defending force are less capable of combat and more likely to surrender. 

MARIUPOL UNDER SIEGE

The hospital attack is just one of the many strikes that Russia has conducted on Mariupol on 9 March, as it tries to seize the city. Maxar’s very high-resolution satellite imagery reveals the extent of damage caused by Russian shelling in the past 24 hours. As the photos show, residential homes, apartment complexes, and shopping centers have been badly damaged and destroyed. The deliberate targeting of shopping centers that include hypermarkets and other large grocery stores aims to create a food shortage. This is another siege tactic that the Russian military uses to deteriorate living conditions and force a surrender.

Imagery from Maxar Technologies shows the extent of damage in Mariupol as of 9 March 2022 (compilation by T-Intelligence)

Mariupol was under a limited ceasefire negotiated between Ukraine and Russia on Sunday to allow evacuations. However, Russia has breached the ceasefire by shelling the humanitarian corridors, stalling the evacuation in the process. 

The collapse of Mariupol will enable Russia to link Crimea with the separatist territories in Donbas by land, which has likely been a Russian aim since the 2014 Donbas offensive. Back in 2014-2015, Mariupol represented the maximum point of advance of the Russian military during the Donbas offensive. Ukrainian forces managed to stop the Russian advance and keep Mariupol. 

Russian control of Mariupol will also leave Ukraine without access to the Azov Sea, as Russia has already captured 99% of the coastline.  


 

Comments Off on Russia Bombs Maternity Ward & Children’s Hospital in Mariupol As Part of Siege

T-Intell’s OSINT Training Marks One Year Anniversary

On 15 November 2021, T-Intelligence’s sister branch and training service, Knowmad OSINT, marked one year since its inception. Around 100 people went through the Knowmad OSINT training to acquire or…

On 15 November 2021, T-Intelligence’s sister branch and training service, Knowmad OSINT, marked one year since its inception. Around 100 people went through the Knowmad OSINT training to acquire or enhance their OSINT skills during the past year. Students, career starters, seasoned professionals, and hobbyists took up our course. Various Individuals, private companies, and government-sector agencies entrusted us with OSINT training, including one of the world’s leading postgraduate programs in Security, Intelligence, and Strategic Studies

 


When planning started for the course, seeing the increased interest on the civilian job market for OSINT skills, we based our training design on three main pillars:

  1. OSINT for all: we wanted our course to be accessible to beginners and bring value to established professionals. In addition, our content and lessons would be exclusively based on openly and freely available resources so that participants do not stumble across paywalls or other barriers. 
  2. INT back into OSINT: First and foremost, OSINT is an intelligence practice at its core. Our training underscores this aspect and takes an interdisciplinary and analytical approach to OSINT.
  3. More than just an INT: While honouring OSINT’s original mission in national security and defense, we choose to take an innovative approach to the field. We wanted our course to embody Mark Lowenthal’s idea from the late 1990s, namely that OSINT is slowly becoming a facet of the other collection disciplines. As a result, our course covers the open-source applications of IMINT, GEOINT, SIGINT, and HUMINT/SOCMINT.

We’re happy to report that our training helped people break into the intelligence field, climb the job ladder or find their calling as early career-starters. We want to thank everyone, not only our Knowmads but also our T-Intelligence readers, for tuning in for our periodical articles and engaging with us on social media. It’s been a blast! 

Moving forward into Year Two, Knowmad OSINT will continue to grow and proliferate OSINT expertise to both the public and clandestine communities. T-Intelligence will continue to provide the OSINT action it has done for the past five years. 

If you or your organization is interested in developing OSINT skills, send us a message! 

The T-Intelligence & Knowmad OSINT team

Comments Off on T-Intell’s OSINT Training Marks One Year Anniversary

IS-K Never Left

Yesterday’s deadly suicide attacks at Kabul airport serve as a grim reminder that “Islamic State-Khorasan province” (IS-K) is still strong, despite the group losing its physical territory in eastern Afghanistan. …

Yesterday’s deadly suicide attacks at Kabul airport serve as a grim reminder that “Islamic State-Khorasan province” (IS-K) is still strong, despite the group losing its physical territory in eastern Afghanistan. 

TWIN BOMBINGS NEAR KABUL AIRPORT

Over 70 civilians and at least 12 U.S. service members died in the twin suicide bombing that rocked Abbey gate at Hamid Karzai International Airport in Kabul (KBL) and the nearby Baron hotel on Thursday (26 August 2021). Taliban fighters were reportedly also wounded in the attack. 

Map showing Abbey gate and Baron hotel via Maxar Technologies (basemap) and NPR (annotations)

The first explosion took place at the “Abbey gate,” the airport’s southeast entrance, where thousands of Afghans gather daily to be processed for evacuations. Following the blast, a “number” of IS-K gunmen opened fire on civilian and military forces at Abbey gate, according to the U.S. Central Command (CENTCOM). Videos that surfaced online show the grim aftermath of the attack, with dozens of wounded or killed civilians floating in the nearby drainage ditch. 

