News / Updates / Blog:

  • Falun Gong Explained: From Chinese Persecution to a Global Media Empire

    On April 25, 1999, roughly 10,000 practitioners of a qigong-based spiritual movement called Falun Gong surrounded the Zhongnanhai compound in central Beijing — the walled seat of Chinese Communist Party leadership — and sat in silent meditation for twelve hours. They were protesting recent media criticism of their movement and the arrest of practitioners in Tianjin. The protest was peaceful. It was also the largest unauthorized demonstration in Beijing since the 1989 Tiananmen Square protests a decade earlier. Chinese President Jiang Zemin, observing the gathering from inside the compound, reportedly reached a conclusion that would define the next twenty-five years of Chinese religious policy: a movement that could mobilize 10,000 people to a guarded government facility without the state’s intelligence services knowing about it in advance was a threat to CCP authority, regardless of whether its stated aims were political. Three months later, on July 20, 1999, the Chinese government banned Falun Gong, declared it an “evil cult,” and created an extra-constitutional body called the 6-10 Office — named after the date of its founding, June 10, 1999 — with a mandate to eradicate the movement. What followed has become one of the most sustained religious persecution campaigns of the 21st century, and one of the most politically consequential diaspora networks in the world.

    What Falun Gong is

    Falun Gong — also called Falun Dafa — was introduced to the Chinese public in May 1992 by Li Hongzhi, a former clerk at the Changchun Cereals and Oil Company who had spent the previous year studying qigong under various masters. The practice combines five meditation exercises with a moral framework built on the three principles of zhen (truthfulness), shan (compassion), and ren (forbearance). Its theological content draws on Buddhist, Taoist, and Confucian elements, incorporating beliefs about cosmology, karma, spiritual cultivation, and — in Li’s later teachings — extraterrestrials, multiple dimensions, and racial cosmology that critics have called pseudoscientific and bigoted. During the Chinese qigong boom of the 1980s and early 1990s, when traditional Chinese health practices were being rebranded as scientific wellness techniques, Falun Gong grew faster than any of its competitors. By 1999, the Chinese government’s own estimate put adherents at 70 million — more than the membership of the Chinese Communist Party itself. Li’s own estimate was 100 million. Freedom House’s more recent estimates put the figure between 7 and 20 million. The discrepancy between those numbers is itself part of what the Chinese state found threatening.

    Li moved to the United States in 1998, citing health reasons. Critics argued he was leaving before a crackdown he saw coming. He settled in Deerpark, New York, where Falun Gong’s global headquarters remain — a 400-acre compound called Dragon Springs that now houses schools, temples, and rehearsal space for the Shen Yun performing arts company. Li rarely speaks publicly. His lectures and writings, particularly the foundational text Zhuan Falun, are the basis for practice worldwide. His views on race, sexual orientation, interracial relationships, and modern medicine have drawn sustained criticism — Li has taught that mixed-race children are part of a plot by aliens to destroy humanity’s connection to higher spiritual realms, that homosexuality is an expression of demonic possession, and that medicine interferes with the karmic cleansing that illness provides. Practitioners argue these teachings are misinterpreted. Former practitioners interviewed by Western journalists have confirmed them as authentic.

    The persecution

    The state campaign that began in July 1999 has been documented by Amnesty International, Human Rights Watch, the UN Special Rapporteur on Torture, the U.S. Commission on International Religious Freedom, the State Department’s annual religious freedom reports, and multiple independent tribunals. The pattern is consistent across sources. Practitioners who refuse to renounce the practice are subject to detention in “legal education” facilities — the Chinese state’s euphemism for forced reeducation camps predating the Xinjiang camps by two decades. Torture techniques documented by detainees include sleep deprivation, forced feeding, electric shocks, stress positions, psychiatric abuse, and sexual violence. Practitioners who publicly identify themselves face job termination, school expulsion, and pressure on family members. Falun Gong sources have documented more than 4,000 named deaths in custody. Independent estimates suggest the actual number is substantially higher. The New York Times reported in 2009 that at least 2,000 practitioners had been killed in the persecution campaign by that point.

    The most severe allegation — that China harvests organs from living Falun Gong detainees to supply its rapidly growing transplant industry — has been investigated by multiple independent parties. In 2006, former Canadian Secretary of State David Kilgour and human rights lawyer David Matas published the first comprehensive investigation of the allegations, concluding that large-scale organ harvesting from unwilling Falun Gong practitioners was ongoing. Their initial finding was that 41,500 organ transplants in China during 2000-2005 had no plausible source other than executed detainees. Journalist Ethan Gutmann subsequently estimated that 65,000 Falun Gong practitioners had been killed for their organs between 2000 and 2008. In 2019, the China Tribunal — an independent panel chaired by Sir Geoffrey Nice, the British prosecutor who had led the Slobodan Milošević war crimes case — concluded unanimously that forced organ harvesting had been occurring in China “on a significant scale” for at least twenty years and that “Falun Gong practitioners have been one — and probably the main — source of organ supply.” The U.S. Congress has repeatedly cited these findings in legislation, including the 2023 Falun Gong Protection Act. China denies the allegations. The gap between China’s stated transplant volume and the number of registered organ donors — 5,146 registered donors in 2017 against an industry performing tens of thousands of transplants annually — has never been publicly explained.

    The media empire

    What makes Falun Gong a Shadowcraft case study rather than a human rights case study is what the movement built in the United States after 1999. Falun Gong practitioners founded The Epoch Times in 2000 as a Chinese-language newspaper in New York. The outlet expanded into English and other languages over the next decade. It founded New Tang Dynasty Television in 2001, Sound of Hope Radio in 2003, and Shen Yun Performing Arts in 2006. Financial documents suggest the various organizations share executives, staff, and strategic direction, though the formal corporate structures are deliberately separate.

