Submitted:
23 July 2026
Posted:
24 July 2026
You are already at the latest version
Abstract
Hybrid warfare has become a defining feature of twenty-first-century conflict, yet scholarly and policy analysis remains disproportionately anchored in state-centric models. This qualitative study addresses that gap by investigating the role of non-state actors as both perpetrators and instruments of hybrid warfare. Employing a multi-case qualitative design grounded in thematic analysis, the paper examines three principal dimensions of non-state participation: private military companies as extensions of state power, cyber mercenaries and the construction of plausible deniability, and influence operations conducted through non-state media networks. Drawing on documentary analysis, policy documents, open-source intelligence reporting, and peer-reviewed scholarship published through 2024, the study develops an original typology of state–non-state hybrid warfare relationships spanning five modalities: direct proxy, contractual delegation, ideological franchise, tacit enablement, and autonomous convergence. The findings indicate that the deliberate blurring of state and non-state boundaries functions as a strategic asset rather than an analytical inconvenience, enabling actors to circumvent international legal frameworks, evade attribution, and operate below the threshold of conventional armed conflict. Recent evidence further suggests that the deniability dividend is conditional and diminishing, as improvements in public attribution and forensic capability erode the space between political knowledge and legal proof. The paper concludes with policy-relevant recommendations for counter-hybrid strategy, the regulation of private military and commercial cyber capabilities, and the development of international norms adequate to the evolving architecture of contemporary conflict.
Keywords:
hybrid warfare
; non-state actors
; private military companies
; cyber mercenaries
; influence operations
; plausible deniability
; proxy warfare
; and attribution
1. Introduction
The character of warfare has undergone a profound transformation in the opening decades of the twenty-first century. The traditional Clausewitzian paradigm, which understood war as an instrument of state policy conducted between uniformed armed forces within recognized territorial boundaries, has been increasingly supplanted by forms of conflict that defy neat categorization (Münkler, 2005). Among the most consequential of these transformations is the rise of hybrid warfare—a mode of conflict that integrates conventional military operations, irregular tactics, cyber operations, information warfare, economic coercion, and political subversion into a unified strategic approach (Hoffman, 2007). Although the concept has gained considerable traction in academic, military, and policy discourse since the mid-2000s, the literature has exhibited a persistent analytical bias toward states as the principal architects and executors of hybrid strategies. This state-centric orientation, while not without justification given the prominent role of Russia, China, and Iran in pioneering hybrid approaches (Azad et al., 2022), has produced a significant blind spot: the systematic underestimation of non-state actors as both perpetrators and instruments of hybrid warfare.
Non-state actors—a category encompassing private military companies, cyber mercenary groups, transnational media networks, non-governmental organizations co-opted for strategic purposes, terrorist organizations, and organized criminal networks—have become indispensable components of the hybrid warfare ecosystem. Their importance derives not merely from their operational capabilities but from the strategic function they serve in enabling states to project power while maintaining deniability, circumventing legal accountability, and operating in the ambiguous spaces between war and peace (Krieg & Rickli, 2019). The deliberate instrumentalization of non-state entities allows sponsoring states to wage conflict below the threshold of attribution, exploiting the gap between the reality of state-directed aggression and the evidentiary standards required for international legal and political responses. Recent empirical work spanning Sub-Saharan Africa, the cyber domain, and the information environment confirms that this instrumentalization is neither marginal nor episodic but has become a structural feature of contemporary strategic competition (Manfredi Firmian, 2024; Petrosyan, 2023; Pokalova, 2023).
Despite the growing operational significance of non-state actors in hybrid conflict, the theoretical frameworks available for analyzing the complex web of proxy relationships, deniability mechanisms, and attribution challenges that characterize state–non-state interactions remain underdeveloped. Existing models of proxy warfare, originating primarily in Cold War scholarship, were designed to explain relationships in which states armed and directed insurgent groups or allied governments within a bipolar geopolitical structure (Mumford, 2013). These frameworks prove inadequate for capturing fluid, networked, and often commercially mediated relationships that define contemporary hybrid conflict. Similarly, international legal frameworks—particularly the law of armed conflict and the law of state responsibility—struggle to address scenarios in which the nexus between state direction and non-state action is deliberately obscured (Kormych et al., 2023; Tsagourias & Farrell, 2020).
This paper addresses these interrelated gaps by conducting a qualitative investigation into three critical dimensions of non-state participation in hybrid warfare: the use of private military companies as instruments of state power projection, the role of cyber mercenaries in constructing architectures of plausible deniability, and the conduct of influence operations through non-state media networks. Through a multi-case analysis grounded in thematic coding and interpretive synthesis, the study develops an original typology of state–non-state hybrid warfare relationships designed to capture the diversity and complexity of contemporary arrangements. The research is motivated by the conviction that an accurate understanding of hybrid warfare—and effective policy responses to it—requires moving beyond state-centric models to embrace the full spectrum of actors, relationships, and mechanisms that constitute the hybrid threat environment.
The paper is organized as follows. Section 2 provides a comprehensive review of the literature on hybrid warfare, non-state actors in conflict, and the evolving state–non-state nexus. Section 3 articulates the theoretical framework that guides the analysis, drawing on principal-agent theory, network theory, and the concept of organized hypocrisy. Section 4 describes the qualitative methodology. Section 5 presents the analysis and findings organized around the three focal dimensions. Section 6 develops the proposed typology. Section 7 offers a discussion of the findings in relation to existing literature and theoretical expectations. Section 8 addresses the policy implications, Section 9 concludes, and Section 10 sets out targeted recommendations for future research and practice.
2. Literature Review
This review situates the present study within three interrelated bodies of scholarship. It begins by tracing the evolution of hybrid warfare as an analytical concept, from its origins in strategic studies to its contested application to contemporary state behavior. It then surveys the literature on the growing role of non-state actors in armed conflict, including the privatization of military force and the emergence of surrogate warfare. Finally, it examines scholarship on the interface between state and non-state actors, focusing on the problems of deniability, attribution, and accountability that this nexus creates. To orient the reader, Table 1 consolidates the principal strands of scholarship engaged in this study, together with their central contributions and the analytical gaps that motivate the present inquiry. Taken together, these strands reveal a persistent lacuna: the absence of an integrated framework for analyzing the full spectrum of state–non-state relationships in hybrid warfare, which this study seeks to address.
2.1. The Evolution of Hybrid Warfare as a Concept
The concept of hybrid warfare, while relatively recent in its terminological crystallization, draws upon a long intellectual lineage in strategic studies concerned with the blending of conventional and unconventional methods. Frank Hoffman’s (2007) foundational work defined hybrid threats as entities that “incorporate a full range of different modes of warfare, including conventional capabilities, irregular tactics and formations, terrorist acts including indiscriminate violence and coercion, and criminal disorder” (p. 14). Hoffman’s formulation emerged in response to the 2006 Lebanon War, in which Hezbollah integrated guerrilla tactics, advanced weapons systems, media operations, and political mobilization into a coherent operational approach that confounded the Israeli Defense Forces. This conceptualization marked an important departure from earlier dichotomous frameworks that treated conventional and irregular warfare as distinct categories requiring separate analytical treatment.
The concept gained further prominence and underwent significant evolution following Russia’s annexation of Crimea in 2014 and its subsequent involvement in eastern Ukraine. Western analysts employed the hybrid warfare label to describe the integrated deployment of special operations forces without insignia (the so-called “little green men”), local proxy militias, cyber-attacks against Ukrainian infrastructure, information campaigns leveraging both state-controlled and ostensibly independent media, economic pressure, and diplomatic maneuvering (Renz, 2016). This Russian approach, which some analysts linked to the doctrinal writings of General Valery Gerasimov and his emphasis on the “blurring of the lines between the states of war and peace” (Galeotti, 2019, p. 23), became the paradigmatic case around which much of the subsequent literature organized itself. Bērziņš (2014) argued that Russia’s approach represented a new generation of warfare that privileged indirect and non-military means over direct military confrontation, targeting the adversary’s political cohesion, societal resilience, and decision-making processes rather than its armed forces.
The conflation of hybrid warfare with Russian strategic behavior has, however, drawn criticism from several quarters. Fridman (2018) argued that the discourse in the West has been shaped more by geopolitical anxieties about Russian revisionism than by rigorous analytical development, producing a concept simultaneously too broad to be analytically useful and too narrow in its empirical application. Lanoszka (2016) similarly cautioned that the framework risks treating every form of Russian influence activity as a manifestation of a single coherent strategy, when the reality may be more improvisational and context dependent. More recent scholarship has sought to move the debate beyond this impasse. Azad et al. (2022) distinguished analytically between “gray-zone,” “hybrid,” and “ambiguous” warfare, arguing that the defining common feature is the deliberate occupation of the contested space between war and peace, while Kormych et al. (2023) demonstrated—drawing on the Ukrainian case—how gray-zone strategies actively generate overlapping and contested legal orders that participants exploit through “lawfare.” These critiques converge on a shared concern: the hybrid warfare concept has been stretched to encompass an extraordinarily wide range of activities, raising questions about whether it retains sufficient analytical precision unless it is disciplined by attention to specific actors, relationships, and mechanisms.
