Read the morning traffic one item at a time and it looks like noise. A Russian video. A Chinese intrusion. Another North Korean crypto raid. Pull back and the noise resolves into a single move made four ways: Russia, China, Iran, and North Korea are each folding AI into the working core of their cyber and influence operations. Not the strategy papers. The operations. Work that used to need a room full of people now needs a model and a prompt, and it runs faster for less money.
A word on how we talk here. We hold to the estimative discipline of the trade, Kent and ICD 203, so the confidence words below carry weight. High confidence means the evidence converges. Likely and probable mark where the floor sits. They are not filler.
AI adoption is the signal of the cycle. Storm-1516, Russia’s influence machine, has more than doubled its output year over year. A China-nexus crew has been caught running intrusions through commercial coding models, Claude Code and DeepSeek. North Korean operators keep grinding developers for access while pocketing two-thirds of every dollar in crypto stolen worldwide this half. Iran looks like the exception, sitting in a post-strike lull, but with Tehran the quiet has never meant finished. And a NATO paper out of Tallinn puts a name to the thing tying it together: the target of information warfare has shifted from what people believe to how they come to believe anything at all.
Russia: the propaganda shop stops making things by hand
Start with Russia, because Russia is furthest along. The clearest proof that AI has crossed from experiment to production isn’t a new campaign. It’s the size of an old one. Storm-1516 — fabricated videos, counterfeit sites, anonymous “whistleblower” personas — more than doubled its narrative output in the first quarter against the same stretch last year, hitting near-daily production by late March. A companion bot network scrapes real scandals and spins them into synthetic amplification. The lineage runs back to Doppelganger, the operation that hand-cloned Western outlets to smuggle Kremlin copy into circulation. Cloning was slow work. Generation is cheap.
Put **high confidence** on this being a durable shift rather than a spike around one election. Tempo is the tell. Sustained near-daily output means infrastructure, not a sprint. It squares with the wider tally of 150-plus suspected Russian hybrid incidents logged across the EU and NATO since 2025: arson, sabotage, cyberattacks, and disinformation braided into what people have started calling a shadow war.
Then came the Bastille Day video. Three men, hooded, in mismatched fatigues, standing in front of a dummy dressed as a French Foreign Legionnaire with the tricolore smeared across its face. They promise to spill blood on the 14th if Paris keeps arming Israel. The clip cleared close to a million views before anyone slowed it down. The accent was Levantine but wrong for Lebanon. The grammar slipped. The accounts carrying it were the usual pro-Russian crowd. AFP and Euronews put it back on Storm-1516’s doorstep. Notice the escalation: this wasn’t a smear or a forged headline. It was a manufactured terror threat, hung on a real militant group, built to frighten French voters and split them over Israel. **Moderate-to-high confidence** it’s a Storm-1516 false flag, and the first time we’ve watched the operation reach for panic instead of persuasion.
Here’s why it travels. Russia has proven a mid-size state can run a global, always-on synthetic-narrative shop without a matching payroll. Now it has shown it will wear another group’s identity to fake a terror scare. The reputational brakes are off. Everyone downstream is watching and taking notes. Reporting: [Bloomberg](https://www.bloomberg.com/graphics/2026-russia-disinformation-storm-1516-videos/), [Euronews](https://www.euronews.com/my-europe/2026/07/16/storm-1516-fake-hezbollah-video-threatening-bastille-day-attack-possibly-russia-linked), [France 24]
(https://www.france24.com/fr/%C3%A9missions/info-ou-intox/20260714-non-le-hezbollah-n-a-pas-menac%C3%A9-la-france-d-un-attentat-le-14-juillet), [HSToday](https://www.hstoday.us/subject-matter-areas/cybersecurity/report-highlights-ai-driven-russian-bot-network-using-scandals-for-influence-operations/), [CSIS](https://www.csis.org/analysis/russias-shadow-war-against-west).
