Wars fought without precedent or attribution
Technology is creating new forms of asymmetric warfare
Let me bring together three stories I read over the past week that offer a forewarning for how great- and even petite-power wars will be fought in the years ahead.
From my home state of Minnesota came news that hackers had successfully sabotaged several dozen water treatment plants across the prairie state. Since then, more than 12 states have reported hacks on water systems, with Georgia’s Clayton County sending out boil notices to its roughly 300,000 residents. Damage so far has been limited, and it doesn’t seem that any American has completely lost water or sewage. Experts believe the hackers are Iranian-linked.
Second is an on-going story about the Foxtrot Network that operates in Sweden and much of Europe. This group, also believed to be connected to Iran, pays teenagers to commit murder-for-hire for a pittance (or what the BBC described as “violence-as-a-service” — which, how Silicon Valley of these entrepreneurs). Teenagers are recruited with gamified missions distributed through social media channels on platforms like Telegram, and then they are given their final mission with a promise of a windfall cash reward upon success. Even when successful, though, the teenagers are so often caught by authorities that the Network rarely has to pay its bounty.
Third and via Jack Clark’s always useful Import AI Substack, AI models are getting efficient enough that self-evolving malware can propagate and actively adapt to new computing environments by using custom coding harnesses and on-device open-weights models. As the researchers note in their working paper, “because the worm requires no commercial AI platform, centralized safety controls, such as service refusals or rate limiting, are structurally irrelevant.” Malware has been a scourge for decades, and this work offers an early look at how it will evolve in the years ahead.
These three stories offer a pattern for how wars in the future (if we’re being honest, right now, too) will be fought. As we’ve seen in both Ukraine and Iran, head-to-head confrontations are increasingly running up against the hard math of scaled materiel. Given domestic demands, democratic and authoritarian countries lack the needed resolve to go all-out on redirecting industrial capacity to seize victory, and so they trundle along month-after-month and year-after-year toward a Pyrrhic stalemate.
The alternative then is asymmetric operations, which have a number of advantages. Notice first that these operations rarely blaze the flags of the countries conducting them. The water hacks across America are judged to a high degree of certainty by experts to be the work of Iran given the hacking group’s behavior and previous activities. Nevertheless, there are no dog-tagged troops on the battlefield to definitively prove this one way or the other. Can you hold Iran accountable for the work of these adjacent hackers? How?
The Foxtrot Network, not unlike similar criminal networks that operate with the consent of Russia, China, North Korea and others, fills a similarly ambiguous position. Is this the work of a handful of independent evil villains, or a key nexus for power projection by the Islamic Republic in Tehran? This isn’t a minor point at all, given that criminal and international laws, modern rules of engagement and our democratic political systems are not designed to consider, say, teenagers walking down the street with cash from terrorist regimes plotting kills. That ambiguity is useful precisely since it forces clashes of jurisdiction in democratic governments, particularly between traditional law enforcement and intelligence agencies.
Then there’s the fear factor. BBC’s article on the Network leads with a headline image of a teenager brandishing a gun while wearing a black jacket and ski mask. He is astonishingly young, but also clearly someone who can be envisioned as a killer. And that’s the point: even the kid next door could be a mortal threat.
Indeed, in all of the hybrid wars and gray-zone tactics conducted mostly in Europe and mostly by Russia, the propaganda value of these operations is almost worth more than the underlying objectives themselves. The dissolution of basic societal norms, the fear of violence within our communities, and the feeling that the government doesn’t have a grip on its own territory is extraordinarily valuable in terms of our adversaries’ goals. Russia targets young refugees for their economic precarity and their potential penchant for seeking a narrative to redeem their often shattered lives. The fact that it exacerbates nativist tensions makes it downright devious.