    The strategic pivot that made the operation globally consequential happened in 2016. Before 2016, The Epoch Times had been a relatively marginal publication covering primarily Chinese political issues and producing critical coverage of the CCP. In 2016, according to an NBC News investigation published in 2019, the outlet began running aggressively pro-Trump coverage, spent $1.5 million on Facebook advertising in six months during 2019-2020 (at which point Facebook banned it from running political ads), and rapidly expanded its English-language reach through social media distribution, email newsletters, and video content on platforms including YouTube and later Rumble. The outlet’s revenue reportedly doubled during the Trump administration. Its content during the COVID-19 pandemic included pieces promoting ivermectin, questioning vaccine safety, and suggesting the virus had been deliberately released from a Chinese laboratory. Its coverage of the 2020 election featured prominent coverage of fraud allegations, QAnon-adjacent material, and content from sources mainstream conservative media had avoided. Li Hongzhi reportedly stated that Donald Trump had been “sent by heaven to destroy the Chinese Communist Party” — a theological framing that explained why a movement that had been politically marginal in American politics became one of the largest funders of pro-Trump digital content.

    Shen Yun, the performing arts company, operates in parallel. The company tours internationally with productions that combine classical Chinese dance with anti-CCP political content — scenes depicting persecution of Falun Gong practitioners, organ harvesting, and the party’s suppression of traditional Chinese culture. The advertising is ubiquitous in major American cities. The ticket revenue is substantial — Shen Yun’s parent organization reported more than $200 million in revenue across its performing arts operations in recent years. Dragon Springs, the New York compound, houses dancers and rehearsal facilities. Former performers have described the training as involving 10-hour rehearsal days starting at age 13, with limited contact with family members, mandatory religious instruction, and restrictions on outside relationships. The organization denies the characterization.

    Chinese counter-operations

    The CCP has pursued Falun Gong practitioners outside China for twenty-five years. In December 2023, the U.S. Department of Justice charged John Chen and Lin Feng with operating as unregistered agents of the Chinese government in a plot to bribe an IRS official to manipulate the whistleblower program against Shen Yun’s tax-exempt status. Both were convicted in 2024. In November 2024, Ping Li, a 59-year-old Florida resident, was sentenced to four years in prison for acting as an unregistered PRC agent who had provided China’s Ministry of State Security with information about a Florida resident affiliated with Falun Gong. Multiple similar cases — involving surveillance of practitioners, pressure on family members still in China, and attempts to suppress Shen Yun performances through diplomatic complaints to host venues — have been documented across Europe, Australia, and Southeast Asia. Xi Jinping reportedly directed party officials in 2022 to intensify international efforts against the movement. The resources China continues to invest in suppressing Falun Gong abroad are themselves evidence of how seriously the party treats the movement as a threat.

    Why it’s in Shadowcraft

    Falun Gong sits at the intersection of three Shadowcraft categories. As a persecuted religious minority, it belongs with the documented cases of state repression — the CCP’s treatment of the movement constitutes one of the longest-running and best-documented religious persecutions of the post-Cold War era, and the organ harvesting allegations, validated by an independent tribunal led by one of Britain’s most experienced international war crimes prosecutors, describe a category of human rights abuse with few modern parallels. As a religious movement with cult-like characteristics, it raises the same analytical questions as the Gülen Movement — where the line runs between a legitimate civil society organization and a hierarchical group exercising coercive control over members. And as the operator of a major pro-Trump media empire, it represents something genuinely unusual: a foreign-origin spiritual movement that has become one of the most influential funders of American right-wing digital content, with theological reasons for its political positioning that most American consumers of that content have never encountered.

    The analytical question the course raises is not whether Falun Gong’s persecution in China is real — the evidence is overwhelming that it is — but what it means when a religious movement subjected to severe persecution builds, in response, a global media and cultural infrastructure that operates at the intersection of human rights advocacy, religious proselytization, and partisan political influence. The Stasi KoKo apparatus turned sanctions evasion into a state revenue stream. The Western Goals Foundation turned nonprofit status into an intelligence-file preservation vehicle. Falun Gong’s media operations turned the infrastructure of religious persecution into a cross-spectrum media empire that reaches tens of millions of Americans and Europeans weekly, with very few of them knowing what they’re actually consuming.

    We cover Falun Gong alongside the Gülen Movement, China Poly Group, United Front Work Department, and 20 other case studies of covert institutional power across our Shadowcraft course — where a meditation practice that mobilized 10,000 people to Zhongnanhai in 1999 became, twenty-five years later, one of the largest operators of right-wing media in the United States, and the persecution that made it possible is still ongoing.

  • Lazarus Group: North Korea’s State Hacking Apparatus Explained

    On February 4, 2016, a hacker working for the North Korean state sent 35 fraudulent payment instructions through the SWIFT interbank messaging network, routing $951 million from Bangladesh Bank’s account at the Federal Reserve Bank of New York to accounts in Sri Lanka and the Philippines. It would have been the largest bank heist in history. It was stopped by a typo. One of the transfer instructions routed funds to “Shalika Fandation” — a misspelling of “Foundation” — which triggered a routine fraud-screening alert at the correspondent bank Deutsche Bank. The Fed paused the remaining transactions. Of the $951 million attempted, $850 million was recovered. The hackers walked away with $81 million, most of which was laundered through casinos in Manila. The FBI eventually attributed the operation to a North Korean state hacking group that cybersecurity researchers had been tracking since 2009 under the name Lazarus. Nine years and roughly $7 billion in stolen cryptocurrency later, Lazarus is no longer a cybersecurity curiosity. It is North Korea’s single largest source of hard currency, the fiscal backbone of the country’s sanctioned weapons program, and — according to the blockchain analytics firm TRM Labs — not a state-sponsored group in any traditional sense of the term. “Lazarus Group is North Korea. North Korea is Lazarus Group.”

