The Adversary: Capability and Operations

Vulnerabilities and adversaries are different problems. A vulnerability is a property of an architecture: it is there whether or not anyone uses it. An adversary is a person or group that decides to use it, picks a target, and picks a moment.

We characterize adversary capability across eight dimensions: scope of effect, persistence, pre-operational intelligence required, attribution difficulty, reversibility, resource investment, time horizon, and detection difficulty. The conventional single-axis ranking (script-kiddie at one end, nation-state at the other) collapses these into one scale and ties each point on the scale to the actor type historically associated with it. This single-axis approach conflates "what an adversary can technically do" with "what type of actor has historically done it." Rating an operation on each of the eight dimensions separately lets a defender describe what an adversary can do without first deciding what kind of adversary it is, which matters because the two no longer track each other. For example, a small, purely commercial team can hold persistence over long periods of time undetected without the resource investment and support traditionally only available to nation-state operations.

Two shifts mark the present moment. The first is the commercialization gray zone: the same technical capability is available to a broadening buyer base, and whether any given operation counts as legitimate depends on buyer identity and intent rather than on anything the technical analysis can reliably establish. Commercial spyware took that route over the last decade: capability that only governments had built became a product with a customer list. ATG-class techniques are on the same route now. The second is the AI Amplification Factor. An adversary can now have a model generate a different piece of manipulated content for every target, matched to that person's situation at that moment, and that changes what an ATG operation costs to run. When the AI runs on the user's device, part of the operational signature moves inside, where defenders cannot see it from outside. This is the local-AI detection blind spot. The combination of commercialization and AI amplification distinguishes the present moment from previous threat eras.

Adversary scope extends to the full Client Runtime landscape, not the browser alone. The adversary who works against a browser script dependency is the same adversary who works against a vehicle infotainment update channel, a smart-TV plugin marketplace, a productivity-tool extension store, or a mobile over-the-air update pipeline: code pulled straight from a server after the app is installed, without going back through the app store.

Placement, Access, Influence, Control describes how an adversary turns a capability into a running operation.

3.1: ATG Adversary Capability

Eight dimensions characterize ATG adversary capability. Any one operation sits somewhere on all eight at once; it does not get a single score.

Scope of effect: the size and type of population, infrastructure, or system an operation reaches. The range runs from a single targeted device or user, through a specific organization or supply-chain segment, to an entire infrastructure layer. Position on this dimension is determined by where in the digital supply chain the adversary holds placement and what passes through that position. A compromise of a major identity provider reaches every application that authenticates through it; a per-victim deception operation reaches one. Reach is not the same thing as targeting precision. An operation can pass through millions of devices while aiming at one person, so a large number here says nothing about how selective the operation was. Reach is also not the same thing as consequence. A single recipient can carry an entire operation when that recipient's decisions carry institutional weight: a head of government, a chief executive, or a commander directing a force each reads from one screen, and an operation that reaches that screen has reached everything it needed. A small number here therefore says nothing about what the operation was worth.

Persistence: the duration over which a capability remains operational once established. The range runs from transient (a single payload deployment that ends with delivery), through campaign-scoped (operational across a defined window of weeks or months), to indefinite (a position the adversary holds and re-uses across many operations over years). Persistence counts only the time after the position is working. Time horizon, a separate dimension, counts the whole arc from first planning to exit. Position on this dimension is determined by detection-and-removal pressure, the resilience of the underlying placement, and the adversary's discipline in operating quietly enough to remain in place.

Pre-operational intelligence: the volume and specificity of target-specific intelligence the operation requires before activation. The range runs from no target-specific intelligence (an operation that delivers the same payload to every reachable victim), through population-segment intelligence (deception calibrated to a demographic, language community, or device class), to individualized intelligence (deception assembled per target from aggregated data on that specific person). How much an operation needs depends on what it is trying to do and on the intelligence sources the adversary can draw on. AI makes the individually targeted end of the range much cheaper to reach.

