
Ghosts in the Grid: The Secret Cyber War Already Happening Inside Critical Infrastructure
Nation-state competition does not begin only during declared wars. This article explores how strategic reconnaissance, espionage and network pre-positioning during peacetime could shape the outcome of a future conflict—and why discovering an attacker inside infrastructure does not necessarily mean the attack has begun.
Ghosts in the Grid: The Secret Cyber War Already Happening Inside Critical Infrastructure
There is a war happening right now. Not a declared one. Not one with casualties or headlines or emergency sessions at the United Nations. A quiet war, fought in the wiring of power plants, the control systems of water treatment facilities, the networks that route electricity through cities, and the software that manages the flow of natural gas across continents. It's being conducted by nations against nations, during what diplomats still call peacetime, and most of the targets don't even know they're on the battlefield.
If that sounds dramatic, consider this. In the last five years, security researchers and intelligence agencies have discovered sophisticated, state-sponsored malware lurking inside critical infrastructure systems across dozens of countries. Not malware that was actively destroying anything. Not malware that was disrupting operations. Malware that was just there — sitting quietly in industrial control systems, maintaining access, waiting. In some cases, it had been there for years.
This is the ghost war. The war of pre-positioning. And understanding it requires letting go of a fundamental assumption about what cyber warfare looks like and when it begins.
The Assumption That No Longer Holds
Most people, including most policymakers, operate on a simple assumption: if an attacker is inside your network, an attack is happening. The presence of the intruder is the evidence of the attack. You detect the intruder, you expel the intruder, the attack is over.
This assumption works for most cyber incidents. A ransomware gang breaks in, encrypts your files, demands payment. The intrusion and the attack are the same event. A hacktivist defaces your website. The intrusion and the attack are simultaneous. A criminal group steals your customer data. The breach is the attack.
Nation-state cyber operations don't work this way. Or more precisely, the most sophisticated nation-state operations don't work this way. The intrusion and the attack are not the same event. They're separated — sometimes by years. The intruder gets in, establishes access, maintains that access quietly, and waits. The waiting is not inactivity. The waiting is preparation. And the preparation is, in the most literal sense, an act of war — even if the war hasn't started yet.
This is the concept that reframes everything: the intruder inside your infrastructure today may not be attacking you. They may be preparing to attack you later, in a conflict that hasn't begun, against a backdrop of tensions that haven't yet escalated to the point where anyone would call it a crisis. The ghost isn't haunting your house. It's moving in furniture.
Strategic Reconnaissance: Mapping the Battlefield Before the Battle
The first phase of the ghost war is reconnaissance — but not the kind that most security professionals think of. Traditional cyber reconnaissance is about finding vulnerabilities. It's technical, tactical, and focused on the question: how do I get in?
Strategic reconnaissance in the context of critical infrastructure is different. It's about understanding the target's infrastructure well enough to predict how it will behave under stress, how it will fail, and how disrupting specific components will produce the most strategic effect. The question isn't how do I get in. The question is: if I disrupt this specific substation, what happens to the grid? If I manipulate this specific valve, what happens to the gas pipeline? If I corrupt this specific database, what happens to the logistics network?
This kind of understanding takes time. It requires the attacker to live inside the target's systems for months or years, observing how they operate under normal conditions, mapping the relationships between components, understanding the redundancies and failover mechanisms, and identifying the points where a single disruption would cascade into a system-wide failure.
The attackers are building a model of the target's infrastructure that is more detailed and more accurate than the model the target's own operators have. They know which systems are critical and which are peripheral. They know which connections are redundant and which are single points of failure. They know what the system looks like when it's running normally, which means they'll know immediately when something changes — and they'll know how to exploit that change.
This model-building is the foundation of the ghost war. Everything that follows — the pre-positioning, the waiting, the eventual strike — depends on having this deep, patient understanding of the target. And it's happening right now, inside infrastructure systems around the world, conducted by operators who have no intention of attacking today.
Pre-Positioning: Planting the Seeds of Future Destruction
The second phase of the ghost war is pre-positioning — the practice of establishing and maintaining access to critical infrastructure systems so that, if and when a conflict begins, the attacker can disrupt or destroy those systems on command.
Pre-positioning is not the same as traditional persistence. A criminal group that maintains access to a compromised system is doing so to continue stealing data or to ensure they can re-encrypt the system if the ransom isn't paid. The access is persistent, but it's purposeful — it's being actively used.
Pre-positioning for a future conflict is different. The access is established and maintained, but it's not being used for any ongoing operation. It's being kept alive — updated when the target patches systems, adapted when the target changes configurations, and expanded when new vulnerabilities provide deeper access — but it's dormant. The attacker is not stealing data. They're not disrupting operations. They're not doing anything that would trigger an alert or attract attention. They're simply there, maintaining the capability to act, waiting for the day they're told to.