    What Lazarus actually is

    Lazarus operates under many names, which is itself a clue about how the cybersecurity industry thinks about attribution. Researchers have called the group Hidden Cobra, Diamond Sleet, ZINC, Labyrinth Chollima, APT38, BlueNorOff, and Guardians of Peace. The multiple names reflect multiple sub-units conducting different kinds of operations — BlueNorOff specializes in financial theft, Labyrinth Chollima focuses on espionage, APT38 handles large bank heists, Guardians of Peace is the public-facing alias used for ideological operations like the Sony Pictures hack. The umbrella term “Lazarus” is less an organization than a label for the North Korean hacking ecosystem, which operates under the control of the Reconnaissance General Bureau — North Korea’s primary foreign intelligence service.

    The operatives themselves are not shadowy figures typing from Pyongyang basements. North Korea’s cyber operators are trained at institutions like the Kim Il Sung University of Politics and Mirim University (the country’s military signals school), then stationed abroad in places with reliable internet infrastructure — primarily Shenyang in northeastern China, but also Vladivostok, Malaysia, and various African countries where surveillance is limited and North Korean workers maintain a presence. They work in teams of several hundred from IP ranges controlled by the North Korean state, using commercial VPN services and proxy infrastructure to obscure origin. The FBI has publicly named three of them. In September 2018, a federal grand jury indicted Park Jin Hyok, a North Korean national allegedly employed by the Chosun Expo Joint Venture — a North Korean front company operating in China — for his role in the Sony Pictures hack, the Bangladesh Bank heist, and WannaCry. In February 2021, the Justice Department indicted Jon Chang Hyok and Kim Il for cryptocurrency thefts and the fraudulent Marine Chain initial coin offering. Park, Jon, and Kim have never been arrested. North Korea denies they exist.

    The operational record

    The group’s documented operational history begins with a wave of attacks on South Korean government and media systems in the late 2000s and runs through the February 2025 theft of $1.5 billion from the Bybit cryptocurrency exchange — the largest digital asset theft in history. In between, the group conducted operations that would define two decades of financial cybercrime.

    In November 2014, Lazarus-linked hackers publishing under the name “Guardians of Peace” wiped Sony Pictures Entertainment’s systems, leaked confidential emails, and released unreleased films. The attack was retaliation for Sony’s upcoming release of The Interview, a comedy about a CIA plot to assassinate Kim Jong-un. The attack destroyed Sony’s internal IT infrastructure for weeks. U.S. attribution came from the FBI within a month.

    In May 2017, Lazarus deployed the WannaCry ransomware worm, which encrypted files on more than 200,000 computers across 150 countries in a single weekend. The worm spread using EternalBlue — an exploit for a Microsoft Windows vulnerability that had been developed by the U.S. National Security Agency and stolen by a group called the Shadow Brokers, who had leaked it online a month earlier. WannaCry hit the UK’s National Health Service, forcing the cancellation of thousands of medical appointments and surgeries. It hit Renault, Nissan, FedEx, Deutsche Bahn, and Spanish telecom Telefónica. The ransom payments demanded in bitcoin were minimal — the Lazarus operators appeared to have struggled to collect revenue from the operation — but the scale of the disruption established that a single North Korean cyber team could, within 48 hours, affect critical infrastructure in every developed economy simultaneously.

    In March 2022, Lazarus executed what would remain the largest DeFi hack in history until the Bybit operation three years later. The target was the Ronin Network, a blockchain bridge that moved cryptocurrency in and out of the video game Axie Infinity. The attack vector was a fake LinkedIn job offer. A Lazarus operator posing as a recruiter approached a senior engineer at Sky Mavis — Ronin’s developer — with an interview process that ended with a malware-infected PDF offer document. Once inside Sky Mavis’s systems, the operators obtained five of the nine validator keys needed to authorize transactions on the Ronin bridge, generated two fraudulent withdrawals, and walked away with 173,600 Ether and 25.5 million USDC — approximately $625 million at market prices. The breach went undetected for six days. The FBI confirmed attribution the following month. The U.S. Treasury sanctioned the receiving wallet address.

    In June 2022, Lazarus used the same playbook against Harmony’s Horizon Bridge, stealing $100 million. In June 2023, the group hit the non-custodial Atomic Wallet service, draining roughly $100 million from more than 4,100 individual user addresses. In September 2023, the online casino Stake.com lost $41 million. In July 2024, India’s largest cryptocurrency exchange WazirX was drained of $234 million. The operational cadence accelerated rather than slowing. By 2024, blockchain intelligence firms estimated that Lazarus had stolen more than $6 billion in cryptocurrency since 2017 — enough, according to U.S. Treasury assessments, to constitute a meaningful percentage of North Korean GDP.