2.2. Non-State Actors in Contemporary Conflict
Parallel to the development of hybrid warfare scholarship, a substantial body of literature has examined the growing role of non-state actors in armed conflict and international security more broadly. Kaldor’s (2012) influential thesis on “new wars” highlighted the dissolution of clear boundaries between war and peace, combatants and civilians, and public and private violence in post-Cold War conflicts, characterized by the participation of paramilitary groups, warlords, criminal networks, and mercenary forces operating within a globalized political economy of violence that eroded the state’s monopoly on the legitimate use of force. Münkler (2005) advanced a complementary analysis emphasizing the privatization and commercialization of violence, tracing the emergence of “war entrepreneurs” who sustain themselves through the economic exploitation of conflict zones. Petrosyan’s (2023) analysis of Syria and Nagorno-Karabakh brings this tradition up to date, demonstrating that non-state armed groups now operate with advanced, artificial-intelligence-enabled systems and achieve strategic effects that Cold War proxy models did not anticipate.
The privatization of military force has received particularly sustained scholarly attention. Singer (2003) provided one of the earliest comprehensive analyses of the private military industry, documenting the emergence of private military companies (PMCs) as significant actors in conflicts across Africa, the Balkans, and the Middle East, and developing a typology of private military firms based on their proximity to the battlefield—military provider firms that engage in direct combat, military consulting firms that provide training and advisory services, and military support firms that offer logistics and maintenance. Avant (2005) extended this analysis by examining the market dynamics that drive the outsourcing of security functions, arguing that the privatization of force alters patterns of accountability and control in ways that carry significant implications for democratic governance and international order. Recent work situates these dynamics on the African continent, where Ameyaw-Brobbey and Antwi-Danso (2024) argue that the expanding footprint of PMCs such as the Wagner Group may deepen state–citizen tensions and catalyze political violence rather than deliver the stability their contracts promise.
More recently, the concept of surrogate warfare has provided an important analytical bridge between the literatures on non-state actors and hybrid conflict. Krieg and Rickli (2019) defined surrogate warfare as “a strategy whereby an actor outsources war’s burdens and risks to a third party in order to reduce the costs and consequences of conflict” (p. 3). This formulation captures a wide spectrum of arrangements, from the traditional state-to-rebel proxy relationship to the commercial outsourcing of military functions to private contractors and the enlistment of cyber groups for offensive operations. The surrogate warfare framework is valuable because it foregrounds the instrumental logic—cost reduction, risk mitigation, deniability—that motivates state actors to delegate warfighting functions to non-state entities, an emphasis that anticipates the principal-agent perspective developed in Section 3.
2.3. The State–Non-State Nexus and the Attribution Problem
The interface between state and non-state actors in hybrid warfare raises fundamental questions about attribution, accountability, and the applicability of existing legal and normative frameworks. International humanitarian law and the law of state responsibility were designed for a world in which the parties to conflict were clearly identifiable and the chain of command between political authorities and combatants was transparent. Hybrid warfare, by design, subverts these assumptions. The deliberate employment of non-state actors allows sponsoring states to maintain what Cormac and Aldrich (2018) termed “implausible deniability”—a form of covert action in which the sponsoring state’s involvement is widely suspected or even known but cannot be proven to the standard required for legal or political consequences. The concept updates the Cold War notion of plausible deniability by recognizing that, in the contemporary information environment, the goal is not necessarily to convince observers that the state is uninvolved but rather to generate sufficient ambiguity to forestall decisive responses.
The attribution challenge is particularly acute in the cyber domain. Rid and Buchanan (2015) provided a foundational analysis of the technical, political, and strategic dimensions of cyber-attack attribution, arguing that attribution is not a binary determination but a graduated process involving the assessment of technical indicators, operational patterns, strategic context, and political motivation. Tsagourias and Farrell (2020) extended this analysis into international law, showing how the difficulty of establishing state direction over non-state cyber actors produces persistent “responsibility gaps,” and proposing institutional and evidentiary reforms to close them. Libicki (2009) argued that the inherent ambiguity of cyberspace undermines the logic of deterrence, since retaliatory threats lose credibility when the identity of the attacker cannot be established with confidence. Maurer (2018) developed the concept of “cyber proxies,” documenting the diverse mechanisms through which states cultivate, tolerate, co-opt, or directly employ non-state hackers. Importantly, a growing body of work now questions whether deniability still pays: Canfil (2022) argues formally and empirically that, as victims grow willing to attribute on circumstantial evidence, capable states increasingly “insource” operations they would once have delegated, while Egloff and Smeets (2021) show how public attribution has itself become a strategic instrument for shaping the normative environment of cyber conflict.
The information domain presents analogous attribution challenges. The proliferation of digital media platforms and the decline of traditional gatekeeping mechanisms have created an environment in which state-directed influence operations can be conducted through ostensibly independent outlets, social media accounts, and civil society organizations. Woolley and Howard (2018) documented the rise of computational propaganda—the use of automated accounts, algorithmic manipulation, and coordinated inauthentic behavior to shape public opinion—while Bradshaw and Howard (2019) found organized social media manipulation campaigns in more than seventy countries, a significant proportion involving collaboration between state agencies and non-state actors. DiResta et al. (2021) sharpened this picture by theorizing why states outsource influence work at all, showing through paired case studies of Russia’s military intelligence and the Internet Research Agency that outsourcing furnishes both plausible deniability and access to cutting-edge manipulation tactics unavailable to established state institutions. Despite these contributions, the literature has not yet produced an integrated framework spanning private force, state-sponsored hacking, and disinformation; studies proceed in disciplinary silos with limited cross-fertilization, and the theoretical tools for analyzing the principal-agent dynamics and control mechanisms that govern these relationships remain rudimentary. This paper addresses these gaps through a systematic, cross-cutting analysis that develops an integrated typology of state–non-state hybrid warfare relationships.
3. Theoretical Framework
The theoretical framework guiding this research integrates three complementary analytical lenses: principal-agent theory, network theory, and the concept of organized hypocrisy in international relations. Each lens illuminates a distinct dimension of the state–non-state hybrid warfare relationship, and together they provide a comprehensive foundation for analyzing the mechanisms, dynamics, and strategic logics that characterize contemporary hybrid conflict. Figure 1 depicts how the three lenses converge on the central object of analysis and the analytical expectations each generates.
Principal-agent theory, originally developed in economics and subsequently applied to political science and security studies, provides a foundational framework for understanding relationships in which one actor (the principal) delegates tasks to another (the agent) under conditions of information asymmetry and divergent interests (Avant, 2005). In hybrid warfare, the sponsoring state functions as the principal, while the non-state actor—whether a PMC, a cyber mercenary group, or a media network—functions as the agent. This framework illuminates several critical dynamics: the challenge of monitoring agents whose operational environment the principal cannot directly observe; the risk of agent shirking, freelancing, or the pursuit of independent agendas; the design of contractual and institutional mechanisms to align agent behavior with principal objectives; and the strategic trade-off between control and deniability, since the very distance that provides deniability also reduces the principal’s capacity for operational oversight. The standard framework nonetheless requires modification for the hybrid warfare context, since the relationship between state sponsors and non-state instruments is often characterized not by formal contracts but by informal understandings, ideological alignment, shared adversaries, or calculated ambiguity regarding the terms of engagement.
Network theory complements the principal-agent lens by capturing the non-hierarchical, distributed, and adaptive character of many state–non-state arrangements. Arquilla and Ronfeldt (2001) introduced the concept of “netwar” to describe conflicts in which at least one protagonist is organized as a network rather than a hierarchy, arguing that network forms confer advantages in flexibility, resilience, and the capacity to operate across multiple domains simultaneously. In the hybrid warfare context, network theory illuminates how states construct and manage distributed ecosystems of non-state actors—PMCs, hacker collectives, media outlets, think tanks, diaspora organizations, and criminal groups—that can be activated, recombined, and directed toward strategic objectives without the formation of a single traceable chain of command. The networked character of these arrangements complicates attribution and legal accountability, since responsibility is diffused across multiple nodes and the connections between them may be informal, intermittent, or deliberately obscured.
