The rapid advancement of information and communication technologies in the twenty-first century has fundamentally transformed the landscape of modern warfare, giving rise to cyberspace as a new domain of armed conflict. This transformation has been accompanied by the emergence of non-state actors operating as proxies or cyber mercenaries employed by states to conduct strategic cyber operations while maintaining plausible deniability. This study aims to examine the evolution and legal status of cyber mercenaries within the framework of International Humanitarian Law and to evaluate the extent to which criminal responsibility may be imposed on these actors under the Rome Statute and the jurisdiction of the International Criminal Court (ICC). Employing a normative juridical legal research method with conceptual and statutory approaches, the study finds that the traditional definition of mercenaries under Article 47 of Additional Protocol I to the Geneva Conventions is ill-suited to the realities of cyber proxies, thereby creating a significant legal gap. Furthermore, although the Rome Statute does not explicitly regulate cyber crimes, a consequences-based approach allows cyber mercenaries to be prosecuted for war crimes when cyber operations result in physical damage or the loss of functionality of civilian infrastructure equivalent to that caused by kinetic attacks. The study concludes that existing legal instruments require reinterpretation, supported by proactive policies within the framework of international criminal justice, to ensure individual criminal accountability for increasingly destructive contemporary cyber conflicts.