Cyber Security News

NSA Allegedly Hacked Northwestern Polytechnical University, China Claims

Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a cyberattack on Northwestern Polytechnical University, a prominent Chinese institution specializing in aerospace and defense research.

The allegations, published by organizations such as Qihoo 360 and the National Computer Virus Emergency Response Center (CVERC), claim that the NSA’s Tailored Access Operations (TAO) unit, referred to as “APT-C-40” by Chinese sources, conducted the attack in 2022 using advanced malware and exploitation frameworks.

Polytechnical UniversityPolytechnical University
Qihoo 360 – Diagram

The university disclosed the breach in June 2022, reporting phishing emails targeting staff and students as the initial vector.

According to Chinese investigators, the NSA allegedly deployed over 40 malware strains and leveraged zero-day vulnerabilities to gain access.

Tools such as NOPEN and SECONDDATE, previously linked to the NSA in leaks, were reportedly used to establish persistence and intercept network traffic.

Attribution and Evidence

Chinese cybersecurity firms attribute the attack to the NSA based on forensic analysis and operational patterns.

Key indicators include:

  • Operational Timing: Nearly all attack activity occurred during U.S. business hours (9 AM–4 PM EST), with no activity on weekends or U.S. holidays such as Memorial Day and Independence Day.
  • Language and System Configuration: Attackers used American English keyboard settings and operating systems configured in English.
  • Human Error: A misconfigured script revealed directory paths linked to TAO’s tools, including a Linux directory associated with NSA operations.

Investigators also identified IP addresses allegedly purchased through cover companies like “Jackson Smith Consultants” to anonymize NSA activities.

These IPs were used to control jump servers and proxy nodes across 17 countries.

Attack Methodology

The alleged attack unfolded in multiple stages:

  1. Initial Access: The attackers reportedly exploited zero-day vulnerabilities in neighboring countries’ servers to establish a foothold before targeting the university through phishing emails embedded with malware.
  2. Network Penetration: Tools such as ISLAND and FOXACID were used to compromise external servers and redirect user traffic for browser exploitation.
  3. Persistence: Malware like NOPEN allowed long-term access, while SECONDDATE enabled traffic interception on network devices.
  4. Lateral Movement: Using stolen credentials, attackers accessed internal systems, including firewalls and telecom equipment, to monitor sensitive data.
  5. Data Exfiltration: Proprietary tools were employed to encrypt and transmit stolen research data via proxy servers, masking the operation’s origin.

China’s claims highlight a growing focus on edge devices like routers and firewalls as targets for cyber espionage due to their limited logging capabilities.

The alleged use of tools consistent with those exposed in prior leaks, such as the Shadow Brokers’ disclosures, underscores longstanding concerns about state-sponsored cyber operations.

While these allegations remain unverified by independent sources, they reflect an intensifying narrative between global powers over cyber activities targeting critical infrastructure.

The NSA has not publicly responded to these claims.

Free Webinar: Better SOC with Interactive Malware Sandbox for Incident Response, and Threat Hunting - Register Here

Aman Mishra

Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Recent Posts

7 Best Third-Party Risk Management Software in 2025

Whether you operate a small business or run a large enterprise, you rely on third-party…

9 minutes ago

Chrome UAF Process Vulnerabilities Actively Exploited

Security researchers have revealed that two critical use-after-free (UAF) vulnerabilities in Google Chrome’s Browser process…

2 hours ago

Microsoft Defender XDR False Positive Leaked Massive 1,700+ Sensitive Documents to Publish

An alarming data leak involving Microsoft Defender XDR has exposed more than 1,700 sensitive documents…

3 hours ago

‘SessionShark’ – A New Toolkit Bypasses Microsoft Office 365 MFA Security

Security researchers have uncovered a new and sophisticated threat to Microsoft Office 365 users: a…

4 hours ago

Hackers Exploit MS-SQL Servers to Deploy Ammyy Admin for Remote Access

A sophisticated cyberattack campaign has surfaced, targeting poorly managed Microsoft SQL (MS-SQL) servers to deploy…

5 hours ago

New Report Reveals How AI is Rapidly Enhancing Phishing Attack Precision

The Zscaler ThreatLabz 2025 Phishing Report unveils the alarming sophistication of modern phishing attacks, driven…

5 hours ago