The concept of organized hypocrisy, drawn from institutional theory and applied to international relations, provides a framework for understanding the normative and legal dimensions of these relationships. States that employ non-state actors for hybrid warfare purposes often do so in contexts where their actions would violate international norms, legal obligations, or publicly articulated policy commitments if undertaken directly. The use of non-state intermediaries enables states to maintain a gap between their formal normative commitments—respect for sovereignty, non-interference, the prohibition of aggressive force—and their actual strategic behavior, relying on the ambiguity of the state–non-state relationship to deflect accountability. This dynamic carries significant implications for the international order, since the systematic exploitation of non-state actors as instruments of deniable state action erodes the credibility and effectiveness of the rules and institutions designed to constrain state behavior (Cormac & Aldrich, 2018).
Together, these three lenses generate a set of analytical expectations that guide the empirical investigation. First, the principal-agent lens predicts that states will face inherent trade-offs between operational control and plausible deniability, and that the design of state–non-state relationships will reflect efforts to manage this tension. Second, the network theory lens predicts that hybrid warfare arrangements will increasingly take distributed, polycentric forms that resist reduction to simple bilateral principal-agent dyads. Third, the organized hypocrisy lens predicts that the state–non-state nexus will be shaped by the need to manage the gap between normative commitments and strategic behavior, with implications for the types of non-state actors selected, the mechanisms of coordination employed, and the narratives constructed to maintain deniability. These expectations are revisited explicitly in the discussion (Section 7).
4. Research Methodology
This study employs a qualitative, multi-case research design informed by interpretivist epistemological assumptions. The approach is grounded in the recognition that hybrid warfare, by its very nature, involves deliberate ambiguity, deception, and the concealment of relationships between actors. Consequently, positivist approaches that seek to identify deterministic causal laws through the observation of regularities across large samples are less well suited to this subject matter than interpretivist approaches that reconstruct the meanings, logics, and strategic calculations informing actors’ behavior through the careful analysis of available evidence (Schwartz-Shea & Yanow, 2012).
The research draws on four categories of empirical material, summarized in Table 2. The first consists of peer-reviewed academic research addressing hybrid warfare, private military companies, cyber conflict, and information warfare. The second encompasses policy documents and strategic communications produced by governmental and intergovernmental organizations, including NATO strategic concepts, European Union strategic communications reports, United States Department of Defense publications, and United Nations reports on mercenary activities. The third consists of open-source intelligence reporting produced by cybersecurity firms, investigative journalism organizations, and non-governmental research institutes—among them Mandiant, the Atlantic Council’s Digital Forensic Research Lab, and Bellingcat—that have documented specific instances of state-sponsored non-state activity. The fourth comprises legal instruments and jurisprudence relevant to the regulation of private military force, state responsibility for non-state actors, and the international law of cyber operations, including the Tallinn Manual 2.0 (Schmitt, 2017).
The analytical method is thematic analysis, following the six-phase approach articulated by Braun and Clarke (2006). The process involved familiarization with the material; the generation of initial codes organized around the three focal dimensions (PMCs, cyber mercenaries, and non-state media networks); the identification of broader themes concerning deniability mechanisms, attribution challenges, control–deniability trade-offs, and legal accountability gaps; the iterative review and refinement of themes; the definition and naming of final themes; and the production of the analytical narrative presented below. Particular attention was paid to identifying patterns and variations in the mechanisms through which states construct and manage relationships with non-state instruments, with the aim of developing a typology that captures the diversity of observed arrangements.
Several methodological limitations should be acknowledged. Reliance on open-source materials means the analysis is necessarily constrained by the availability and reliability of publicly accessible information about activities that are, by design, conducted in secrecy. The cases examined reflect a geographic and geopolitical bias toward those that have received the most extensive documentation—particularly Russian and, secondarily, Chinese and Iranian activities—and the findings may not be fully generalizable to other contexts. To mitigate these constraints, the study triangulates across the four evidence categories, privileging claims corroborated by multiple independent sources, and treats the resulting typology as a theory-building instrument to be tested rather than a definitive empirical mapping. These limitations notwithstanding, the qualitative, interpretivist approach is well suited to the exploratory and theory-building objectives of the study.
5. Findings and Analysis
This section presents the findings of the thematic analysis, organized around the three focal domains of the study. It first examines the employment of private military companies as instruments of state power projection, drawing on the Wagner Group and comparable cases. It then turns to cyber mercenaries and the spectrum of state–hacker relationships that enable offensive operations under conditions of plausible deniability. Finally, it analyzes influence operations conducted through ostensibly independent media networks, social media platforms, and co-opted civil society actors. Across all three domains, the analysis traces a common strategic logic—the exploitation of the gray zone between state action and private initiative to manage deniability, evade accountability, and complicate attribution. As Figure 2 illustrates, non-state instrumentalization concentrates precisely in the ambiguous band below the threshold of armed conflict, where deniability is greatest and conventional legal and military responses are least available.
5.1. Private Military Companies as Instruments of State Power
The employment of private military companies as instruments of state power projection represents one of the most consequential manifestations of the state–non-state nexus in hybrid warfare. While the outsourcing of military functions has a long history—Singer (2003) traces it to the condottieri of Renaissance Italy and the chartered companies of the colonial era—the contemporary phenomenon is distinguished by its scale, sophistication, and integration into broader hybrid strategies designed to achieve geopolitical objectives while maintaining deniability.
The most extensively documented case is that of the Wagner Group, a Russian private military company whose operations across Ukraine, Syria, Libya, the Central African Republic, Mali, Sudan, and Mozambique have been the subject of sustained investigative and scholarly analysis. Wagner exemplifies the complex, ambiguous relationship between state sponsorship and nominally private action that characterizes hybrid warfare. The available evidence indicates that Wagner maintained close operational, financial, and personnel links to the Russian state, including the Ministry of Defense and military intelligence (Galeotti, 2019). Wagner personnel trained at Russian military facilities, deployed alongside or in coordination with Russian conventional forces in Syria, and operated in theaters where their activities aligned with Russian foreign policy objectives. Yet the Russian government consistently denied any formal relationship with the organization, and Wagner had no legal existence under Russian law—a status that simultaneously shielded the state from accountability and left Wagner personnel without the legal protections afforded to state military forces. Recent scholarship reframes Wagner as more than a conventional PMC: Pokalova (2023) characterizes it as a “quasi-state agent of influence” whose service portfolio far exceeds that of traditional private security firms, while Manfredi Firmian (2024) documents how Moscow leveraged Wagner to pursue a form of state capture in fragile African states, a strategy that persisted even after the group’s abortive 2023 mutiny and its restructuring into the Ministry of Defense–controlled Africa Corps.
The Wagner case illustrates several key dynamics of the PMC–state relationship. First, it demonstrates the strategic logic of delegation: by employing contractor personnel rather than regular forces, Russia projected power into conflict zones with reduced domestic political risk (since casualties went officially unacknowledged), reduced diplomatic cost (since operations could be denied or disavowed), and reduced legal accountability (since the framework for state responsibility was difficult to apply absent acknowledged direction). Second, it reveals the control–deniability trade-off predicted by principal-agent theory. Wagner’s operations were broadly aligned with Russian state interests, but the very distance that provided deniability also created space for operational divergence, freelancing, and the pursuit of commercial objectives—such as resource-extraction contracts—that served the organization and its leadership as much as the Russian state (McFate, 2019). Third, the case demonstrates the attribution challenge: while evidence of Russian involvement accumulated to the point where deniability became, in Cormac and Aldrich’s (2018) terms, implausible rather than plausible, the absence of formal legal ties preserved a persistent gap between political knowledge and legal proof. The 2018 clash at Deir ez-Zor in Syria, in which U.S. forces killed a significant number of Wagner personnel who had attacked a position occupied by American advisors, illustrated the strategic ambiguity in stark terms: Russia denied that its citizens were involved, precluding escalation into a direct confrontation between two nuclear powers, even as the dead were later identified as Russian nationals with links to Wagner (Galeotti, 2019).
Beyond the Russian context, the analysis reveals a broader pattern of state reliance on PMCs for hybrid warfare functions, summarized comparatively in Table 3. The United Arab Emirates’ employment of private military contractors—including firms staffed by former Western special operations personnel—in Yemen and Libya follows a similar logic of power projection with reduced visibility and accountability (Krieg & Rickli, 2019). China’s expanding use of private security companies to protect Belt and Road Initiative investments in high-risk environments, while currently focused on protective rather than offensive functions, represents a potentially significant trajectory that merits sustained attention (Kilcullen, 2020). Across the African continent, Ameyaw-Brobbey and Antwi-Danso (2024) warn that competitive PMC deployment may militarize local politics and intensify state–citizen tensions. These cases collectively demonstrate that the instrumentalization of PMCs is not a uniquely Russian phenomenon but an emergent feature of the international security landscape with systemic implications.
