The New Axis of Evil: Mapping China, Russia, Iran & North Korea's Coordination

The New Axis of Evil: Mapping China, Russia, Iran & North Korea’s Coordination

Bottom Line Up Front (BLUF)

From rumor to record - the Caspian Sea reveal, confirmed troop and munitions numbers, and the architecture tying four adversaries together.

Key Judgments

  • ASSESSED: China, Russia, Iran, and North Korea function as an interconnected coordination architecture rather than four separate bilateral relationships with the West. Each nation’s support to another materially shapes a third nation’s capability or leverage – the defining feature that separates this grouping from a simple shared-grievance alignment.
  • CONFIRMED: North Korea supplies Russia with manpower and munitions at a scale assessed to cover roughly half of Russia’s frontline ammunition needs in Ukraine; China supplies calibrated dual-use components; Russia in turn supplies Iran with material and intelligence support in its war with the US and Israel.
  • CONFIRMED: What was long treated as rumored or unconfirmed cooperation moved decisively into the confirmed record in July–August 2026, when Ukrainian strikes on Russian-flagged cargo vessels in the Caspian Sea publicly exposed the Russia-to-Iran shipping route, followed by NBC News’ document-based confirmation of the underlying arms flow.
  • ASSESSED: The term “Axis of Evil” applied to this four-nation grouping is not a CommandEleven coinage – it has circulated in Washington analytical circles since at least 2024. This dossier’s contribution is not the label but the evidentiary architecture beneath it: moving the coordination thesis from analyst speculation to a numbers-backed, cross-referenced assessment.
  • ASSESSED, drawing on CommandEleven’s own prior published assessment: Iran’s relationship with the Taliban in Afghanistan – including a reported December 2025 IRGC acquisition of the Taliban’s biometric database of US-affiliated personnel in exchange for a promised recognition of the Taliban government, subsequently placed on hold when the US-Iran war began – extends this architecture’s regional footprint eastward, with direct relevance to Pakistan’s security environment.

From Rumor to Record: The Reveal

For years, the depth of coordination among these four nations was something analysts inferred more than documented – visible in UN vote patterns, arms-fair appearances, and rhetorical alignment, but rarely in hard logistics. That changed in the summer of 2026:

  • July 25, 2026: Ukrainian forces struck Russian-flagged cargo vessels in the Caspian Sea – the Port Olya 2 and Begey among those identified – publicly exposing a shipping route between Russia and Iran for the first time. President Zelensky confirmed the strikes; Iran’s Foreign Ministry confirmed casualties on an affected vessel and condemned the action.
  • August 17–18, 2026: NBC News published document-based confirmation – a European government document, verified by a Western official – that Russia had been shipping TNT, drone components, and ammunition to Iran via Amirabad Port since July, using vessels owned by MG-FLOT (formerly Transmorflot), a Dagestan-based, already-sanctioned Russian shipping firm with a documented history dating to 2022, when the same vessels ran the route in the opposite direction, carrying Iranian Shahed drones to Russia.

This dossier treats that reveal sequence as the hinge point that justifies moving this coordination architecture from an analytical thesis to a documented case study – not because the underlying cooperation was new, but because its evidentiary basis changed decisively within a matter of weeks.

The Architecture, Mapped

Inbound to Russia (sustaining the Ukraine war):

  • North Korea: an estimated 11,000–15,000 troops deployed to Kursk Oblast; a missile unit of roughly 90 personnel reportedly deploying to Voronezh with up to 120 ballistic missiles and 6 launchers; 5–6 million rounds of artillery/mortar ammunition supplied, assessed by Ukrainian defense intelligence at roughly half of Russia’s frontline needs; 120 Koksan self-propelled artillery systems and 120 multiple-launch rocket systems delivered over a recent three-month window; at least 150 KN-23 ballistic missiles committed, 40 delivered, at least two fired at Ukrainian targets.
  • China: ASSESSED to supply microelectronics and dual-use components for Russian ballistic, hypersonic, and cruise missile production – calibrated below the finished-weapons threshold, preserving Beijing’s public denial and “three principles” posture as a functional part of the arrangement.