The most sophisticated pre-positioning operations go beyond maintaining access to a single system. They establish access across multiple critical systems — power generation, transmission, distribution, and the communications networks that coordinate them — creating a web of access points that could be activated simultaneously to produce a coordinated, multi-layered disruption. The attacker is essentially building a bomb inside the target's infrastructure, piece by piece, connection by connection, over a period of years. The bomb doesn't go off. It just sits there, ready.
This is what was found in those industrial control systems. Not active attacks. Not malware that was designed to destroy. Access. Quiet, patient, maintained access to systems that control the physical infrastructure that millions of people depend on. The ghosts weren't doing anything. They were just there.
Why Discovery Doesn't Mean the Attack Has Begun
One of the most counterintuitive aspects of the ghost war is that discovering an attacker inside your infrastructure does not necessarily mean the attack has begun. In fact, it might mean the opposite — that the attack is still far off, and the attacker was simply maintaining the access they would need when the time came.
This creates a serious dilemma for defenders. When you discover a sophisticated intruder inside your critical infrastructure, what do you do? The obvious answer is: expel them immediately. And that's almost always the right answer from a security perspective. But it raises a strategic question that goes beyond the immediate incident.
If you expel the intruder, you lose the intelligence opportunity. You learn that they were there, but you don't learn what they were planning. You don't learn which systems they were most interested in. You don't learn what capabilities they had positioned. You don't learn whether they had established access to other systems you haven't found yet. By expelling the intruder, you close the one window you had into the adversary's strategic intentions.
If you don't expel the intruder — if you monitor them, feed them false information, and use their presence to understand their objectives — you gain intelligence, but you accept the risk that they might activate their capabilities before you're ready. The ghost might stop being patient. The bomb might go off.
Intelligence agencies have wrestled with this dilemma for decades in the physical world. The cyber world makes it harder because the decision timeline is compressed. In the physical world, if you discover a spy in your midst, you have time to decide what to do — the spy isn't going to destroy a power plant in the next five minutes. In the cyber world, a pre-positioned attacker could potentially activate their capabilities in seconds. The window for deliberation is much shorter, and the cost of wrong decision is much higher.
The Peacetime War: How Tensions Shape the Ghosts
The ghost war doesn't happen in a political vacuum. The pace, intensity, and targeting of pre-positioning operations are shaped by the geopolitical climate — but with a lag. When tensions between two nations rise, the pre-positioning operations don't immediately escalate. The attackers don't shift from reconnaissance to disruption just because a diplomatic crisis has emerged. They deepen their access. They expand their mapping. They prepare for the possibility that the crisis will escalate to a point where offensive action is ordered.
This means that the infrastructure compromise you discover today may be the result of decisions made years ago, during a previous period of tension. The current political climate tells you nothing about when the pre-positioning was established or how long it's been running. A nation might discover sophisticated access to its power grid during a period of warming relations with the suspected adversary — the access was established during a previous crisis and has been maintained ever since.
This temporal disconnect makes attribution and response extraordinarily complex. If you discover pre-positioning today and attribute it to Nation X, what do you do? Confront Nation X diplomatically? They might deny it. Expel the intruders? They might re-establish access within months. Retaliate in kind? You might escalate a situation that the other side didn't intend to escalate. The ghost war operates outside the traditional framework of diplomatic response because it exists in the grey zone between peace and war — too aggressive to be called espionage, too quiet to be called an attack.
The Infrastructure That Doesn't Know It's a Battlefield
One of the most troubling aspects of the ghost war is that most critical infrastructure operators don't know they're on the battlefield. The company that runs the regional power grid thinks of itself as a utility. The organization that manages the water treatment system thinks of itself as a public service. The firm that operates the gas pipeline thinks of itself as an energy company. They don't think of themselves as military targets. They don't think of their control systems as contested terrain. They don't think of the software running their operations as the front line of a geopolitical conflict.
But the attackers do.
The nation-state operators who are pre-positioning inside critical infrastructure aren't thinking about the utility company or the water treatment plant. They're thinking about the nation that depends on them. They're thinking about the strategic effect of disrupting those services during a future conflict. They're thinking about the leverage that comes from having the ability to turn off the lights, stop the water, or freeze the fuel supply — and from the target not knowing you have that ability.
The gap between how the operator sees their infrastructure and how the attacker sees it is one of the most dangerous asymmetries in modern cyber warfare. The operator is defending against cybercrime — against ransomware, data theft, and the threats they read about in the news. The attacker is preparing for cyber warfare — for the disruption of critical services during a geopolitical crisis that may be years away. The operator's defenses are calibrated for the threats they know about. The attacker's operations are designed to evade those defenses entirely, because they're not the same kind of threat.