Very high resolution imagery shows crowds of civilians gathered at Abbey gate (source: Maxar Technologies)

The second attack took place near Baron hotel, which is just a few meters from Abbey gate. This attack was also conducted through a person-borne improvised explosive device (PBIEV), according to CENTCOM. Baron Hotel served as an evacuee processing center and was therefore frequented by foreign citizens, Afghans seeking extraction, and international military staff, mainly British. 

 

ISIS-K claimed the attack through the group’s media wing Amaq Agency and said that one of its fighters detonated a suicide vest only five meters away from U.S. Marines posted at Abbey gate. The group has not claimed responsibility for the second attack near Baron hotel, although there is no doubt that IS-K is behind it too.  

IS-K: THE EXPECTED (AND IMMINENT) THREAT

On the day of the attack, the United States Department of State warned Americans remaining in Afghanistan to avoid Kabul airport and Americans at the airport to leave the site immediately. The intelligence was solid and indicated an imminent threat. 

For days, the U.S. intelligence community warned that IS-K is likely to take advantage of the chaos in Kabul and launch mass-casualty attacks on the crowds of Afghans and U.S. soldiers at Hamid Karzai International Airport. The looming IS-K threat was a significant factor for President Biden to decide against extending the evacuations beyond August 31st.

The threat assessment did not come as a surprise for seasoned analysts, given the security vacuum resulting from the Taliban’s takeover of Kabul and the chaotic international military withdrawal. Mass-casualty attacks have been ISIS-K signature modus operandi in Afghanistan and Pakistan since the offshoot emerged in 2015-2016. The situation in Kabul presented an opportunity for the group to strike the U.S., rival the Taliban, and regain media attention. 

For IS-K, Thursday’s twin bombings are also a message to Afghanistan’s new overlords (and the group’s old rivals), the Taliban. As the U.S. leaves the country, Afghanistan is up for grabs for all militant jihadi groups that want to establish sanctuaries, attract followers, and expand. 

IS-K IN AFGHANISTAN’S THREAT LANDSCAPE

IS-K has been part of Afghanistan’s security landscape for at least six years and was responsible for some of the most gruesome attacks against civilians in South Asia, including a mass casualty attack at a maternity ward in Kabul that killed over 20 doctors, nurses, mothers, and newborn babies in 2020.

IS-K fighters in Kunar province sometime in 2017 (screenshot of Amaq Agency video via Long War Journal)

Established by disenfranchised Pakistani Taliban, Islamic Movement of Uzbekistan (IMU) militants, and foreign fighters, IS-K seeks to establish an Islamic State in Central Asia (including, but not limited to Afghanistan and Pakistan), which would act as a province of the broader global caliphate once envisioned by IS “central” in Syria and Iraq. 

IS-K built its territorial foothold in the Pakistani Taliban’s and IMU’s areas of influence. The group never succeeded in capturing urban centers but did secure sanctuaries in several key valleys in the N2KL area (Nangarhar, Nuristan, Kunar, and Laghman provinces) and a few Uzbek villages in Jowjzan province.

IS-K presence in N2KL area (source: Telegraph)

Joint US-Afghan operations and a separate Taliban offensive rooted IS-K out of its safe havens in 2019-2020 – read more about that here. The Taliban can be credited with defeating IS-K in southern Nangarhar province following a series of battles described by US CENTCOM commander as a “bloody mess.” However, the group retained sleeper cells across the country, including Kabul, Jalalabad, and Herat, periodically conducting terrorist attacks. 

In the past year, IS-K saw an unexpected influx of recruits from the Afghan Taliban. Many Taliban fighters, especially those affiliated with the hardline Haqqani network, condemned the Doha peace process, slamming it as a deviation from Jihad in favor of negotiating with the enemy. 

IS-K’s message still resonates with many diehard Taliban that are unhappy with the group’s decision to allow the safe evacuation of international forces, their citizens, and Afghan allies out of Kabul. IS-K has been inciting followers and sympathizers to attack the evacuation. 

OUTLOOK

IS-K will continue to be a favorable alternative for jihadists disgruntled with the Taliban’s “moderate extremism” showcased to convince the international community that they have changed. IS-K will also continue to attract hardcore militant Salafists with an appetite for violence against the country’s Shia and other non-Sunni communities and a wish for the caliphate to spread beyond Afghanistan’s border. 

With less than four days left before the evacuation’s “z-day,” there is no reason to believe that IS-K will cease to attack. IS-K will likely try to mount new attacks against international forces and civilians at the airport, and the Taliban. As a result, international governments will probably pull the plug prematurely on their evac missions, as many countries have already formally announced an end to all airlift operations out of Kabul. 

The already chaotic withdrawal is slowly ending in a bloody disaster. 

Comments Off on IS-K Never Left

NATO Special Operators Now Exfiltrate People Directly from Kabul

Recently emerged open-source information suggests that special operations forces (SOFs) of several NATO members are now evacuating people stranded in Taliban-controlled Kabul.  STUCK IN KABUL Thousands of NATO citizens and…

Recently emerged open-source information suggests that special operations forces (SOFs) of several NATO members are now evacuating people stranded in Taliban-controlled Kabul. 

