Executive Summary
Over five decades, the character of great-power competition has shifted away from declared war and toward a deliberately ambiguous middle ground – action calibrated to achieve strategic effect while remaining below the threshold that would trigger a conventional military response. This series examines how China, Russia, Iran, and North Korea are each operating in that middle ground against global infrastructure and allied deterrence architecture, using a common analytical framework developed and previously published by CommandEleven.
CommandEleven’s standing methodology is predictive rather than retrospective: our dossiers are built to identify threat patterns before they reach formal government policy response, not to catalogue them afterward. That discipline is why the platform is tracked by multiple foreign intelligence services as a monitored open-source resource – a distinction earned through accuracy under our own tradecraft standards, not asserted. This series is held to that same standard.
Key Judgments
- ASSESSED: “Grey zone” activity is best understood not as a separate category of conflict but as a deliberate operating space between diplomacy and war, in which state and state-aligned actors pursue strategic objectives while managing escalation risk.
- ASSESSED: Global infrastructure – subsea communications cables, port and maritime chokepoints, energy transmission systems, and satellite/navigation architecture – has become the preferred target set across all four actors profiled in this series, precisely because it sits outside traditional military escalation ladders while carrying direct strategic and economic leverage.
- ASSESSED: No single framework term fully captures any one actor’s behavior. Each of the four nations profiled in this series occupies a distinct position across the four terms defined below; the series is structured to make those differences legible rather than flattening them into a single threat narrative.
What “Grey Zone” Means for CommandEleven
The term “grey zone warfare” is used loosely across open-source and government reporting, often as a catch-all for any state activity short of declared war. CommandEleven applies it more narrowly, in a way that distinguishes it from two adjacent and frequently conflated concepts:
Not the same as hybrid warfare
Hybrid warfare typically describes the blended use of conventional and unconventional military means within an active or imminent conflict. Grey zone activity, by contrast, is calibrated specifically to avoid crossing into that conflict state – its defining feature is the deliberate management of ambiguity and deniability, not the blending of tactics.
Not the same as conventional proxy conflict
Proxy warfare – arming and directing a third party to fight on one’s behalf – is one tool used within the grey zone, not a synonym for it. A state can operate in the grey zone through cyber intrusion, economic coercion, or infrastructure interdiction without any proxy involved at all.
CommandEleven’s working definition
Grey zone warfare is the sustained pursuit of strategic advantage through actions designed to remain below the threshold of conventional armed conflict, using ambiguity, deniability, and calibrated escalation as core operating principles rather than incidental features.
The Four-Term Framework
This series applies four analytical terms, each previously developed and published on the CommandEleven platform, consistently across all four profiled actors. Each term captures a distinct mechanism of grey-zone activity:
Grey Zone Interdiction Zone
Geographic or infrastructural space where a state applies sustained pressure short of open conflict to control, disrupt, or hold at risk a chokepoint of strategic value (a strait, a cable landing site, a port complex) without formally contesting sovereignty or triggering collective-defense obligations.
Kinetic Gate
The threshold at which grey-zone activity could escalate into overt, conventional military engagement. Actors operating near the Kinetic Gate are making a continuous, calculated judgment about how close to the line they can operate without crossing it; the series treats proximity to this threshold, and the deliberateness with which it is managed, as itself analytically meaningful.
Cyber-Kinetic Convergence
The point at which cyber intrusion into operational technology (OT) or industrial control systems (ICS) creates the *capability* for physical-world disruption or damage, whether or not that capability is exercised. This term captures pre-positioning and access as a form of leverage in its own right, distinct from an executed attack.
Deniability/Proxy Warfare
The use of intermediaries, cut-outs, calibrated ambiguity, or plausible-deniability postures (including formal state denial) to pursue an objective while avoiding direct attribution or accountability. This is the broadest of the four terms and the one most actors in this series rely on most heavily.
These four terms are not mutually exclusive, and a single actor’s behavior in a single domain frequently implicates more than one simultaneously – that overlap is itself part of what makes grey-zone activity difficult to counter through traditional deterrence frameworks, which tend to assume a cleaner separation between peace, crisis, and war.