5.2. Cyber Mercenaries and Plausible Deniability
The cyber domain has emerged as a critical theater of hybrid warfare, and the role of non-state cyber actors in executing state-directed or state-tolerated operations represents a second major dimension of the state–non-state nexus. The term “cyber mercenaries” encompasses a diverse category of actors: commercial hacking firms that sell offensive capabilities to state clients, hacker groups that operate with the tacit toleration or active encouragement of state authorities, and criminal organizations whose activities serve state interests either by design or by convenient coincidence (Maurer, 2018). Maurer’s analysis identified a spectrum of delegation models—reproduced schematically in Figure 3—ranging from the direct integration of non-state hackers as adjuncts to state intelligence agencies to the mere sanctioning of criminal hacking that targets foreign adversaries.
Between the poles of the spectrum lie a variety of intermediate arrangements, including the provision of tools and targeting information to ostensibly independent groups, the exploitation of “patriotic hackers” who act on perceived state interests without explicit direction, and the commercial procurement of offensive capabilities from private vendors. This spectrum generates corresponding variations in the degree of state control, the deniability afforded, and the attribution challenges confronting the target. States with sophisticated intelligence capabilities—notably Russia, China, Iran, and North Korea—have developed distinctive models reflecting their domestic institutional contexts. Russia’s approach is characterized by a fluid boundary between state intelligence services, organized criminal networks, and patriotic hacker communities: intelligence agencies have recruited hackers from criminal backgrounds, tolerated criminal activity directed at foreign targets, and employed intermediary structures to maintain distance from operational execution (Greenberg, 2019). Operations attributed to Fancy Bear (APT28) and Cozy Bear (APT29)—widely assessed to be associated with Russian military intelligence and the Federal Security Service, respectively—illustrate the integration of advanced persistent threat groups into an ecosystem spanning state agencies, contractors, and criminal actors.
A second pattern concerns the growing commercial market for offensive cyber capabilities, which has created new mechanisms for states to acquire and deploy cyber weapons through non-state intermediaries. The proliferation of commercial spyware firms—exemplified by the NSO Group and its Pegasus platform—demonstrates how private-sector innovation can be harnessed for state surveillance while inserting a layer of commercial intermediation between the state and the target (Maurer, 2018). This market is particularly significant because it democratizes access to sophisticated offensive tools, enabling states with limited indigenous capabilities to acquire advanced surveillance and attack capabilities through market transactions. Table 4 summarizes the delegation models, mapping each to its characteristic control level, deniability, and attribution difficulty.
A third theme concerns the technical characteristics of cyberspace that compound the attribution challenge: the routing of attacks through multiple jurisdictions, the use of false-flag techniques to mimic the toolkits and signatures of other actors, and the difficulty of distinguishing state-directed from independently motivated activity in real time (Rid & Buchanan, 2015). These technical challenges interact with the strategic ambiguity generated by non-state intermediaries to create a permissive environment for offensive operations. Yet this permissiveness is not static. Canfil (2022) argues that as norms of attribution shift—as victims grow willing to accuse on circumstantial evidence—the deniability dividend erodes, and “usual suspects” who expect to be blamed regardless have diminishing incentives to rely on proxies, prompting capable states to insource operations they would once have delegated. Tsagourias and Farrell (2020) reach a complementary conclusion from the legal side, noting that the Tallinn Manual 2.0 acknowledges the difficulty of establishing the degree of state direction or control over non-state cyber actors required to trigger state responsibility (Schmitt, 2017). The implication for hybrid warfare is profound but conditional: the availability of non-state cyber actors allows states to sustain persistent offensive operations below the threshold of armed attack—generating cumulative effects through espionage, intellectual-property theft, infrastructure disruption, and information manipulation—but the strategic value of this arrangement depends on an attribution environment that is itself in flux.
5.3. Influence Operations Through Non-State Media Networks
The third dimension concerns the conduct of influence operations through ostensibly independent media networks, civil society organizations, and digital platforms. Information warfare—the strategic use of information and communication to shape the perceptions, beliefs, and behaviors of target audiences—has long been recognized as a component of hybrid conflict (Rid, 2020). The digital revolution has fundamentally transformed this landscape by lowering the barriers to entry for large-scale operations, enabling the micro-targeting of audiences through social media, and creating new opportunities for states to project influence through non-state intermediaries. The analysis identifies three principal mechanisms, which Table 5 summarizes together with their exemplary cases and characteristic attribution challenges.
The first mechanism involves the creation or co-optation of media outlets that maintain an appearance of editorial independence while serving as vehicles for state-directed narratives. This approach has been most extensively documented in the Russian context, where outlets such as RT (formerly Russia Today) and Sputnik occupy an ambiguous position between state media and ostensibly independent journalism. Funded by the Russian state and broadly aligned with Russian foreign policy, these organizations nonetheless employ Western journalists, produce content that is not uniformly propagandistic, and frame themselves as alternative voices offering perspectives excluded from mainstream Western media (Rid, 2020). This ambiguity is strategically functional: it lends a credibility and reach that purely state-branded media would not enjoy while preserving alignment with state communication objectives.
The second mechanism involves the exploitation of social media platforms to amplify state-directed narratives through networks of automated accounts, coordinated human operators, and co-opted influencers. The Internet Research Agency (IRA), a St. Petersburg organization linked to the Russian government, exemplifies this approach. Documented investigations of IRA operations, particularly around the 2016 United States presidential election, revealed a sophisticated apparatus for creating fictitious personas, generating divisive content calibrated to exploit existing cleavages, and amplifying that content through coordinated networks (Woolley & Howard, 2018). Critically, DiResta et al. (2021) show that the decision to route such work through a nominally private entity was not incidental but strategic: outsourcing furnished both deniability and access to platform-native manipulation tactics that established state institutions lacked, and the IRA’s tailored content outperformed the longform output of Russia’s military intelligence on the same platforms. This finding directly substantiates the principal-agent logic developed in Section 3.
The third mechanism involves the strategic cultivation of relationships with genuine non-state actors—journalists, academics, think tanks, activists, and diaspora organizations—who can be enlisted, wittingly or unwittingly, to amplify state-directed narratives within their own communities. This approach, which Rid (2020) traces to Soviet “active measures,” relies on existing social networks and trust relationships to lend credibility to messaging that would be dismissed if traced directly to a foreign state. The digital environment has dramatically expanded the scope for such operations by enabling the identification and targeting of potential amplifiers through social media analytics and by providing platforms for building relationships and disseminating content at scale.
The attribution challenges in the information domain are in some respects even more acute than in the cyber domain, as Figure 4 conveys. Whereas a cyber-attack leaves technical forensic evidence—malware signatures, command-and-control infrastructure, network traffic—that can support attribution, influence operations produce and disseminate content that is, in form and distribution, indistinguishable from organic public discourse (Prier, 2017). Distinguishing a state-directed campaign from the independent activity of individuals who happen to share the sponsoring state’s preferred narrative requires evidence of coordination, funding, or direction that is deliberately concealed. The emergence of generative artificial intelligence capable of producing convincing text, images, and video further complicates the landscape by enabling the production of influence content at scale without the human operational footprint that has historically provided attribution indicators (Chesney & Citron, 2019).
The analysis of influence operations underscores a theme running through all three dimensions: the strategic exploitation of the gray zone between state action and private initiative. By operating through outlets that maintain a veneer of independence, accounts that mimic organic users, and civil society contacts who may be unaware of their instrumentalization, state actors can shape the information environment of target societies while maintaining sufficient distance to deflect attribution and accountability. The effectiveness of this approach derives not from the persuasive power of any single message but from the cumulative, persistent, and multisector character of operations that target the epistemic foundations of democratic discourse—trust in institutions, shared factual foundations, and the capacity for reasoned deliberation (Bradshaw & Howard, 2019; Kalniete & Pildegović, 2021).
6. A Typology of State–Non-State Hybrid Warfare Relationships
The cross-cutting analysis of PMCs, cyber mercenaries, and non-state media networks reveals a spectrum of state–non-state relationships that varies along several dimensions: the degree of state direction and control, the formality of the relationship, the mechanisms of coordination employed, the deniability afforded, and the alignment of interests between state and non-state actors. Drawing on the empirical findings and guided by the theoretical framework in Section 3, this study proposes a five-fold typology, defined in Table 6 and positioned graphically in Figure 5 along the two axes of state control and deniability.
