Tailored Access Operations
![]() | |
| Abbreviation | TAO |
|---|---|
| Formation | c. 1997–2001 |
| Purpose | |
| Headquarters | Fort Meade |
Region served | United States |
Official language | English |
Parent organization | S3 Data Acquisition |
National Security Agency surveillance |
|---|

The Office of Tailored Access Operations (TAO), structured as S32,[1] is a cyberwarfare intelligence-gathering unit of the National Security Agency (NSA).[2] It has been active since at least 1998, possibly 1997, but was not named or structured as TAO until "the last days of 2000," according to General Michael Hayden.[3][4][5]
TAO identifies, monitors, infiltrates, and gathers intelligence on computer systems being used by entities foreign to the United States.[6][7][8][9]
History
[edit]TAO is reportedly "the largest and arguably the most important component of the NSA's huge Signals Intelligence Directorate (SID),[10] consisting of more than 1,000 military and civilian computer hackers, intelligence analysts, targeting specialists, computer hardware and software designers, and electrical engineers. The office is currently known as Office of Computer Network Operations (OCNO)."[4]
Snowden leak
[edit]A document leaked by former NSA contractor Edward Snowden describing the unit's work says TAO has software templates allowing it to break into commonly used hardware, including "routers, switches, and firewalls from multiple product vendor lines".[11] TAO engineers prefer to tap networks rather than isolated computers, because there are typically many devices on a single network.[11]
Organization
[edit]TAO's headquarters are termed the Remote Operations Center (ROC) and are based at the NSA headquarters at Fort Meade, Maryland. TAO has expanded to NSA Hawaii (Wahiawa, Oahu), NSA Georgia (Fort Gordon, Georgia), NSA Texas (Joint Base San Antonio, Texas), and NSA Colorado (Buckley Space Force Base, Denver).[4]
- S321 – Remote Operations Center (ROC): six hundred employees gather information from around the world.[12][13]
- S323 – Data Network Technologies Branch (DNT): develops automated spyware
- S3231 – Access Division (ACD)
- S3232 – Cyber Networks Technology Division (CNT)
- S3233 –
- S3234 – Computer Technology Division (CTD)
- S3235 – Network Technology Division (NTD)
- Telecommunications Network Technologies Branch (TNT): improve network and computer-hacking methods[14]
- Mission Infrastructure Technologies Branch: operates the software provided above[15]
- S328 – Access Technologies Operations Branch (ATO): Reportedly includes personnel seconded by the CIA and the FBI, who perform what are described as "off-net operations", which means they arrange for CIA agents to surreptitiously plant eavesdropping devices on computers and telecommunications systems overseas so that TAO's hackers may remotely access them from Fort Meade.[4] Specially equipped submarines, currently the USS Jimmy Carter,[16] are used to wiretap fibre optic cables around the globe.
- S3283 – Expeditionary Access Operations (EAO)
- S3285 – Persistence Division
Virtual locations
[edit]Details[17] on a program titled QUANTUMSQUIRREL indicate NSA ability to masquerade as any routable IPv4 or IPv6 host.[18] This enables an NSA computer to generate false geographical location and personal identification credentials when accessing the Internet utilizing QUANTUMSQUIRREL.[19]
Leadership
[edit]From 2013 to 2017,[20] the head of TAO was Rob Joyce, a longtime employee who had previously worked in the NSA's Information Assurance Directorate (IAD). In January 2016, Joyce made a rare public appearance, giving a presentation at the Usenix’s Enigma conference.[21]
NSA ANT catalog
[edit]The NSA ANT catalog is a fifty-page classified document listing technology available to the United States National Security Agency (NSA) Tailored Access Operations (TAO) by the Advanced Network Technology (ANT) Division to aid in cyber surveillance. Most devices are described as already operational and available to US nationals and members of the Five Eyes alliance. According to Der Spiegel, which released the catalog to the public on December 30, 2013, "The list reads like a mail-order catalog, one from which other NSA employees can order technologies from the ANT division for tapping their targets' data." The document was created in 2008.[22] Security researcher Jacob Appelbaum gave a speech at the Chaos Communications Congress in Hamburg, Germany, in which he detailed techniques that the simultaneously published Der Spiegel article he coauthored disclosed from the catalog.[22]