Why Infrastructure Is the Common Target Set
Across the four actors this series profiles, one pattern holds consistently: the preferred target set is civilian and dual-use infrastructure rather than military assets. Subsea cables, port operations, energy transmission systems, and satellite/navigation networks share three characteristics that make them attractive under grey-zone logic:
- Strategic leverage without military escalation. Disrupting a cable landing site or a power grid component achieves real strategic effect without engaging a military target, keeping the action below most collective-defense thresholds (including NATO’s Article 5).
- Deniability by design. Infrastructure incidents – a severed cable, a compromised industrial control system, a satellite-dependent guidance failure – are frequently attributable only with difficulty, giving state actors a built-in plausible-deniability posture even when the pattern of activity strongly suggests state involvement.
- Dual-use ambiguity. Much of this infrastructure has legitimate civilian and commercial uses in addition to any military or intelligence value, complicating both attribution and proportional response.
This is the throughline the series will trace across each actor: China’s dual cyber-and-kinetic infrastructure posture (Part II), Russia’s role as the hub of a four-nation proxy coordination system (Part III), Iran’s proxy architecture built on infrastructure interdiction (Part IV), and North Korea’s emergence as an independent kinetic threat to infrastructure and allied deterrence alike (Part V).
Series Roadmap
- Part II – China: the series’ only dual-role actor, spanning both Cyber-Kinetic Convergence (critical infrastructure intrusion, anchored by the August 2026 US executive order restricting foreign grid equipment) and Kinetic Gate/Deniability activity (satellite-navigation support enabling Iranian missile and drone precision during the current war).
- Part III – Russia: positioned as the coordination hub of a four-nation architecture – North Korean and Chinese support flowing in to sustain the Ukraine war, Russian material and intelligence support flowing out to Iran – set against the confirmed August 2026 US warning to Moscow against testing NATO’s resolve in the Baltics.
- Part IV – Iran: the clearest Deniability/Proxy Warfare case in the series, built on Houthi, Iraqi militia, and Lebanese proxy layering, alongside Iran’s own Grey Zone Interdiction Zone activity in the Strait of Hormuz and Red Sea.
- Part V – North Korea: profiled independently as a kinetic threat actor in its own right – the 2026 US intelligence reclassification of North Korea’s ICBM capability as homeland-reaching, and Pyongyang’s direct threats against Japan.
- Part VI – Synthesis: a comparative closing assessment of how all four actors sit across the four-term framework, and what the convergence between them means for government, business, and public audiences.
Sourcing & Methodology Note
This dossier, and the series it opens, applies CommandEleven’s standing tradecraft standards throughout:
Every non-trivial claim is tiered
- CONFIRMED – independently corroborated across multiple credible sources
- ASSESSED – analytically well-supported but resting on single-source or inferential reasoning
- SPECULATIVE – circulating claims, single-source reporting, or CommandEleven’s own sourcing channels that have not been independently corroborated
Claims touching current governmental control, active military posture, or leadership status are re-verified at the time of drafting rather than carried forward from earlier reporting, given the pace at which these situations move.
Single-source and speculative material is explicitly flagged as such and excluded from Key Judgments sections throughout the series – it is presented, where included, as a named and dated item for the reader’s awareness, not as an analytical conclusion.
This dossier cites CommandEleven’s April 2026 Global Counter-Terrorism Assessment as prior-art precedent for the framework applied here.
This series does not include operational or technical how-to detail of any kind. Analysis throughout is held at the organizational, strategic, and policy level, consistent with CommandEleven’s standing public-facing editorial standard.
GREY ZONE WARFARE SERIES
PART I – Grey Zone Warfare Explained: The Framework Behind China, Russia, Iran & North Korea
PART II – China’s Grey Zone Playbook: Salt Typhoon, EO 14420 & Iran’s BeiDou Pivot
PART III – Russia’s Grey Zone Hub: North Korea, China & the Iran Weapons Pipeline
PART IV – Iran’s Proxy Empire: The Axis of Resistance and the Grey Zone Playbook
PART V – North Korea’s New Threat: ICBMs, Japan, and the Homeland Reclassification
PART VI – Grey Zone Warfare Synthesis: How China, Russia, Iran & North Korea Connect