Full Report
Russia is conducting a "shadow war," head of Germany's foreign intelligence service (BND), Martin Jaeger, said.
Analysis Summary
# Threat Actor: Russian Intelligence Services (State-Sponsored)
## Attribution & Identity
- **Actor Name:** Russian Intelligence Services / Moscow
- **Associated Entities:**
- BND (German Foreign Intelligence) identifies the threat as "Russia" and "Moscow."
- Associated domestic and military intelligence bodies including the BfV and MAD confirm these activities are state-driven.
- **Nature:** State-sponsored intelligence and paramilitary organizations described as "highly professional and reckless."
## Activity Summary
Intelligence chiefs from Germany (BND, BfV, and MAD) have warned of a "shadow war" conducted by Russia against Western interests. Recent activities include:
- **July 31, 2026:** An attempted drone attack at Leipzig airport.
- **Ongoing Sabotage:** Operations aimed at critical infrastructure and logistics to disrupt aid to Ukraine.
- **Hybrid Warfare:** "Low-level" military activity, particularly in the Baltic region, and nuclear intimidation campaigns.
- **Lethal Operations:** Intent to carry out assassinations on foreign soil.
## Tactics, Techniques & Procedures
- **Physical Sabotage:** Targeting of transportation and logistics hubs (e.g., airports).
- **Uncrewed Aerial Systems (UAS):** Use of drones for kinetic or reconnaissance operations.
- **Psychological Operations:** Nuclear intimidation and strategic messaging to halt European arms deliveries.
- **Kinetic Action:** Assassination attempts and violent disruption.
- **Cyber Operations:** Offensive cyberattacks targeting weapons programs and government infrastructure.
- **MITRE ATT&CK IDs (Inferred):**
- T1583 (Acquire Infrastructure - for drone/sabotage ops)
- T1059 (Command and Scripting Interpreter - in context of cyberattacks)
- T1566 (Phishing - inferred via "shadow war" intelligence gathering)
## Targeting
- **Sectors:** Military/Defense, Transportation (Aviation), Energy, and Government.
- **Geography:** Germany, Baltic States (Estonia, Latvia, Lithuania), and wider NATO territory.
- **Victims:** Leipzig Airport, German Military (Bundeswehr), and weapons development programs.
## Tools & Infrastructure
- **Drones/UAS:** Utilized in airport disruption attempts.
- **Malware:** (Not specific to a family in this article, but noted as a capability for cyber sabotage).
- **C2/Infrastructure:** Defanged references to physical and digital reach:
- Leipzig Airport [Leipzig[.]airport]
- Baltic Region [Baltic[.]region]
## Implications
The German intelligence community assesses that Russia is engaged in an undeclared "shadow war" that falls outside conventional military definitions. The strategic objective is to coerce Berlin and European capitals into withdrawing support for Ukraine. The willingness to utilize violent sabotage and assassinations marks an escalation in risk for NATO member states, signaling that the threat is "real and present" rather than theoretical.
## Mitigations
- **Institutional Reform:** Strengthening the mandates of intelligence agencies (BND, BfV, MAD) to allow for offensive counter-capabilities.
- **Infrastructure Hardening:** Enhanced security protocols for critical transport hubs and military installations.
- **Cyber Defense:** Proactive monitoring and sabotage of adversarial cyber and weapons programs.
- **International Cooperation:** Reaffirming bilateral relations (e.g., German-Ukrainian cooperation) to maintain a united front against hybrid threats.