{{Short description|Unit of the U.S. National Security Agency}} {{Merge from |1=Equation Group |target=Tailored Access Operations |afd=Equation Group |date =May 2026 }}{{Infobox organization | name = Tailored Access Operations | logo = File:Tailored Access Operations logo.png | logo_size = 165px | mapframe = yes | abbreviation = TAO | formation = {{circa}} 1997–2001{{ref|a}} | type = | purpose = {{hlist|Cyberespionage|Cyberwarfare}} | headquarters = Fort Meade | region_served = United States | language = English | parent_organization = S3 Data Acquisition }} {{NSA surveillance}}The '''Office of Tailored Access Operations''' ('''TAO'''), also known as ''Equation Group'' by ''Kaspersky''<ref name=":6" /> or APT-C-40 by China,<ref>{{Cite web |last=Lau |first=Lina |last2= |last3= |last4= |last5= |first5= |date=2025-02-18 |title=An inside look at NSA (Equation Group) TTPs from China’s lense |url=https://www.inversecos.com/2025/02/an-inside-look-at-nsa-equation-group.html |access-date=2026-05-30 |language=en-GB}}</ref> structured as '''S32''',<ref>{{cite news |url=https://www.washingtonpost.com/world/national-security/nsa-employee-who-worked-on-hacking-tools-at-home-pleads-guilty-to-spy-charge/2017/12/01/ec4d6738-d6d9-11e7-b62d-d9345ced896d_story.html |title=NSA employee who worked on hacking tools at home pleads guilty to spy charge |first=Ellen |last=Nakashima |date=1 December 2017 |newspaper=The Washington Post |access-date=4 December 2017 |archive-date=16 April 2021 |archive-url=https://web.archive.org/web/20210416173847/https://www.washingtonpost.com/world/national-security/nsa-employee-who-worked-on-hacking-tools-at-home-pleads-guilty-to-spy-charge/2017/12/01/ec4d6738-d6d9-11e7-b62d-d9345ced896d_story.html |url-status=live }}</ref> is an elite cyberwarfare intelligence-gathering unit of the National Security Agency (NSA).<ref>{{Cite journal|last=Loleski|first=Steven|date=2018-10-18|title=From cold to cyber warriors: the origins and expansion of NSA's Tailored Access Operations (TAO) to Shadow Brokers|url=https://dx.doi.org/10.1080/02684527.2018.1532627|journal=Intelligence and National Security|volume=34|issue=1|pages=112–128|doi=10.1080/02684527.2018.1532627|s2cid=158068358|issn=0268-4527|url-access=subscription}}</ref><ref name="Hayde2016">{{cite book|last=Hayden|first=Michael V.|url=https://books.google.com/books?id=kjepCQAAQBAJ|title=Playing to the Edge: American Intelligence in the Age of Terror|date=23 February 2016|publisher=Penguin Press|isbn=978-1594206566|access-date=1 April 2021}}</ref><ref name="fp2013">{{cite journal|last=Aid|first=Matthew M.|date=10 June 2013|title=Inside the NSA's Ultra-Secret China Hacking Group|url=https://foreignpolicy.com/2013/06/10/inside-the-nsas-ultra-secret-china-hacking-group/|journal=Foreign Policy|access-date=11 June 2013|archive-date=12 February 2022|archive-url=https://web.archive.org/web/20220212231030/https://foreignpolicy.com/2013/06/10/inside-the-nsas-ultra-secret-china-hacking-group/|url-status=live}}</ref><ref>{{cite news|last=Paterson|first=Andrea|date=30 August 2013|title=The NSA has its own team of elite hackers|newspaper=The Washington Post|url=https://www.washingtonpost.com/blogs/the-switch/wp/2013/08/29/the-nsa-has-its-own-team-of-elite-hackers/ |url-access=subscription |access-date=31 August 2013 |url-status=live |archive-url=https://web.archive.org/web/20131019200845/https://www.washingtonpost.com/blogs/the-switch/wp/2013/08/29/the-nsa-has-its-own-team-of-elite-hackers/?tid=d_pulse |archive-date= Oct 19, 2013 }}</ref>

TAO identifies, monitors, infiltrates, and gathers intelligence on computer systems being used domestically and by entities foreign to the United States.<ref name="Kingsbury">{{cite web|last=Kingsbury|first=Alex|title=The Secret History of the National Security Agency|url=https://www.usnews.com/opinion/articles/2009/06/19/the-secret-history-of-the-national-security-agency|work=U.S. News & World Report|access-date=22 May 2013|date=June 19, 2009|archive-date=1 July 2016|archive-url=https://web.archive.org/web/20160701222028/http://www.usnews.com/opinion/articles/2009/06/19/the-secret-history-of-the-national-security-agency|url-status=live}}</ref><ref>{{cite web|last1=Kingsbury|first1=Alex|title=U.S. is Striking Back in the Global Cyberwar|url=https://www.usnews.com/news/articles/2009/11/18/us-is-striking-back-in-the-global-cyberwar|access-date=22 May 2013|first2=Anna|last2=Mulrine|date=November 18, 2009|work=U.S. News & World Report|archive-date=1 July 2016|archive-url=https://web.archive.org/web/20160701222150/http://www.usnews.com/news/articles/2009/11/18/us-is-striking-back-in-the-global-cyberwar|url-status=live}}</ref><ref name="Riley">{{cite web|last=Riley|first=Michael|title=How the U.S. Government Hacks the World|url=http://www.businessweek.com/articles/2013-05-23/how-the-u-dot-s-dot-government-hacks-the-world|archive-url=https://web.archive.org/web/20130525063903/http://www.businessweek.com/articles/2013-05-23/how-the-u-dot-s-dot-government-hacks-the-world|url-status=dead|archive-date=May 25, 2013|work=Bloomberg Businessweek|access-date=23 May 2013|date=May 23, 2013}}</ref><ref name="Aid2010">{{cite book|last=Aid|first=Matthew M.|title=The Secret Sentry: The Untold History of the National Security Agency|url=https://books.google.com/books?id=x_K2rb-OShMC&pg=PA311|access-date=22 May 2013|date=8 June 2010|publisher=Bloomsbury USA|isbn=978-1-60819-096-6|page=311}}</ref>

