Skip to content

When Code Becomes War: The Rise of Algorithmic Conflict

Explore how cyber warfare has evolved far beyond disinformation campaigns - merging artificial intelligence, psychological manipulation, and deep surveillance systems. This analysis dissects real-world conflicts, from Ukraine to Gaza, and examines how AI reshapes both attack and defense in the digital age.

/ ARTICLE
[ FIG. 1 ]
Cyber soldier standing amid a digital battlefield, symbolizing AI-driven warfare and hybrid conflict.

TL;DR

Cyber warfare stopped being about defaced homepages somewhere around 2010, when Stuxnet destroyed physical centrifuges with code. What replaced it is harder to categorise: data control, kinetic operations timed to digital ones, and influence campaigns run at machine speed — with nation-states, ransomware syndicates, and anyone holding an open-weight model operating in the same space.

Defenders responding to this have converged on much the same short list: zero-trust architecture, behavioural detection, and aggressive data minimisation. None of it is exotic. What follows is how the threat got here, and why those particular defences are the ones that survived contact.


Timeline of Modern Cyber Conflicts

YearEvent / OperationImpact
2010Stuxnet (US/Israel vs. Iran)The first known malware engineered to cause physical destruction, sabotaging Iranian nuclear centrifuges and rewriting the rules of digital warfare.
2014Russia-Ukraine Hybrid ConflictState-backed cyber offensives ran concurrently with the physical annexation of Crimea, establishing the template for hybrid war.
2016US Presidential Election InterferenceCoordinated botnets and disinformation campaigns exploited social platforms to deepen political polarisation ahead of election day.
2017NotPetya Supply-Chain AttackMalware disguised as ransomware caused over $10 billion in global damage, bringing shipping giants, pharmaceutical firms, and government agencies to a halt.
2020SolarWinds InfiltrationRussian state actors embedded malicious code into a routine software update, giving them months of silent access to US government networks.
2021Colonial Pipeline & KaseyaRansomware groups crippled critical energy infrastructure and a major IT provider, forcing the US to treat cyber extortion as a national security crisis.
2022Full-Scale Invasion of UkraineKinetic military operations merged with wiper malware campaigns, satellite network attacks, and mass information warfare in real time.
2023–2025AI-Assisted Targeting (Gaza)The first documented use of AI-assisted targeting platforms in active combat raised urgent questions about automated lethal decision-making.
2024The Global AI Election YearGenerative AI dramatically lowered the cost of producing localised disinformation, flooding dozens of national elections with synthetic content.
Advertisement

The New Threat Landscape

Nation-States and Proxy Groups

Major powers now run standing cyber commands built for espionage, infrastructure sabotage, and public manipulation. Russian doctrine has embedded psychological operations inside tactical campaigns for decades; Chinese operations run at industrial scale against governments, corporations, and research institutions, with a persistent focus on long-horizon intellectual property collection rather than immediate disruption.

The proxy layer is what makes attribution so slow. States increasingly work through informal “patriotic” hacker coalitions and criminal contractors who pursue state objectives without a state fingerprint — which buys deniability for the sponsor and creates a genuine analytical problem for defenders. By the time attribution is confident enough to publish, it is usually months past the point where it would have changed anyone’s decisions.

The Cybercrime Syndicate

Ransomware operations have organised themselves like businesses, because that is what works: affiliate programmes, negotiation desks, support channels for victims struggling to buy cryptocurrency, and in several cases published “policies” about which sectors are off-limits. Profit drives the targeting. But the targets frequently align with state interests anyway — hospitals, energy distribution, municipal services — producing geopolitical pressure without anyone having to declare anything.

That overlap is the analytically awkward part. When a ransomware crew takes a city’s emergency dispatch offline, the difference between opportunism and sanctioned sabotage may not exist in the operators’ own minds, let alone in the evidence available to the responders.

Hacktivists and Ideological Actors

Decentralised movements like Anonymous, along with dozens of smaller cause-driven collectives, sit on the boundary between activism and sabotage without ever settling on one side. No hierarchy means no leadership to negotiate with, no doctrine to model, and nothing to deter — the usual tools of statecraft assume an addressee.