Self-adapting malware may seem to be a science-fiction counterpart to these other two stories, but really, it’s much the same. Asymmetry is all about rapid flexibility in the face of an overwhelmingly powerful force. The United States and Israel (assumed but never officially confirmed) were behind the notorious Stuxnet cybersecurity attack on Iranian centrifuges that significantly delayed the country’s sprint to a nuclear weapon. Stuxnet worked by targeting the SCADA control systems that underpin much of modern industrial automation — including the water and sewage systems that were targeted this week across America.
We don’t have tools to fight back . After all, these hacking groups may only be a few dozen or hundreds of people in an office block outside a major city. Are we going to start nuclear war to get at them?
Cybersecurity experts working with unclassified data believe Stuxnet was developed over roughly five years and then actively deployed for upwards of a decade. It was an extraordinary invention, but what would a Stuxnet attack look like today in a world of coding agents and LLMs? We can presume that as local AI models become ubiquitous, this form of malware would have greater adaptability to find new flaws in the systems they breach. The years of careful tinkering and searching for zero-day bugs that underpinned Stuxnet could be accelerated many-fold.
Worse, this new malware may be even harder to attribute than typical cybersecurity attacks. Attribution is a form of investigative alchemy, combining everything from behavioral signals (work on the code happens during Moscow’s office hours) to coding style (the source is written in Russian) in order to identify a likely attacker. But self-evolving malware could limit the power of these key signals. After multiple generations of evolution, malware may be almost unrecognizable from its earliest incarnations, making future attacks even more ambiguous and fraught.
This is a different concern than the use of frontier models like Anthropic’s Fable to conduct cyberwar by state actors. Indeed, such cyberattacks generally follow some form of rules of engagement and tend to be more limited in scope given the risk of tit-for-tat responses. What should be alarming is the use of these tools by hybrid groups with much more plausible deniability while operating outside the general norms of international relations. We don’t have tools to fight back here. After all, these hacking groups may only be a few dozen or hundreds of people in an office block outside a major city. Are we going to start nuclear war to get at them when they are otherwise protected by their host governments?
Conflict is accelerating faster than our institutions have adapted. That’s not a great position in a world where the weapons themselves can self-adapt.
There is growing frustration in the West about the societal costs of these asymmetric operations and our completely inadequate response to them, leading to more calls for an offensive response. Renee Pruneau Novakoff, writing in The Cipher Brief this week, argued, “We need to be upfront that leading in gray zone operations is good for US national security. If we do not quickly make gray zone strategies a key part of our national security then we risk our global leadership role.” That matches an essay earlier this year in Small Wars Journal, in which Daniel Pullan and Joshua Young wrote that “If [U.S. special operations forces] were authorized and enabled to conduct persistent, disparate, small-scale gray zone operations across diverse geographic areas, the US could steadily increase the resource and cognitive burden on its adversaries, allowing it to proactively combat adversarial operations in this space.”
Motions toward offensive operations have increased, but the administrative burdens remain keen. In a report for the Council on Foreign Relations last month, F. David Diaz notes that “no single U.S. government agency is responsible for integrating each of the warning indicators before a crisis, and no standing mechanism exists to orchestrate a rapid government-wide response during one.” That’s the problem that has remained true for two decades of asymmetric warfare, even as its frequency becomes ever higher.
Conflict is accelerating faster than our institutions have adapted. That’s not a great position in a world where the weapons themselves can self-adapt and fight an arms race all on their own. Yet, we still have time, as the relatively limited damage from these three stories attest. We need to use the remaining time we have as best as we can to shore up our defenses and response protocols while also committing to a more robust form of offensive hybrid war in order to ensure that tomorrow’s super cyberweapon, developed by an angsty teenager backed by a foreign adversary, doesn’t lead to the taps running themselves dry.
Also check out
Reporting from the frontlines of data-center NIMBYism.
Or you can just build your own new backyard somewhere else, but it might get shut down.
Twenty-five years after 9/11, whatever happened to al Qaeda?
Why the UAE is making nice with Iran.
And why the USA is making not-nice with Cuba.




It’s an odd world, trying to balance the fighting of monsters without becoming one while staying open to the things they make us a democracy yet render us vulnerable.