Attribution difficulty: the analytical effort required to trace an operation back to the operator who launched it. The range runs from straightforward (clear technical signatures, named infrastructure, public attribution within weeks), through moderate (multi-month investigation across several reporting institutions before attribution stabilizes), to structural (nothing is recording at the rendering surface, so the evidence that would identify the operator is never captured in the first place). Position on this dimension is determined by operational tradecraft, infrastructure compartmentalization, and what defenders can see at the layer where the operation runs.

Reversibility: the extent to which an operation's effects can be undone after detection. The range runs from fully reversible (a payload removed from a CDN ends the operation), through partially reversible (the immediate payload is removed but the data already exfiltrated, the inferences already drawn, or the decisions already taken cannot be reversed), to fundamentally irreversible (information delivered, beliefs shifted, financial transactions executed, or physical-world actions taken based on the manipulated surface). Position on this dimension is largely determined by the D5 effect being produced; manipulation effects sit toward the irreversible end of the range, because the manipulation has already affected the user's actions by the time the payload is removed.

Resource investment: the investment the adversary is required to make to acquire and operate the capability, across financial, technical, and operational categories. Financial cost runs from negligible (recruiting or co-opting an existing position-holder) to multi-million-dollar (commercial acquisition of a delivery-layer entity). Technical cost runs from modest (off-the-shelf tooling) to advanced (custom runtime instrumentation, AI-augmented payload generation). Operational cost runs from low (a single insider operating from inside an existing role) to high (a coordinated infrastructure of dormant assets staged across jurisdictions). An operation therefore carries three separate cost figures, and a low figure in one category says nothing about the other two. Intelligence cost is treated separately under Pre-operational intelligence required.

Time horizon: the total arc from planning and position acquisition through activation and exit. The range runs from short (weeks from compromise to activation, typical of opportunistic exploitation of a known vulnerability), through campaign-scale (months), to long-horizon (years between the acquisition of a placement and the activation that monetizes it). Time horizon includes the pre-operational positioning that Persistence does not measure: a long-horizon operation with transient persistence spends years staging a payload that runs once. Where an operation sits depends on how valuable the position is, how disciplined the operator is, and how well the operator can keep the position looking ordinary while waiting.

Detection difficulty: the level at which the operation can be detected, given the instrumentation that exists. The range runs from signature-detectable (the payload matches a known indicator and trips a static control), through behavioral-detectable (the payload's effect on the runtime is anomalous and would be flagged by a monitor watching the right signal), to structurally undetectable (no instrumentation exists at the layer the operation runs at, so the signal that would trigger detection is never captured). Position on this dimension is largely determined by what the operation does and where it does it; an operation that runs entirely inside a Client Runtime on the user's device sits near the structurally undetectable end of the range with current instrumentation.

The dimensions are analytically distinct, not strictly independent. Where an operation sits on one dimension narrows where it can sit on the others without fixing it. What describes the operation is the whole set of eight positions.

Capability is not bound to actor type. Precision-targeted operations are most often run by nation-state actors, but the technical capability ceiling is reachable by any sufficiently resourced and patient adversary. Well-funded criminal organizations, hedge funds, large corporations, contracted private intelligence firms, and political operations all command the resources, the procurement pathways, and the discipline to acquire and operate placement at the levels associated historically with state actors. Motivations, risk calculus, objectives, and operational signatures differ across types of adversarial actors. The technical capability ceiling does not.

Resources are not the only thing that decides what an adversary can do. Where the adversary sits decides at least as much. An employee with relatively few personal resources, working in a high-leverage supply-chain position, can hold ATG capability that exceeds what most external adversaries could acquire through any combination of access points. A developer inside a widely deployed analytics SDK reaches every site that loads the SDK. A maintainer of a major CDN service reaches every dependent application that fetches from it. An engineer inside a common API library reaches every integration that calls it. A developer inside a mobile over-the-air update pipeline reaches every device on the channel. A maintainer of a vehicle infotainment update feed reaches every vehicle on that platform. The scale of insider-enabled capability is proportional to the organizational reach of the insider's employer.