STUCK IN KABUL

Thousands of NATO citizens and Afghan associate staff are stuck in Kabul after the Taliban have established checkpoints at Hamid Karzai International Airport (KBL), the epicenter of international evacuations. Airport security – mainly consisting of international military forces – is also slow and cautious to let people in after the August 17 mayhem when thousands of Afghans overran the airport, occupying the runways and disrupting flights for hours – read our situation report here.

According to local reports, the Taliban are already going door to door, searching for Afghans that have worked with the now-defunct Afghan government or foreign forces. The Taliban have executed, tortured, and imprisoned collaborators in other cities they control, and are likely doing the same in Kabul, especially as international media attention shifts away. Foreign citizens are also in danger, and there is no guarantee that the Taliban will continue “to play nice.” 

Overview of Kabul and Hamid Karzai International Airport

DARING RAIDS

The British Special Air Service (SAS) is conducting raids in Kabul to evacuate British citizens and Afghans at risk, according to the Mirror. SAS operators are joined by Afghan translators and American special mission units, according to the same source. The rescue mission retrieved around 200 people from and around Kabul. 

French SOFs are reportedly also conducting their own operations to locate and extract French citizens and associated staff from Kabul. French President Emmanual Macron announced on Twitter that around 200 French and allied Afghans were evacuated and thanked French service members and diplomatic staff for organizing these “sensitive operations.” Two French cargo planes – one A400M and one C-130 – service the air bridge between KBL and the French military base in the UAE. 

Spain is another NATO member that is sending forces into Kabul to exfiltrate vulnerable persons. The Spanish press has identified the Grupo Especial de Operaciones (GEO/ English: Special Operations Group) of the National Police as spearheading the search & rescue efforts. GEO extracted 53 Afghan collaborators on Wednesday alone, as per an El Pais report. 

Spanish GEO escort civilians at Kabul airport (source: El Pais)

Germany will soon start exfiltrating its citizens and vulnerable associated Afghans from Kabul city, the German ministry of defense announced on Twitter. Two H-145 helicopters will arrive today at KBL and will link up with approximately 40 German SOFs from the Kommando Spezialkräfte (KSK). The KSK contingent inserted aboard the first German evacuation flight on August 17. 

The United States is missing from the list as there are no concrete reports or evidence suggesting otherwise. In fact, U.S. Secretary of Defense (ret.) Gen. Lloyd Austin said on 19 August that he “does not currently have the capability to go out and extend operations into Kabul.” Instead, Secretary Austin said that the U.S. is coordinating with the Taliban to let U.S. citizens through, although more de-confliction is needed. 

Secretary Austin’s statement is probably political, and not based on military facts. It is unlikely that special mission units like Delta Force or DEVGRU are not deployed at KBL, or that specialized U.S. Army or Marines formation are not up to the task. Alternatively, there is a slight chance that U.S. search & rescue operations in Kabul are actually taking place, but their activity is kept secret or outsourced to contractors for reasons of operations security and political deniability. 

Other countries, including non-NATO, are likely conducting similar raids, but information is sparse given the sensitive nature of these operations. Turkey, Italy, the Netherlands, Romania, and others, have also sent SOFs to help coordinate the evacuation at KBL, but there is no indication that they are traveling into downtown Kabul to retrieve their citizens and allies. 

OVER 10K TROOPS GUARD KBL

Currently, there are around 10,000 international military forces at KBL. At least 7,000 of them are U.S. forces (mainly from the 82nd Airborne Division), nearly 1,000 British, and several hundred French. Many other countries have also deployed dozens of troops to provide site security. 

International evacuations continue at a steady pace since August 17. With thousands of people still stranded outside of KBL and unable to reach the airport, the evacuation will likely last at least another week with no guarantee that all vulnerable people will make it out. 


Cover photo: A U.S. Marine Corps MV-22B Osprey lands to extract Marines assigned to Alpha Company, 1st Reconnaissance Battalion while conducting night raid operations training on Camp Pendleton, Calif., Nov. 26, 2013. The live-fire training prepared the Marines for their upcoming assignment as the Maritime Raid Force for the 11th Marine Expeditionary Unit. (U.S. Marine Corps photo by Cpl. Alejandro Pena, 1st Marine Division Combat Camera/Released)

Comments Off on NATO Special Operators Now Exfiltrate People Directly from Kabul

Russian Pipe-Layer Resumes Work on Nord Stream 2

The Russian-flagged “Fortuna” pipe-laying vessel has resumed work on the controversial “Nord Stream 2” pipeline on January 24. AIS trackers show Fortuna anchored 27 km south of Bornholm island (Denmark),…

The Russian-flagged “Fortuna” pipe-laying vessel has resumed work on the controversial “Nord Stream 2” pipeline on January 24. AIS trackers show Fortuna anchored 27 km south of Bornholm island (Denmark), where gaps remain in the 94%-completed pipeline. 

