In 2009, On nth Order Attacks (NATO CCDCOE, Responses to Cyber Terrorism) predicted that PLA shashoujian logic, read through the Highly Optimized Tolerance lens, would produce an operational signature in which state adversaries target the mission-sustaining ancillary systems of advanced computerized societies, rather than end systems, and do so through tradecraft that exploits defender assumptions rather than defender code. The chapter framed this as an nth-order bleeding strategy: forced economic exhaustion of the defender via over-defense of every similar potential target. This short paper reads the February 2024 joint advisory AA24-038A (CISA/FBI/NSA), the January 2024 DOJ disclosure of the KV Botnet disruption, and FBI Director Wray's January 2024 congressional testimony against the 2009 predictions. Three features of the public record align precisely: strategic rather than tactical targeting (prepositioning as placement of optionality), a near-identical critical-infrastructure sector set (communications, energy, transportation, water), and living-off-the-land tradecraft as a textbook HOT failure mode at the defender's detection layer. The paper then records honestly where the 2009 framework was silent or incomplete: five-year dwell times, specific Windows-utility tool inventories, and the SOHO-router concealment substrate. A closing observation draws the parallel HOT failure mode from the kinetic side of the same Pacific theater: two decades of U.S. underinvestment in hardened aircraft shelters at Andersen AFB, against China's construction of over 400 such shelters in the past decade.
Daniyel Yaacov Bilar (Mon,) studied this question.