The first type, direct proxy, describes relationships in which the state exercises a high degree of operational direction, providing funding, equipment, training, targeting information, and strategic guidance. The non-state actor functions essentially as a deniable extension of state military or intelligence capabilities, with limited autonomy in operational decision-making. Its principal advantage is operational effectiveness and alignment; its principal disadvantage is that the close relationship creates attribution vulnerabilities, since the proxy’s capabilities, tradecraft, and targeting patterns may reveal state sponsorship. The second type, contractual delegation, describes relationships mediated through commercial or quasi-commercial arrangements. The Wagner Group’s provision of military services in exchange for lucrative resource-extraction contracts exemplifies this type, as does the procurement of offensive cyber capabilities from commercial vendors. The transactional logic may enhance deniability—the relationship can be characterized as a private commercial matter—but it also introduces the principal-agent problem that the actor’s commercial incentives may not align with the state’s strategic objectives.
The third type, ideological franchise, describes relationships in which the non-state actor is motivated primarily by ideological alignment rather than material incentive. Patriotic hacker groups that operate against a state’s adversaries without explicit direction, and diaspora organizations that amplify a state’s preferred narratives out of conviction, exemplify this type. It provides significant deniability, since the actor’s behavior can be attributed to autonomous motivation, but the absence of direct control means the state cannot reliably coordinate timing, targeting, or content, and the actor may take actions that embarrass or compromise the state. The fourth type, tacit enablement, describes relationships in which the state does not directly instruct or resource the non-state actor but creates permissive conditions through deliberate regulatory forbearance, non-enforcement, or the provision of sanctuary. The tolerance of criminal hacking directed at foreign targets falls within this category. It provides maximum deniability—the state can truthfully claim it did not direct the activity—but correspondingly minimal control over scope, timing, and consequences.
The fifth type, autonomous convergence, describes situations in which a non-state actor independently pursues activities that align with a state’s hybrid warfare objectives without any direct, contractual, ideological, or enabling relationship. While this type does not involve instrumentalization in the strict sense, it is included because the effects of autonomous activity may be strategically indistinguishable from state-directed action, and because states may opportunistically exploit or amplify such activity after the fact. Autonomous convergence further complicates attribution, since the alignment of a non-state actor’s behavior with state interests cannot, by itself, serve as evidence of direction. As Figure 5 makes visually explicit, the five types trace an inverse relationship between state control and deniability: the tighter the direction a state exercises, the greater the attribution exposure it accepts. Yet these types are positions along a continuum rather than rigid categories, and empirical cases may exhibit features of several types simultaneously or shift between them over time. A single state may employ different types for different actors within the same campaign, assembling a layered, diversified portfolio of non-state instruments that maximizes operational flexibility while complicating adversary attribution.
7. Discussion
The findings carry several implications for the scholarly understanding of hybrid warfare and the role of non-state actors in contemporary conflict. First, the analysis confirms that non-state actors are not peripheral or incidental features of hybrid warfare but integral components of hybrid strategies, whose employment is driven by a coherent strategic logic centered on the management of deniability, the circumvention of legal accountability, and the exploitation of normative and institutional gaps in the international order. This finding challenges the state-centric orientation of much existing scholarship and argues for analytical frameworks that treat the state–non-state nexus as a central rather than secondary feature of hybrid conflict—an argument reinforced by recent cross-regional evidence that quasi-state actors have become primary vehicles of great-power competition in fragile states (Manfredi Firmian, 2024; Pokalova, 2023).
Second, the study reveals that the deniability benefits of employing non-state actors are not absolute but are mediated by the type of relationship and by the evolving capacity of adversaries and third parties to conduct attribution. The progression from plausible to implausible deniability, observed in the Wagner and Russian cyber cases, suggests that the deniability dividend may diminish over time as attribution capabilities improve and evidentiary standards evolve. This study extends the original manuscript’s argument by connecting it to recent formal and empirical work: Canfil (2022) demonstrates that shifting attribution norms can invert the outsourcing calculus altogether, prompting capable states to insource, while Egloff and Smeets (2021) show that public attribution has become a deliberate instrument of norm-shaping. The persistence of the gap between political knowledge and legal proof nonetheless indicates that even implausible deniability retains strategic value, since the international legal and institutional framework continues to demand a degree of evidentiary certainty that is difficult to achieve in the hybrid context (Tsagourias & Farrell, 2020).
Third, the cross-cutting analysis reveals significant commonalities in the mechanisms and dynamics of state–non-state relationships across the three domains, notwithstanding the substantial differences in the operational characteristics of PMCs, cyber mercenaries, and media networks. In all three, the analysis identified the same fundamental tension between control and deniability predicted by principal-agent theory; the same exploitation of ambiguous legal and normative frameworks predicted by the organized hypocrisy lens; and the same trend toward distributed, networked organizational forms predicted by network theory. These cross-domain commonalities suggest that the nexus is governed by general strategic logics rather than domain-specific dynamics, reinforcing the case for integrated, cross-cutting frameworks such as the typology proposed here. The convergence of empirical findings on the three theoretical expectations articulated in Section 3 lends the framework a measure of internal validation.
Fourth, the study highlights the inadequacy of existing legal frameworks. The criteria for determining state responsibility for the actions of non-state actors—particularly the “effective control” and “overall control” standards developed by the International Court of Justice and the International Criminal Tribunal for the former Yugoslavia—were not designed for situations in which states deliberately construct relationships characterized by ambiguity, informality, and plausible deniability (Schmitt, 2017; Tsagourias & Farrell, 2020). Similarly, the law of armed conflict’s distinction between combatants and civilians is undermined by the participation of PMC personnel, hackers, and media operatives who function as instruments of state conflict but do not meet the criteria for combatant status. Emerging legal scholarship on Wagner-type entities confirms that their hybrid profiles fit awkwardly within existing categories of attribution and liability and calls for clarified standards and stronger enforcement (Kormych et al., 2023).
Finally, the findings invite reflection on the implications for democratic governance and civil-military relations. The outsourcing of warfighting, intelligence, and influence functions reduces the transparency and accountability mechanisms through which democratic societies oversee the use of force and the conduct of foreign policy. When military operations are conducted by contractors rather than uniformed soldiers, cyber operations by commercial firms rather than military units, and influence campaigns through ostensibly independent outlets rather than government communications, the institutional mechanisms designed to ensure civilian control—legislative authorization, budgetary oversight, judicial review, media scrutiny—are weakened or circumvented (Avant, 2005). This dynamic is not limited to authoritarian states; democracies, too, have relied extensively on private military contractors and commercial cyber capabilities, raising important questions about the compatibility of non-state instrumentalization with democratic values and institutional norms.
8. Policy Implications
The findings generate several policy-relevant implications addressed to governmental agencies, international organizations, and the broader policy community concerned with counter-hybrid strategy, legal regulation, and international norms development.
In the domain of counter-hybrid strategy, defense and security agencies require updated threat assessment frameworks that systematically account for the role of non-state actors as instruments of state hybrid warfare. Models focused on the conventional military capabilities of state adversaries fail to capture the distributed, multi-domain character of threats channeled through non-state intermediaries. The typology developed here offers a starting point for more nuanced assessments that distinguish among relationship types and their associated indicators, vulnerabilities, and response options. Counter-hybrid strategies should also invest in attribution capabilities across the military, cyber, and informational domains, recognizing that timely and credible attribution is a prerequisite for effective deterrence and response, and that—as recent scholarship emphasizes—attribution can itself be wielded strategically to shape the normative environment (Egloff & Smeets, 2021). This investment should encompass not only technical capabilities such as cyber forensics and open-source intelligence analysis but also institutional mechanisms for consolidating, evaluating, and communicating attribution findings across agencies and with international partners.
In the domain of legal regulation, the analysis underscores the urgent need for strengthened international frameworks governing private military companies, commercial cyber capabilities, and state-sponsored influence operations. Existing instruments applicable to private military force—the 2008 Montreux Document and the 2010 International Code of Conduct for Private Security Service Providers—represent important but insufficient steps. A more robust framework would establish binding standards for the registration, licensing, and oversight of PMCs; clarify the legal status of PMC personnel under international humanitarian law; and develop mechanisms for holding both companies and their state sponsors accountable. Similarly, the largely unregulated market for commercial offensive cyber capabilities requires international attention, with the Wassenaar Arrangement on dual-use technologies offering a potential platform for export controls on surveillance and intrusion tools.
In the domain of international norms, the study highlights the need for sustained diplomatic engagement to establish clearer norms governing state behavior in the gray zone. The existing framework, premised on relatively clear distinctions between war and peace, state and non-state action, and military and civilian domains, is poorly calibrated to the realities of hybrid conflict. Norm development should focus on clearer standards for state responsibility for the actions of state-affiliated non-state actors, on reducing the gap between political knowledge and legal proof that currently enables implausible deniability, and on articulating expected standards regarding the use of PMCs, cyber proxies, and information capabilities. These efforts should be pursued through multiple channels—the United Nations, NATO, the European Union, and bilateral engagement—recognizing that norm development in contested domains is a long-term process requiring sustained commitment.