Overview of Fortuna’s location

Owned by “KVT-RUS,” a Russian company, Fortuna has been recently sanctioned by the U.S. Department of Treasury over its involvement in the Nord Stream 2 project. Any company that does business with Fortuna or its owner, whether a port that provides servicing or an insurer, risks losing access to the U.S. financial system

Thanks to Sentinel-1’s synthetic aperture radar, we can see the ship formation through cloud cover and confirm Fortuna’s location. Dated January 24, the low-res imagery shows Fortuna positioned for pipe-laying operations and assisted by tugs, and other support vessels. 

Sentinel-1 SAR shows Fortuna initiating pipe-laying operations

Fortuna left the German port of Rostock after Danish authorities cleared further constructions on Nord Stream 2 on January 15. Berlin has also greenlighted work on the pipeline in German waters. 

UNSTOPPABLE

It seems that the Nord Stream 2 will go ahead despite bipartisan U.S. sanctions, criticism from Eastern European states, and even a recent resolution passed by the European Parliament that urges Brussels to halt the project. While opposition to the project grew in Germany following Navalny’s poisoning and arrest, Chancellor Merkel remains steadfast.  

The German state of Mecklenburg-Vorpomman even plans to establish an “expandable” foundation to shield the companies involved in Nord Stream 2. The German foundation “for environmental protection” will absorb the heat of U.S. sanctions such as freezing assets, as it does not have commercial plans beyond the pipeline. As a result, the real stakeholders will be unharmed – at least in theory. This operation’s success will largely depend on the Biden administration’s willingness to sanction Germany over Nord Stream 2. 

KEY BACKGROUND

What is Nord Stream 2?

Nord Stream 2 is a submarine pipeline that will carry natural gas from Siberia to a terminal on Germany’s Baltic sea coast. Russian energy giant Gazprom owns 50% of the pipeline. Royal Dutch Shell, Uniper SE, Engie SA, and Wintershall AG hold the rest. Nord Stream 2 is 1,200 km long and will double the throughput of Nord Stream 1.  

Nord Stream 2 map (source: Gazprom)

Why did work on Nord Stream 2 stop?

U.S. sanctions temporarily froze the Nord Stream 2 pipeline. In December 2019, the Swiss company “Allseas” suspended pipe-laying operations after it came in the crosshairs of U.S. departments of State and Treasury. Since then, the Nord Stream 2 consortium has scrambled to devise countermeasures against U.S. sanctions, and searched for a new pipe-laying vessel. 

The consortium contracted Fortuna and the Gazprom-owned Akademik Cherskiy” to complete the job. T-Intelligence wrote about Akademik Cherskiy’s entrance into the Baltic Sea in March 2020, after a nine-month voyage from Russia’s far east. The pipe-layer is currently docked in Wismar, Germany. 

Why is Nord Stream 2 a problem?

  • The project strengthens Russia’s grip on European energy. Nord Stream 2 goes against NATO’s and the European Union’s energy security policies that call for diversifying suppliers so that 30 or 27 nations are not at the mercy of one supplier. As the dominant force on Europe’s energy market, Russia has a long history of using gas exports as a tool of coercion. Gas is also a significant component of the Kremlin’s broader “hybrid warfare” strategy that aims to expand its influence using means other than military. 
  • It undermines Transatlantic unity. A highly divisive topic, Nord Stream 2 exacerbated existing rifts between the U.S (supported by Eastern European states) and NATO’s European core, led by Germany. 
  • It weakens Eastern Europe. Nord Stream 2 will reduce Russia’s dependence on Ukraine and Poland to transport gas into Europe. This could open up eastern Europe to more strong-arm tactics, including further aggression against Ukraine. 

by IRT

Comments Off on Russian Pipe-Layer Resumes Work on Nord Stream 2

Azerbaijan Adds Armenian S-300 to Kill List

Azerbaijan has destroyed an Armenian S-300PS air defense system (AIFC/NATO: SA-10 “Grumble”) on 17 September 2020. The Azeri Ministry of Defense has released footage of an air strike on at…

Azerbaijan has destroyed an Armenian S-300PS air defense system (AIFC/NATO: SA-10 “Grumble”) on 17 September 2020. The Azeri Ministry of Defense has released footage of an air strike on at least two entities consistent with S-300 tractor erector launchers (TELs). The blast radius indicates that Azerbaijan has used a heavy payload, possibly the Israeli ballistic missile LORA. 

Geolocation puts the strike location in Syunik province in southeastern Armenia. The attack marks another direct engagement between Armenia and Azerbaijan outside of the disputed Nagorno-Karabakh region. 

STRIKE THREE?

This is the third time that Azerbaijan has neutralized Armenian S-300 hardware components in the past month. On 29 September, a video of what appears to be an S-300 TEL in the crosshairs of a drone was leaked online. The footage does not show the actual strike, but the target was geolocated near Xankendi, Nagorno-Karabakh – a known S-300 site. 

On October 10, the Azeri military released several videos showing the destruction of various S-300 hardware components, including two 36D6 “Tin Shield” radars and one 5P85 TEL, based in Kaghnut, Armenia. One of the radars was active and spinning during the attack. 