They are also convenient cover. A state that wants an operation conducted without owning it can amplify an existing hacktivist campaign rather than run its own, and the resulting activity is genuinely hard to distinguish from spontaneous ideological action, because part of it is.

AI-Enabled Threat Actors

The specific thing generative AI changed is the cost of fluency. Writing a convincing phishing email in a language you don’t speak used to require a person who did; now it requires a prompt. The awkward-grammar heuristic that a decade of security awareness training was built around is simply gone, and most training programmes have not been rewritten to reflect that.

The capability ceiling has not risen much — a well-resourced intelligence service could already do all of this. The floor has collapsed. Reconnaissance, pretext generation, and voice cloning are now available to operators with a consumer GPU and no particular skill, which changes the volume of credible attacks far more than it changes the sophistication of the best ones.


PsyOps and Digital Influence Warfare

The target moved from territory to the population’s information diet. Leaflets became recommendation algorithms, rumours became synthetic video, and state broadcasts became accounts engineered to read as ordinary people who happen to agree with each other.

  • Botnets and Troll Farms: Thousands of synthetic accounts manufacture the appearance of consensus — amplifying hashtags, saturating replies, and making a fringe position look like a majority one. The mechanism exploits a real cognitive shortcut: people infer legitimacy from apparent popularity.
  • Deepfakes and Synthetic Media: Generated audio and video can now impersonate a politician or a company executive well enough to survive a first viewing. The dangerous window is narrow and specific — the hours during a crisis before verification catches up.
  • Spear-Phishing at Scale: Public data plus a language model produces personalised messages with no grammatical tell. Whatever your awareness training says about spotting bad English, it is now training staff on a signal that no longer exists.
  • Clone Media Networks: Fake outlets with invented mastheads and non-existent bylines publish fabricated stories that get indexed, surfaced in search, and cited onward by people acting in good faith.
  • Cognitive Targeting: Behavioural data identifies which emotional triggers land with which demographic segment, and content is generated to fit. The objective is rarely persuasion. It is usually to deepen an existing division until compromise becomes impossible.

The collective term is cognitive warfare, and its aim is not to break infrastructure. It is to degrade the shared factual basis a society needs in order to agree on anything, including what just happened to its infrastructure.


AI in Cyber Conflict

Artificial intelligence sits on both sides of the same engagement, and the asymmetry between those two roles is not in the defender’s favour.

Offensively, it automates reconnaissance, adapts malware to what it finds, and tailors social engineering per target. Work that once needed a skilled developer on payroll can be done with a fine-tuned open-weight model on consumer hardware.

Defensively, machine learning is what makes log volumes at modern scale tractable at all — behavioural baselining, anomaly scoring, automated containment. The trade-off is rarely stated plainly: these systems generate false positives at a rate that exhausts analysts, and every tuning decision that reduces alert fatigue also widens a blind spot. Teams that treat detection models as an install-and-forget control end up with confident dashboards over uninspected gaps.

The direction of travel is toward information operations that run without a human in the loop. Systems can already draft posts, argue in replies, and adjust framing based on live engagement metrics. The 2024 election cycle demonstrated that the pipeline for this is built and operational. The realistic worry is not a machine deciding to start a war — it is a crisis being narrated and escalated at a tempo no editorial process, and no diplomatic one, can match.

AI humanoid projecting light from its core, representing artificial intelligence and data control in cyber warfare.

Case Studies: Real Conflicts in the Digital Age

Ukraine (2022–Present): The First Full-Scale Hybrid War

Ukraine is the most thoroughly documented fusion of kinetic and cyber operations to date. In the weeks before the February 2022 invasion, wiper families including WhisperGate and HermeticWiper hit Ukrainian government and financial networks — destructive, not extortionate, with no recovery path offered because recovery was never the point.

