Blog_en

Cyberwarfare as a Tool of Hybrid Aggression

Hybrid warfare today is no longer limited to traditional military confrontation. It also encompasses the information, cognitive, and cyber domains, where the struggle for control over data, public perception, and technological resources is taking place. In this context, the hybrid - or asymmetric - dimension of cyberwarfare should be viewed as a geopolitical instrument.

Given the highly covert nature of hostile actions in cyberspace, as well as the production of manipulative and deceptive media content, cyberspace has become a key platform for the implementation of hybrid warfare. At the same time, specialized units of armed forces and intelligence services in leading countries are increasingly involved in military cyber operations. In addition, as states introduce modern information technologies into the defense and security sector - especially unified automated command systems and other national information infrastructure - national defense becomes more vulnerable to cyberattacks targeting military and information-support systems. For these reasons, and under the conditions that have emerged in recent years, the issue of cyber defense has become a matter of national importance as one of the essential mechanisms for countering hybrid threats and aggression in cyberspace, including cyberwarfare.

Cyberwarfare can be defined as a complex set of technical, organizational, and technological measures within the framework of a hybrid warfare strategy, aimed at gaining an advantage in information networks and cyberspace or disabling them in order to weaken the opponent’s operational capability. Cyberwarfare is closely connected with information confrontation and network-centric interstate conflict, which are among the main manifestations of hybrid war. Experts also include information operations, psychological operations, and cyberattacks directed both at the technical infrastructure of a state and at the consciousness of its citizens. Today, cyberwarfare has become part of modern interstate hybrid confrontation.

Aggression in cyberspace is an extremely dangerous component of hybrid war. For example, in April 2024, Michael Casey, head of the U.S. National Counterintelligence and Security Center (NCSC), stated that the scale of foreign espionage operations, cyberattacks, and economic espionage against the United States is “staggering and alarming.” The U.S. faces a significant number of security threats related to espionage and cyberattacks from China, Russia, Iran, and North Korea. NATO Deputy Secretary General Mircea Joane expects an increase in Russian cyberattacks and disinformation amid elections in the European Union. He noted that Russia will use disinformation and cyberattacks to influence European elections and improve results for political forces favorable to it. Earlier, in 2016, U.S. intelligence agencies accused the Russian leadership of organizing cyber sabotage during the U.S. election campaign.

During cyberwars, massive attacks are carried out against government and corporate websites, cyber espionage is conducted, and warfare in social media is waged by the “troll factories” of the aggressor state. On May 16, 2016, German intelligence officials accused Russian hackers of cyberattacks on government information servers in Germany. It was also emphasized that another serious danger could originate from the Russian side — sabotage at industrial and energy infrastructure facilities. The then head of Germany’s Federal Office for the Protection of the Constitution, Hans-Georg Maaßen, also expressed concern about cyberattacks from abroad: “Hybrid wars are being waged in cyberspace, and new opportunities for espionage and sabotage are emerging.”

The emergence and use of widely known malware such as Stuxnet, Flame, Duqu, Gauss, Wiper, Shamoon, Regin, and their variants marked the beginning of the cyberwar era. Most experts classify these programs as forms of cyber weapons used at the state level in the following ways:

  • Stuxnet was used to carry out destructive actions against the automated control systems of the uranium enrichment facility in Natanz, Iran. In essence, Stuxnet became the first digital virus-weapon.
  • Shamoon was used to attack key oil and gas companies within the critical energy infrastructure in the Middle East, including Saudi Aramco in Saudi Arabia and Ras Gas in Qatar.
  • Flame, Duqu, and Gauss were used to enable the leakage of confidential information about critical facilities, institutions, and individuals connected to Iran’s missile and nuclear program, as well as those in other Middle Eastern countries.
  • Wiper was used to erase confidential data from computers belonging to the Iranian government.

Such cyberwars - or more accurately, large-scale cyber operations - can only be conducted by state structures or organizations closely linked to the state, operating not only in cyberspace but also through intelligence cover and operational support.

In the near future, other examples of cyber weapon deployment in cyberwars should be expected, possibly even more destructive than those already mentioned.

At the same time, despite the practical use of special cyber operations characteristic of cyberwarfare, the theory of interstate conflict in cyberspace is still in a stage of formation and development.

Considering these examples and trends, a number of fundamental principles can be identified that reflect the evolution of cyberwarfare as part of hybrid confrontation.

Cyberwarfare is therefore a systemic set of complex procedures and technologies of transformational and informational influence on an opponent’s command centers, which only at the final stage - and not always - involves the high-intensity use of conventional armed forces.

The defining trends of modern cyberwarfare are:

  1. The growing role of cyber operations in modern warfare.
  2. The high vulnerability of national information infrastructures, especially critical ones.
  3. The effectiveness of cyber espionage in global economic and political competition.
  4. Activities in cyberspace are often driven by ambitious pragmatic goals, including the pursuit of global economic advantage by a particular state.
  5. Cyberattacks are increasingly characterized by a high level of technological sophistication and effectiveness in penetrating information and communication systems for intelligence gathering, and are less related to outdated tactics such as DDoS attacks or content spoofing.

In general, the key elements of modern concepts of “cyberwarfare,” “information confrontation,” and “network warfare” are:

  • Intelligence warfare, based on the ability to collect and analyze, in near real time, information in various languages gathered or intercepted by electronic means.
  • Through cyberwarfare, states seek dominance in cyberspace, the ability to disrupt, intercept, and monitor an opponent’s communications while protecting their own.
  • In the course of interstate computer network attacks, malicious software is introduced into the opponent’s information systems.
  • Psychological warfare, or PsyOps, uses social information tools to destabilize the population and political leadership of the opposing state.

Thus, the concept of cyberwarfare is becoming increasingly relevant. Cyberwarfare involves achieving superiority over an opponent through the broad implementation of new technologies in command-and-control and communications systems and, importantly, through the improvement of organization and management in the military sphere.

For a more detailed discussion of the technologies, methods, manifestations, and tools of hybrid warfare against the state, society, business, and individuals, see SIDCON’s book Modern hybrid warfare technologies.
2026-06-25 09:11 Hybrid warfare