STRATEGIC IMPLICATIONS

The persistent targeting of Armenia’s S-300 marks a clear change in Azerbaijan’s mission objectives. After successfully employing drone warfare in Nagorno Karabakh to clear out Armenian frontline positions, Azerbaijan is now knocking down the door of Armenia’s airspace and weakening Yerevan’s defensive position. 

Armenia’s strategic deterrent depends on the notorious Iskander ballistic missile system (SS-26 “Stone ‘) for offense and the S-300 for defense. The collapse of one of these assets would significantly weaken Armenia’s hand. 


This article was made using Open-Source Intelligence (OSINT) tools and techniques. Learn how to do that too on Knowmad OSINT

Comments Off on Azerbaijan Adds Armenian S-300 to Kill List

Russia Sends Fighter Jets to Libya

Russia has deployed military aircraft to Libya to support General Haftar’s self-styled Libyan National Army (LNA), Imagery Intelligence (IMINT) from the United States Africa Command (US AFRICOM) shows. The new…

Russia has deployed military aircraft to Libya to support General Haftar’s self-styled Libyan National Army (LNA), Imagery Intelligence (IMINT) from the United States Africa Command (US AFRICOM) shows. The new intelligence confirms claims, previously made by the Government of National Accord (GNA) in Tripoli, that Haftar is receiving aerial reinforcements from Russia. 

Recently, the LNA has been caught on their heels by the GNA. Backed by Turkish airpower, the GNA has forced the LNA out of strategic positions in northwestern Libya. The GNA’s successful offensive and Turkey’s aerial onslaught have marked the most significant setback for Haftar yet. The Russian intervention aims to tip the balance back into the LNA’s favor. 



FROM RUSSIA WITH LOVE: A FOURTH GENERATION PACKAGE

The flock of Russian fourth-generation aircraft deployed to Libya consists of at least four MiG-29 multi-role fighters (NATO Reporting name: Fulcrum) and an unknown number of Su-24 (Fencer) and Su-34 (Fullback) fighter-bombers. Two Su-35 air superiority fighters (Flanker-E) of the Russian Aerospace Forces (RuAF) provided counter-air escort for the formation. 

The aircraft first relocated from Astrakhan (Russia) to Hmeimim Air Base near Latakia, Syria with a stopover at Hamadan Air Base Iran) to refuel on 12 and 14 May.

At Hmeimin Air Base, they received a new paint job to camouflage their origin and refueled before continuing to Libya on 18 May.

When they entered Libyan airspace, the unmarked Russian aircraft made another refueling stop near Tobruk. They then resumed their journey to al-Jafra Air Base on the same day. At least 14 unmarked Russian aircraft were delivered to al-Jafra using this air bridge, according to US AFRICOM. 

On the next day, satellite imagery showed a MiG-29 Fulcrum on the taxiway of the LNA-held al-Jafra Air Base. The geospatial imagery prompted extensive speculations regarding the ownership of the aircraft on social media. Some claimed that the MiG-29 is a RuAF jet. Others argued that the United Arab Emirates bought it from Belarus for Haftar’s air wing. 

While we know that the aircraft belong to the RuAF now, it is still unknown who will operate them. Faced with a massive shortage of trained personnel, the LNA has previously hired mercenary pilots for its legacy Su-22s and MiG-23s. Fourth-generation fighter jets are nevertheless a completely different league. Even the most experienced pilots require months of training to master these machines. While Russia may have sent pilots, the Kremlin traditionally prefers to operate in the shadows. Russia makes extensive use of state-backed private military corporations (PMCs) and irregular forces to do dirty work overseas instead. 

STATE-BACKED MERCENARIES 

It is noteworthy that US AFRICOM specifically identified the “Wagner Group” PMC as the primary beneficiary of Russia’s new air power in Libya. While the Russian government has never officially acknowledged the existence of Wagner, the PMC has been the go-to choice of the Russian Military Intelligence (GRU), when it comes to outsourcing politically sensitive external operations. Wagner is known for fighting in Eastern Ukraine, Syria, the Central African Republic (CAR), Sudan, Libya, and other countries. 


The article was updated to include the latest information released by US AFRICOM on 27 May 2020.

Comments Off on Russia Sends Fighter Jets to Libya

NATO Special Operators Among First Responders at Kabul Maternity Ward Attack

American and possibly British, Norwegian, and Australian special operations forces (SOF) were part of the reaction force that responded to the maternity ward attack in Kabul (Afghanistan) on 12 May…

American and possibly British, Norwegian, and Australian special operations forces (SOF) were part of the reaction force that responded to the maternity ward attack in Kabul (Afghanistan) on 12 May 2020, according to Social Media Intelligence (SOCMINT). In the early hours of Tuesday, unidentified gunmen disguised as police officers stormed the Barchi National Hospital in Kabul. The attackers killed 24 people, including medical personnel, patients, and even two newborn babies. 



THE TIER ONE COUNTER-FORCE

In the SOF counterattack that ensued, the foreign and Afghan operators of the Crisis Response Unit (CRU) 222 managed to rescue 100 women and children, including three foreigners.