A motivated external actor can target employment or personnel in a high-leverage position as a deliberate strategy for establishing placement. The insider category extends beyond direct employees to board members, consultants, advisors, contractors, and third-party vendors. Every position in the supply chain that holds placement and access is a potential line of infiltration.

ATG capability is not bound by traditional actor categories or resource requirements.

State capability in this class is not only inferred. The Great Cannon, documented by the Citizen Lab in 2015, sat alongside China's national filtering infrastructure and intercepted requests bound for servers hosting widely used analytics and advertising scripts. For a selected fraction of requesters, chosen by address, it dropped the request before it reached the intended host and answered with substituted JavaScript. Browsers outside China executed that code and were enlisted, without their operators' knowledge, in denial-of-service attacks against GreatFire.org and GitHub. Attribution rested on co-location with the filtering system across multiple network links, a shared side-channel indicating common code, and target selection consistent with the state's censorship objectives.

Two qualifications keep the case honest. Its placement route was on-path interception rather than compromise of a supply-chain component, so it is not evidence for the acquisition or maintainer routes. And the intercepted scripts were served over unencrypted HTTP; the researchers who documented the system named HTTPS as the remedy, and the operation as run in 2015 would not repeat unchanged against an encrypted path. What it establishes is the rest of the chain. Content substituted for the resource an application referenced, delivered to requesters selected by attribute, executing inside ordinary Client Runtimes at population scale, invisible to the user, to the site operator, and to the provider whose script was impersonated. The operation was run by a state, in public, in 2015, and it was documented at the time.

3.2: The Commercialization Gray Zone

The commercial spyware industry is the established precedent. Over the last decade and a half, tools that only governments had built became products that a widening set of private customers could buy. The Citizen Lab and Amnesty International produced the technical attribution work; the 2021 US Entity List action and the 2024 Pall Mall Process are the policy response. The trajectory from state-only capability to commercially-available-product is now well documented.

The same dynamic is in motion for ATG-relevant capabilities. Six commercial pathways put this capability within reach of buyers who are not governments.

Commercial CDN acquisition. Acquiring a content delivery network, or a domain or organization with established CDN customers, is a commercial transaction with no special security review. The 2024 Funnull and cdn.polyfill.io case is the example: a domain previously serving a widely used JavaScript polyfill service was acquired and subsequently used to deliver second-stage payloads to the dependent sites. The acquisition itself was the attack vector. The same pathway applies to specialty CDNs, regional CDNs, content edge networks, and the long tail of small but widely integrated delivery providers.

Behavioral-profiling-as-a-service. The ad-tech and digital-marketing industries operate continuously running infrastructure for collecting per-user behavioral telemetry, segmenting populations, and targeting content to individuals. The same infrastructure, viewed from the adversary's perspective, is pre-operational intelligence collection at scale across potentially large populations. Buying access to a behavioral-profiling provider, or to the data products derived from one, is a commercial transaction. Surveillance-industry data brokers do related work. Whether any given dataset is marketing data or pre-operational intelligence depends on the buyer.

Contracted private intelligence and influence operations. Private intelligence firms, opposition-research operations, and contracted influence-campaign operators sell capabilities that include the discovery, surveillance, and targeted manipulation of specific persons, organizations, or populations. The contracted operator's clients are the actors with the strategic interest; the operator carries the operational capability and the technical infrastructure on the clients' behalf. Several public cases over the last decade document this pattern.

Red-team and adversary-emulation services. The market for offensive-security tooling and contracted adversary emulation has matured into an industry, and several providers explicitly include supply-chain compromise and runtime-injection techniques in their playbooks. The legitimate use case is defensive testing under contract. The same tooling and the same operational tradecraft are available to anyone who can afford the contract or replicate the techniques.

Open-source ATG tooling. Public tooling now exists to assist with several stages of an ATG operation, from identifying vulnerable third-party scripts on a target site to generating manipulated content for delivery to specific user segments. The tooling carries no buyer screening. The barrier to entry is technical literacy, not capital.