==History==

=== Red Team === The Red Team was created in 1997, with the objective to carry out Operation Eligible Receiver, which was envisioned to see the most amount of damage a group of skilled hackers could do, during the operation the team thrashed the Cybersecurity of the Department of Defense; it was later stopped after four days following concerns of stalling the functionality of the american military. After this mission, four people, Michael V. Hayden, Bill Marshall, Bill Black and Ken Minihan seeked to make this group a permanent section within the NSA, after seeing the value it would bring to the agency. They put together a team with members of different NSA branches, but after 9/11 and a new influx of budget centered around intelligence and countermeasures.<ref name="Hayde2016" /><ref name=":2">{{Cite AV media |url=https://www.youtube.com/watch?v=fxqcwK5OMag |title=The Biggest Hacking Mystery of Our Time: Shadow Brokers |date=2025-07-03 |last=Cybernews |access-date=2026-05-28 |via=YouTube}}</ref><ref>{{Cite news |last=Sloan |first=Peter |date=2017-09-06 |title=The TAO of Cyber Warfare: Dark Territory |url=https://www.informationbytes.com/2017/09/tao-cyber-warfare-dark-territory/ |archive-url=http://web.archive.org/web/20251207024937/https://www.informationbytes.com/2017/09/tao-cyber-warfare-dark-territory/ |archive-date=2025-12-07 |access-date=2026-05-28 |work=Information Bytes |language=en-US}}</ref>

By May 11, 2008, the TAO had 60 total official members at Texas, 30 civilians and 30 in the military (10 USAF, 8 USA, 10 USN, 2 USC) with an admitted unknown number of external military agents, with only 1 contractor for the TAO-ANT. The agency had planned to grow to 270 agents by the end of Fiscal Year 2015.<ref name=":9">{{Cite news |date=2014-02-17 |title=NSA's TAO Unit Introduces Itself |url=https://www.spiegel.de/fotostrecke/nsa-s-tao-unit-introduces-itself-fotostrecke-111225.html |access-date=2026-05-31 |work=Der Spiegel |language=en |issn=2195-1349}}</ref>

Before 2013, the existence of this office was a rumour, where nobody truly knew what it was.<ref>{{Cite news |last=Kingsbury |first=Alex |date=June 19, 2009 |title=The Secret History of the National Security Agency |url=https://www.usnews.com/opinion/articles/2009/06/19/the-secret-history-of-the-national-security-agency |work=U.S. News & World Report}}</ref> By this year there were already 1.000 hackers, which were not necessarily agents of the NSA, since, because of the increase in operations, they needed personel growth, so they hired cybersecurity contractors with previous experience in the intelligence field, looking for people with obsessive attention to detail.<ref name="Hayde2016" /><ref name=":3">{{Cite AV media |url=https://www.youtube.com/watch?v=2TZWf-rDfwM |title=Ex-NSA Hacker on Being Exposed by Russian Intelligence {{!}} Jake Williams #002 |date=2025-07-10 |last=Cybernews |access-date=2026-05-28 |via=YouTube}}</ref>

===Snowden leak=== [[File:XKeyscore presentation from 2008.pdf|page=24|thumb|A reference to Tailored Access Operations in an XKeyscore slide leaked by Snowden.|left|258x258px]]{{Main|Snowden disclosures}} Edward Snowden received an offer to be part of the TAO, but declined the offer.<ref>{{Cite news |last=Kaplan |first=Fred |date=2016-09-16 |title=The Leaky Myths of Snowden |url=https://slate.com/news-and-politics/2016/09/what-snowden-gets-wrong-about-its-hero.html |access-date=2026-05-28 |work=Slate |language=en-US |issn=1091-2339}}</ref>instead working for the intelligence consulting agency Booz Allen Hamilton, that was being contracted by the NSA.

After seeing the level of surveillance by the NSA he decided to leak several files to ''The Guardian'' and ''The Washington Post'' on June 9th, 2013, where the global surveillance operations by the TAO were in the eye of the storm.<ref>{{Cite news |last=Walters |first=Joanna |date=2013-12-29 |title=NSA 'hacking unit' infiltrates computers around the world – report |url=https://www.theguardian.com/world/2013/dec/29/der-spiegel-nsa-hacking-unit-tao |access-date=2026-05-28 |work=The Guardian |language=en-GB |issn=0261-3077}}</ref>

A document leaked by Snowden describes the unit's work in the following way: "The TAO has software templates allowing it to break into commonly used hardware, including "routers, switches, and firewalls from multiple product vendor lines".<ref name="gellman-nakashima-2013">{{cite news|title=U.S. spy agencies mounted 231 offensive cyber-operations in 2011, documents show|url=https://www.washingtonpost.com/world/national-security/us-spy-agencies-mounted-231-offensive-cyber-operations-in-2011-documents-show/2013/08/30/d090a6ae-119e-11e3-b4cb-fd7ce041d814_story.html|access-date=7 September 2013|newspaper=The Washington Post|date=August 30, 2013|first1=Barton|last1=Gellman|first2=Ellen|last2=Nakashima|quote=Much more often, an implant is coded entirely in software by an NSA group called, Tailored Access Operations (TAO). As its name suggests, TAO builds attack tools that are custom-fitted to their targets. The NSA unit's software engineers would rather tap into networks than individual computers because there are usually many devices on each network. Tailored Access Operations has software templates to break into common brands and models of "routers, switches, and firewalls from multiple product vendor lines," according to one document describing its work. TAO engineers prefer to tap networks rather than isolated computers, because there are typically many devices on a single network.}}</ref>