    The Bybit operation

    On February 21, 2025, the Dubai-based cryptocurrency exchange Bybit lost $1.5 billion in approximately 30 minutes. The attack vector followed the social-engineering pattern Lazarus had refined since Ronin: a single developer at Safe{Wallet}, a third-party multi-signature wallet provider used by Bybit for cold storage, was compromised through a targeted attack on their laptop. The operators then waited weeks, monitoring Bybit’s internal transaction approval flow, until they identified a routine transfer from one of the exchange’s cold wallets. At the moment of transfer, they substituted a fake Safe{Wallet} interface that Bybit’s signers approved without recognizing the malicious smart contract they were authorizing. 400,000 Ether — about 70% of Bybit’s on-exchange Ethereum reserves — vanished into wallets controlled by the attackers. The FBI attributed the operation to Lazarus within five days. By March 20, TRM Labs reported, 86% of the stolen Ether had already been converted to Bitcoin through a cascade of decentralized exchanges, cross-chain bridges, and mixer services — infrastructure built up over five years specifically for laundering North Korean crypto theft proceeds at industrial scale.

    The Bybit heist, by itself, was worth more than North Korea’s entire estimated crypto-theft take from 2023 and 2024 combined. It was worth more than all traditional bank heists in history combined. And it was executed by a group operating from a country whose GDP is smaller than that of Vermont, under sanctions that have formally excluded North Korea from the global financial system for nearly two decades.

    Why it’s Lecture 14

    Lazarus Group is the Shadowcraft case study that demonstrates how state-level covert finance evolves when the state has no legitimate financial access. North Korea cannot use SWIFT. It cannot hold foreign currency reserves at Western banks. Its formal commercial exports — weapons, labor, agricultural goods — are heavily sanctioned and monitored. What it has is one of the world’s best-trained cyber workforces, operating from jurisdictions where Western law enforcement cannot reach them, against targets — cryptocurrency exchanges — that hold billions of dollars in bearer assets with no reversal mechanism after a successful theft. The match between the state’s needs and the attack surface is close to optimal.

    The other Shadowcraft case studies in the North Korean financial apparatus — Room 39, the party office that coordinates the country’s overall hard-currency operations including counterfeit dollars, insurance fraud, and narcotics trafficking — operate alongside Lazarus within the same overall system. Stasi KoKo generated 25 billion Deutsche Marks for East Germany through similar sanctions-evading commercial operations during the Cold War. BCCI provided the institutional laundering infrastructure for multiple state programs simultaneously. Marc Rich built the commodity-trading template for moving sanctioned Iranian and South African goods through shell company structures. Lazarus operates the modern iteration: sanctions-evading revenue generation through digital theft rather than commodity smuggling, with laundering infrastructure built into decentralized finance protocols that were designed without the regulatory oversight traditional banks operate under.

    The detail that matters most for the Shadowcraft framework is that the attack surface Lazarus exploits — multi-signature wallet providers, cross-chain bridges, decentralized exchanges, stablecoin issuers — was built by the cryptocurrency industry specifically to minimize points of centralized control. The design philosophy was adversarial to regulators. The adversary it optimized for was government surveillance. The adversary it got was a state-level threat actor for whom the lack of regulatory intermediation was the exact feature that made sustained theft possible.

    We cover Lazarus alongside Crypto AG, Mossack Fonseca, GRU Unit 29155, and 20 other case studies of covert institutional power across our Shadowcraft course — where a North Korean hacking group that started by wiping Sony Pictures’ servers to retaliate for a Seth Rogen movie became the single largest source of foreign exchange for a nuclear-armed state.

  • The Gülen Movement: From Schools to Alleged Coup — Turkey’s Most Controversial Organization

    On the night of July 15, 2016, a faction within the Turkish military seized bridges over the Bosphorus, bombed the parliament building in Ankara, occupied state television, and attempted to arrest President Recep Tayyip Erdoğan at his hotel in Marmaris. The coup failed within hours. Civilians filled the streets in response to Erdoğan’s call, climbed onto tanks, and helped loyalist forces retake the strategic positions. By the morning of July 16, the coup was over. Roughly 250 people were dead. More than 2,000 were wounded. Erdoğan named the culprit immediately: Fethullah Gülen, a reclusive Islamic cleric living in a 25-acre compound in Saylorsburg, Pennsylvania, who had been a U.S. resident since 1999. Within days, Turkey had arrested thousands of military officers, judges, prosecutors, academics, and civil servants. Within months, the purge had removed more than 100,000 people from their jobs. Within a year, the Turkish government had formally designated Gülen’s movement — known as Hizmet, the Turkish word for “service” — as a terrorist organization called FETÖ, the Fethullahist Terror Organization. The United States, examining Turkey’s extradition request, declined to send Gülen back. He died in Pennsylvania on October 20, 2024, at the age of 83, without ever returning to Turkey. What actually happened on July 15, 2016, and what the Gülen movement actually was, remain among the most contested questions in modern political history.

    What the movement is

    Hizmet was founded in the late 1970s by Fethullah Gülen, a Turkish cleric whose theological roots lay in the Nur movement of Said Nursi — an early 20th-century Islamic scholar whose teachings emphasized the compatibility of Islam with science and modernity. Gülen’s version of this synthesis emphasized education, civic engagement, interfaith dialogue, and what his followers called “service” to humanity. Starting from a network of boarding houses for students in İzmir, the movement grew over four decades into one of the largest Islamic civil society organizations in the world — by 2015, operating in 180 countries with estimated assets of $20 to $50 billion.

    The educational network was the movement’s signature. At its peak, the Gülen movement operated approximately 1,000 schools in Turkey that educated an estimated 1.2 million Turkish students over several decades — including members of Erdoğan’s own extended family. Internationally, Gülen-affiliated schools operated in more than 100 countries, enrolling more than 2 million students. In the United States, the movement’s educational arm includes Harmony Public Schools, the largest charter school network in Texas, with more than 60 campuses and tens of thousands of students. The schools teach standard secular curricula and do not explicitly proselytize — a feature that distinguished them from madrasa education and made them attractive to non-Muslim parents in countries from Mongolia to Kenya to the United States.