Outbound from Russia (extending into the Iran war)

  • Material: TNT, drone components, and ammunition, confirmed shipped via Caspian Sea routes since July 2026, using MG-FLOT vessels, delivered to Amirabad Port.
  • Intelligence: ASSESSED, Joint Chiefs-level sourcing – satellite imagery and targeting-relevant data, including reported information on US/allied installations and a list of Israeli energy-infrastructure targets.
  • Standing contractual relationship (pre-dating and outlasting the current war): a 48-aircraft Su-35 contract, Yak-130 trainers delivered since 2024, up to six Mi-28 attack helicopters by January 2026, and a €500 million Verba MANPADS contract signed February 2026.
  • Reciprocal flow: Iran’s own transfer of Shahed-series drones and production technology to Russia, ongoing since 2022 – the relationship runs in both directions.

China’s parallel, direct contribution to Iran

Iran’s migration from GPS to China’s BeiDou-3 satellite navigation system since 2025, reportedly improving missile precision to under 5 meters circular error probable and enabling long-range drone/missile retasking via BeiDou’s short-message feature.

  • ASSESSED, not CONFIRMED: whether this reflects active Chinese coordination versus passive infrastructure access. See CommandEleven’s China’s Iran 2026 Attrition Strategy for the full strategic analysis.

Russia’s technology transfer to Iran, beyond material and intelligence

CommandEleven’s FindFace: Assessing Iran’s Secret Russian Surveillance Grid documents Russian-supplied facial-recognition/surveillance infrastructure inside Iran – a direct, independently-sourced technology-transfer channel distinct from, and additive to, the shipping-route material.

The Connective Judgment

North Korean and Chinese support sustains Russia’s capacity to sustain its own war; that same capacity is what allows Russia to extend material and intelligence support to Iran. China separately and directly extends satellite infrastructure support to Iran. No single bilateral relationship in this picture is fully explicable without reference to at least one other.

The Deterrence Response: Washington Treats This as One Problem

The clearest evidence that this architecture is now being read as a linked system, not four separate files, comes from the US response itself:

  • CONFIRMED: US intelligence assessed Russia may be preparing to test NATO’s Article 5 resolve through a limited attack or hybrid incursion against a Baltic state or Poland.
  • CONFIRMED: CIA Director Ratcliffe’s unannounced August 25, 2026 Moscow trip carried a direct warning against this, alongside a demand that Russia curtail its military and economic support to Iran – the two demands delivered in the same visit, timed alongside the Treasury’s “Operation Economic Outcast” sanctions announcement. Russia’s SVR confirmed a “working-level meeting”; Peskov confirmed Putin was briefed but did not attend.

Calibrating counterweight

Baltic officials themselves downplayed the visit’s significance – Estonia’s foreign minister described it as something that “should not be seen as pivotal.”

  • DATA DEFICIT, excluded from Key Judgments: a claim that Putin ordered a shutdown or drawdown of the US embassy in Moscow tied to this visit remains uncorroborated by any independent reporting found by CommandEleven. The C-17 Globemaster cited in connection with this claim has a fully mundane, confirmed explanation (Ratcliffe’s own transport, routed via Riga) that does not require the embassy claim to account for it.

The fact that a single diplomatic visit carried warnings on both the Ukraine and Iran fronts simultaneously is itself the strongest available evidence that US policymakers now view this as one coordinated threat picture rather than two unconnected regional files.