The Viasat KA-SAT compromise on the morning of the invasion is the clearest illustration of why this domain resists containment. The operation targeted Ukrainian military communications and also bricked tens of thousands of modems across Europe, including several thousand German wind turbines’ remote monitoring links. Collateral effect on that scale is not a bug in cyber operations. It is a structural property of attacking shared commercial infrastructure.

Ukraine’s IT Army — a distributed volunteer force of developers and researchers running DDoS campaigns against Russian government portals, logistics systems, and state media — went the other direction. Its direct military effect was modest, and the more interesting outcome was legal rather than tactical: thousands of civilians in dozens of countries participating in hostilities from their bedrooms, a category that existing law of armed conflict handles badly.


Gaza (2023–2025): Algorithmic Targeting in Active Combat

Gaza marked the first publicly documented use of AI-assisted targeting systems in live combat. Investigative reporting by +972 Magazine and Local Call described platforms named Lavender and The Gospel, which ingest surveillance data — phone records, location history, social graph connections — and produce ranked target recommendations at machine speed.

Israeli officials confirmed using AI tools to accelerate targeting while maintaining that a human analyst authorises every strike. Human rights organisations and independent defence researchers disputed what that authorisation amounted to in practice, arguing that the volume and pace of recommendations reduced human review to a formality measured in seconds.

That dispute is the substance of the issue, not a detail of it. A human-in-the-loop requirement is only a meaningful constraint if the loop runs slower than the human can think. Whatever the operational reality in this specific case, the precedent is established and unlikely to be walked back: machine recommendation now sits inside lethal targeting, and the legal frameworks meant to govern it were written for a world where every target was assessed by a person with time to disagree.


Iran and Regional Infrastructure Targeting

Iranian operations have persistently targeted critical infrastructure across the region — municipal water treatment, power distribution, hospital networks. The strategic logic is deliberate and, from the actor’s perspective, sound: cyber operations project force at low cost and sit below the threshold that would justify a conventional military response.

That threshold is the whole game, and nobody has defined it. Attacks on Israeli water treatment control systems attributed to Iranian actors, and the retaliatory disruption of Iranian port operations, both stayed carefully short of casualties. The uncomfortable part is that staying short of casualties in an operation against a water plant depends partly on the attacker understanding a control system they did not build.


Supply-Chain Attacks: The Trusted Vector

SolarWinds and Kaseya set a template that has not been improved on because it does not need improving. Compromise one trusted vendor, ship malicious code through the legitimate signed update channel, and thousands of downstream organisations install it themselves. Every control the victim operates works exactly as designed: the signature validates, the vendor is on the allowlist, the change window was approved.

That is what makes the vector so hard to answer. The attack does not defeat the trust model — it uses it. And the standard advice, “patch promptly”, is the same behaviour the attacker is relying on. SBOM adoption, build provenance attestation, and staged rollouts all help, and all cost something in deployment speed at precisely the moment a real emergency patch needs to go out fast.


Defensive Evolution: From Firewalls to Zero Trust

Implementing Zero-Trust Architecture

Perimeter security assumes that anything inside the network has already been vouched for. Zero Trust discards that: every user, device, and connection is authenticated and authorised at each step regardless of origin. Assume breach, verify continuously.

The components are unglamorous — phishing-resistant multi-factor authentication, micro-segmentation that reduces each workload’s reachable neighbours, least-privilege access scoped to what a credential actually needs. Zero Trust does not stop attackers getting in. It shortens what they can reach once they have.

Say the cost out loud, because the vendor material never does: micro-segmentation breaks things. Every undocumented service-to-service dependency in your estate surfaces as an outage during rollout, and the organisations that fail at Zero Trust mostly fail here — they hit the third production incident, cut a broad allow-rule to stop the bleeding, and never come back to narrow it. Budget for the discovery work before the enforcement work, or the enforcement work will be abandoned.

Cybernetic defense soldier monitoring digital shields and networks in a futuristic command interface.

