
Marek Kohv, head of the “Security and Resilience” research program at The International Centre for Defence and Security (ICDS), discusses the most significant changes on the fronts of hybrid warfare in the past year in an interview with Propastop. “The most striking new development is Russia’s large-scale tactic of recruiting individuals for hybrid attacks through social media,” Kohv states.
What are the key changes in the field of hybrid threats in 2024?
The most striking new development is Russia’s large-scale tactic of recruiting individuals for hybrid attacks through social media. While this has been done before, such large-scale efforts began at the start of 2024. The Soviet-era sabotage doctrine also included the possibility of recruiting individuals from third countries, but typically those with specific skills.

Compared to classic face-to-face recruitment, social media recruitment is significantly less reliable because it lacks the ability to vet and train individuals. This has made Russia’s hybrid attacks in the West, particularly in Europe, much more dangerous. Recruiting agents through so-called short-term, quick job postings can result in significantly more casualties if an untrained agent makes a critical mistake.
What caused this shift in Russia’s tactics?
Nearly 700 spies operating under diplomatic cover were expelled from Europe, significantly limiting Russia’s ability to conduct on-the-ground recruitment. Visa regimes have been tightened, and the movement of Russian citizens to Europe has been heavily restricted.
One hybrid threat expert recently stated at the Strategic Communication Annual Conference that in 2024, “Russia brought the war to the West” through various hybrid activities. What examples confirm that Russia has used hybrid pressure to intimidate and influence public opinion in Western countries?
All of Russia’s activities in the hybrid domain aim to divide our societies and weaken support for Ukraine. We can cite dozens of examples. For instance, Poland has become a primary target because it serves as the largest logistical hub for supporting Ukraine and is one of Ukraine’s strongest backers in the West. Almost every week, there are reports from Poland of arson attacks, individuals being apprehended for observing military facilities, and similar incidents.
In Lithuania, an IKEA store was set on fire in May this year. While this act seemed to have no direct military purpose, one of the objectives of hybrid attacks is to generate societal anxiety and provoke public debates, such as whether our support for Ukraine is prolonging an already lengthy war. Russia continuously undermines our societies through hybrid activities, its narratives, and accompanying disinformation.
How effectively did Lithuania handle the recent DHL plane crash in Vilnius, where no direct blame was assigned to Russia, although the neighboring country was hinted at as a probable cause?

Lithuania’s handling of this incident was very professional. Perhaps former Foreign Minister Gabrielius Landsbergis was a bit more vocal, but other officials remained fairly composed.
A criminal investigation was launched, and no one was prematurely blamed. Time will tell. I am confident that Lithuania will uncover the cause of the accident since the second pilot survived, the black box was recovered, and there are multiple videos of the plane’s crash. We simply need to wait because speculation will not help in any way.
According to Estonian diplomats, the term “hybrid threats” has been a top priority in both Estonia’s and its partners’ agendas this year. However, there is no shared understanding of what “hybrid” means or how to respond collectively. A hybrid attack can be addressed by attributing blame politically—like Estonia did in 2007 by assigning responsibility for cyberattacks to Russia—or legally, by taking time to identify the perpetrator through an investigation. Is a consensus emerging among Western allies to develop a unified understanding and response to hybrid threats by 2025?
For the European Union, adherence to the rule of law is a fundamental principle, and Russia exploits this. On one hand, this is our weakness; on the other, it is our strength, as we do not want to become like Russia, disregarding laws and international rules.
When it comes to attributing blame, it is clear that determining guilt in a criminal process takes a very long time. We saw this last year with the Chinese ship Newnew Polar Bear, which damaged the Balticconnector gas pipeline. A criminal investigation was launched, but we ultimately received no clear answers from China, and nearly a year later, China declared the incident an accident.

Today, NATO and the European Union are discussing how to respond to such incidents. Efforts are also being made to enhance resilience, which is undoubtedly important. However, merely focusing on resilience will not win a war. If you only invest in defense in a war, you will simply die more slowly.
Recently, one of our experts claimed it is only a matter of time before Russia kills a Western citizen in a hybrid attack. When the FSB attempted to poison a former GRU officer in Salisbury in 2018, the West responded by expelling diplomats. If a hybrid attack by Russia results in casualties today, what will the West’s reaction be now?
It largely depends on the country where the attack occurs. There have already been casualties—such as the two Czech citizens who died in a 2014 ammunition depot explosion. Additionally, the assassination plot against the CEO of the German company Rheinmetall has been uncovered.