SOFs regularly operate without national identification and wear masks to conceal their identity for operation security (OPSEC) reasons and to preserve political deniability. Yet, there are still plenty of elements that can help identify a SOF group’s nationality, such as uniform camouflage patterns, gear, weapons, accessories, and other equipment pieces. 

Twitter users with knowledge of tactical equipment have recognized the country and units of the SOFs deployed on-site. As the tweets below show, one of the first special mission units identified is the Combat Applications Group(CAG) or 1st Special Forces Operational Detachment-Delta (SFOD-D), which is more commonly known as “Delta Force.” Specializing in counter-terrorism, hostage rescue, and counter-proliferation, Delta is among the most secretive and lethal American SOF groups.

Twitter users recognized the American SOFs by their distinctive night-vision goggles (NVGs), custom pistol stock, pouch, and holster.  Social media speculations also place British SOFs, likely the Special Air Service (SAS) alongside Delta in one of the photos.

The Norwegian Forsvarets Spesialkommando (FSK) is another foreign SOF group recognized by Twitter users. While less known than its anglophone counterparts, the FSK is one of the most experienced NATO special mission units. Besides Afghanistan, they also operated, and are probably still active in Syria and Iraq.  

As Twitter users pointed out, at least one Australian SOF was also present during the counter-terrorist raid. If indeed from the land down below, the operator was likely part of the Special Air Service Regiment (SASR), Australia’s equivalent of the British SAS. Australia is one of NATO’s closest strategic partners. Australian SOFs have seen extensive service alongside their Euro-Atlantic allies in the Global War on Terror.  

RESOLUTE SUPPORT MISSION 

Regardless of their exact unit or nationality, it is virtually certain that foreign SOFs played a significant role in neutralizing the terrorist threat in Kabul. Without them and their Afghan counterparts, the death toll would have been dramatically higher. 

The foreign SOFs are in Afghanistan as part of their respective national military deployments. Their objective is to conduct counter-terrorism missions and train, advise, and assist the Afghan National Army and Security Forces (ANASF). 

RSM Commands via NATO

Following the end of major combat operations, NATO initiated the Resolute Support Mission at the invitation of the Afghan government in 2015. RSM is a capacity-building operation and consists of 39 NATO and non-NATO participating states. RSM advisors train the Afghan National Army (ANA) and Air Force (ANAF) so that Kabul can defend itself after the end of NATO’s military mandate. The RSM also helped the ANA build its first-ever SOF component, including the Crisis Response Unit 222, that spearheaded the response to the maternity attack. 

Afghan CRU 222 operators via Recoilweb.com

Apart from the RSM, the U.S. SOFs are also engaged in Operation “Freedom’s Sentinel,” an overseas contingency counter-terrorism mission against ISIS’s regional franchise, the “Islamic State-Khorasan” (IS-K).

IS-K LIKELY BEHIND THE ATTACK

While the horrific attack is still unclaimed, “Islamic State-Khorasan” (IS-K) is the likely culprit. The Dashti Barchi Hospital sits in a predominantly Shia neighborhood – an area that IS-K has also attacked in the past. 

Afghan intelligence has captured the IS-K commander and two of his aides in Kabul, just a day before the attack. The senior operatives were likely in Kabul to oversee the execution of the mission. 

Another circumstantial piece of evidence linking the massacre to IS-K was a second attack on 12 May 2020. A suicide bomber killed at least 32 people at a funeral in Nangarhar province. While Afghanistan experiences sporadic countrywide violence daily, the funeral and hospital attacks may be connected. 



Shiite communities are IS-K’s main targets apart from political institutions, according to our assessment from 2019, which you can find here. The attack is consistent with IS-K’s strict interpretation of Sunni Islam, militant Salafism, which views Shiites and other Muslim sects as heretics. IS-K uses sectarian and takfiri violence to mobilize hardcore Salafists/ Deobandi and establish an Islamic State in South Asia, encompassing Afghanistan, Pakistan, and the Kashmir region. 

IS-K has refrained from taking credit for its attacks in the past. In this case, the unclaimed attack on the maternity ward likely aimed at sabotaging the Afghan-Taliban peace process. By not claiming the attack, IS-K wanted to cast suspicion on the Taliban. IS-K has no interest in seeing a reduction of violence in Afghanistan. IS-K consists of disenfranchised Pakistani Taliban, splinter groups from the Islamic Movement of Uzbekistan (IMU), and a few foreign fighters. The Taliban is not only IS-K’s main competitor on the extremist market but also its existential threat. 

Afghanistan conflict map as of 29 February 2020 via Al-Jazeera

The Taliban has publicly denied involvement in the attack. While many Taliban cells continue to defy the “reduction of violence” agreement with Kabul, it is unlikely that the group was involved in the maternity ward massacre. Afghan President Ghani has nevertheless ordered the Afghan military to resume offensive operations against all militant groups in Afghanistan, including the Taliban. President Ghani was likely concerned to look weak in the face of Tuesday’s bloodbath in the center of Kabul. 