The amount of information now available of its targets and methods was so abundant that several security companies seeked to catch and expose the TAO red handed, with only one succeeding, ''Kaspersky'', with its 2015 report "''Equation Group: Questions And Answers''", in which they named the TAO ''Equation Group'', given its proclivity to use complex algorithms to avoid detection in their methods, those being so exaggerated that it was more than obvious that a highly skilled, trained and select group of people with enough time and resources were the perpretators of these sophisticated attacks.<ref name=":12">{{Cite web |last=Goodin |first=Dan |date=2015-02-16 |title=How “omnipotent” hackers tied to NSA hid for 14 years—and were found at last |url=https://arstechnica.com/information-technology/2015/02/how-omnipotent-hackers-tied-to-the-nsa-hid-for-14-years-and-were-found-at-last/ |access-date=2026-05-28 |website=Ars Technica |language=en}}</ref><ref name=":6">{{Cite book |last=Lab |first=Kaspersky |url=https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/08064459/Equation_group_questions_and_answers.pdf |title=Equation Group: Questions and Answers |date=February 2015 |publisher=Kaspersky}}</ref>

=== The Shadow Brokers === {{Main|The Shadow Brokers}} On August 13, 2016, a user by the handle ''@shadowbrokerss'' on Pastebin, and similar usernames on Tumblr, GitHub and Twitter, made a post auctioning "Equation Group's cyberweapons" (TAO's).<ref>[https://archive.ph/20160815133924/http://pastebin.com/NDTU5kJQ#selection-373.0-376.0 Equation Group - Cyber Weapons Auction]</ref> To prove their validity, on the same post they uploaded 2 ZIP files, both of which were password protected, with only one of the keys being provided; inside of that first file were the tools JETPLOW, EPICBANANA and EXTRABANANA, these were confirmed as legitimate exploits for industrial-grade firewalls by Cisco, the password of the second file was not published, as its contents were being the center of the auction and stated as "better than Stuxnet". The public auciton had a goal of 1.000.000 bitcoin on the listed bitcoin address, where, after it was reached, the contents of the file would be made accessible to the general public.

On October 31, 2016, another ''dump'' was published, this time on ''Medium'', named "''Trick or Treat''",<ref>{{Cite web |last=theshadowbrokers |date=2016-10-31 |title=Message#5 — Trick or Treat? |url=https://medium.com/@shadowbrokerss/message-5-trick-or-treat-e43f946f93e6 |access-date=2026-05-28 |website=Medium |language=en}}</ref> where they leaked the server addresses of victims of the TAO, and the proxies that were used to do so.<ref>{{Cite web |last=Kirk |first=Jeremy |last2= |date=November 1, 2016 |title=Shadow Brokers Says 'Trick or Treat' Over Attack Tool Leak |url=https://www.bankinfosecurity.com/shadow-brokers-says-trick-or-treat-over-attack-tool-leak-a-9494 |access-date=2026-05-28 |website=www.bankinfosecurity.com |language=en}}</ref> The 352 servers showed 49 targeted countries, China, Japan and Korea being the top three, 32 addresses of the total were educational institutes in China and Taiwan.<ref name=":13">{{Cite news |date=2016-11-01 |title='Shadow Brokers' Reveal List Of Servers Hacked By The NSA; China, Japan, And Korea The Top 3 Targeted Countries; 49 Total Countries, Including: China, Japan, Germany, Korea, India, Italy, Mexico, Spain, Taiwan, & Russia - Fortuna's Corner |url=http://fortunascorner.com/2016/11/01/shadow-brokers-reveal-list-of-servers-hacked-by-the-nsa-china-japan-and-korea-the-top-3-targeted-countries-49-total-countries-including-china-japan-germany-korea-india-italy-mexico-sp/ |archive-url=https://web.archive.org/web/20170116172122/http://fortunascorner.com/2016/11/01/shadow-brokers-reveal-list-of-servers-hacked-by-the-nsa-china-japan-and-korea-the-top-3-targeted-countries-49-total-countries-including-china-japan-germany-korea-india-italy-mexico-sp/ |archive-date=2017-01-16 |access-date=2026-05-28 |work=Fortuna's Corner |language=en-US}}</ref> thumb|TAO's JETPLOW tool.|361x361px As a result of the wholesale of the exploits not being purchased on its entirety, even after lowering the price to 10.000 bitcoin, the Shadow Brokers made a post from a ZeroNet account, in the Darknet, where they sold the exploits separately with the prices ranging between 10 to 100 bitcoin each, exploits such as DANDERSPRITZ and FUZZBUNCH were listed as products, aswell as other tools that were only referenced in the files published by Snowden.<ref>{{Cite web |last=Agudo |first=Sergio |date=2016-12-15 |title=Shadow Brokers vuelve a la carga: exploits de la NSA en venta directa |url=https://www.genbeta.com/actualidad/shadow-brokers-vuelve-a-la-carga-exploits-de-la-nsa-en-venta-directa |access-date=2026-05-28 |website=Genbeta |language=es}}</ref><ref name=":1" /> These posts caused a wave of massive patches by the companies that were targeted.