China: espionage as the supply line for cognitive warfare
China’s lesson is about espionage, and about what espionage now feeds. Security Affairs reported a PRC campaign running intrusions through commercial coding models, Claude Code and DeepSeek. Take it for what it is: frontier models wired straight into an operational kill chain, out in the open, no longer a thing we get to call hypothetical.
Lay that next to Volt Typhoon and Flax Typhoon, still burrowed into foreign critical infrastructure. Power. Water. Communications. **Likely** they aren’t there to act today. They’re there to hold. Access banked against a later contingency, Taiwan the obvious one. The patience is the part people keep underrating.
Doctrine binds it. OODA Loop reads Chinese espionage as the intake for Beijing’s “intelligentized warfare,” where bulk data theft, quiet access to communications, and machine-driven perception management feed one instrument aimed at how whole societies think. Read that way, the intrusions aren’t the objective. They’re collection for a longer influence play. **Moderate-to-high confidence** the pipeline from espionage to influence is deliberate now, not opportunistic. For anyone running a network that matters, that changes the arithmetic. A Chinese breach may not be a theft. It may be step one. Sources: [Security Affairs](https://securityaffairs.com/195474/ai/claude-code-and-deepseek-powered-chinese-cyber-espionage-campaign.html), [OODA Loop](https://oodaloop.com/analysis/security-and-resiliency/how-chinese-cyber-espionage-is-powering-its-cognitive-warfare-program/), [CISA](https://www.cisa.gov/topics/cyber-threats-and-advisories/nation-state-cyber-actors/china).
Iran: the quiet one
Iran is the quiet one, and the quiet is the tell. After the 7–8 July exchange, Iranian strikes on Hormuz shipping answered by CENTCOM hitting more than eighty IRGC targets, nothing new has come up in the cyber column. Don’t read that as cooling. **Likely** it’s temporary.
The standing indicators all point at positioning. CISA’s AA26-097A lays out IRGC-linked exploitation of programmable logic controllers across U.S. infrastructure, the operational-technology targeting that has become Tehran’s calling card. Treasury has sanctioned six IRGC Cyber-Electronic Command officers over CyberAv3ngers, which puts a state hand behind what usually wears a hacktivist mask. Handala keeps dialing its tempo up and down in step with the shooting. Assemble those and it turns **probable** that the eventual retaliation ships as a bundle: OT disruption plus a hacktivist-fronted story about the disruption, timed to land together. Where others log the silence as de-escalation, we log it as the pause before the swing. Sources: [CISA AA26-097A](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a), [Flare](https://flare.io/learn/resources/blog/cyberattacks-us-israel-iran-military-conflict), [CSIS](https://www.csis.org/blogs/strategic-technologies-blog/beyond-hacktivism-irans-coordinated-cyber-threat-landscape).
North Korea: theft at scale, machine-run
North Korea turns the AI story into bookkeeping. TRM Labs puts DPRK actors at roughly $643 million in stolen crypto for the first half of 2026, about two-thirds of the global total, most of it from two April raids: $285 million out of Drift, $292 million out of KelpDAO. All-time haul now sits north of $6.75 billion. This isn’t a side hustle. It’s a sanctioned government paying its bills by robbery.
What makes the coming year worse is the tradecraft, and this cycle it showed up in clean form. Elastic Security Labs took apart a Contagious Interview technique, tracked as REF9403. The operators chop their malware into pieces and tuck them inside the HTML comment blocks of SVG country-flag images, then let a victim’s own machine stitch the fragments back together and run them at server start. SVG is text. Comments in it are legal syntax. So an antivirus engine that renders the flag or scans it pixel by pixel never reads the code sitting in the markup. At disclosure, not one engine had flagged the poisoned repositories. What lands is a four-part OtterCookie kit: a browser-and-wallet stealer, a file stealer, a Socket.IO remote-access trojan, a clipboard grabber, all delivered through fake coding-test “recruiter” lures. The lure gets them in. The steganography is what keeps the scanners blind. **High confidence** the revenue and the tradecraft are pulling each other forward, and that the SVG trick gets copied within weeks.