Finally, the study points to the importance of societal resilience as a complement to governmental strategies. Hybrid warfare, particularly in its informational dimension, targets not only state institutions but the broader social fabric—public trust, media integrity, democratic participation, and social cohesion. Building resilience therefore requires whole-of-society approaches encompassing media literacy education, support for independent journalism, transparency in media ownership and funding, regulation of digital platforms to reduce coordinated inauthentic behavior, and public awareness of the tactics and objectives of hybrid campaigns (Kalniete & Pildegović, 2021; Nye, 2011). Democratic societies that invest in their own epistemic resilience—the capacity to maintain shared factual foundations and reasoned deliberation in the face of deliberate manipulation—will be better positioned to withstand hybrid campaigns regardless of whether those campaigns are conducted by state or non-state actors.
9. Conclusions
This study has sought to address a significant gap in the hybrid warfare literature by investigating the role of non-state actors as instruments of state power projection in contemporary conflict. Through a qualitative, multi-case analysis of private military companies, cyber mercenaries, and non-state media networks, the research has demonstrated that non-state actors are not peripheral but central to the architecture of hybrid warfare, serving strategic functions related to deniability, legal circumvention, risk mitigation, and operational flexibility that cannot be replicated by state forces operating under their own flag. The five-fold typology proposed here—direct proxy, contractual delegation, ideological franchise, tacit enablement, and autonomous convergence—provides a structured analytical vocabulary for describing, comparing, and assessing the diverse arrangements that characterize the contemporary hybrid threat landscape.
The findings carry implications for both scholarship and practice. Theoretically, the study argues for frameworks that move beyond state-centric models to embrace the full complexity of actor constellations in hybrid warfare, integrating insights from principal-agent theory, network theory, and the institutional analysis of organized hypocrisy. Empirically, the cross-domain analysis reveals significant commonalities in the strategic logics governing state–non-state relationships across the military, cyber, and informational domains, suggesting the potential for integrated, cross-cutting approaches. In normative and policy terms, the study underscores the inadequacy of existing legal and institutional frameworks for addressing attribution, accountability, and regulation, and identifies specific areas where legal development, norm entrepreneurship, and institutional investment are urgently required. Above all, the analysis suggests that the deniability on which non-state instrumentalization depends is a contingent and contestable resource rather than a permanent strategic endowment—an insight that reframes counter-hybrid policy as, in part, a contest over the norms and capabilities of attribution itself.
The deliberate blurring of the boundary between state and non-state action in hybrid warfare is not an analytical inconvenience to be resolved but a strategic reality to be understood, confronted, and addressed through frameworks commensurate with its complexity. This study represents one contribution to that ongoing intellectual and practical endeavor.
10. Recommendations
Building directly on the findings and discussion, this section sets out a concise, forward-looking agenda organized around two complementary tracks: directions for future research and priorities for policy and practice. Table 7 consolidates these recommendations, linking each to the specific finding that motivates it and to the best positioned actor to act, while Figure 6 depicts the integrated response architecture on which the practice recommendations converge.
On the research track, four directions follow from the limitations of the present study. First, comparative case studies extending beyond the Russian-dominated evidence base—incorporating Iranian, Chinese, Gulf, and non-great-power sponsors—would strengthen the empirical foundations of the typology and reveal variations the current analysis may not capture. Second, longitudinal research tracking specific state–non-state relationships over time would illuminate the dynamics of escalation, adaptation, and institutional learning, including transitions between typological categories such as Wagner’s shift from contractual delegation toward direct state control under the Africa Corps. Third, research integrating the perspectives of non-state actors themselves—the strategic calculations, organizational dynamics, and normative frameworks of PMC personnel, hackers, and media operatives—would complement the state-centric vantage that continues to structure much of the field. Fourth, the accelerating role of generative artificial intelligence in influence and cyber operations warrants dedicated investigation, since it promises to lower operational footprints further and to compress the timelines within which attribution must occur (Chesney & Citron, 2019).
On the practice track, the analysis converges on a three-pillar response architecture, represented in Figure 6. The first pillar, attribution capability, treats timely and credible attribution as the linchpin of deterrence and as a strategic instrument in its own right, requiring investment in cyber forensics, open-source intelligence, cross-agency fusion, and coordinated public attribution. The second pillar, legal and regulatory frameworks, calls for binding oversight of private military and security companies, export controls on commercial spyware, and clarified standards of state responsibility for state-affiliated non-state actors. The third pillar, societal resilience, recognizes that hybrid warfare targets the social fabric and therefore requires whole-of-society investment in media literacy, independent journalism, platform transparency, and epistemic security. These pillars are mutually reinforcing attribution without legal frameworks yields naming without consequence, legal frameworks without resilience address symptoms rather than vulnerabilities, and resilience without attribution leaves societies defending against threats they cannot identify. Their integration, sustained through long-term investment and international cooperation, offers the most credible path toward countering the evolving architecture of state–non-state hybrid warfare.
Taken together, the research and practice tracks describe an agenda whose coherence depends less on any single measure than on the sequencing and coordination among them. The three practice pillars in particular resist piecemeal adoption. Attribution capability is expensive and slow to mature, and its deterrent value is realized only when credible findings can be translated into legal or political consequence; investment in forensics and fusion that is not matched by frameworks for state responsibility therefore yields naming without accountability. Legal and regulatory reform, in turn, presupposes an attribution base robust enough to satisfy evidentiary and diplomatic thresholds, while societal resilience conditions whether attributions and sanctions are believed and acted upon by the publics they are meant to protect. The practical implication is that these measures should be pursued as an integrated portfolio rather than as competing budget lines, with early emphasis on the attribution and resilience foundations that give the legal instruments something to stand on.
Several obstacles temper any optimism about implementation. The deniability that these recommendations seek to penetrate is not an incidental weakness but a deliberate design feature that sponsoring states have strong incentives to preserve, and the same asymmetry of interest that sustains proxy relationships also frustrates the collective action required to constrain them (Canfil, 2022). International frameworks depend on the cooperation of actors who are frequently the beneficiaries of the very ambiguity under negotiation, and export-control or oversight regimes are only as effective as their least willing participant. Domestic obstacles compound these external ones: attribution capacity is concentrated in a handful of well-resourced states, resilience-building competes with more visible security priorities for finite public attention, and the whole-of-society coordination the architecture envisions cut across institutional and jurisdictional boundaries that are rarely aligned. These constraints do not invalidate the agenda, but they do caution against expecting rapid or uniform progress across the pillars.
Realistic reading therefore treats the recommendations advanced here not as a checklist promising resolution but as a framework for raising the costs and narrowing the space within which hybrid actors operate. The measure of success is not the elimination of state–non-state hybrid threats—an unattainable goal given the structural incentives documented throughout this study—but the steady erosion of the plausible deniability on which those threats depend and the construction of societies less susceptible to the manipulation they seek to exploit. So framed, the value of the agenda lies in its direction of travel: sustained, coordinated, and mutually reinforcing investment across attribution, law, and resilience offers the most credible path toward contesting an adversarial architecture that will continue to adapt faster than any single countermeasure can anticipate.
Funding
This work was supported and funded by the Deanship of Scientific Research at Imam Mohammad ibn Saud Islamic University (IMSIU) (grant number IMSIU-DDRSP2602).
Institutional Review Board Statement
not applicable.
Informed Consent Statement
not applicable.
Conflicts of Interest
The authors declare no conflicts of interest.
Transparency: The author confirms that the manuscript is an honest, accurate and transparent account of the study that no vital features of the study have been omitted and that any discrepancies from the study as planned have been explained. This study followed all ethical practices during writing.
References
- Ameyaw-Brobbey, T.; Antwi-Danso, V. Selling security to Africa: Private military and security companies (PMSCs) and the fate of African intrastate security. Small Wars. Insur. 2024, 35(6), 1050–1078. [Google Scholar] [CrossRef]
- Arquilla, J.; Ronfeldt, D. Networks and netwars: The future of terror, crime, and militancy; RAND Corporation, 2001; Available online: https://www.rand.org/pubs/monograph_reports/MR1382.html.
- Avant, D. D. The market for force: The consequences of privatizing security; Cambridge University Press, 2005. [Google Scholar] [CrossRef]
- Azad, T. M.; Haider, M. W.; Sadiq, M. Understanding gray zone warfare from multiple perspectives. World Aff. 2022, 186(1), 81–104. [Google Scholar] [CrossRef]
- Bērziņš, J. Russia’s new generation warfare in Ukraine: Implications for Latvian defense policy (Policy Paper No. 2). In National Defence Academy of Latvia, Center for Security and Strategic Research; 2014; Available online: https://sldinfo.com/wp-content/uploads/2014/05/New-Generation-Warfare.pdf.