On April 8, 2017, in another ''Medium'' publication titled "''Don't Forget Your Base''",<ref>{{Cite web |last=theshadowbrokers |date=2017-04-08 |title=Don’t Forget Your Base |url=https://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b1 |access-date=2026-05-28 |website=Medium |language=en}}</ref> they ranted about Trump's presidency as they felt bretayed by his changes from discourse to praxis, inside the post there was the key to the second ZIP file from their first post. It contained tools to exploit practicallly every Operating System, ranging from the most well known ones like Windows to those used only industrially and militarily, like Unix based systems. Everything free and public.<ref>{{Cite web |last=Cox |first=Joseph |date=2017-04-08 |title=They're Back: The Shadow Brokers Release More Alleged Exploits |url=https://www.vice.com/en/article/theyre-back-the-shadow-brokers-release-more-alleged-exploits/ |access-date=2026-05-28 |website=VICE |language=en-US}}</ref> A week later, on April 14, another dump was published on Steemit, named "''Lost In Translation''",<ref>{{Cite web |last=Theshadowbrokers |first= |date=2017-04-14 |title=Lost in Translation |url=https://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation |access-date=2026-05-28 |website=Steemit |language=en}}</ref> which contained tools specifically '''''tailored''''' to exploit Windows and Swift, aswell as internal NSA evidence of the tools being used in the context of the agency with the uncensored names of the authors of these ops. Among the exploits was ETERNALBLUE, which was, in essence, a master key to any single up-to-date computer that ran Windows without it being signaled in any way, and could be remotely controlled by DOUBLEPULSAR. This leak caused the creation of the ransomware attacks of WannaCry and Not_Petya.[[File:TSB tools.jpg|left|thumb|335x335px|Screenshot showing TAO's tools published in one of The Shadow Brokers' leaks.]]During this month, folowing the lack of coverage by the media,the group started to reply to the Twitter accounts of TAO employees, i.e, Jake Wiliiams, a cybersecurity researcher who at the time was a classified member of the TAO,<ref name=":3" /> they were also threatening to dox the members.<ref name=":2" /><ref name=":4">{{Cite news |last=Shane |first=Scott |last2=Perlroth |first2=Nicole |last3=Sanger |first3=David E. |date=2017-11-12 |title=Security Breach and Spilled Secrets Have Shaken the N.S.A. to Its Core |url=https://www.nytimes.com/2017/11/12/us/nsa-shadow-brokers.html |access-date=2026-05-29 |work=The New York Times |language=en-US |issn=0362-4331}}</ref>

In October they released their final statements which were rants towars the United States and their discourses. After which, they dissappeared.<ref name=":4" /><ref name=":2" />

Most of the clues and the threads that sew the story and its relation to the TAO remain unavailable to the general public. There are identifiers that point us to possible workers inside Kaspersky, who already had knowledge and possession of these tools, after looking for the signatures of TAO's tools through their antivirus,<ref>{{Cite web |date=2017-11-16 |title=Investigation Report for the September 2014 Equation malware detection incident in the US |url=https://securelist.com/investigation-report-for-the-september-2014-equation-malware-detection-incident-in-the-us/83210/ |access-date=2026-05-29 |website=Securelist |language=en-US}}</ref><ref>{{Cite news |last=Lubold |first=Gordon |last2=Harris |first2=Shane |date=2017-10-05 |title=Russian Hackers Stole NSA Data on U.S. Cyber Defense |url=https://www.wsj.com/articles/russian-hackers-stole-nsa-data-on-u-s-cyber-defense-1507222108 |access-date=2026-05-29 |work=Wall Street Journal |language=en-US |issn=0099-9660}}</ref> these allegedly were deleted by director's orders,<ref>{{Cite news |date=2017-11-16 |title=Kaspersky defends its role in NSA breach |url=https://www.bbc.com/news/technology-42009599 |access-date=2026-05-29 |language=en-GB}}</ref> but TSB's dumps match negative news cycles by western media targetting Russia and during bad state of affairs with the US. It is clear that they were not doing it for the money, because there is an entire market to sell zero-day exploits, and could go sell them there anonymously and earn a lot more than 10 bitcoin; they decided to chase the media spotlight and try to keep it on them through political and media rants. It is also speculated if it was an inside job by the TAO. In both theories, the use of broken english used in the statements is seen as performative to signal russian agency.<ref name=":2" />

This leak set them back years of work and tools.<ref name=":4" /><ref name=":3" /> It is unknown the operating ways of the office since the disruption, but in 2020 the NSA informed Microsoft of a bug in the certifications protocol which could potentially allow someone to spoof legitimate software and surveil or control the target's device.<ref>{{Cite AV media |url=https://www.youtube.com/watch?v=Y4k0Ctb4uT4 |title=NSA discovers security flaw in Microsoft Windows operating system |date=2020-01-14 |last=CBS News |access-date=2026-05-31 |via=YouTube}}</ref> This could have been perfectly be used by the TAO, so wether this disclosure is to ensure their own ways or means a shift of objectives will remain unclear until another data dump sheds light on the agency once again.

The office is currently known as Office of Computer Network Operations (OCNO)."<ref name="fp2013" />

==Organization== {{see also|Signals intelligence}}TAO is reportedly "the largest and arguably the most important component of the NSA's huge Signals Intelligence Directorate (SID),<ref>{{Cite web|url=https://www.aclu.org/files/assets/eo12333/NSA/Signals%20Intelligence%20Directorate%20%28SID%29%20Management%20Directive%20422%20United%20States%20SIGINT%20System%20Mission%20Delegation.pdf|title=FOIA #70809 (released 2014-09-19)}}</ref> consisting of more than 1,000 military and civilian computer hackers, intelligence analysts, targeting specialists, computer hardware and software designers, and electrical engineers.

TAO's headquarters are termed the ''Remote Operations Center'' (ROC) and are based at the NSA headquarters at Fort Meade, Maryland. TAO has expanded to NSA Hawaii (Wahiawa, Oahu), NSA Georgia (Fort Gordon, Georgia), NSA Texas (Joint Base San Antonio, Texas), and NSA Colorado (Buckley Space Force Base, Denver).<ref name="fp2013" />

The structure is '''approximately''' as follows:<ref>{{Cite web |last=P/K|title=NSA's organizational designations|url=https://www.electrospaces.net/2014/01/nsas-organizational-designations.html|access-date=2026-05-28|language=en}}</ref>