Ad-tech and tag-management infrastructure. The infrastructure that delivers scripts (the advertising industry calls them tags) and configuration to billions of pages every day is built the same way an adversary would build infrastructure to deliver a second-stage payload. The risk is the ad network's own loader script, which runs in the page itself with the same powers as the site's own code, not the advertisement, which commonly renders in a separate frame and where malicious creatives are a long-recognized problem with established countermeasures. The integration patterns, the trust relationships, and the runtime behavior are all the same. Whether the operation is legitimate is a matter of who is operating the infrastructure and what payload is being delivered, neither of which is visible at the rendering surface. Targeted Delivery runs on the same rules that decide which advertisement a person sees.

Each of these vectors reaches across the Client Runtime landscape, not the browser alone. Mobile attribution and over-the-air update providers, vehicle infotainment update aggregators, IoT management dashboards, productivity-tool extension marketplaces, and AR/VR asset distributors are each following the same commercial pattern as the web script-delivery and CDN businesses. The same vectors that operate against websites operate against phones, vehicles, appliances, and headsets, and the same buyers can transact in those markets.

The Cost of Free is a related pattern. Many technologies positioned as "free" establish placement and access as their actual purpose. A free analytics library obtains visit history that is monetized as marketing data and that doubles as pre-operational intelligence on the populations it observes. A free open-source utility establishes placement in many systems where it is adopted, providing both an attack surface and an intelligence-collection channel. The "free" positioning is itself a placement strategy, and the resulting placement is a foundation for both pre-operational intelligence collection and direct exploitation. The placement a free component establishes can change hands with the component, including to gray-zone actors who monetize the access it carries.

Build, Buy, Influence, Coerce, and Exploit are five ways to end up holding a supply-chain position, each with a different cost and a different operational signature.

  • Build: establish a technology services company organically and operate the position from inside it. High time horizon, high resource investment, low attribution risk because the position is genuinely the operator's.
  • Buy: acquire an existing entity by commercial purchase, as in the Funnull and cdn.polyfill.io case. Quick relative to building; cost depends on the size and visibility of the target.
  • Influence: acquire effective control of an entity through investment, board seats, partnership, joint venture, or analogous mechanisms. Less visible than acquisition; the entity's nominal ownership does not reflect operational control.
  • Coerce: apply hostile pressure to an entity or its position-holders through extortion, blackmail, threats, or analogous tools. Compatible with operational discipline; the coerced position can be operated for years if the pressure is maintained.
  • Exploit: break into the entity technically, using ordinary cyber intrusion tradecraft. Breaking in is only one of the five ways to end up holding the position. The pathways are composable. A single position may be acquired through a combination: an exploitation foothold that is later converted into an influence position through hiring, or a financial acquisition followed by coercion of the existing personnel.

Supply-chain depth amplifies the leverage of any acquisition. Software A integrates library B, which depends on web service C; influence or control of C reaches A through the transitive dependency chain. The leverage is greatest when the chain passes assets through (data, media, code), because the deeper position can substitute, modify, or instrument those assets before they reach the rendering surface. Two conditions let a deep position be used this way. First, checking stops before running: integrity checks happen before delivery, and nothing checks the pieces again once the runtime starts assembling them. Second, the Just-in-Time App Blueprint: the runtime assembles whatever the chain delivers without re-establishing trust at the point where each piece joins. When an adversary holds the deeper position, those conditions enable transitive control.

The deeper a position sits in the chain, the more systems it reaches and the harder it is to see from the surface. A surface-side dependency review that ends at the first hop does not reveal what the third or fourth hop is doing.

The technical capability is the same regardless of who buys it or how the position was acquired. Whether an operation is legitimate depends on buyer identity and intent, neither of which the technical analysis can reliably establish.

Actor identity no longer predicts capability. Capability no longer predicts actor identity. The threat model that relied on either prediction was built for a buyer set that no longer exists.

3.3: ATG Operational Patterns

ATG operations draw from a broader range of supply-chain adversary tradecraft. Long-term infrastructure pre-positioning, trust-laundering through legitimate-looking infrastructure, supply-chain foot-holding via mergers and acquisitions, multi-step infrastructure resilience, public-cloud service abuse, geographic and jurisdictional staging, asset cycling, and operational compartmentalization are all in active use and all documented in the public supply-chain security literature.