QUANTUM attacks
[edit]

The TAO has developed an attack suite they call QUANTUM. It relies on a compromised router that duplicates internet traffic, typically HTTP requests, so that they go both to the intended target and to an NSA site (indirectly). The NSA site runs FOXACID software, which sends back exploits that load in the background in the target web browser before the intended destination has had a chance to respond, although it is unclear whether the compromised router facilitates this race on the return trip. Prior to the development of this technology, FOXACID software made spear-phishing attacks the NSA referred to as spam. If the browser is exploitable, further permanent "implants" (rootkits, etc.) are deployed in the target computer; e.g., OLYMPUSFIRE for Windows, which gives complete remote access to the infected machine.[23] This type of attack is part of the man-in-the-middle attack family, though more specifically it is called man-on-the-side attack. It is difficult to execute without controlling some of the Internet backbone.[24]
There are numerous services that FOXACID can exploit this way. The names of some FOXACID modules are given below:[25]
- alibabaForumUser
- doubleclickID
- rocketmail
- hi5
- HotmailID
- mailruid
- msnMailToken64
- Tencent QQ
- Yahoo
- Gmail
- YouTube
By collaboration with the British Government Communications Headquarters (GCHQ) (MUSCULAR), Google services could be attacked too, including Gmail.[25]
Finding machines that are exploitable and worth attacking is done using analytic databases such as XKeyscore.[26] A specific method of finding vulnerable machines is interception of Windows Error Reporting traffic, which is logged into XKeyscore.[27]
QUANTUM attacks launched from NSA sites can be too slow for some combinations of targets and services as they essentially try to exploit a race condition, i.e. the NSA server is trying to beat the legitimate server with its response.[28] As of mid-2011, the NSA was prototyping a capability codenamed QFIRE, which involved embedding their exploit-dispensing servers in virtual machines (running on VMware ESX) hosted closer to the target, in the so-called Special Collection Sites (SCS) network worldwide. The goal of QFIRE was to lower the latency of the spoofed response, thus increasing the probability of success.[29]
COMMENDEER [sic] is used to commandeer (i.e. compromise) untargeted computer systems. The software is used as a part of QUANTUMNATION, which also includes the software vulnerability scanner VALIDATOR. The tool was first described at the 2014 Chaos Communication Congress by Jacob Appelbaum, who characterized it as tyrannical.[30][31][32]
QUANTUMCOOKIE is a more complex form of attack which can be used against Tor users.[33]
Targets and collaborations
[edit]Suspected, alleged and confirmed targets of the Tailored Access Operations unit include national and international entities like China,[4] Northwestern Polytechnical University,[34] OPEC,[35] and Mexico's Secretariat of Public Security.[27]
The group has also targeted global communication networks via SEA-ME-WE 4 – an optical fibre submarine communications cable system that carries telecommunications between Singapore, Malaysia, Thailand, Bangladesh, India, Sri Lanka, Pakistan, United Arab Emirates, Saudi Arabia, Sudan, Egypt, Italy, Tunisia, Algeria and France.[31] Additionally, Försvarets radioanstalt (FRA) in Sweden gives access to fiber optic links for QUANTUM cooperation.[36][37]
TAO's QUANTUM INSERT technology was passed to UK services, particularly to GCHQ's MyNOC, which used it to target Belgacom and GPRS roaming exchange (GRX) providers like the Comfone, Syniverse, and Starhome.[27] Belgacom, which provides services to the European Commission, the European Parliament and the European Council discovered the attack.[38]
In concert with the CIA and FBI, TAO is used to intercept laptops purchased online, divert them to secret warehouses where spyware and hardware is installed, and send them on to customers.[39] TAO has also targeted Tor and Firefox.[24]