* S321 – Remote Operations Center (ROC): Six hundred employees gather information from around the world.<ref>{{cite web |url=http://blogs.computerworld.com/cybercrime-and-hacking/22321/secret-nsa-hackers-tao-office-have-been-pwning-china-nearly-15-years|title=Secret NSA hackers from TAO Office have been pwning China for nearly 15 years|publisher=Computerworld|date=2013-06-11|access-date=2014-01-27|url-status=dead|archive-url=https://web.archive.org/web/20140125123015/http://blogs.computerworld.com/cybercrime-and-hacking/22321/secret-nsa-hackers-tao-office-have-been-pwning-china-nearly-15-years|archive-date=2014-01-25}}</ref><ref>{{cite web|last=Rothkopf|first=David|url=https://foreignpolicy.com/articles/2013/06/10/inside_the_nsa_s_ultra_secret_china_hacking_group|title=Inside the NSA's Ultra-Secret China Hacking Group|work=Foreign Policy|access-date=2014-01-27}}</ref> ** S321? – Network Operations Center (NOC) ** S321? – Oper. Readiness Division (ORD) ** S321? – Interactive Operations Division (IOD) ** S321? – Production Operations Division (POD) ** S321? – Access Operations Division (AOD) * S322 – Advanced Network Technology (ANT) ** S3221 – (persistence sofftware) ** S3222 – (software implants) *** S32221 – ? *** S32222 – (routers, server, etc.) ** S3223 – (hardware implants) ** S3224 – ? *** S32241 – ? *** S32242 – (GSM Cellular communications) *** S32243 – (Retroreflective Radar) * S323 – Data Network Technologies Branch (DNT): Develops automated spywarethumb|DNT Logo ** S3231 – Access Division (ACD) *** S32313 – Application Vulnerabilites Branch ** S3232 – Cyber Networks Technology Division (CNT) ** S3234 – Computer Technology Division (CTD) ** S3235 – Network Technology Division (NTD) *** S32354 – STDP (FASHIONCLEFT) * S324 – Telecommunications Network Technologies Branch (TNT): Improve network and computer hacking methods<ref>{{cite news |url=http://www.tagesanzeiger.ch/ausland/amerika/Die-Speerspitze-des-amerikanischen-Hackings/story/30196342|title=Hintergrund: Die Speerspitze des amerikanischen Hackings - News Ausland: Amerika|newspaper=Tages-Anzeiger|publisher=tagesanzeiger.ch|access-date=2014-01-27|archive-date=2013-06-21|archive-url=https://web.archive.org/web/20130621034041/http://www.tagesanzeiger.ch/ausland/amerika/Die-Speerspitze-des-amerikanischen-Hackings/story/30196342|url-status=live}}</ref> * S325 – Mission Infrastructure Technologies Branch (MIT): Operates the software provided above<ref>{{Cite web |date=2013-06-11|title=Inside the NSA's Ultra-Secret Hacking Group|url=https://www.atlanticcouncil.org/blogs/natosource/inside-the-nsas-ultrasecret-hacking-group/|access-date=2023-07-27|website=Atlantic Council|language=en-US|archive-date=2020-10-21|archive-url=https://web.archive.org/web/20201021183735/https://www.atlanticcouncil.org/blogs/natosource/inside-the-nsas-ultrasecret-hacking-group/|url-status=live}}</ref> * S326 – Access Operations ** S3261 – Access and Target Development * S237 – Requirements & Targeting (TNT) * S328 – Access Technologies Operations Branch (ATO): Reportedly includes personnel seconded by the CIA and the FBI, who perform what are described as "off-net operations", which means they arrange for CIA agents to surreptitiously plant eavesdropping devices on computers and telecommunications systems overseas so that TAO's hackers may remotely access them from Fort Meade.<ref name="fp20132">{{cite journal|last=Aid|first=Matthew M.|date=10 June 2013|title=Inside the NSA's Ultra-Secret China Hacking Group|url=https://foreignpolicy.com/2013/06/10/inside-the-nsas-ultra-secret-china-hacking-group/|journal=Foreign Policy|access-date=11 June 2013|archive-date=12 February 2022|archive-url=https://web.archive.org/web/20220212231030/https://foreignpolicy.com/2013/06/10/inside-the-nsas-ultra-secret-china-hacking-group/|url-status=live}}</ref> Specially equipped submarines, currently the USS ''Jimmy Carter'',<ref>{{cite web |author=noahmax|url=http://defensetech.org/2005/02/21/jimmy-carter-super-spy/|title=Jimmy Carter: Super Spy?|publisher=Defense Tech|date=2005-02-21|access-date=2014-01-27|url-status=usurped|archive-date=2014-02-20|archive-url=https://web.archive.org/web/20140220170720/http://defensetech.org/2005/02/21/jimmy-carter-super-spy/}}</ref> are used to wiretap fibre optic cables around the globe.thumb|ATO Logo ** S3283 – Expeditionary Access Operations (EAO) ** S3285 – Persistence POLITERAIN team * S32P – TAO Program Planning Integration * S32? – Network Warfare Team (NWT) * S32X – ?

===Virtual locations=== Details<ref>https://www.eff.org/files/2014/04/09/20140312-intercept-the_nsa_and_gchqs_quantumtheory_hacking_tactics.pdf (slide 8)</ref> on a program titled QUANTUMSQUIRREL indicate NSA ability to masquerade as any routable IPv4 or IPv6 host.<ref>{{Cite journal|last=Dealer|first=Hacker|title=Dealer, Hacker, Lawyer, Spy: Modern Techniques and Legal Boundaries of Counter-cybercrime Operations|journal=The European Review of Organised Crime}}</ref> This enables an NSA computer to generate false geographical location and personal identification credentials when accessing the Internet utilizing QUANTUMSQUIRREL.<ref>{{cite web |url=https://firstlook.org/theintercept/document/2014/03/12/nsa-gchqs-quantumtheory-hacking-tactics/ |title=The NSA and GCHQ's QUANTUMTHEORY Hacking Tactics |publisher=firstlook.org |date=2014-07-16 |access-date=2014-07-16 |archive-date=2015-07-20 |archive-url=https://web.archive.org/web/20150720191342/https://firstlook.org/theintercept/document/2014/03/12/nsa-gchqs-quantumtheory-hacking-tactics/ |url-status=dead }}</ref> thumb|QUANTUMSQUIRREL illustration slide.