Extending East: Iran, the Taliban, and Pakistan’s Exposure

This architecture’s regional footprint extends beyond the four core nations through Iran’s relationship with the Taliban government in Afghanistan:

  • ASSESSED: Iran has pursued a deepening, pragmatic relationship with the Taliban since 2021 – the February 2026 handover of the Afghan embassy in Tehran to Taliban diplomats, trade volume Iranian officials describe as exceeding Iran’s total trade with all of Europe combined, and IRGC intelligence cooperation with Taliban counterparts to track Afghan nationals who assisted Western forces, intensifying after 2025 assassinations of anti-Taliban figures on Iranian soil.
  • ASSESSED, per CommandEleven’s own prior published assessment: in December 2025, the IRGC acquired the Taliban’s complete biometric database of personnel who assisted US-affiliated operations, in exchange for a promised Iranian recognition of the Taliban government – recognition subsequently placed on hold when the US-Iran war began in early 2026. CommandEleven’s full existing assessment of this, The Taliban Grid: Hybrid Biometric Threats in Afghanistan, is the primary reference for this claim.
  • ASSESSED: Pakistan’s exposure here is direct, not incidental. Pakistan borders both Iran and Afghanistan; Afghanistan-Pakistan relations have deteriorated into active cross-border hostilities during the period this series covers; and an Iran with deepening Taliban intelligence ties sits directly adjacent to that instability, adding a fifth-nation regional dimension to a picture otherwise framed around four.

What Holds the Architecture Together – and What Could Fracture It

Existing open-source analysis (predating and independent of this series) has consistently flagged that this grouping is a partnership of convenience rather than a formal alliance, with real friction beneath the surface:

  • China’s relationship with the other three is calibrated and deniable specifically because Beijing has broader economic interests with the West that Moscow, Tehran, and Pyongyang do not share to the same degree – the “three principles” posture reflects a genuine constraint, not just messaging.
  • North Korea’s relationship with Russia is transactional and plausibly time-limited to the duration of the Ukraine war’s most intensive phase – what happens to this flow of manpower, munitions, and reciprocal technology once that conflict’s tempo changes is a live open question this dossier flags rather than resolves.
  • Analysts outside CommandEleven have specifically noted that cooperation among these four is likely to diminish once the Russia-Ukraine war ends, and that treating the grouping as a permanent bloc risks becoming a self-fulfilling prophecy rather than a description of durable fact.

This dossier’s position: the architecture is real and evidentially supported as of 2026, but should not be over-read as a permanent alliance structure. Its coordination is crisis-contingent – most visible and most consequential precisely when multiple member states are simultaneously at war.

Strategic Implications

  • For government audiences: the Ratcliffe visit’s dual framing – Baltic deterrence and Iran-support curtailment delivered together – suggests the most effective policy lever may be treating constraints on any single relationship (sanctions enforcement against shipping entities like MG-FLOT, for instance) as having potential effects across the whole architecture, not just the targeted bilateral relationship.
  • For regional/allied audiences, Pakistan specifically: the Iran-Taliban relationship’s intelligence-sharing dimension, and the specific biometric-database, represent a live counterintelligence and personal-security concern for individuals in the region who assisted Western operations, and a data point Pakistani security planners should weigh directly given geographic proximity.
  • For business/infrastructure audiences: this architecture’s cyber and space-infrastructure dimensions (China’s role, covered at length in CommandEleven’s broader grey-zone series) mean commercial exposure to this coordination isn’t limited to companies operating in the four core nations – it extends to any organization dependent on infrastructure or navigation systems these actors have shown willingness to leverage.

Sourcing & Methodology Note

This dossier draws directly on and cross-references CommandEleven’s six-part Grey Zone Warfare series (Parts I–VI), particularly Part III (Russia’s hub role, North Korea’s contribution figures), Part II (China’s BeiDou role and EO 14420), Part IV (Iran’s proxy architecture), and Part V (North Korea’s independent threat profile). Readers seeking the full analytical depth behind any single thread in this dossier should consult the corresponding part of that series directly.

Two items in this dossier are carried at SPECULATIVE or ASSESSED-pending-corroboration tier and should be actively revisited in future updates rather than allowed to persist indefinitely at their current tier:

  • The Moscow embassy-shutdown claim (Section 3) – uncorroborated as of drafting.
  • The specific coordination-versus-access question on BeiDou (Section 2) – ASSESSED, not CONFIRMED.

This dossier functions as a standalone deep-dive companion to the Grey Zone Warfare series.

Linked Entities

Operational Theater

Area of Responsibility Map