- Bradshaw, S.; Howard, P. N. 2019. The global disinformation order: 2019 global inventory of organised social media manipulation (Working Paper No. 2019.3). Oxford Internet Institute, University of Oxford. Available online: https://demtech.oii.ox.ac.uk/research/posts/the-global-disinformation-order-2019-global-inventory-of-organised-social-media-manipulation/.
- Braun, V.; Clarke, V. Using thematic analysis in psychology. Qual. Res. Psychol. 2006, 3(2), 77–101. [Google Scholar] [CrossRef]
- Canfil, J. K. The illogic of plausible deniability: Why proxy conflict in cyberspace may no longer pay. J. Cybersecur. 2022, 8(1), tyac007. [Google Scholar] [CrossRef]
- Chesney, R.; Citron, D. K. Deep fakes: A looming challenge for privacy, democracy, and national security. Calif. Law. Rev. 2019, 107(6), 1753–1820. [Google Scholar] [CrossRef]
- Cormac, R.; Aldrich, R. J. Grey is the new black: Covert action and implausible deniability. Int. Aff. 2018, 94(3), 477–494. [Google Scholar] [CrossRef]
- DiResta, R.; Grossman, S.; Siegel, A. In-house vs. outsourced trolls: How digital mercenaries shape state influence strategies. Political Commun. 2021, 39(2), 222–253. [Google Scholar] [CrossRef]
- Egloff, F. J.; Smeets, M. Publicly attributing cyber attacks: A framework. J. Strateg. Stud. 2021, 46(3), 502–533. [Google Scholar] [CrossRef]
- Fridman, O. Russian “hybrid warfare”: Resisting geopolitics; Hurst & Company, 2018; ISBN 978-1849049849. [Google Scholar]
- Galeotti, M. Russian political war: Moving beyond the hybrid; Routledge, 2019. [Google Scholar] [CrossRef]
- Greenberg, A. Sandworm: A new era of cyberwar and the hunt for the Kremlin’s most dangerous hackers; Doubleday, 2019; ISBN 978-0385544405. [Google Scholar]
- Hoffman, F. G. Conflict in the 21st century: The rise of hybrid wars. In Potomac Institute for Policy Studies; 2007; Available online: https://www.potomacinstitute.org/images/stories/publications/potomac_hybridwar_0108.pdf.
- Kaldor, M. New and old wars: Organised violence in a global era, 3rd ed.; Polity Press, 2012; ISBN 978-0745655635. [Google Scholar]
- Kalniete, S.; Pildegović, T. Strengthening the EU’s resilience to hybrid threats. Eur. View 2021, 20(1), 23–33. [Google Scholar] [CrossRef]
- Kilcullen, D. The dragons and the snakes: How the rest learned to fight the West; Oxford University Press, 2020; ISBN 978-0190265687. [Google Scholar]
- Kormych, B.; Malyarenko, T.; Wittke, C. Rescaling the legal dimensions of grey zones: Evidence from Ukraine. Glob. Policy 2023, 14(3), 516–530. [Google Scholar] [CrossRef]
- Krieg, A.; Rickli, J.-M. Surrogate warfare: The transformation of war in the twenty-first century; Georgetown University Press, 2019; ISBN 978-1626166608. [Google Scholar]
- Lanoszka, A. Russian hybrid warfare and extended deterrence in eastern Europe. Int. Aff. 2016, 92(1), 175–195. [Google Scholar] [CrossRef]
- Libicki, M. C. Cyberdeterrence and cyberwar; RAND Corporation, 2009. [Google Scholar] [CrossRef]
- Manfredi Firmian, F. Russia’s state capture strategy in Africa, from Wagner to the Africa Corps. Small Wars. Insur. 2024, 36(4), 783–812. [Google Scholar] [CrossRef]
- Maurer, T. Cyber mercenaries: The state, hackers, and power; Cambridge University Press, 2018. [Google Scholar] [CrossRef]
- McFate, S. The new rules of war: Victory in the age of durable disorder; William Morrow, 2019; ISBN 978-0062843586. [Google Scholar]
- Mumford, A. Proxy warfare; Polity Press, 2013; ISBN 978-0745651040. [Google Scholar]
- Münkler, H. The new wars; Polity Press, 2005; ISBN 978-0745633367. [Google Scholar]
- Nye, J. S. The future of power; PublicAffairs, 2011; ISSN ISBN 978-1610390699. [Google Scholar]
- Petrosyan, M. The role of non-state actors in modern warfare: The case of Syria and Nagorno-Karabakh. J. Balk. Near East. Stud. 2023, 26(2), 149–163. [Google Scholar] [CrossRef]
- Pokalova, E. The Wagner Group in Africa: Russia’s quasi-state agent of influence. Stud. Confl. Terror. 2023, 49(3), 259–281. [Google Scholar] [CrossRef]
- Prier, J. Commanding the trend: Social media as information warfare. Strateg. Stud. Q. 2017, 11(4), 50–85. Available online: https://www.airuniversity.af.edu/Portals/10/SSQ/documents/Volume-11_Issue-4/Prier.pdf.
- Renz, B. Russia and ‘hybrid warfare. Contemp. Politics 2016, 22(3), 283–300. [Google Scholar] [CrossRef]
- Rid, T. Active measures: The secret history of disinformation and political warfare; Farrar, Straus and Giroux, 2020; ISBN 978-0374287269. [Google Scholar]
- Rid, T.; Buchanan, B. Attributing cyber attacks. J. Strateg. Stud. 2015, 38(1–2), 4–37. [Google Scholar] [CrossRef]
- Schmitt, M. N. (Ed.) Tallinn manual 2.0 on the international law applicable to cyber operations, 2nd ed.; Cambridge University Press, 2017. [Google Scholar] [CrossRef]
- Schwartz-Shea, P.; Yanow, D. Interpretive research design: Concepts and processes; Routledge, 2012. [Google Scholar] [CrossRef]
- Singer, P. W. Corporate warriors: The rise of the privatized military industry; Cornell University Press., 2003; ISBN 978-0801441141. [Google Scholar]
- Tsagourias, N.; Farrell, M. Cyber attribution: Technical and legal approaches and challenges. Eur. J. Int. Law. 2020, 31(3), 941–967. [Google Scholar] [CrossRef]
- Woolley, S. C.; Howard, P. N. (Eds.) Computational propaganda: Political parties, politicians, and political manipulation on social media; Oxford University Press, 2018. [Google Scholar] [CrossRef]
-
Author BioDr. Safran Safar Almakaty is a Professor at Imam Mohammad ibn Saud Islamic University (IMSIU) in Riyadh, specializing in communication, media studies, and higher education in Saudi Arabia and the Middle East.He holds an MA from Michigan State University and a PhD from the University of Kentucky. His research examines media transformation, international communication, digital technologies, and their influence on public discourse and information exchange.Beyond academia, Dr. Almakaty advises government, corporate, and nonprofit organizations on communication strategy, corporate communications, international relations, media literacy, digital transformation, and higher education policy.His work addresses topics such as hybrid conferences, diplomatic communication, strategic conferences, and Saudi Arabia’s Vision 2030 initiatives. He has published in peer-reviewed journals, participated in international forums, and collaborated on cross-cultural research.As an educator, Dr. Almakaty mentors emerging scholars and practitioners while promoting international engagement, public diplomacy, and the modernization of knowledge institutions in the Middle East.
Figure 1.
Integrated Three-Lens Theoretical Framework for Analyzing the State–Non-State Nexus. Note. Each lens contributes a distinct analytical expectation that guides the empirical investigation in Section 5 and Section 6. Figure created by the authors.

Figure 2.
Non-State Instrumentalization Across the Gray Zone Between Peace and War. Note. The horizontal band represents the continuum from peace to armed conflict; non-state instruments cluster below the threshold of armed attack. Figure created by the authors.
Figure 2.
Non-State Instrumentalization Across the Gray Zone Between Peace and War. Note. The horizontal band represents the continuum from peace to armed conflict; non-state instruments cluster below the threshold of armed attack. Figure created by the authors.

Figure 3.
The Spectrum of State–Cyber Actor Delegation Models. Note. Models are arrayed from highest state control and lowest deniability (left) to lowest control and highest deniability (right). Adapted by the authors from Maurer’s (2018) analysis of state–cyber proxy relationships.
Figure 3.
The Spectrum of State–Cyber Actor Delegation Models. Note. Models are arrayed from highest state control and lowest deniability (left) to lowest control and highest deniability (right). Adapted by the authors from Maurer’s (2018) analysis of state–cyber proxy relationships.

Figure 4.
Attribution Dynamics Across the Three Domains of Analysis. Note. Values are conceptual and ordinal, synthesizing the qualitative analysis in Section 5; they represent relative rather than measured magnitudes. Figure created by the authors.
Figure 4.