The Afghan peace process remains as fragile as always. 

Comments Off on NATO Special Operators Among First Responders at Kabul Maternity Ward Attack

Mission Failed: Inside Silvercorp’s Bizarre Plan to Overthrow Maduro

The Venezuelan authorities announced that they thwarted a coup against the Maduro regime, on 4 May 2020. Venezuelan forces captured eight and killed two men who tried to infiltrate the country’s…

The Venezuelan authorities announced that they thwarted a coup against the Maduro regime, on 4 May 2020. Venezuelan forces captured eight and killed two men who tried to infiltrate the country’s seacoast by boat. Among the arrested were two American citizens, both former U.S. Army Special Forces. Caracas claims that the infiltration attempt is proof of the Trump administration’s plan to overthrow the Venezuelan government. While the raiding party intended to oust Venezuela’s Socialist dictator, Nicholas Maduro, no evidence links the United States government to the operation. Instead, a group of Venezuelan dissidents led by the Florida-based security company “Silvercorp USA” is to be blamed.  

The recent events are nevertheless an excellent opportunity for the Maduro regime to stir anti-American fervor and to move against the opposition.   



SILVERCORP USA: FROM SECURITY AT CONCERTS TO REGIME CHANGE

Silvercorp, a Florida-based security company, was founded by former U.S. Green Beret Jordan Goudreau. Silvercorp has operated in over 50 countries and provided protection services for several Trump campaign rallies in 2018, as Bellingcat discovered. In early 2019, Silvercorp ran security for Venezuela Aid Live, a charitable concert on the Venezuelan-Columbian border. Through this Columbian connection, Silvercorp CEO Goudreau met with Venezuelan military dissidents to plot the overthrow of the Maduro regime in Carcass.

Goudreau at a Trump rally in Pennsylvania on 10 March 2018 (source: Bellingcat)

Goudreau liaised with retired General Cliver Alcala, the ringleader of a hotchpotch of Venezuelan military dissidents and former politicians. Alcala, who was a former associate of Hugo Chavez, claimed to be representing Juan Guaido, the leader of the Venezuelan opposition.

THE $212 MILLION CONTRACT

Reports suggest that the two sides signed a contract, which promises $50 million to Silvercorp in exchange for undisclosed security services. If successful, Silvercorps was to receive a total of $212 million, “backed/secured by Venezuelan barrels of oil.”  A scan of the contract was shared by @FactoresdePoder on Twitter. Guaido’s people argue that they only signed an exploratory contract and that they broke ties with Silvercorp in late-2019.

SILVERCORP’S UNILATERAL ACTION

Venezuelan military dissidents first met with the Trump administration to discuss military options against the Maduro regime in 2018. The White House nevertheless declined to partake in a coup. When the CIA learned of Silvercorp’s operation, it urged Mr. Goudreau to abort the plan, according to the website Connecting Vets.

Sources told Associated Press that Columbian intelligence also warned Alcala, Silvercorp’s Venezuelan accomplice, to stop promoting an invasion of Venezuela. Columbian authorities eventually arrested Alcala in March 2020 and extradited him to the United States to face drug-trafficking charges. 

Eventually, the Venezuelan opposition withdrew support for the operation and refused to pay even the contract retainer. Silvercorp’s CEO Goudreau nevertheless refused to drop the job, stating that he was a “freedom fighter” and wanted to liberate Venezuela. 



Preparations, therefore, continued on a tight budget. Goudreau allegedly raised funds from Roaen Kraft, a descendent of a cheese-making family, and his associates. The Associated Press suggests that Kraft lured further donors with promises of preferential access to the Venezuelan energy market. 

With funding secured, Goudreau recruited a few former Green Berets buddies to help him prepare the operation. After they drafted a plan, Gaudreau opened training camps in eastern Columbia, where Silvercorp trained around 300 Venezuelan dissident soldiers. 

OPERATION GIDEON

Silvercorp commenced with Operation “Gideon” on 3 May 2020 at 1700 hours local time. Mr. Goudreau publicly announced the operation in a Tweet (now deleted) on the same day. He tagged President Trump, probably a last attempt to secure political backing. 

3 MAY 2020: 62 Silvercorp operatives (60 Venezuelans, and two former U.S. Army Special Forces) left Columbia. 

The first of two amphibious assault groups attempted to disembark in the Bay of Macuto, four kilometers east of Venezuela’s main port (La Guaria), and 42 km north of Caracas. The Venezuelan Navy and Coast Guard captured them as soon as they began “hugging” the coastline.

4 MAY 2020: A video on Twitter showed Jordan Goudreau and a Venezuelan commander of the assault, Javier Quintero Nieto, claiming responsibility for the incursion. Despite the setback, Goudreau and Nieto announced that the operation would go forward. They added that many other units are active in southern, western, and eastern Venezuela. The objective of the raid, as described in the video, was to prosecute Maduros’ hardline loyalists, free the political prisoners and spark a revolution to overthrow the regime. 

Later that day, the second assault force approached Playa de Chuao, a coastal town north of Caracas (Venezuela). Local security forces also interdicted this element. Eight men were captured, including the two former Green Berets, Luke Denman and Aaron Barry. 