=== Leadership === From 2013 to 2017,<ref>{{cite news |last1=Landler |first1=Mark |date=April 10, 2018 |title=Thomas Bossert, Trump's Chief Adviser on Homeland Security, Is Forced Out |work=New York Times |url=https://www.nytimes.com/2018/04/10/us/politics/tom-bossert-trump-homeland-security.html |access-date=March 9, 2022 |archive-date=April 11, 2018 |archive-url=https://web.archive.org/web/20180411094811/https://www.nytimes.com/2018/04/10/us/politics/tom-bossert-trump-homeland-security.html |url-status=live }}</ref> the head of TAO was Rob Joyce, a longtime employee who had previously worked in the NSA's Information Assurance Directorate (IAD). In January 2016, Joyce made a rare public appearance, giving a presentation at the Usenix’s Enigma conference.<ref name=":5">{{cite web|publisher=The Register|url=https://www.theregister.com/2016/01/28/nsas_top_hacking_boss_explains_how_to_protect_your_network_from_his_minions/|title=NSA's top hacking boss explains how to protect your network from his attack squads|date=January 28, 2016|first=Iain|last=Thomson|access-date=July 27, 2023|archive-date=July 27, 2023|archive-url=https://web.archive.org/web/20230727132818/https://www.theregister.com/2016/01/28/nsas_top_hacking_boss_explains_how_to_protect_your_network_from_his_minions/|url-status=live}}</ref> On 2019 Anne Neuberger's leadership started.<ref>{{Cite news |last=Myre |first=Greg |date=2019-08-26 |title='Persistent Engagement': The Phrase Driving A More Assertive U.S. Spy Agency |url=https://www.npr.org/2019/08/26/747248636/persistent-engagement-the-phrase-driving-a-more-assertive-u-s-spy-agency |access-date=2026-05-29 |work=NPR |language=en}}</ref> In 2021, Rob Joyce went back to his leadership, only to retire on 2024.<ref>{{Cite news |title=National Security Agency Announces Retirement of Cybersecurity Director |url=https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3681065/national-security-agency-announces-retirement-of-cybersecurity-director/ |archive-url=http://web.archive.org/web/20260526022812/https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3681065/national-security-agency-announces-retirement-of-cybersecurity-director/ |archive-date=2026-05-26 |access-date=2026-05-29 |work=National Security Agency/Central Security Service |language=en-US}}</ref> Since 2026 David Imbordino has been in charge of the office.<ref>{{Cite web |title=NSA cyber directorate gets new acting leadership |url=https://therecord.media/nsa-cyber-directorate-new-acting-leadership |access-date=2026-05-29 |website=therecord.media |language=en}}</ref> However this information is not clear, since it is one of the most classified groups in the world. It is assumed that the leader is the Head of the Cibersecurity Directorate at the NSA, since that is the title that Rob Joyce held when he stated it.<ref name=":5" />

==NSA ANT catalog== {{Main|NSA ANT catalog}}

The NSA ANT catalog is a fifty-page classified document listing technology available to the United States National Security Agency (NSA) Tailored Access Operations (TAO) by the Advanced Network Technology (ANT) Division to aid in cyber surveillance. Most devices are described as already operational and available to US nationals and members of the Five Eyes alliance. According to ''Der Spiegel'', which released the catalog to the public on December 30, 2013, "The list reads like a mail-order catalog, one from which other NSA employees can order technologies from the ANT division for tapping their targets' data." The document was created in 2008.<ref name=See_NSA-ANT-catalog>This section copied from NSA ANT catalog; see there for sources</ref> Security researcher Jacob Appelbaum gave a speech at the Chaos Communications Congress in Hamburg, Germany, in which he detailed techniques that the simultaneously published ''Der Spiegel'' article he coauthored disclosed from the catalog.<ref name=See_NSA-ANT-catalog />

===QUANTUM attacks=== thumb|NSA's QUANTUMTHEORY overview slide with various codenames for specific types of attack and integration with other NSA systems

The TAO has developed an attack suite they call QUANTUM. It relies on a compromised router that duplicates internet traffic, typically HTTP requests, so that they go both to the intended target and to an NSA site (indirectly). The NSA site runs FOXACID software, which sends back exploits that load in the background in the target web browser before the intended destination has had a chance to respond, although it is unclear whether the compromised router facilitates this race on the return trip. Prior to the development of this technology, FOXACID software made spear-phishing attacks the NSA referred to as spam. If the browser is exploitable, further permanent "implants" (rootkits, etc.) are deployed in the target computer; e.g., OLYMPUSFIRE for Windows, which gives complete remote access to the infected machine.<ref>{{cite web |url=https://www.spiegel.de/netzwelt/netzpolitik/quantumtheory-wie-die-nsa-weltweit-rechner-hackt-a-941149.html |title=Quantumtheory: Wie die NSA weltweit Rechner hackt |work=Der Spiegel |date=2013-12-30 |access-date=2014-01-18 |archive-date=2014-03-23 |archive-url=https://web.archive.org/web/20140323022240/http://www.spiegel.de/netzwelt/netzpolitik/quantumtheory-wie-die-nsa-weltweit-rechner-hackt-a-941149.html |url-status=live }}</ref> This type of attack is part of the man-in-the-middle attack family, though more specifically it is called man-on-the-side attack. It is difficult to execute without controlling some of the Internet backbone.<ref name="Schneier">{{cite web |url= https://www.schneier.com/blog/archives/2013/10/how_the_nsa_att.html |first=Bruce |last=Schneier |title=How the NSA Attacks Tor/Firefox Users With QUANTUM and FOXACID |publisher=Schneier.com |date=2013-10-07 |access-date=2014-01-18}}</ref>

There are numerous services that FOXACID can exploit this way. The names of some FOXACID modules are given below:<ref name=":0" />