Attribution Dynamics Across the Three Domains of Analysis. Note. Values are conceptual and ordinal, synthesizing the qualitative analysis in Section 5; they represent relative rather than measured magnitudes. Figure created by the authors.

Figure 5.
The Typology Mapped on the Control–Deniability Plane. Note. Each node marks a relationship type’s approximate position; the dashed line traces the inverse relationship between state control and deniability. Figure created by the authors.
Figure 5.
The Typology Mapped on the Control–Deniability Plane. Note. Each node marks a relationship type’s approximate position; the dashed line traces the inverse relationship between state control and deniability. Figure created by the authors.

Figure 6.
An Integrated Counter-Hybrid Response Architecture. Note. The three mutually reinforcing pillars rest on a foundation of sustained investment, international cooperation, and a whole-of-society approach. Figure created by the author.
Figure 6.
An Integrated Counter-Hybrid Response Architecture. Note. The three mutually reinforcing pillars rest on a foundation of sustained investment, international cooperation, and a whole-of-society approach. Figure created by the author.

Table 1.
Principal Strands of Scholarship on Hybrid Warfare and Non-State Actors.
| Scholarly strand | Representative works | Central contribution | Analytical gap addressed here |
| Conceptualizing hybrid & gray-zone warfare | Hoffman (2007); Renz (2016); Fridman (2018); Azad et al. (2022) | Defines hybrid threats and situates them in the ambiguous space between war and peace | Persistent state-centric framing; limited theorization of non-state agency |
| Non-state actors & privatized force | Singer (2003); Avant (2005); Kaldor (2012); Krieg & Rickli (2019) | Documents the privatization of violence and the logic of surrogate warfare | Functional silos; weak integration across military, cyber, and information domains |
| PMCs as foreign-policy instruments | Pokalova (2023); Manfredi Firmian (2024); Ameyaw-Brobbey & Antwi-Danso (2024) | Reframes Wagner-type actors as quasi-state agents of influence | Case-bound; lacks a cross-domain comparative typology |
| Cyber proxies & attribution | Rid & Buchanan (2015); Maurer (2018); Tsagourias & Farrell (2020); Canfil (2022) | Maps state–hacker delegation and the technical–legal limits of attribution | Deniability treated as static rather than contingent and eroding |
| Influence operations & resilience | Woolley & Howard (2018); Bradshaw & Howard (2019); DiResta et al. (2021); Kalniete & Pildegović (2021) | Explains computational propaganda and outsourced digital manipulation | Under-connected to the broader state–non-state instrumentalization logic |
Note. PMC = private military company; OSINT = open-source intelligence. The table is the authors’ synthesis of the literature reviewed in Section 2.
Table 2.
The Empirical Corpus: Categories of Documentary Evidence.
| Evidence category | Representative sources | Analytical function |
| Peer-reviewed scholarship | Journal articles, monographs, and edited volumes (2001–2024) | Establishes conceptual and theoretical baselines and cross-case patterns |
| Policy & strategic documents | NATO, EU StratCom, U.S. DoD, and UN reports on mercenaries and PMCs | Captures official threat framing, doctrine, and regulatory posture |
| Open-source intelligence | Mandiant, DFRLab, Bellingcat investigative and forensic reporting | Provides case-level documentation of covert state–non-state activity |
| Legal instruments & jurisprudence | Tallinn Manual 2.0; Montreux Document; ICJ and ICTY control standards | Anchors the analysis of attribution, responsibility, and accountability |
Note. DFRLab = Digital Forensic Research Lab; ICJ = International Court of Justice; ICTY = International Criminal Tribunal for the former Yugoslavia. Compiled by the authors.
Table 3.
Comparative Analysis of State Reliance on Private Military and Security Companies.
| Sponsor / case | Principal theaters | Primary function | Deniability logic | Dominant relationship type |
| Russia — Wagner Group / Africa Corps | Ukraine, Syria, Libya, CAR, Mali, Sudan | Combat, regime protection, resource extraction | No legal existence; state denial despite documented ties | Contractual delegation shading into direct proxy |
| UAE — contracted PMCs | Yemen, Libya | Combat support and force augmentation | Commercial framing; foreign personnel reduce visibility | Contractual delegation |
| China — private security companies | Belt and Road corridors (Africa, Central Asia) | Protective security for overseas investments | Ostensibly commercial; below offensive threshold | Tacit enablement / contractual delegation |
Note. CAR = Central African Republic; PMC = private military company; UAE = United Arab Emirates. Relationship types correspond to the typology developed in Section 6. Compiled by the authors from the sources reviewed in Section 5.1.
Table 4.
Delegation Models in the State–Cyber Actor Relationship.
| Delegation model | Mechanism | State control | Deniability | Attribution difficulty |
| Integration | Hackers embedded as adjuncts of intelligence agencies | High | Low | Moderate |
| Delegation / orchestration | Tools and targeting supplied to nominally independent groups | Moderate–high | Moderate | High |
| Commercial procurement | Offensive capabilities purchased from spyware vendors | Moderate | Moderate–high | High |
| Ideological mobilization | Patriotic hackers act without explicit direction | Low | High | Very high |
| Sanctioning / toleration | Criminal hacking of foreign targets left unprosecuted | Minimal | Very high | Very high |
Note. Control, deniability, and attribution ratings are ordinal and analytical, derived from the qualitative synthesis in Section 5.2. Compiled by the authors, drawing on Maurer (2018), Rid and Buchanan (2015), and Canfil (2022).
Table 5.
Three Mechanisms of Influence Operations Through Non-State Media Networks.
| Mechanism | Description | Exemplary case | Attribution challenge |
| Co-opted “independent” outlets | Media that preserve an appearance of editorial autonomy while carrying state-aligned narratives | RT and Sputnik in the Russian information ecosystem | Blends state funding with genuine journalism, blurring intent |
| Platform manipulation | Bots, troll farms, and recruited influencers amplifying state narratives | Internet Research Agency operations (e.g., 2016 U.S. election) | Coordinated inauthentic behavior mimics organic discourse |
| Cultivation of authentic actors | Enlistment of journalists, academics, activists, and diaspora networks | Soviet-lineage “active measures,” updated for digital reach | Amplifiers may be unwitting; direction is deliberately hidden |
Note. Cases are illustrative rather than exhaustive. Compiled by the authors from Rid (2020), Woolley and Howard (2018), DiResta et al. (2021), and Bradshaw and Howard (2019).
Table 6.
A Five-Fold Typology of State–Non-State Hybrid Warfare Relationships.
| Type | Defining feature | Illustrative case | Principal advantage | Principal vulnerability |
| Direct proxy | High operational direction; funding, equipment, targeting, and guidance supplied | Intelligence-linked core of groups such as APT28 | Operational effectiveness and tight alignment with state aims | Close ties create attribution vulnerabilities |
| Contractual delegation | Commercial or quasi-commercial procurement of capabilities or services | Wagner Group; commercial spyware vendors | Transactional framing enhances deniability | Commercial incentives may diverge from strategic aims |
| Ideological franchise | Non-state actor motivated by ideological alignment rather than material reward | Patriotic hacker groups; conviction-driven diaspora networks | Strong deniability; actions read as autonomous | Limited state control over timing, targeting, and content |
| Tacit enablement | State creates permissive conditions via forbearance, non-enforcement, or sanctuary | Tolerated criminal hacking of foreign targets | Maximum deniability; truthful denial of direction | Minimal control over scope and consequences |
| Autonomous convergence | Independent non-state activity that happens to align with state objectives | Self-mobilized actors whose effects mirror state-directed action | No instrumental tie to expose; opportunistic amplification | No reliable control; alignment cannot prove direction |
Note. APT = advanced persistent threat. The five types are positions along a continuum rather than discrete categories; empirical cases may exhibit features of several types or shift between them over time. Developed by the authors.
Table 7.
Consolidated Recommendations for Research and Practice.
| Domain | Recommendation | Grounding finding | Primary actor(s) |
| Research | Broaden comparative cases beyond the Russian evidence base | Geographic bias in the documented record (Section 4) | Academic and policy research community |
| Research | Conduct longitudinal studies of typological transitions | Relationships shift type over time (Section 5 and Section 6) | Academic researchers; think tanks |
| Practice — attribution | Build cross-domain, cross-agency attribution and public-attribution capacity | Deniability is contingent on attribution norms (Section 7) | National security agencies; alliances |
| Practice — legal | Establish binding PMC oversight and export controls on offensive cyber tools | Legal frameworks inadequate for hybrid actors (Section 7 and Section 8) | States; UN; Wassenaar Arrangement |
| Practice — resilience | Invest in media literacy, independent journalism, and platform transparency | Influence operations target epistemic foundations (Section 5.3) | Governments; civil society; platforms |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.