Red-Teaming and Offensive Auditing

Controls that have never been tested against a competent adversary are assumptions with a budget line. Red-team exercises put skilled operators against your environment to find what an attacker would find, on a schedule you control, with a report at the end. Finding a critical path in an exercise is not a failure — it is the deliverable you paid for.

The value depends entirely on what happens next. An exercise that produces a report nobody is resourced to act on has bought you a precise inventory of problems you will still have next year, and a certain amount of false comfort in the meantime.

Collective Threat Intelligence

Nobody sees enough of the threat landscape alone. Sharing communities — ISACs, sector groups, MISP instances — let organisations pool campaign details, indicators, and technique observations so a detection built by one member protects the rest.

The friction is real and worth naming: indicator feeds age badly, low-confidence entries generate noise, and legal teams are reasonably cautious about what leaves the building. Treat shared intelligence as context that sharpens your own detection, not as a blocklist to import wholesale.

Privacy-First Data Practices

For individuals, end-to-end encrypted messaging, a reputable VPN, and a browser that resists fingerprinting shrink the surface available to profiling. None of it defeats a targeted state adversary, and it is not meant to — it removes you from bulk collection, which is the threat most people actually face.

For organisations, data minimisation is the only control with no bypass. Data never collected cannot be exfiltrated, subpoenaed, or leaked by a third-party processor you have never heard of. It also costs you analytics you might have wanted later, which is exactly why the conversation is hard to win internally.


Essential Zero-Trust Security Checklist

Security ActionPrimary Defensive Purpose
Enforce Multi-Factor Authentication (MFA)Renders stolen passwords insufficient for account access.
Segment Internal NetworksLimits an attacker’s ability to move laterally after gaining initial access.
Apply Least-Privilege AccessRestricts credentials to only the resources a user actually needs.
Continuous Security MonitoringDetects unusual behavioural patterns before they escalate into incidents.
Implement Automated Patch ManagementCloses known vulnerabilities before exploit scripts can reach them.
Store Encrypted Offline BackupsProvides a clean recovery path when ransomware locks production systems. Test the restore, not just the backup job.
Conduct Regular Security Awareness TrainingPrepares staff to recognise social engineering — provided the training reflects what phishing looks like now, not in 2015.

Privacy and Autonomy in the Surveillance Age

The aggregation problem is the one that matters, and it is easy to miss because no single component looks alarming. A smart meter’s consumption curve is dull. A wearable’s step count is dull. A car’s location history is dull. Joined together, they describe when you sleep, when the house is empty, and who you visited last Thursday — and each dataset was collected under a separate consent nobody read.

IoT and the Physical Envelope

Connected devices collect more than their function suggests. Wi-Fi sensing — inferring physical activity from how bodies perturb radio signals — can already detect movement and coarse posture within a room, and research systems have estimated breathing rate through interior walls. The relevant shift is conceptual: privacy stopped being only about data on a screen and started including your physical presence in a space you thought was unmonitored.

Wearable Augmented Reality

Smart glasses put a forward-facing camera into ordinary social situations, and the consent problem is structural rather than technical. The wearer agreed to the terms; everyone in frame did not, and cannot meaningfully be asked. Recording-indicator LEDs are the current answer, and they are a weak one — small, easily obscured, and trivially disabled on modified hardware.

Neural Interfaces and Cognitive Privacy

Brain-computer interfaces are moving from clinical research toward consumer products faster than any governing framework is being written. Neural data is the least revocable category of personal information there is. You can change a password and you can close an account, but there is no mechanism for withdrawing a signal that has already been recorded, modelled, and used to train something.

The Data Broker Ecosystem

Local processing does not mean local data. Telemetry and metadata travel regardless, and brokers combine those streams across sources into consumer profiles sold onward to advertisers, insurers, and — through commercial purchase rather than legal process — government agencies. The purchase route matters: it functions as an acquisition channel that does not require the warrant the direct route would.

Counter-Surveillance Techniques

Researchers are building privacy-preserving techniques that inject deliberate noise into collected signals — differential privacy in aggregate datasets, adversarial perturbation against face recognition, MAC randomisation against location tracking. They work, within limits. Each is tuned against a specific collection technique, and each degrades as the technique it counters improves.