Defender takeaway, blunt: the fake-recruiter lure is aimed straight at your engineers, and your coding-test and SVG-asset workflows are a blind spot on the way in. A recruiter you never went looking for is an attack surface, not a compliment. Sources: [UPI](https://www.upi.com/Top_News/World-News/2026/07/03/North-Korea-crypto-theft-two-thirds-H1-TRM-Labs/4361783069480/), [Elastic Security
Labs](https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography), [The Hacker News](https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html).
The proxies and the profiteers
Below the four states, the same logic runs through the proxies and the profiteers, where the information operation and the kinetic event increasingly go out as one show.
The Houthi-Hezbollah machine gave a tidy example. Saudi jets hit Sanaa International Airport on 13 July, with U.S. backing per officials the next day. The Houthi Political Bureau’s line: the real target was an Iranian Mahan Air passenger jet on approach. **Likely** fabricated or stretched, meant to turn a military strike into a massacre story. The track record earns the skepticism. This is a group that has claimed maritime attacks that never happened, including a strike on the tanker *Essex* that the shipping line flatly denied. Tehran, meanwhile, has reportedly told the Houthis to be ready to choke the Red Sea oil route if Washington hits Iranian power. Half order, half message meant to be overheard. The discipline is pure Hezbollah: own the story, hardest exactly when the ground truth cuts against you. Sources: [Critical Threats](https://www.criticalthreats.org/analysis/iran-update-special-report-july-14-2026), [FDD](https://www.fdd.org/overnight-brief/july-17-2026/), [Amwaj Media](https://amwaj.media/en/article/houthi-campaign-of-abductions-and-arrests).
Russia’s Wagner heirs showed strain and tightening at once. In northern Mali the Azawad Liberation Front, running with the al-Qaeda-linked JNIM, says it took the Anéfis base in early-July fighting against Malian troops and Africa Corps, downed a Russian-flown Mi-24, and ambushed the relief column. Mali’s own army chief admitted around thirty dead retaking Anéfis; another convoy got hit in the Gao region on 18 July. The aircraft and casualty numbers are the rebels’ own and stay unconfirmed. The trend line is real anyway. Russia’s gun arm is bleeding in the Sahel. The piece that matters more for influence tracking sits behind the fighting: reporting that the SVR has swallowed Wagner’s old disinformation shop, the roughly hundred-head outfit called “Africa Politology,” or “The Company,” while the Defense Ministry keeps the security file through Africa Corps. **Moderate confidence** that split hands the influence work to professionals, which reads as sharper tradecraft, not less of it. A loss like Anéfis is exactly what that shop exists to paper over, so expect the cover stories on schedule. Sources: [Al Jazeera, Gao ambush](https://www.aljazeera.com/news/2026/7/18/armed-groups-attack-malian-military-convoy-in-gao-region), [Al Jazeera,
Anéfis](https://www.aljazeera.com/news/2026/7/12/some-30-malian-soldiers-killed-during-anefis-retaking-says-army-chief), [Societal News](https://societalnews.com/news/global-conflicts/russia-africa-corps-svr-wagner-africa-strategy-2026.html).
The criminal tier brought the usual mix of urgent and new. CISA dropped a freshly patched Microsoft SharePoint Server bug into its Known Exploited Vulnerabilities list with a 19 July federal deadline. With a KEV listing and a public proof-of-concept, in-the-wild exploitation is **almost certain**. Patch it first. A U.S.-Estonian dual national was extradited on Scattered Spider charges. Researchers tagged a new ransomware strain, GodDamn, that runs the PoisonX kernel driver to kill endpoint defenses before it encrypts. The thread worth pulling is the blur between hacktivist and criminal, with Iran’s Handala working extortion and influence out of the same operation. Sources: [The Hacker News](https://thehackernews.com/), [BleepingComputer](https://www.bleepingcomputer.com/tag/ransomware/), [Infosecurity](https://www.infosecurity-magazine.com/news-features/why-hacktivists-joining-ransomware/).