We have already exhausted the options provided by international diplomacy, from entry bans to declaring individuals wanted by the International Criminal Court. These measures do not work with Russia, as the country is entirely indifferent to the crimes they are accused of. This is in stark contrast to China, which is very concerned about its reputation and seeks to avoid being labeled a pariah state.
In the future, it is likely that the affected country, along with a group of like-minded states, will issue a coordinated response. While various high-ranking officials have mentioned that hybrid attacks could potentially lead to the activation of Article 5, it is clear that NATO’s Article 5 was not designed to address hybrid activities. Russia is well aware of this and operates below the threshold that would trigger a collective NATO response under Article 5.
What might the response be, for example, to a plane being shot down in a NATO country? Would allies respond in kind, or would they target the organizers of Russia’s hybrid attacks personally, similar to how Ukrainians are currently hunting those responsible for specific war crimes on Russian territory?
That is unlikely to happen. Instead, a package of asymmetrical responses would probably be developed. For example, there are still many categories of goods being imported from Russia to Western countries and vice versa. One possible response could involve banning the import or export of these goods entirely, potentially leading to a complete cessation of trade with Russia to reduce funding for Putin’s regime.
It is also likely that asymmetrical responses could be executed in cyberspace, targeting state-related facilities or infrastructure that directly supports military operations.
What is needed for a political decision to be made to provide symmetrical responses to Russian attacks in cyberspace? This is not being done currently.
There are NATO and European Union member states that are more supportive of Russia, and such decisions require broad consensus. That’s why I mentioned that a more effective response could come from a group of like-minded countries. This group would not necessarily act on behalf of NATO or the European Union but would instead consist of allies with a shared perspective.
If sociologists were to ask 1,000 people what exactly “hybrid warfare” or “hybrid threat” means, likely 95% wouldn’t know the answer. Would it not be more practical, at least in Estonia, to start talking about sabotage and subversive activities instead of hybrid threats and attacks?
This is an ongoing debate. In Estonia, we were the ones who adopted the term “hybrid,” but now it seems to us that this term dilutes the gravity of Russia’s crimes.
When we talk about acts of sabotage or terrorism, people indeed understand these terms better. However, “hybrid attacks” carry a broader meaning. If we label individual crimes as sabotage and treat them as isolated incidents, we lose sight of the bigger picture.
The Americans used the term “organized political warfare” as early as the 1950s, where the visible aspect might have been traditional diplomacy, but it also included covert operations—sabotage, intelligence activities, and so on. The key value of the term “hybrid warfare” is that it describes how smaller actions work toward achieving a larger goal. Hybrid attacks are not isolated events; they all contribute to the pursuit of a massive overarching objective.
The world is watching what will change after Donald Trump assumes the U.S. presidency on January 20. Looking ahead to the new year, what might be Russia’s next move to increase hybrid pressure on NATO and the European Union?
A few days ago, Sergei Naryshkin, head of Russia’s Foreign Intelligence Service, claimed that Russia is “almost achieving its goals in Ukraine.” This statement is likely intended to prepare Russian society. In reality, Russia has not abandoned its 2021 demands to effectively dismantle Ukraine as a state and rewrite Europe’s entire security architecture. Instead of achieving this, NATO has expanded to include Finland and Sweden.
Much depends on what happens on the frontlines in Ukraine. This will significantly influence Russia’s behavior toward the West. If the West continues to support Ukraine, and China and North Korea maintain their backing of Russia, the war of attrition will persist, with Russia placing considerable emphasis on hybrid operations directed at Europe.
In Europe, 2025 will mark a critical turning point in the protection of critical infrastructure, both underwater and on land. This is an area where Western countries can—and must—strengthen their defenses.
You have said that the new “axis of evil” nations—Russia, North Korea, China, and Iran—learn from one another and cooperate. How?
Historically, all these “axis of evil” countries have engaged in influence operations abroad. Perhaps it’s more accurate to look at them in pairs. For Russia and North Korea, criminal activity is an integral part of their systems and foreign policy. Historically, North Korea has harassed South Korea and Japan by kidnapping their citizens and conducting operations with numerous casualties, including multiple assassination attempts on South Korean presidents.
Iran and China primarily target dissidents from their own countries who live abroad. China, for example, should not be underestimated—there are several documented cases from Denmark, Germany, and the Netherlands where Chinese intelligence has successfully recruited local citizens. Such incidents have even occurred in Estonia. China and Russia clearly cooperate in the realm of disinformation, with Chinese media echoing the narratives of Russian news outlets. One might think it doesn’t matter much what Chinese citizens believe, but Chinese media also reaches their vast diaspora overseas and the so-called Global South.
In terms of hybrid activities, these countries learn from each other’s practices. For instance, Russia has adapted North Korea’s tactics for smuggling coal when dealing with sanctions on oil products. When North Korean coal shipments were sanctioned and their ships couldn’t dock in foreign ports, they carried out ship-to-ship transfers at sea. Russia now employs a similar shadow fleet for transporting oil products, grain, and weapons. This shadow fleet is characterized by difficult-to-trace ownership, frequent flag changes, and deceptive practices, such as hiding a ship’s location while at sea.

Glossary
Hybrid warfare was defined by Frank Hoffman in 2007 as the emerging simultaneous use of multiple types of warfare by flexible and sophisticated adversaries who understand that successful conflict requires a variety of forms designed to fit the goals at the time.
Hybrid attack is an assault that combines combat operations, covert intelligence agency missions, and widespread public disinformation.