According to a 2013 article in Foreign Policy, TAO has become "increasingly accomplished at its mission, thanks in part to the high-level cooperation it secretly receives from the 'big three' American telecom companies (AT&T, Verizon and Sprint), most of the large US-based Internet service providers, and many of the top computer security software manufacturers and consulting companies."[40] A 2012 TAO budget document claims that these companies, on TAO's behest, "insert vulnerabilities into commercial encryption systems, IT systems, networks and endpoint communications devices used by targets".[40] A number of US companies, including Cisco and Dell, have subsequently made public statements denying that they insert such back doors into their products.[41] Microsoft provides advance warning to the NSA of vulnerabilities it knows about, before fixes or information about these vulnerabilities is available to the public; this enables TAO to execute so-called zero-day attacks.[42] A Microsoft official who declined to be identified in the press confirmed that this is indeed the case, but said that Microsoft cannot be held responsible for how the NSA uses this advance information.[43]
Equation Group
[edit]| Type | Advanced persistent threat |
|---|---|
| Products |
The Equation Group, also known in China as APT-C-40,[44][45] is a highly sophisticated threat actor that has been tied to the NSA and hence TAO. Kaspersky Labs describes them as one of the most sophisticated advanced persistent threats in the world and "the most advanced (...) we have seen", operating alongside the creators of Stuxnet and Flame.[46][47] Most of their targets have been in Iran, Russia, Pakistan, Afghanistan, India, Syria and Mali.[47]
The name originated from the group's extensive use of encryption. By 2015, Kaspersky documented 500 malware infections by the group in at least 42 countries, while acknowledging that the actual number could be in the tens of thousands due to its self-terminating protocol.[47][48]
In 2017, WikiLeaks published a discussion held within the CIA on how it had been possible to identify the group.[49] One commenter wrote that "the Equation Group as labeled in the report does not relate to a specific group but rather a collection of tools" used for hacking.[50]
Discovery
[edit]At the Kaspersky Security Analysts Summit held in Mexico on February 16, 2015, Kaspersky Lab announced its discovery of the Equation Group. According to Kaspersky Lab's report, the group has been active since at least 2001, with more than 60 actors.[51] The malware used in their operations, dubbed EquationDrug and GrayFish, was found to be capable of reprogramming hard disk drive firmware.[46] Because of the advanced techniques involved and high degree of covertness, the group is suspected of ties to the NSA, but Kaspersky Lab has not identified the actors behind the group.
Alleged links to Stuxnet and the NSA
[edit]In 2015 Kaspersky's research findings on the Equation Group noted that its loader, "GrayFish", had similarities to a previously discovered loader, "Gauss",[repository] from another attack series, and separately noted that the Equation Group used two zero-day attacks later used in Stuxnet; the researchers concluded that "the similar type of usage of both exploits together in different computer worms, at around the same time, indicates that the EQUATION group and the Stuxnet developers are either the same or working closely together".[52]: 13
Firmware
[edit]They also identified that the platform had at times been spread by interdiction (interception of legitimate CDs sent by a scientific conference organizer by mail),[52]: 15 and that the platform had the "unprecedented" ability to infect and be transmitted through the hard drive firmware of several major hard drive manufacturers, and create and use hidden disk areas and virtual disk systems for its purposes, a feat which would require access to the manufacturer's source code to achieve,[52]: 16–18 and that the tool was designed for surgical precision, going so far as to exclude specific countries by IP and allow targeting of specific usernames on discussion forums.[52]: 23–26
Codewords and timestamps
[edit]The NSA codewords "STRAITACID" and "STRAITSHOOTER" have been found inside the malware. In addition, timestamps in the malware seem to indicate that the programmers worked overwhelmingly Monday–Friday in what would correspond to an 08:00–17:00 (8:00 AM - 5:00 PM) workday in an Eastern United States time zone.[53]
The LNK exploit
[edit]Kaspersky's global research and analysis team, otherwise known as GReAT, claimed to have found a piece of malware that contained Stuxnet's "privLib" in 2008.[54] Specifically it contained the LNK exploit found in Stuxnet in 2010. Fanny is classified as a worm that affects certain Windows operating systems and attempts to spread laterally via network connection or USB storage.[repository] Kaspersky stated that they suspect that the Equation Group has been around longer than Stuxnet, based on the recorded compile time of Fanny.[46]