{{Div col|colwidth=20em}} * alibabaForumUser * doubleclickID * rocketmail * hi5 * HotmailID * LinkedIn * mailruid * msnMailToken64 * Tencent QQ * Facebook * Twitter * Yahoo * Gmail * YouTube {{Div col end}} thumb|FOXACID internal illustration. By collaboration with the British Government Communications Headquarters (GCHQ) (MUSCULAR), Google services could be attacked too, including Gmail.<ref name=":0">{{cite web |url=https://www.spiegel.de/fotostrecke/nsa-dokumente-so-knackt-der-geheimdienst-internetkonten-fotostrecke-105326-12.html |title=NSA-Dokumente: So knackt der Geheimdienst Internetkonten |work=Der Spiegel |date=2013-12-30 |access-date=2014-01-18 |archive-date=2014-01-16 |archive-url=https://web.archive.org/web/20140116065646/http://www.spiegel.de/fotostrecke/nsa-dokumente-so-knackt-der-geheimdienst-internetkonten-fotostrecke-105326-12.html |url-status=live }}</ref>[[File:NSA quantum cat.jpg|thumb|Lolcat image from an NSA presentation explaining in part the naming of the QUANTUM program|alt="I iz in ur space-time continuum, upsetting all your gravity and quantums and stuffs."|205x205px]]Finding machines that are exploitable and worth attacking is done using analytic databases such as XKeyscore.<ref>{{cite news|url=https://arstechnica.com/tech-policy/2013/08/nsas-internet-taps-can-find-systems-to-hack-track-vpns-and-word-docs/|title=NSA's Internet taps can find systems to hack, track VPNs and Word docs|author=Gallagher, Sean|date=August 1, 2013|access-date=August 8, 2013|archive-date=August 4, 2013|archive-url=https://web.archive.org/web/20130804045202/http://arstechnica.com/tech-policy/2013/08/nsas-internet-taps-can-find-systems-to-hack-track-vpns-and-word-docs/|url-status=live}}</ref> A specific method of finding vulnerable machines is interception of Windows Error Reporting traffic, which is logged into XKeyscore.<ref name="spiegel1">{{cite web |url=https://www.spiegel.de/international/world/the-nsa-uses-powerful-toolbox-in-effort-to-spy-on-global-networks-a-940969-2.html |title=Inside TAO: Targeting Mexico |work=Der Spiegel |date=2013-12-29 |access-date=2014-01-18 |archive-date=2014-01-17 |archive-url=https://web.archive.org/web/20140117212339/http://www.spiegel.de/international/world/the-nsa-uses-powerful-toolbox-in-effort-to-spy-on-global-networks-a-940969-2.html |url-status=live }}</ref>

QUANTUM attacks launched from NSA sites can be too slow for some combinations of targets and services as they essentially try to exploit a race condition, i.e. the NSA server is trying to beat the legitimate server with its response.<ref>{{cite web|author=Fotostrecke |url=https://www.spiegel.de/fotostrecke/qfire-die-vorwaertsverteidigng-der-nsa-fotostrecke-105358-14.html |title=QFIRE - die "Vorwärtsverteidigng" der NSA |work=Der Spiegel |date=2013-12-30 |access-date=2014-01-18}}</ref> As of mid-2011, the NSA was prototyping a capability codenamed QFIRE, which involved embedding their exploit-dispensing servers in virtual machines (running on VMware ESX) hosted closer to the target, in the so-called Special Collection Sites (SCS) network worldwide. The goal of QFIRE was to lower the latency of the spoofed response, thus increasing the probability of success.<ref>{{cite web |url=https://www.spiegel.de/fotostrecke/qfire-die-vorwaertsverteidigng-der-nsa-fotostrecke-105358-8.html |title=QFIRE - die "Vorwärtsverteidigng" der NSA |work=Der Spiegel |date=2013-12-30 |access-date=2014-01-18 |archive-date=2014-01-16 |archive-url=https://web.archive.org/web/20140116124439/http://www.spiegel.de/fotostrecke/qfire-die-vorwaertsverteidigng-der-nsa-fotostrecke-105358-8.html |url-status=live }}</ref>

COMMENDEER {{sic}} is used to commandeer (i.e. compromise) untargeted computer systems. The software is used as a part of QUANTUMNATION, which also includes the software vulnerability scanner VALIDATOR. The tool was first described at the 2014 Chaos Communication Congress by Jacob Appelbaum, who characterized it as tyrannical.<ref>{{cite web|url=https://www.youtube.com/watch?v=b0w36GAyZIA#t=28m34s|title="Chaos Computer Club CCC Presentation" at 28:34|website=YouTube|access-date=2014-09-09|archive-date=2014-09-09|archive-url=https://web.archive.org/web/20140909002300/https://www.youtube.com/watch?v=b0w36GAyZIA#t=28m34s|url-status=live}}</ref><ref name=pwnage>{{cite news |last=Thomson |first=Iain |url=https://www.theregister.co.uk/2013/12/31/nsa_weapons_catalogue_promises_pwnage_at_the_speed_of_light |title=How the NSA hacks PCs, phones, routers, hard disks 'at speed of light': Spy tech catalog leaks |work=The Register |location=London |date=2013-12-31 |access-date=2014-08-15}}</ref><ref>{{cite news |last=Mick |first=Jason |url=http://www.dailytech.com/Tax+and+Spy+How+the+NSA+Can+Hack+Any+American+Stores+Data+15+Years/article34010.htm |title=Tax and Spy: How the NSA Can Hack Any American, Stores Data 15 Years |publisher=DailyTech |date=2013-12-31 |access-date=2014-08-15 |url-status=dead |archive-url=https://web.archive.org/web/20140824193107/http://www.dailytech.com/Tax+and+Spy+How+the+NSA+Can+Hack+Any+American+Stores+Data+15+Years/article34010.htm |archive-date=2014-08-24 }}</ref>

QUANTUMCOOKIE is a more complex form of attack which can be used against Tor users.<ref>{{cite magazine|last=Weaver |first=Nicholas |url=https://www.wired.com/opinion/2013/11/this-is-how-the-internet-backbone-has-been-turned-into-a-weapon/ |title=Our Government Has Weaponized the Internet. Here's How They Did It |magazine=Wired |date=2013-03-28 |access-date=2014-01-18}}</ref>