Three of these patterns matter most for ATG, because they decide what a defender is able to detect and what a defender will miss.

Dormancy and activation timing. Dormancy and activation is the most important pattern. Adversaries acquire a position, operate it legitimately for an extended period that can run from months to years, and activate at the moment that maximizes operational value. During the dormancy phase the position is indistinguishable from a benign service, by design: traffic shapes, response patterns, deployment cadence, and update behavior all conform to the benign category the position belongs to. Activation is the only detectable event. The shape is the one the Two-Stage Attack has at the resource level, moved up to the operation: everything a defender can inspect is benign, and what makes it an attack arrives afterwards.

Defensive postures built for active-attack signatures miss the dormancy window entirely, and the dormancy window is where the position is acquired, hardened, instrumented, and woven into legitimate dependency graphs. By the time the activation event arrives, the position is already trusted by every dependent runtime, every reviewing analyst, and every static integrity check the dependent applications carry. Detection at activation is not the same as defense; the activation often is the irreversible event. Defending against a dormancy-and-activation operation requires detecting the dormancy phase, which by construction looks benign.

The cdn.polyfill.io domain served a legitimate Polyfill library under several successive operators, then changed ownership and began delivering second-stage payloads. The XZ Utils contributor infiltration followed the same arc inside an open-source project: years of credibility-building, then activation.

Commercial acquisition as APA pathway. Adversarial Placement and Access (APA) names the case where the party holding a supply-chain position is hostile to the systems depending on it. In the cases where the buyer purchases a supply-chain position that feeds content into a Client Runtime, through an ordinary commercial transaction that raises no security alert. The Funnull and cdn.polyfill.io case is one instance of the broader commercialization-gray-zone pattern. The acquisition is the attack. No exploit is run; no credential is stolen; no perimeter is crossed. The pattern is not browser-specific. Mobile over-the-air update services, vehicle infotainment update aggregators, productivity-tool extension marketplaces, and IoT management providers can all be bought, and each of them feeds a Client Runtime somewhere in the platform landscape.

The security review run during a corporate acquisition rarely asks what the buyer will do with the position once they own it. Buyer-due-diligence frameworks for digital-infrastructure transactions are not built around the adversarial use of the position.

Insider and positional-access leverage at provider scale. An insider in a high-leverage position holds population-scale ATG capability at low resource investment. The pattern is different from external compromise because the access already exists. No exploit is needed; the operator was hired, contracted, advised onto the board, or installed through one of the other pathways the supply chain runs through.

Detection of the insider pattern requires monitoring the operator-side activity at the provider, and the provider's own internal monitoring is the only practical vantage point. External defenders see only the provider's externally observable behavior, which under the dormancy-and-activation pattern is benign by construction. The insider's operational signature is internal; the externally visible signal arrives only at activation, and often only after the irreversible event has already happened.

3.4: The AI Amplification Factor

Generative AI does not create a new kind of weakness. It amplifies the one already at work: supply chain injection that lands at client-side rendering. The change is one of kind, not just of volume: it changes what an ATG operation costs the adversary to run, and it moves part of what the operation would leave visible to a layer existing defenses do not reach.

Four economic shifts mark the change.

  • Pre-operational intelligence cost falls. Per-target precision becomes economically feasible at volumes the analyst-driven approach could not reach. A model can pull together information about one person from scattered sources (resume sites, LinkedIn profiles, social media content, public records, leaked datasets) and assemble a profile of that person at machine speed.
  • Content production cost approaches zero. Each deception target can receive tailored content: language, vocabulary, voice, context, and media. Producing one more tailored deception costs no more than one more request to a model.
  • Detection-evasion improves. Generated content is harder to signature-match because the per-target variation is built into the generation process. Static signatures, hash matches, and template heuristics all degrade against content that was assembled for one target and not seen anywhere else.
  • Operational scale increases. Operations that previously required analyst time per target can now run at population scale. How many people an adversary can reach is now limited by what the compute costs, not by how many analysts they employ. All four shifts come from one capability: multi-source target intelligence aggregation. The system ingests information about a target from disparate sources and optimizes message, voice, vocabulary, and context for the specific user, group, or demographic. The aggregation step previously required human analyst time and was the rate-limiting cost in precision-targeted operations. AI completes it at machine speed and at population scale, and the result is per-target deception that defender detection systems were not designed to handle.