Link to IRATEMONK
[edit]
F-Secure claims that the Equation Group's malicious hard drive firmware is TAO program "IRATEMONK",[55] one of the items from the NSA ANT catalog exposed in a 2013 Der Spiegel article. IRATEMONK provides the attacker with the ability to have their software application persistently installed on desktop and laptop computers, despite the disk being formatted, its data erased or the operating system re-installed. It infects the hard drive firmware, which in turn adds instructions to the disk's master boot record that causes the software to install each time the computer is booted up.[56] It is capable of infecting certain hard drives from Seagate, Maxtor, Western Digital, Samsung,[56] IBM, Micron Technology and Toshiba.[46]
2016 breach of the Equation Group
[edit]In August 2016, a hacking group calling itself "The Shadow Brokers" announced that it had stolen malware code from the Equation Group.[57] Kaspersky Lab noticed similarities between the stolen code and earlier known code from the Equation Group malware samples it had in its possession including quirks unique to the Equation Group's way of implementing the RC6 encryption algorithm, and therefore concluded that this announcement is legitimate.[58] The most recent dates of the stolen files are from June 2013, thus prompting Edward Snowden to speculate that a likely lockdown resulting from his leak of the NSA's global and domestic surveillance efforts stopped The Shadow Brokers' breach of the Equation Group. Exploits against Cisco Adaptive Security Appliances and Fortinet's firewalls were featured in some malware samples released by The Shadow Brokers.[59] EXTRABACON, a Simple Network Management Protocol exploit against Cisco's ASA software, was a zero-day exploit as of the time of the announcement.[59] Juniper also confirmed that its NetScreen firewalls were affected.[60] The EternalBlue exploit was used to conduct the damaging worldwide WannaCry ransomware attack.
2022 alleged Northwestern Polytechnical University hack
[edit]In 2022, an investigation conducted by the Chinese National Computer Virus Emergency Response Center (CVERC) and computer security firm Qihoo 360 attributed an extensive cyber attack on China's Northwestern Polytechnical University (NPU) to the NSA's Office of Tailored Access Operations (TAO),[45][61] compromising tens of thousands of network devices in China over the years and exfiltrating over 140GB of high-value data.[61]
The CVERC alleged that the attack involved a "longer period of preparatory work", setting up an anonymized attack infrastructure by leveraging SunOS zero-days to compromise institutions with large network traffic in 17 countries, 70% of which neighbored China. Those compromised machines were used as "springboards" to gain access into the NPU by leveraging man-in-the-middle and spear-phishing attacks against students and teachers. The report also claims the NSA had used two cover companies, "Jackson Smith Consultants" and "Mueller Diversified Systems", to purchase US-based IP addresses that would later be used in the FOXACID platform to launch attacks on the Northwestern.[45][61]
CVERC and 360 identified 41 different tools and malware samples during forensic analysis, many of which were similar or consistent with TAO weapons exposed in the Shadow Brokers leak. Investigators also attributed the attack to the Equation Group due to a mixture of attack times, human errors and American English keyboard inputs. Forensic analysis on one of the tools, called "NOPEN", which required human input, indicated that 98% of all attacks occurred during U.S. working hours, with no cyber-attacks being logged during weekends or during American holidays such as Memorial Day and Independence Day.[45]
See also
[edit]References
[edit]- ↑ Nakashima, Ellen (1 December 2017). "NSA employee who worked on hacking tools at home pleads guilty to spy charge". The Washington Post. Archived from the original on 16 April 2021. Retrieved 4 December 2017.
- ↑ Loleski, Steven (2018-10-18). "From cold to cyber warriors: the origins and expansion of NSA's Tailored Access Operations (TAO) to Shadow Brokers". Intelligence and National Security. 34 (1): 112–128. doi:10.1080/02684527.2018.1532627. ISSN 0268-4527. S2CID 158068358.
- ↑ Hayden, Michael V. (23 February 2016). Playing to the Edge: American Intelligence in the Age of Terror. Penguin Press. ISBN 978-1594206566. Retrieved 1 April 2021.