    The movement’s financial infrastructure inside Turkey was extensive: television stations, the country’s largest-circulation newspaper Zaman, gold mines, a bank (Bank Asya), insurance companies, and a network of business associations. The organizational structure — described by scholars as a “flexible network” rather than a formal hierarchy — consisted of local communities organized around schools and prayer groups, each with an informal leader (imam), linked into regional and national networks without centralized control. Gülen himself lived in a small apartment on the Pennsylvania compound — a mattress on the floor, a desk, a treadmill, a prayer mat. He did not control the movement’s operations directly. What he controlled was the theological authority that defined what it meant to be part of the movement.

    The AKP alliance and the break

    The Gülen movement’s political arc is the part that makes it a Shadowcraft case study. Throughout the 1990s, the movement’s members pursued careers in the Turkish state — police, judiciary, military, civil service, academia — with the explicit goal, according to the movement’s internal materials, of creating an “elite to lead the state.” This was not hidden. Gülen’s own speeches encouraged followers to pursue positions of institutional influence. Critics within Turkey’s secular establishment accused the movement of infiltrating state institutions to advance a religious agenda. The movement’s response was that it was exercising the same civil rights any other group exercised.

    In 2002, when the AKP won its first national election under Erdoğan, the Gülen movement threw its support behind the new government. Both were Islamic-oriented movements that had faced exclusion under Turkey’s secularist establishment. The alliance was operational. Gülenist prosecutors and judges led investigations (the Ergenekon and Balyoz cases) that targeted secularist military officers and journalists — weakening the military and judicial institutions that had historically constrained Islamic political movements. Gülenist media outlets amplified AKP narratives. Gülenist civil servants staffed positions across the state. The AKP-Gülen alliance was one of the most consequential political partnerships in modern Turkish history. And it was based on a shared understanding: the Gülenists would staff the bureaucratic apparatus, and the AKP would hold elected office.

    The alliance fractured in 2013. The specific trigger was Erdoğan’s decision to close the Gülen-linked dershaneler — private tutoring centers that prepared students for university entrance exams and served as major recruitment channels for the movement. The deeper trigger was power. Both sides had become too influential to share. In December 2013, prosecutors — reportedly Gülenists — launched a corruption investigation targeting four of Erdoğan’s cabinet ministers. Leaked wiretap recordings allegedly captured Erdoğan and his son discussing hiding large sums of cash. Erdoğan denounced the investigation as a coup attempt by a “parallel state” within the Turkish government. Over the next two years, Erdoğan’s government purged suspected Gülenists from the police, judiciary, and prosecutor’s offices. Zaman was seized in March 2016. Bank Asya was taken over by regulators. The movement was designated a terrorist organization internally even before the coup.

    July 15, 2016

    The coup attempt began the evening of July 15 and was defeated by dawn on July 16. Within 24 hours, Erdoğan attributed it to the Gülen movement. Turkish prosecutors indicted thousands of alleged Gülenists. The U.S. government sent extradition requests to Turkey asking for evidence that would satisfy American legal standards. The Turkish response — according to U.S. officials who spoke to journalists — did not meet those standards. The extradition never happened.

    Whether the Gülen movement organized, authorized, or carried out the coup remains disputed. The Turkish government’s position is definitive: FETÖ planned it and executed it. The Gülen movement’s position was equally definitive: they had nothing to do with it, and the coup may have been staged. Western analysts have been more ambivalent. A 2016 European Council on Foreign Relations report by Asli Aydıntaşbaş argued that Gülenist officers within the military were likely involved in the coup attempt, but the operation was broader than just the Gülenist faction and included non-Gülenist Kemalist officers motivated by different grievances. The full membership of the coup plotters has never been publicly disclosed in a way that would resolve the question. In December 2018, the U.S. Department of Justice indicted two former associates of Michael Flynn — Trump’s first national security adviser — for operating as unregistered agents of the Turkish government in a campaign to discredit Gülen and facilitate his extradition. The indictment added a further complication to the attribution question.

    The aftermath, regardless of attribution, was sweeping. More than 100,000 people were removed from their jobs. Tens of thousands were arrested. Schools were closed. Newspapers were shut down. Academics were dismissed. The scope of the purge far exceeded what could plausibly be explained by the number of people actually involved in the coup itself. Whatever the Gülen movement was before 2016, by 2018 it had been dismantled as an organized presence in Turkey — its members imprisoned, exiled, or driven underground. The international network of schools and businesses continued operating in countries that had not designated Hizmet a terrorist organization. Gülen lived out his remaining years in Pennsylvania, denying involvement in the coup, publishing op-eds critical of Erdoğan’s authoritarianism, and refusing interviews.

    Why it’s in Shadowcraft

    The Gülen movement is the Shadowcraft case study that resists clean categorization. Every other case in the course — BCCI, Crypto AG, the Safari Club, Operation Gladio, P2 — involves documented covert institutional power operating toward documented ends. The Gülen movement involves a civil society organization that built educational and media infrastructure at a massive scale, encouraged its members to pursue positions in the state, allied with an Islamist political party, fell out with that party, was blamed for a coup attempt, and was then systematically destroyed by the government that had previously been its partner. The question the course raises is not whether the movement’s influence was real — it demonstrably was — but what the difference is between “civil society network with members in positions of institutional power” and “parallel state operating covertly within state institutions.”