The D5 effect Deceive is where the change bites hardest. Content built for one person at one moment is a different problem from swapping in one fake page that everyone sees: there is no shared copy for anyone to compare against. A defender inspecting one user's experience cannot reliably tell, even with full inspection authority, that the content arriving on that user's screen was assembled to match that user's profile and would not have arrived in that form for another user. Information manipulation is the most likely and most dangerous ATG attack mode. AI amplification operates most directly on that mode and compounds every dimension of it.

Figure 22: Per-target content leaves no shared copy for anyone to compare against.

The Hong Kong synthetic-video conference fraud is another illustrative case. An employee authorized a major financial transfer after a video conference with what the employee believed to be the company's CFO. The video conference was synthetic. AI-generated per-context deception is operational reality today, not a forecast.

The local-AI detection blind spot is the second qualitative change. When the adversarial intelligence work happens on the target's device using the device's own integrated AI, there is no outbound network traffic to fingerprint. Detection systems built on network-level monitoring of suspicious calls to remote AI services miss the activity entirely. The operational signature moves inside the device, where defenders cannot see it from outside.

Local AI is reaching multiple Client Runtimes at once. Phones, laptops, vehicles, AR/VR headsets, smart appliances, and productivity tools are each gaining on-device AI capability through different pathways and on different schedules. The detection blind spot is therefore not a desktop-browser problem; it is reaching every Client Runtime gaining on-device AI.

AI capability is commercializing on the same terms: the tooling, the profile-building it performs, and the content it produces are all for sale, and a buyer's purpose is no more visible here than it is in the older ATG markets. The capability that produces tailored deception is in market alongside the placement that delivers it.

Detection systems built for static-payload signature matching will not scale to per-target AI-generated content, and detection systems built for network-level fingerprinting will miss the local-AI case. AI-augmented behavioral detection at the rendering layer is the architectural requirement. Current Client Runtimes do not provide it, and no instrument inside the runtime can see a model that is running on the device itself. The boundary is unprotected.

AI shifted ATG's adversary economics. Local AI moved the operational signature into the device. The defender's instruments predate both.

3.5: Placement, Access, Influence, and Control

Placement, Access, Influence, Control is the mechanism every ATG adversary operates through. Capability profile, actor type, and AI amplification shape how the mechanism is used; they do not replace it. P&A combines Placement and Access.

Placement is where the actor sits in the supply chain.

Access is what the actor can do from that position. A maintainer of an open-source package has Placement in the project; a maintainer who can publish releases has Access.

An OEM inside a vehicle infotainment update channel has Placement; an OEM whose engineers can ship updates has Access. Every ATG operation requires both.

Influence is what P&A produces. When P&A is exercised repeatedly and broadly, the systems, content, and decisions downstream of the position bend toward the operator's intent. Influence is the cumulative effect of operating the position through repeated cycles of payload, observation, and adjustment.

Control is sustained Influence at population scale: when the operator's decisions effectively determine system behavior for the population, Influence has crossed into Control. There is no line where one becomes the other; the difference is how much of the population is affected and how consistently.

The causal chain is P&A → Influence → Control. Each stage is a quantitative escalation of the previous one. The chain is not specific to ATG; it operates in every supply chain. ATG is the chain at work at the rendering surface inside Client Runtimes. APA is when an actor in a P&A position acts against the systems that depend on the position.

Figure 23: Placement and access produce influence. Sustained influence at population scale is control.

Adversarial Influence Operation (AIO) is the activity by which an APA holder uses the position against those systems to create effects and outcomes.