- 1 2 3 4 5 Aid, Matthew M. (10 June 2013). "Inside the NSA's Ultra-Secret China Hacking Group". Foreign Policy. Archived from the original on 12 February 2022. Retrieved 11 June 2013.
- ↑ Paterson, Andrea (30 August 2013). "The NSA has its own team of elite hackers". The Washington Post. Archived from the original on Oct 19, 2013. Retrieved 31 August 2013.
- ↑ Kingsbury, Alex (June 19, 2009). "The Secret History of the National Security Agency". U.S. News & World Report. Archived from the original on 1 July 2016. Retrieved 22 May 2013.
- ↑ Kingsbury, Alex; Mulrine, Anna (November 18, 2009). "U.S. is Striking Back in the Global Cyberwar". U.S. News & World Report. Archived from the original on 1 July 2016. Retrieved 22 May 2013.
- ↑ Riley, Michael (May 23, 2013). "How the U.S. Government Hacks the World". Bloomberg Businessweek. Archived from the original on May 25, 2013. Retrieved 23 May 2013.
- ↑ Aid, Matthew M. (8 June 2010). The Secret Sentry: The Untold History of the National Security Agency. Bloomsbury USA. p. 311. ISBN 978-1-60819-096-6. Retrieved 22 May 2013.
- ↑ "FOIA #70809 (released 2014-09-19)" (PDF).
- 1 2 Gellman, Barton; Nakashima, Ellen (August 30, 2013). "U.S. spy agencies mounted 231 offensive cyber-operations in 2011, documents show". The Washington Post. Retrieved 7 September 2013.
Much more often, an implant is coded entirely in software by an NSA group called, Tailored Access Operations (TAO). As its name suggests, TAO builds attack tools that are custom-fitted to their targets. The NSA unit's software engineers would rather tap into networks than individual computers because there are usually many devices on each network. Tailored Access Operations has software templates to break into common brands and models of "routers, switches, and firewalls from multiple product vendor lines," according to one document describing its work.
{{cite news}}: CS1 maint: deprecated archival service (link) - ↑ "Secret NSA hackers from TAO Office have been pwning China for nearly 15 years". Computerworld. 2013-06-11. Archived from the original on 2014-01-25. Retrieved 2014-01-27.
- ↑ Rothkopf, David. "Inside the NSA's Ultra-Secret China Hacking Group". Foreign Policy. Retrieved 2014-01-27.
- ↑ "Hintergrund: Die Speerspitze des amerikanischen Hackings - News Ausland: Amerika". Tages-Anzeiger. tagesanzeiger.ch. Archived from the original on 2013-06-21. Retrieved 2014-01-27.
- ↑ "Inside the NSA's Ultra-Secret Hacking Group". Atlantic Council. 2013-06-11. Archived from the original on 2020-10-21. Retrieved 2023-07-27.
- ↑ noahmax (2005-02-21). "Jimmy Carter: Super Spy?". Defense Tech. Archived from the original on 2014-02-20. Retrieved 2014-01-27.
- ↑ https://www.eff.org/files/2014/04/09/20140312-intercept-the_nsa_and_gchqs_quantumtheory_hacking_tactics.pdf (slide 8)
- ↑ Dealer, Hacker. "Dealer, Hacker, Lawyer, Spy: Modern Techniques and Legal Boundaries of Counter-cybercrime Operations". The European Review of Organised Crime.
- ↑ "The NSA and GCHQ's QUANTUMTHEORY Hacking Tactics". firstlook.org. 2014-07-16. Archived from the original on 2015-07-20. Retrieved 2014-07-16.
- ↑ Landler, Mark (April 10, 2018). "Thomas Bossert, Trump's Chief Adviser on Homeland Security, Is Forced Out". New York Times. Archived from the original on April 11, 2018. Retrieved March 9, 2022.
- ↑ Thomson, Iain (January 28, 2016). "NSA's top hacking boss explains how to protect your network from his attack squads". The Register. Archived from the original on July 27, 2023. Retrieved July 27, 2023.