What the Ghosts Are Really After
To understand the ghost war, you need to understand what the pre-positioning is ultimately designed to achieve. It's not designed to disrupt infrastructure today. It's designed to create the option to disrupt infrastructure in the future — and, critically, to create uncertainty in the adversary's mind about whether that option exists.
A nation that suspects — but cannot confirm — that an adversary has pre-positioned capabilities inside its critical infrastructure faces a strategic dilemma. It cannot be certain that its infrastructure would function during a conflict. It cannot be certain that mobilizing its military would be supported by the power, communications, and logistics systems it depends on. It cannot be certain that the threat is real or that the access is still active. This uncertainty is itself a weapon — it degrades the adversary's confidence in its own capabilities and complicates their strategic calculus.
In some cases, the mere discovery of pre-positioned access can achieve strategic effects without the access ever being activated. If a nation discovers that an adversary has maintained deep access to its power grid for years, the political and psychological impact of that discovery may be as significant as an actual disruption. The revelation shakes public confidence in the government's ability to protect critical services. It raises questions about what else might be hidden. It creates pressure for defensive investment that diverts resources from other priorities.
This is the ghost war's most insidious feature. The ghosts don't need to attack to be effective. Their presence — or even the possibility of their presence — is enough to shape the strategic landscape. The target doesn't know what's inside its infrastructure. It doesn't know what the ghosts have access to. It doesn't know what they could do if activated. It doesn't even know, for certain, whether they're still there or whether they've already been expelled. The uncertainty is the weapon.
What Nations Need to Do
If the ghost war is already happening — and the evidence strongly suggests it is — then nations need to rethink how they defend critical infrastructure. The current model, which treats cyber defense as an incident-response activity — detect intrusions, expel intruders, restore systems — is insufficient against adversaries who are not conducting attacks but preparing for them.
First, critical infrastructure needs continuous, proactive threat hunting — not just detection of active threats, but systematic searching for the quiet, patient access that pre-positioning operations depend on. This means looking for the anomalies that don't look like attacks: unusual account activity that's too subtle to trigger alerts, configuration changes that are too small to notice, network connections that are too infrequent to flag. The ghosts are designed to be invisible to standard security tools. Finding them requires tools and techniques designed specifically to detect presence rather than activity.
Second, nations need to treat critical infrastructure compromise as a national security issue, not just a cybersecurity issue. When a state-sponsored actor is found inside a power grid, the response cannot be limited to the utility company's IT team. It needs to involve intelligence agencies, military cyber commands, and national security leadership. The pre-positioning is a strategic operation by a foreign power. The response needs to be strategic too.
Third, nations need to invest in understanding their own infrastructure better than the adversary does. The ghosts succeed because they build a better model of the target's infrastructure than the target has itself. Closing this gap means investing in infrastructure mapping, dependency analysis, and impact modeling — understanding exactly which components are critical, which are redundant, and how failures cascade — so that when pre-positioning is discovered, the defender can assess what the attacker was after and what they could have done.
Fourth, the grey zone between peace and war needs clearer rules. The international community has spent years debating cyber norms — what's acceptable, what's not, what constitutes an attack. The ghost war exposes the inadequacy of these frameworks. Pre-positioning inside another nation's critical infrastructure is not espionage in the traditional sense. It's not an attack in the traditional sense. It's something in between, and the lack of international agreement on how to categorize and respond to it gives the attackers freedom to operate.
The Bottom Line
The ghosts are already in the grid. They've been there for years, in some cases. They're not attacking. They're not disrupting. They're waiting. And the infrastructure they're waiting in is the infrastructure that every person in every developed nation depends on for electricity, water, fuel, communications, and the basic functions of modern life.
This is the secret war. Not a war of the future, but a war of the present — conducted quietly, during peacetime, by nations that are preparing for a conflict they hope never comes but are determined to be ready for if it does. The discovery of pre-positioned access in critical infrastructure doesn't mean the attack has begun. It means the preparation has been ongoing, probably for longer than anyone realizes, and the question is not whether the ghosts are there — they almost certainly are — but whether the nations that host them have the capability to find them before they're needed.
The ghosts don't announce themselves. They don't trigger alarms. They don't leave obvious traces. They simply exist, quietly, inside the systems that keep the lights on and the water flowing, waiting for the day when someone gives the order to stop waiting and start fighting.
That day may never come. The tensions may ease. The conflicts may be resolved through diplomacy. The ghosts may be discovered and expelled before they're ever activated. But until that day, they're there. In the grid. In the pipeline. In the control system. In the wiring of the modern world. And the nations that don't look for them will never know how close they came.



