Friday, February 21, 2025
HomeCyber AttackNSA Allegedly Hacked Northwestern Polytechnical University, China Claims

NSA Allegedly Hacked Northwestern Polytechnical University, China Claims

Published on

SIEM as a Service

Follow Us on Google News

Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a cyberattack on Northwestern Polytechnical University, a prominent Chinese institution specializing in aerospace and defense research.

The allegations, published by organizations such as Qihoo 360 and the National Computer Virus Emergency Response Center (CVERC), claim that the NSA’s Tailored Access Operations (TAO) unit, referred to as “APT-C-40” by Chinese sources, conducted the attack in 2022 using advanced malware and exploitation frameworks.

Polytechnical University
Qihoo 360 – Diagram

The university disclosed the breach in June 2022, reporting phishing emails targeting staff and students as the initial vector.

According to Chinese investigators, the NSA allegedly deployed over 40 malware strains and leveraged zero-day vulnerabilities to gain access.

Tools such as NOPEN and SECONDDATE, previously linked to the NSA in leaks, were reportedly used to establish persistence and intercept network traffic.

Attribution and Evidence

Chinese cybersecurity firms attribute the attack to the NSA based on forensic analysis and operational patterns.

Key indicators include:

  • Operational Timing: Nearly all attack activity occurred during U.S. business hours (9 AM–4 PM EST), with no activity on weekends or U.S. holidays such as Memorial Day and Independence Day.
  • Language and System Configuration: Attackers used American English keyboard settings and operating systems configured in English.
  • Human Error: A misconfigured script revealed directory paths linked to TAO’s tools, including a Linux directory associated with NSA operations.

Investigators also identified IP addresses allegedly purchased through cover companies like “Jackson Smith Consultants” to anonymize NSA activities.

These IPs were used to control jump servers and proxy nodes across 17 countries.

Attack Methodology

The alleged attack unfolded in multiple stages:

  1. Initial Access: The attackers reportedly exploited zero-day vulnerabilities in neighboring countries’ servers to establish a foothold before targeting the university through phishing emails embedded with malware.
  2. Network Penetration: Tools such as ISLAND and FOXACID were used to compromise external servers and redirect user traffic for browser exploitation.
  3. Persistence: Malware like NOPEN allowed long-term access, while SECONDDATE enabled traffic interception on network devices.
  4. Lateral Movement: Using stolen credentials, attackers accessed internal systems, including firewalls and telecom equipment, to monitor sensitive data.
  5. Data Exfiltration: Proprietary tools were employed to encrypt and transmit stolen research data via proxy servers, masking the operation’s origin.

China’s claims highlight a growing focus on edge devices like routers and firewalls as targets for cyber espionage due to their limited logging capabilities.

The alleged use of tools consistent with those exposed in prior leaks, such as the Shadow Brokers’ disclosures, underscores longstanding concerns about state-sponsored cyber operations.

While these allegations remain unverified by independent sources, they reflect an intensifying narrative between global powers over cyber activities targeting critical infrastructure.

The NSA has not publicly responded to these claims.

Free Webinar: Better SOC with Interactive Malware Sandbox for Incident Response, and Threat Hunting - Register Here

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix

In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer...

Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key

A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing...

ACRStealer Malware Abuses Google Docs as C2 to Steal Login Credentials

The ACRStealer malware, an infostealer disguised as illegal software such as cracks and keygens,...

Nagios XI Flaw Exposes User Details and Emails to Unauthenticated Attackers”

A security vulnerability in Nagios XI 2024R1.2.2, tracked as CVE-2024-54961, has been disclosed, allowing...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix

In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer...

Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key

A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing...

ACRStealer Malware Abuses Google Docs as C2 to Steal Login Credentials

The ACRStealer malware, an infostealer disguised as illegal software such as cracks and keygens,...