- 1 2 This section copied from NSA ANT catalog; see there for sources
- ↑ "Quantumtheory: Wie die NSA weltweit Rechner hackt". Der Spiegel. 2013-12-30. Archived from the original on 2014-03-23. Retrieved 2014-01-18.
- 1 2 Schneier, Bruce (2013-10-07). "How the NSA Attacks Tor/Firefox Users With QUANTUM and FOXACID". Schneier.com. Retrieved 2014-01-18.
- 1 2 "NSA-Dokumente: So knackt der Geheimdienst Internetkonten". Der Spiegel. 2013-12-30. Archived from the original on 2014-01-16. Retrieved 2014-01-18.
- ↑ Gallagher, Sean (August 1, 2013). "NSA's Internet taps can find systems to hack, track VPNs and Word docs". Archived from the original on August 4, 2013. Retrieved August 8, 2013.
- 1 2 3 "Inside TAO: Targeting Mexico". Der Spiegel. 2013-12-29. Archived from the original on 2014-01-17. Retrieved 2014-01-18.
- ↑ Fotostrecke (2013-12-30). "QFIRE - die "Vorwärtsverteidigng" der NSA". Der Spiegel. Retrieved 2014-01-18.
- ↑ "QFIRE - die "Vorwärtsverteidigng" der NSA". Der Spiegel. 2013-12-30. Archived from the original on 2014-01-16. Retrieved 2014-01-18.
- ↑ ""Chaos Computer Club CCC Presentation" at 28:34". YouTube. Archived from the original on 2014-09-09. Retrieved 2014-09-09.
- 1 2 Thomson, Iain (2013-12-31). "How the NSA hacks PCs, phones, routers, hard disks 'at speed of light': Spy tech catalog leaks". The Register. London. Retrieved 2014-08-15.
- ↑ Mick, Jason (2013-12-31). "Tax and Spy: How the NSA Can Hack Any American, Stores Data 15 Years". DailyTech. Archived from the original on 2014-08-24. Retrieved 2014-08-15.
- ↑ Weaver, Nicholas (2013-03-28). "Our Government Has Weaponized the Internet. Here's How They Did It". Wired. Retrieved 2014-01-18.
- ↑ "China Accuses US of Repeated Hacks on Polytechnic University". Bloomberg. September 5, 2022 – via www.bloomberg.com.
- ↑ Gallagher, Sean (2013-11-12). "Quantum of pwnness: How NSA and GCHQ hacked OPEC and others". Ars Technica. Retrieved 2014-01-18.
- ↑ "Läs dokumenten om Sverige från Edward Snowden - Uppdrag Granskning". SVT.se. Archived from the original on 2014-02-23. Retrieved 2014-01-18.
- ↑ "What You Wanted to Know" (PDF). documentcloud.org. Retrieved 2015-10-03.
- ↑ "British spies reportedly spoofed LinkedIn, Slashdot to target network engineers". Network World. 2013-11-11. Archived from the original on 2014-01-15. Retrieved 2014-01-18.
- ↑ "Inside TAO: The NSA's Shadow Network". Der Spiegel. 2013-12-29. Archived from the original on 2017-04-20. Retrieved 2014-01-27.
- 1 2 Aid, Matthew M. (2013-10-15). "The NSA's New Code Breakers". Foreign Policy. Retrieved 2023-07-27.
- ↑ Farber, Dan (2013-12-29). "NSA reportedly planted spyware on electronics equipment | Security & Privacy". CNET News. Archived from the original on 2014-01-25. Retrieved 2014-01-18.
- ↑ Schneier, Bruce (2013-10-04). "How the NSA Thinks About Secrecy and Risk". The Atlantic. Archived from the original on 2014-01-10. Retrieved 2014-01-18.
- ↑ Riley, Michael (2013-06-14). "U.S. Agencies Said to Swap Data With Thousands of Firms". Bloomberg. Archived from the original on 2015-01-12. Retrieved 2014-01-18.
- ↑ Ionut Arghire (21 February 2025). "How China Pinned University Cyberattacks on NSA Hackers". Security Week. Retrieved 10 May 2025.