    That distinction matters because the label determines what response is justified. If Hizmet was a civil society organization whose members exercised legitimate careers in the state, the post-2016 purge was a political repression campaign targeting an entire class of citizens for their religious affiliation. If Hizmet was a covert organization operating as a parallel state and responsible for attempting to overthrow an elected government, the purge was a counterterrorism response, however excessive. Both framings have had serious proponents. The evidence publicly available is not conclusive for either. The P2 Lodge was clearly the second — a documented 962-name membership list, a written “Plan for Democratic Rebirth,” conviction records. Hizmet is less clear. What is clear is that building influence through educational institutions, media ownership, and civil service careers is a recognized pattern in the history of covert institutional power — and that once a government decides the pattern constitutes a threat, the response can be disproportionate to any evidence actually available.

    We cover the Gülen movement alongside Western Goals Foundation, Stasi KoKo, Wagner Group, and 20 other case studies of covert institutional power across our Shadowcraft course — where Hizmet is the lecture that demonstrates how much of what the Shadowcraft framework studies depends on how you answer a single question: when does influence become infiltration, and who gets to decide?

  • GRU Unit 29155: Russia’s Assassination and Sabotage Squad Explained

    On March 4, 2018, a former GRU colonel named Sergei Skripal was found slumped on a park bench in Salisbury, England, next to his daughter Yulia. Both were unconscious. Both were foaming at the mouth. The substance that poisoned them — smeared on the front door handle of Skripal’s home — was Novichok, a Soviet-developed nerve agent with a lethal dose measured in milligrams. Skripal had been a double agent for British intelligence during the 1990s and early 2000s, was imprisoned in Russia in 2006, and had been released to the UK in a 2010 spy swap. Both Skripals survived. A police officer who responded to the scene was hospitalized. Four months later, a man named Charlie Rowley found a discarded perfume bottle in a charity bin in nearby Amesbury, gave it to his partner Dawn Sturgess, and Sturgess died from Novichok exposure. The two Russian operatives British police identified as responsible — operating under the names Alexander Petrov and Ruslan Boshirov — went on Russian state television to claim they had traveled to Salisbury as tourists to see the cathedral’s 123-meter spire. Within weeks, the investigative site Bellingcat had identified them as Alexander Mishkin, a military doctor, and Anatoliy Chepiga, a decorated special forces colonel — both members of GRU Unit 29155. The unit had existed since at least 2008. Its existence had never been publicly confirmed before.

    What Unit 29155 is

    Unit 29155 is a subdivision of the GRU — Russia’s military intelligence directorate, now formally called the GU but still referred to by its Cold War abbreviation — specialized in foreign assassination, sabotage, and destabilization operations. It operates from the headquarters of the 161st Special Purpose Specialist Training Center in eastern Moscow. Its members are drawn from GRU special forces veterans of Russia’s wars in Afghanistan, Chechnya, and Ukraine. It was commanded, through most of the period it has been publicly documented, by Major General Andrei Vladimirovich Averyanov — a man whose daughter’s 2017 wedding photos, obtained by The New York Times in 2019, show him posing alongside Chepiga, the Skripal operative who had been given the Hero of the Russian Federation, Russia’s highest honor.

    The unit’s operational profile is distinct from the GRU’s other cyber and signals intelligence units. Unit 29155 does human operations — sending officers across borders on false passports to conduct assassinations, detonate ammunition depots, and destabilize foreign governments. The unit’s existence only became publicly known in 2019, eleven years after it is believed to have begun operating. Its tradecraft, according to the security officials who study it, is notable for its sloppiness — a pattern of operations that either fail outright or succeed despite leaving trails the unit apparently didn’t believe anyone would follow.

    The operational record

    The documented case history, compiled by Bellingcat, Czech intelligence, British authorities, The Insider, and multiple European intelligence services working from open-source data, includes operations across at least eight countries over more than a decade.

    In 2014, during Russia’s annexation of Crimea and the outbreak of war in eastern Ukraine, Unit 29155 operatives were deployed to eastern Czechia. On October 16, 2014, ammunition warehouses at Vrbětice exploded. Two Czech citizens were killed. A second explosion followed in December. The Czech government initially treated the blasts as industrial accidents. Seven years later, on April 17, 2021, Czech Prime Minister Andrej Babiš announced that Czech counterintelligence had determined Unit 29155 was responsible — and that the operatives involved were the same men wanted in Britain for the Skripal poisoning, including Chepiga and Mishkin. The motive, reconstructed by investigators, was operational: the Vrbětice warehouses stored munitions belonging to Bulgarian arms dealer Emilian Gebrev, scheduled for delivery to Ukraine, which desperately needed them to fight Russia-backed separatists. The GRU was destroying weapons bound for Russia’s adversary in an undeclared war.

    In April 2015, Gebrev — the Bulgarian arms dealer whose munitions had been in the Vrbětice warehouses — was poisoned in Sofia. A substance was smeared on the handle of his car. He was hospitalized alongside his son and an employee. Released from the hospital, he was poisoned again with the same substance and survived. Bulgarian investigators identified at least eight Unit 29155 officers who had traveled to Bulgaria in the weeks surrounding the attack, including the man British authorities later identified as the commander of the Skripal team — Denis Sergeev, operating under the alias Sergei Fedotov. Three Russians were eventually charged. The case, according to The Times, became the “Rosetta Stone” that let Western intelligence services decode Unit 29155’s operational pattern after the Skripal attack three years later.

    In October 2016, Montenegro’s government announced it had foiled a coup attempt on the day of the country’s parliamentary elections. The plan, according to Montenegrin prosecutors: occupy the parliament building, assassinate Prime Minister Milo Đukanović, and prevent Montenegro from joining NATO. Fourteen people were charged, including Russian citizens. Two — Eduard Shishmakov and Vladimir Popov — were identified as Unit 29155 operatives. Both were convicted in absentia in 2019.

