Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a cyberattack on Northwestern Polytechnical University, a prominent Chinese institution specializing in aerospace and defense research.
The allegations, published by organizations such as Qihoo 360 and the National Computer Virus Emergency Response Center (CVERC), claim that the NSA’s Tailored Access Operations (TAO) unit, referred to as “APT-C-40” by Chinese sources, conducted the attack in 2022 using advanced malware and exploitation frameworks.
The university disclosed the breach in June 2022, reporting phishing emails targeting staff and students as the initial vector.
According to Chinese investigators, the NSA allegedly deployed over 40 malware strains and leveraged zero-day vulnerabilities to gain access.
Tools such as NOPEN and SECONDDATE, previously linked to the NSA in leaks, were reportedly used to establish persistence and intercept network traffic.
Chinese cybersecurity firms attribute the attack to the NSA based on forensic analysis and operational patterns.
Key indicators include:
Investigators also identified IP addresses allegedly purchased through cover companies like “Jackson Smith Consultants” to anonymize NSA activities.
These IPs were used to control jump servers and proxy nodes across 17 countries.
The alleged attack unfolded in multiple stages:
China’s claims highlight a growing focus on edge devices like routers and firewalls as targets for cyber espionage due to their limited logging capabilities.
The alleged use of tools consistent with those exposed in prior leaks, such as the Shadow Brokers’ disclosures, underscores longstanding concerns about state-sponsored cyber operations.
While these allegations remain unverified by independent sources, they reflect an intensifying narrative between global powers over cyber activities targeting critical infrastructure.
The NSA has not publicly responded to these claims.
Free Webinar: Better SOC with Interactive Malware Sandbox for Incident Response, and Threat Hunting - Register Here
Whether you operate a small business or run a large enterprise, you rely on third-party…
Security researchers have revealed that two critical use-after-free (UAF) vulnerabilities in Google Chrome’s Browser process…
An alarming data leak involving Microsoft Defender XDR has exposed more than 1,700 sensitive documents…
Security researchers have uncovered a new and sophisticated threat to Microsoft Office 365 users: a…
A sophisticated cyberattack campaign has surfaced, targeting poorly managed Microsoft SQL (MS-SQL) servers to deploy…
The Zscaler ThreatLabz 2025 Phishing Report unveils the alarming sophistication of modern phishing attacks, driven…