Monday, April 28, 2025
HomeCyber AttackNSA Allegedly Hacked Northwestern Polytechnical University, China Claims

NSA Allegedly Hacked Northwestern Polytechnical University, China Claims

Published on

SIEM as a Service

Follow Us on Google News

Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a cyberattack on Northwestern Polytechnical University, a prominent Chinese institution specializing in aerospace and defense research.

The allegations, published by organizations such as Qihoo 360 and the National Computer Virus Emergency Response Center (CVERC), claim that the NSA’s Tailored Access Operations (TAO) unit, referred to as “APT-C-40” by Chinese sources, conducted the attack in 2022 using advanced malware and exploitation frameworks.

Polytechnical University
Qihoo 360 – Diagram

The university disclosed the breach in June 2022, reporting phishing emails targeting staff and students as the initial vector.

- Advertisement - Google News

According to Chinese investigators, the NSA allegedly deployed over 40 malware strains and leveraged zero-day vulnerabilities to gain access.

Tools such as NOPEN and SECONDDATE, previously linked to the NSA in leaks, were reportedly used to establish persistence and intercept network traffic.

Attribution and Evidence

Chinese cybersecurity firms attribute the attack to the NSA based on forensic analysis and operational patterns.

Key indicators include:

  • Operational Timing: Nearly all attack activity occurred during U.S. business hours (9 AM–4 PM EST), with no activity on weekends or U.S. holidays such as Memorial Day and Independence Day.
  • Language and System Configuration: Attackers used American English keyboard settings and operating systems configured in English.
  • Human Error: A misconfigured script revealed directory paths linked to TAO’s tools, including a Linux directory associated with NSA operations.

Investigators also identified IP addresses allegedly purchased through cover companies like “Jackson Smith Consultants” to anonymize NSA activities.

These IPs were used to control jump servers and proxy nodes across 17 countries.

Attack Methodology

The alleged attack unfolded in multiple stages:

  1. Initial Access: The attackers reportedly exploited zero-day vulnerabilities in neighboring countries’ servers to establish a foothold before targeting the university through phishing emails embedded with malware.
  2. Network Penetration: Tools such as ISLAND and FOXACID were used to compromise external servers and redirect user traffic for browser exploitation.
  3. Persistence: Malware like NOPEN allowed long-term access, while SECONDDATE enabled traffic interception on network devices.
  4. Lateral Movement: Using stolen credentials, attackers accessed internal systems, including firewalls and telecom equipment, to monitor sensitive data.
  5. Data Exfiltration: Proprietary tools were employed to encrypt and transmit stolen research data via proxy servers, masking the operation’s origin.

China’s claims highlight a growing focus on edge devices like routers and firewalls as targets for cyber espionage due to their limited logging capabilities.

The alleged use of tools consistent with those exposed in prior leaks, such as the Shadow Brokers’ disclosures, underscores longstanding concerns about state-sponsored cyber operations.

While these allegations remain unverified by independent sources, they reflect an intensifying narrative between global powers over cyber activities targeting critical infrastructure.

The NSA has not publicly responded to these claims.

Free Webinar: Better SOC with Interactive Malware Sandbox for Incident Response, and Threat Hunting - Register Here

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

China Claims U.S. Cyberattack Targeted Leading Encryption Company

China has accused U.S. intelligence agencies of carrying out a sophisticated cyberattack against one...

Critical FastCGI Library Flaw Exposes Embedded Devices to Code Execution

A severe vulnerability (CVE-2025-23016) in the FastCGI library-a core component of lightweight web server...

Viasat Modems Zero-Day Vulnerabilities Let Attackers Execute Remote Code

A severe zero-day vulnerability has been uncovered in multiple Viasat satellite modem models, including...

Obfuscation Techniques: A Key Weapon in the Ongoing War Between Hackers and Defenders

Obfuscation stands as a powerful weapon for attackers seeking to shield their malicious code...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

China Claims U.S. Cyberattack Targeted Leading Encryption Company

China has accused U.S. intelligence agencies of carrying out a sophisticated cyberattack against one...

Critical FastCGI Library Flaw Exposes Embedded Devices to Code Execution

A severe vulnerability (CVE-2025-23016) in the FastCGI library-a core component of lightweight web server...

Viasat Modems Zero-Day Vulnerabilities Let Attackers Execute Remote Code

A severe zero-day vulnerability has been uncovered in multiple Viasat satellite modem models, including...