    In October 2018, Dutch officials caught four GRU officers in a rented car outside the headquarters of the Organisation for the Prohibition of Chemical Weapons in The Hague, attempting to hack into the organization’s Wi-Fi network. The OPCW was investigating the Novichok used to poison Skripal. At least one of the operatives has been linked to Unit 29155.

    Parallel operations have been documented or credibly alleged in Moldova (a 2014 destabilization campaign), France (15 operatives tracked visiting the Haute-Savoie region between 2014 and 2018), Switzerland (surveillance of World Anti-Doping Agency investigators in 2016-2017), and Spain (possible destabilization operations during the 2017 Catalonia independence referendum). In April 2024, a joint investigation by 60 Minutes, Der Spiegel, and The Insider alleged that Unit 29155 was connected to cases of “Havana syndrome” — the neurological symptoms reported by U.S. diplomats and intelligence officers in multiple countries since 2016. The Kremlin denied the allegations. The U.S. National Intelligence Council’s 2023 assessment concluded that adversary involvement was “unlikely.” The investigation disputed the assessment.

    The tradecraft failures

    The detail that makes Unit 29155 distinctive in the history of foreign intelligence services is how badly it operates. The two Skripal operatives used passport numbers that were sequential — four digits apart — suggesting they had been issued in a batch from a GRU-controlled office rather than produced through normal passport-issuance channels. Their cover identities could be penetrated by cross-referencing travel records with Russian databases that Bellingcat and its collaborators could access online. The perfume bottle containing Novichok was discarded where a Salisbury resident could find it, resulting in the death of a British citizen who had no connection to the operation. The 2017 Chechen guerrilla hit failed when the target’s wife shot the assassin. The Montenegro coup was rolled up on the day of the elections. The OPCW hack was caught in the parking lot.

    The sloppiness is so consistent that some Western intelligence analysts have concluded it is not entirely accidental. Moscow’s willingness to conduct operations that can be traced back to the Russian state, with operatives who receive state awards and whose handlers appear in family wedding photographs, signals a particular kind of message: the operations are deniable in the formal diplomatic sense, but the authorship is not supposed to be invisible. The targets — dissidents, journalists, arms dealers supplying Ukraine, NATO candidate countries — are meant to understand who is coming for them. The deterrent function requires attribution. The operational failures are embarrassing. The structural message — Russia reaches its enemies wherever they are — is preserved by the attribution itself.

    Why Unit 29155 is Lecture 24

    Unit 29155 is the final lecture of the Shadowcraft course because it’s the most current case study and the most operationally straightforward. The course’s earlier lectures — United Fruit, the British South Africa Company, BCCI, P2, the Vatican Bank — document covert power operating through commercial, financial, or institutional intermediaries. Unit 29155 operates through officers traveling on false passports with vials of nerve agent. The mediation layer is thin. The state is directly conducting the operations.

    But the structural logic is the same. Operation Gladio maintained Cold War paramilitary networks for purposes beyond their stated defensive mission. Wagner Group provides Russia’s state with deniable violence in theaters where direct military involvement would be politically costly. Unit 29155 provides deniable violence in theaters where even Wagner’s presence would be too visible — London, Salisbury, Sofia, Prague, Podgorica. Each institution fills a different rung on the deniability ladder. The Safari Club outsourced covert operations to allies. Western Goals outsourced surveillance to a nonprofit. Unit 29155 doesn’t outsource. It does the work in-house, sloppily, and relies on the formal deniability of state denials to maintain the architecture that lets the state keep denying.

    We cover Unit 29155 alongside Crypto AG, Mossack Fonseca, China Poly Group, and 20 other case studies of covert institutional power across our Shadowcraft course — where the final lecture is about a unit whose tradecraft fails often enough that it proves a harder point: the failures are visible because the attributions are the point.

  • Operation Gladio: NATO’s Secret Stay-Behind Armies Explained

    On October 24, 1990, Italian Prime Minister Giulio Andreotti stood before the Chamber of Deputies and confirmed what had been rumored for decades: a secret paramilitary network had been operating inside Italy since 1956, coordinated by NATO and the CIA, armed with weapons caches hidden in forests and mountain meadows, trained in unconventional warfare on remote Mediterranean islands and at British and American special operations centers, and composed of recruits who included ex-fascists and neo-fascists from the Italian far right. The network was called Gladio — the Latin word for sword. Similar networks existed in every NATO country in Western Europe: France, Belgium, the Netherlands, Luxembourg, Germany, Denmark, Norway, Portugal, Spain, Greece, Turkey. Parallel networks existed in neutral countries — Sweden, Switzerland, Finland, Austria. The networks had been internationally coordinated through the Allied Clandestine Committee in Brussels, whose last known meeting had taken place on October 23-24, 1990 — the day Andreotti gave his speech. Within weeks, the European Parliament condemned the stay-behind armies by resolution. Within months, similar parliamentary investigations were underway in Belgium and Switzerland. Italian magistrates who had been investigating unsolved terrorism for nearly two decades suddenly had a framework that tied the attacks together. The press called it “the best-kept and most damaging political-military secret since World War II.”

    What stay-behind was supposed to do

    The stay-behind doctrine emerged from a straightforward Cold War scenario. If the Soviet Union invaded Western Europe and NATO forces were pushed back, someone needed to remain behind the lines to conduct sabotage, gather intelligence, and support resistance movements — the same function the British Special Operations Executive and the American OSS had performed against Nazi occupation during World War II. The stay-behind networks were built on that model. Weapons caches were buried across Western Europe — in Italy alone, 139 cache sites were eventually disclosed, though ten of them couldn’t be recovered in 1973 because they’d been hidden in locations requiring “complex demolition work.” The networks were to activate only after a Soviet invasion. Their members were civilians, mostly vetted for anti-communist reliability, trained in guerrilla warfare and communications. The founding premise was defensive: preparation for an invasion that, as it turned out, never came.