The idea underneath: going after how we know
The most durable thing this cycle isn’t an incident. It’s an idea. A 2026 paper out of NATO’s Cooperative Cyber Defence Centre of Excellence in Tallinn reframes what cognitive warfare actually goes after. Not what you know. How you come to know anything. The attack targets the process, not the fact. Poison the way a population weighs evidence and decides whom to trust, and you stop needing to win any single argument. You win by making argument feel pointless.
That recasts everything above. The flood of synthetic clips, the bot farms, the cloned outlets, the “liar’s dividend” that lets anyone wave off a real recording as a possible fake, none of it is really about selling one specific lie. It wears down the machinery people use to tell true from false. We treat the framing as foundational, not academic. Sources: [ComplexDiscovery](https://complexdiscovery.com/invisible-by-design-natos-2026-cognitive-warfare-paper-and-the-crisis-of-discovery/), [NATO STO Chief Scientist report](https://www.sto.nato.int/wp-content/uploads/chief-scientist-report-cognitive-warfare-final.pdf), [NDU/INSS](https://digitalcommons.ndu.edu/strategic-insights/44/).
The proof is showing up on schedule in the U.S. midterms, where deepfakes have gone from stunt to standard kit. This cycle alone: an AI-forged image of Governor Wes Moore folded into June election-meddling claims, AI-generated candidate videos put out by the NRSC, and Maryland becoming the thirtieth state to legislate against election deepfakes, the law chasing a threat already in the field. Intelligence reporting keeps flagging Russian, Chinese, and Iranian bot farms faking grassroots noise. **Very likely** the pace climbs through November. Sources: [liar’s dividend analysis](https://politics-government.news-articles.net/content/2026/07/16/deepfakes-and-the-paradox-of-the-liar-s-dividend.html), [R Street](https://www.rstreet.org/commentary/ai-and-elections-what-to-watch-for-in-2026/), [deepfake legislation tracker](https://stackcyber.com/posts/ai-deepfake-laws).
Follow the money
One report ties the whole thing together at the wallet. Chainalysis’s 2026 Crypto Crime Report has sanctioned entities in Russia, Iran, and North Korea moving around $104 billion in cryptocurrency across 2025, up nearly sevenfold in value received. The breakdown reads like three programs plugged into one pipe. Russia’s A7A5 ruble-backed stablecoin alone cleared $93 billion in ten months as sanctioned trade went on-chain. IRGC-linked wallets took in more than half of all Iranian value in the fourth quarter, over $3 billion, feeding militias, oil sales, and dual-use buys. North Korea stole better than $2 billion, the record $1.5 billion Bybit hack inside that number. Stablecoins now carry about 84 percent of illicit volume.
The aggregate is the point, not the line items. **High confidence** crypto is now the common financial floor under all three states’ offensive and influence work, the thing that turns a drained wallet or a dodged sanction into an operating budget. A deepfake shop, an OT implant, and a mercenary column in the Sahel look unrelated until you trace the money. Then they line up. Sources: [Chainalysis](https://www.chainalysis.com/blog/crypto-sanctions-2026/), [CoinDesk](https://www.coindesk.com/business/2026/03/05/sanctions-evasions-using-crypto-increased-by-700-in-2025-chainalysis).
What to hold onto
Strip the flags off and one call stands. The cost of running a fast, deniable campaign of influence and intrusion has fallen through the floor, and every adversary that counts has noticed. Russia proved the model. The rest are adapting it to their own ends, China wiring it onto espionage, Pyongyang onto theft, Tehran biding its time. One idea sits under all of it: go after how people know, not only what they know.
The to-do list isn’t mysterious, only heavy. Patch what’s being hit now; SharePoint is today’s. Cold technical-recruiting should be treated as hostile until it proves otherwise. And a state intrusion might be the front end of an influence operation rather than a standalone theft, so scope it that way. The hard one is the last. Keeping a population able to tell real from fake while the fakes get cheaper and sharper every week. That’s the ground the adversary most wants us to give up. Right now we are not holding it.