Advertisement

The Next Frontier: AI, Ethics, and Accountability

The question is no longer whether AI participates in military decision-making. It does, and that argument is over. What remains open is how much authority gets delegated to systems that cannot explain their reasoning in terms a commander could be cross-examined on.

  • Legal Responsibility: When an autonomous system contributes to a catastrophic error, the chain of accountability has no obvious link to hold. The engineers who built the model, the officers who acted on it, the procurement staff who specified it, or the government that authorised the programme — each has a defensible claim that the decision was substantially somebody else’s.
  • The Interpretability Problem: Deep networks reach outputs through paths their own developers cannot reconstruct. Military law is built on reviewable decisions. A system that produces a ranked list with no auditable reasoning does not fail that requirement loudly; it fails it silently, and only under investigation.
  • Automated Escalation: Systems that respond at machine speed can act before any human has assessed the situation. Two such systems interacting produce escalation dynamics that nobody designed and nobody is positioned to interrupt — a failure mode with a well-documented analogue in algorithmic trading, where the consequence was a market disruption rather than a war.

These are not hypotheticals awaiting a future conflict. They are live questions about systems already fielded.

Soldier merging with circuit patterns, illustrating the convergence of human warfare and cyber operations.

Building Digital Resilience

Resilience is not only a technical property. Hybrid campaigns combine infrastructure disruption with narrative manipulation precisely because the second amplifies the first: a power outage is an inconvenience, and a power outage that half the population believes was caused by their own government is something else. No firewall addresses the second half of that.

Which puts individual digital literacy somewhere it does not comfortably belong — inside national security. Being able to check a source, notice when agreement has been manufactured, and keep your own data footprint small is civic defence in a fairly literal sense. It is also, unhelpfully, the hardest capability on this page to build at scale, because it cannot be procured.


Privacy Survival Guidelines (2025–2030)

  • Use End-to-End Encryption: Pick messaging and storage that encrypts before data leaves the device. Note what this does not hide: metadata. Who you contacted, when, and how often survives encryption, and it is frequently the more revealing half.
  • Minimise Public Sharing: Family names, home area, employer, and routine schedule are the standard ingredients of a convincing pretext call. Most of what makes social engineering work was published voluntarily.
  • Review App Permissions Regularly: Audit camera, microphone, and location access, and revoke anything without a functional justification. Pay particular attention to “while using the app” permissions granted years ago to apps you now leave open in the background.
  • Support Decentralised Alternatives: Where practical, prefer open-source and federated services over a single commercial custodian. Accept the trade: worse polish, occasional breakage, and you are your own support desk.
  • Treat Biometrics as Permanent: A leaked password is an afternoon’s inconvenience. A leaked faceprint or voiceprint is permanent, because you cannot issue yourself a new face. Weigh biometric enrolment accordingly, especially with services that store the template rather than a device-local hash.
  • Practise Basic OSINT Hygiene: Search yourself periodically, including image search and the data-broker aggregator sites. What you find in ten minutes is the same starting material an attacker would use.

Closing Thoughts

The through-line across all of it is delegation. Targeting delegated to a ranking model. Narrative delegated to generation systems tuned on engagement. Detection delegated to classifiers whose blind spots nobody has mapped. Each delegation is individually reasonable and locally efficient, which is exactly why they accumulate without anyone deciding to accumulate them.

From volunteer cyber forces in Eastern Europe to machine-assisted targeting in the Middle East, from ransomware crews with support desks to sensors in domestic appliances, the operating environment now includes every connected system and everyone using one.

Keeping adversaries out of networks is the tractable problem. The harder one is preserving human judgement — actual judgement, with time to disagree — in systems built to run faster than a person can exercise it.

In tomorrow’s conflicts, the most dangerous weapon may not be code designed to destroy — but code trusted to decide.


Share article

Subscribe to my newsletter

Receive my case study and the latest articles on my WhatsApp Channel.

Warning

Ask CyberROX AI