    The Italian network was formalized through a bilateral agreement between Italian military intelligence (SIFAR) and the CIA signed on November 28, 1956, under the supervision of Defense Minister Paolo Taviani. A classified 1959 SIFAR document — later released to Italian parliamentary investigators — described the operation under the title “The Special Forces of SIFAR and Operation Gladio.” The document confirmed NATO coordination and CIA involvement. It described a network of trained operatives, buried arms, and communications infrastructure designed to activate in the event of occupation.

    What stay-behind actually did

    The Italian investigation that led to the 1990 disclosures began with a specific case — the 1972 Peteano bombing, in which three Carabinieri were killed by a car bomb. The attack was initially blamed on left-wing terrorists. Italian magistrate Felice Casson reopened the case in the 1980s and discovered that the bombing had been carried out by a far-right militant named Vincenzo Vinciguerra, that Italian officials had deliberately misdirected the investigation to implicate the left, and that the explosives used matched materials from a NATO stay-behind arms cache. Vinciguerra testified at his 1984 trial that he had been part of a broader network — the first public admission of Gladio’s existence, five years before Andreotti’s speech. Casson’s investigation led him to the archives of the Italian military intelligence service, where he found the 1959 SIFAR document confirming what Vinciguerra had described.

    The pattern Casson uncovered — a terrorist attack carried out by far-right operatives, initially blamed on the left, investigators steered away from the real perpetrators, explosives traced to stay-behind caches — matched a series of bombings and massacres that had defined Italy’s “Years of Lead” (anni di piombo) from 1969 to 1980. The 1969 Piazza Fontana bombing in Milan killed 17 people. The 1974 Piazza della Loggia bombing in Brescia killed eight. The 1974 Italicus Express train bombing killed twelve. The 1980 Bologna railway station bombing — the deadliest terrorist attack in postwar Italian history — killed 85 and wounded more than 200. In each case, the initial investigation implicated the far left. In each case, subsequent investigations found far-right operatives with intelligence service connections. The term that emerged from Italian historiography to describe the pattern was the “strategy of tension” — the deliberate use of terrorism to create public fear, discredit the left, and justify authoritarian responses.

    The 1980 Bologna bombing is the case with the strongest documented connection to Gladio and P2. Licio Gelli — the grandmaster of the P2 Masonic Lodge — and Pietro Musumeci, the deputy director of Italian military intelligence and a P2 member, were both convicted of obstructing the investigation. Gelli’s P2 network and the Gladio stay-behind network overlapped significantly in personnel: military officers, intelligence officials, and far-right operatives who appeared on one list frequently appeared on the other. The structural relationship between P2 and Gladio was the link between a political conspiracy and an operational one.

    The Belgian parallel

    Italy was not unique. Belgium’s stay-behind network — code-named SDRA8 — came under investigation after the Brabant massacres, a series of supermarket robberies and shootings between 1982 and 1985 that killed 28 people and were never fully solved. The attacks were carried out with military precision, often left valuable cash behind, and appeared designed to terrorize the Belgian public rather than generate revenue. Belgian parliamentary investigators concluded that elements of the country’s stay-behind network had been involved. Belgian Defense Minister Guy Coëme confirmed the existence of the Belgian stay-behind army in November 1990, weeks after Andreotti’s disclosure.

    The Swiss network — P-26 — was discovered by coincidence a few months before Andreotti’s speech and exposed as extremist in ideology rather than merely anti-communist. Swiss Defense Minister Kaspar Villiger resigned. The Swedish stay-behind network was acknowledged by General Bengt Gustafsson in 1990, who denied NATO or CIA involvement — a denial contradicted by CIA officer Paul Garbler, who confirmed Sweden was “a direct participant.” In every country where parliamentary investigations took place, the pattern was similar: the official purpose of the network was stay-behind resistance to Soviet invasion; the actual operational history included connections to domestic right-wing terrorism, political manipulation, and obstruction of democratic oversight.

    Why it’s Lecture 6

    Gladio is the Shadowcraft case study that demonstrates how covert infrastructure outlives its original purpose. The stay-behind armies were built for one scenario — Soviet invasion — that never happened. The infrastructure they created — trained operatives, weapons caches, communications networks, command structures, relationships with far-right organizations — existed for 40 years across 15 countries without ever being activated for its stated purpose. What it was activated for, in documented cases across multiple countries, was domestic political manipulation: terror attacks designed to shift public opinion, investigations steered away from state-connected perpetrators, and coordination with organizations like P2 that operated outside democratic accountability.

    The Safari Club was built to continue covert operations abroad when Congress constrained the CIA. Gladio was built to prepare for an invasion and became, in documented cases, an instrument of domestic political violence when the invasion didn’t come. Both share the same structural logic: capacity created for one purpose becomes available for others, and the oversight mechanisms that should catch the drift don’t catch it, because the capacity was classified into invisibility before anyone could define what it was for. Western Goals preserved surveillance files that Congress had ordered destroyed. Gladio preserved operational capacity that should have ended when the Cold War ended — and in some documented cases, began using that capacity against the democracies it was built to defend.

    We cover Operation Gladio alongside BCCI, the Vatican Bank, Wagner Group, and 20 other case studies of covert institutional power across our Shadowcraft course — where a network built to resist an invasion that never came became the single most documented example of how Cold War infrastructure outlived the Cold War.