BOUNTY HUNTING?

In an interview with Venezuelan state media, Luke Denman later stated that the team’s objective was to seize an airstrip and bring in a plane to fly Maduro to the United States. In his own televised confession, Airan Berry names “La Carlota” (Air Base Generalisimo Francisco de Miranda) as being the airstrip they had intended to seize.  He also added that seizing Maduro however necessary was the operation’s end goal. The cells referenced by Goudreau and Quintero were likely responsible for getting a fix on Maduro, capturing him and bringing him to the airport. It is unknown why the objective was not to neutralize Maduro but to bring him out of the country – an infinitely more difficult task. There is reason to believe that Silvercorp was hoping to claim the $15 million bounty that the U.S. Department of Justice placed on Maduro’s head for narco-terrorism. The reward would have been an instant pay-off for Silvercorp’s “suicide mission.”



THE VENEZUELANS KNEW

It is virtually certain that the Maduro government was aware of the plot. Whether they collected intelligence on Silvercorp’s preparatory work in Columbia or were tipped off by the Associated Press reporting (the article appeared on 1 May 2020), Carcass prepared for the impending assault. 

Open-Source Intelligence (OSINT) suggested the Venezuelan Navy and Coast Guard were on high alert for the past five weeks. On 30 March 2020, the Venezuelan Navy attempted to intercept the Portughese-flagged “RCGS Resolute,” an empty cruise ship en route to Curacao. A Venezuelan destroyer attempted to push the RCGS Resolute into Venezuelan waters but sank after ramming the cruise ship. The Venezuelans accused the cruise ship of transporting mercenaries and weapons but were unable to detain it.


On 29 April 2020, the Venezuelan Coast Guard moved two speedboats from Guiria to La Guaria, the approximate objective of Silvercorp’s first landing party.

In hindsight, Silvercorp should have read these movements as a sign that Caracas had caught up with its plot.

Comments Off on Mission Failed: Inside Silvercorp’s Bizarre Plan to Overthrow Maduro

Leaked ‘Five Eyes’ Intel Report: China Lied About the Coronavirus

China lied to the world about the human-to-human transmission of the virus, disappeared whistleblowers, and spread disinformation to deflect blame for the virus, a “Five Eyes” report found. The “Five…

China lied to the world about the human-to-human transmission of the virus, disappeared whistleblowers, and spread disinformation to deflect blame for the virus, a “Five Eyes” report found. The “Five Eyes” is an anglophone intelligence sharing organization between the United States, the United Kingdom, Canada, Australia, and New Zealand. The report is the latest intelligence to cast light on Beijing’s cover-up and mismanagement of the pandemic. 

CENSORSHIP AND DISINFORMATION

China began censoring virus-related news on search engines and social media in late-December 2019, the report finds. This is consistent with a recent Citizen Lab study suggesting that the Chinese government deleted sentences containing the terms “New SARS,” “SARS variation,” “Wuhan Seafood market,” “shortness of breath,” and “Wuhan Unknown Pneumonia” among other 45 keywords that spiked on the Chinese internet in November. 



The report finds that China successfully pressured the European Union to water down its report on Beijing’s coronavirus disinformation. This claim is also consistent with recent reports that the EU amended its report on coronavirus disinformation to be less critical of Beijing after Chinese diplomats threatened to react. Three sources told Politico that the EU removed sentences referring to China’s orchestrated disinformation campaign to deflect blame for the pandemic. The European External Action Service had however denied the accusations.

The dossier is also critical of the World Health Organization (WHO), stating that it uncritically echoed the Chinese line about the lack of human-to-human transmission although “officials in Taiwan raised concerns as early as December 31, as did experts in Hong Kong on January 4.” This echoes the recent international criticism of the WHO for ignoring Taiwan and effusively praising China. The perceived Chinese influence within the WHO is also one of the reasons claimed by President Trump for his decision to cut funding for the organization. 

CORONAVIRUS ORIGIN: WUHAN

The origin of the virus is still under review but the widespread belief remains that the novel coronavirus originated in the form of an animal-human transmission from one of Wuhan’s wet markets. 

The United States increasingly believes that the virus is the result of an accident at the Wuhan Institute of Virology. A senior U.S. intelligence source speaking to the press said around 70-75% of the 17 U.S. intelligence agencies believe it came from a laboratory, but without a “smoking gun” they cannot reach consensus. 



AUSTRALIA AND CHINA IN WAR OF WORDS

It is no surprise that the report leaked in Australia, a country that had been recently threatened by China with a trade war. Beijing threatened to ban Australian products and boycott tourism after the Government in Cabera called for an international inquiry into the origin of the coronavirus. 


Cover photo; the P4 laboratory at the Wuhan Institute of Virology in China’s Hubei province, April 17, 2020.HECTOR RETAMAL/AFP via Getty Images

Comments Off on Leaked ‘Five Eyes’ Intel Report: China Lied About the Coronavirus

Type on the field below and hit Enter/Return to search