- 1 2 3 4 Lina Lau (18 February 2025). "An inside look at NSA (Equation Group) TTPs from China's lense". Retrieved 10 May 2025.
- 1 2 3 4 GReAT (February 16, 2015). "Equation: The Death Star of Malware Galaxy". Securelist.com. Kaspersky Lab. Retrieved August 16, 2016.
SecureList, Costin Raiu (director of Kaspersky Lab's global research and analysis team): "It seems to me Equation Group are the ones with the coolest toys. Every now and then they share them with the Stuxnet group and the Flame group, but they are originally available only to the Equation Group people. Equation Group are definitely the masters, and they are giving the others, maybe, bread crumbs. From time to time they are giving them some goodies to integrate into Stuxnet and Flame."
- 1 2 3 Goodin, Dan (February 16, 2015). "How "omnipotent" hackers tied to NSA hid for 14 years—and were found at last". Ars Technica. Retrieved November 24, 2015.
- ↑ Kirk, Jeremy (17 February 2015). "Destroying your hard drive is the only way to stop this super-advanced malware". PCWorld. Retrieved November 24, 2015.
- ↑ Goodin, Dan (7 March 2017). "After NSA hacking exposé, CIA staffers asked where Equation Group went wrong". Ars Technica. Retrieved 21 March 2017.
- ↑ "What did Equation do wrong, and how can we avoid doing the same?". Vault 7. WikiLeaks. Retrieved 21 March 2017.
- ↑ "Equation Group: The Crown Creator of Cyber-Espionage". Kaspersky Lab. February 16, 2015. Retrieved November 24, 2015.
- 1 2 3 4 "Equation Group: Questions and Answers (Version: 1.5)" (PDF). Kaspersky Lab. February 2015. Archived from the original (PDF) on February 17, 2015. Retrieved November 24, 2015.
- ↑ Goodin, Dan (March 11, 2015). "New smoking gun further ties NSA to omnipotent "Equation Group" hackers". Ars Technica. Retrieved November 24, 2015.
- ↑ "A Fanny Equation: "I am your father, Stuxnet"". Kaspersky Lab. February 17, 2015. Retrieved November 24, 2015.
- ↑ "The Equation Group Equals NSA / IRATEMONK". F-Secure Weblog : News from the Lab. February 17, 2015. Retrieved November 24, 2015.
- 1 2 Schneier, Bruce (January 31, 2014). "IRATEMONK: NSA Exploit of the Day". Schneier on Security. Retrieved November 24, 2015.
- ↑ Goodin, Dan (August 15, 2016). "Group claims to hack NSA-tied hackers, posts exploits as proof". Ars Technica. Retrieved August 19, 2016.
- ↑ Goodin, Dan (August 16, 2016). "Confirmed: hacking tool leak came from "omnipotent" NSA-tied group". Ars Technica. Retrieved August 19, 2016.
- 1 2 Thomson, Iain (August 17, 2016). "Cisco confirms two of the Shadow Brokers' 'NSA' vulns are real". The Register. Retrieved August 19, 2016.
- ↑ Pauli, Darren (August 24, 2016). "Equation Group exploit hits newer Cisco ASA, Juniper Netscreen". The Register. Retrieved August 30, 2016.
- 1 2 3 "西北工业大学遭美国NSA网络攻击事件调查报告(之一)" (in Chinese). National Computer Virus Emergency Response Center. 5 September 2022. Retrieved 11 May 2025.
External links
[edit]- Inside TAO: Documents Reveal Top NSA Hacking Unit
- NSA 'hacking unit' infiltrates computers around the world – report
- NSA Tailored Access Operations
- NSA Laughs at PCs, Prefers Hacking Routers and Switches
- N.S.A. Devises Radio Pathway Into Computers
- Getting the 'Ungettable' Intelligence: An Interview with TAO's Teresa Shea
- Equation Group: Questions and Answers by Kaspersky Lab, Version: 1.5, February 2015
- A Fanny Equation: "I am your father, Stuxnet" by Kaspersky Lab, February 2015
- fanny.bmp source - at GitHub, November 30, 2020
- Technical Write-up - at GitHub, February 10, 2021