==Methods, collaborations and targets== Since its inception it is clear the TAO is not a cyberattack or cyberdefence unit, rather focused on finding and storing exploits that are useful to use in a calculated way to generate internal problems or collect intel on its target instead of attacking bluntly.<ref name=":2" />

Its method relies on looking for the best and most efficent way to break into a network, securing its place and escalating privileges within the systems and map out every single piece of the target's environment; once this is considered done, the agents will infiltrate completely to know its targets routines and files until all the necessary intelligence os gathered another target is placed. The objectives are mainly nation-states or related, so that the information collected can be used by policy makers and manage the intelligence objectives.<ref name=":2" /><ref name=":6" /><ref name=":3" />

They use primarily RC5 encryption in their malware, aswell as RC6, RC4 or AES in some others, apart from hashes and cryptographic functions.<ref name=":6" />

Confirmed targets of the Tailored Access Operations unit include national and international entities such as China,<ref name="fp2013" /> Northwestern Polytechnical University,<ref>{{Cite news|url=https://www.bloomberg.com/news/articles/2022-09-05/china-accuses-us-of-repeated-hacks-on-polytechnic-university|title=China Accuses US of Repeated Hacks on Polytechnic University|newspaper=Bloomberg |date=September 5, 2022|via=www.bloomberg.com}}</ref> OPEC,<ref>{{cite web|last=Gallagher |first=Sean |url=https://arstechnica.com/information-technology/2013/11/quantum-of-pwnness-how-nsa-and-gchq-hacked-opec-and-others/ |title=Quantum of pwnness: How NSA and GCHQ hacked OPEC and others |publisher=Ars Technica |date=2013-11-12 |access-date=2014-01-18}}</ref> Mexico's Secretariat of Public Security and president, Brazil, Iran, the entire internet, Syria, Afghanistan, Russia, Pakistan, India, Korea, Japan and Mali, among many others.<ref name="spiegel1" /><ref name=":13" /> It is hard to know the entirety of its victims, aswell as their level of infiltriation and real number of enemies, since it is one of, if not, the most sophisticated ciberexploitation group currently and a self-destruct protocol in several of its malware.<ref name=":12" />

The group has also targeted global communication networks via SEA-ME-WE 4 – an optical fibre submarine communications cable system that carries telecommunications between Singapore, Malaysia, Thailand, Bangladesh, India, Sri Lanka, Pakistan, United Arab Emirates, Saudi Arabia, Sudan, Egypt, Italy, Tunisia, Algeria and France.<ref name="pwnage" /> Additionally, Försvarets radioanstalt (FRA) in Sweden gives access to fiber optic links for QUANTUM cooperation.<ref>{{cite web |url=http://www.svt.se/ug/las-dokumenten-om-sverige-fran-edward-snowden |title=Läs dokumenten om Sverige från Edward Snowden - Uppdrag Granskning |publisher=SVT.se |access-date=2014-01-18 |archive-date=2014-02-23 |archive-url=https://web.archive.org/web/20140223152908/http://www.svt.se/ug/las-dokumenten-om-sverige-fran-edward-snowden |url-status=live }}</ref><ref>{{cite web|url=http://s3.documentcloud.org/documents/894386/legal-issues-uk-regarding-sweden-and-quantum.pdf |title=What You Wanted to Know |publisher=documentcloud.org |access-date=2015-10-03}}</ref>

TAO's QUANTUM INSERT technology was passed to UK services, particularly to GCHQ's MyNOC, which used it to target Belgacom and GPRS roaming exchange (GRX) providers like the Comfone, Syniverse, and Starhome.<ref name="spiegel1" /> Belgacom, which provides services to the European Commission, the European Parliament and the European Council discovered the attack.<ref>{{cite web |url=http://www.networkworld.com/news/2013/111113-british-spies-reportedly-spoofed-linkedin-275807.html |title=British spies reportedly spoofed LinkedIn, Slashdot to target network engineers |publisher=Network World |date=2013-11-11 |access-date=2014-01-18 |url-status=dead |archive-url=https://web.archive.org/web/20140115014135/http://www.networkworld.com/news/2013/111113-british-spies-reportedly-spoofed-linkedin-275807.html |archive-date=2014-01-15 }}</ref>

In concert with the CIA and FBI, TAO is used to intercept laptops purchased online, divert them to secret warehouses where spyware and hardware is installed, and send them on to customers.<ref>{{cite web |url=http://www.spiegel.de/international/world/the-nsa-uses-powerful-toolbox-in-effort-to-spy-on-global-networks-a-940969-3.html |title=Inside TAO: The NSA's Shadow Network |work=Der Spiegel |date=2013-12-29 |access-date=2014-01-27 |archive-date=2017-04-20 |archive-url=https://web.archive.org/web/20170420112316/http://www.spiegel.de/international/world/the-nsa-uses-powerful-toolbox-in-effort-to-spy-on-global-networks-a-940969-3.html |url-status=live }}</ref> TAO has also targeted Tor and Firefox.<ref name="Schneier" />

According to a 2013 article in ''Foreign Policy'', TAO has become "increasingly accomplished at its mission, thanks in part to the high-level cooperation it secretly receives from the 'big three' American telecom companies (AT&T, Verizon and Sprint), most of the large US-based Internet service providers, and many of the top computer security software manufacturers and consulting companies."<ref name="fp" /> A 2012 TAO budget document claims that these companies, on TAO's behest, "insert vulnerabilities into commercial encryption systems, IT systems, networks and endpoint communications devices used by targets".<ref name="fp">{{Cite web |last=Aid |first=Matthew M. |date=2013-10-15 |title=The NSA's New Code Breakers |url=https://foreignpolicy.com/2013/10/15/the-nsas-new-code-breakers/ |access-date=2023-07-27 |website=Foreign Policy |language=en-US}}</ref> A number of US companies, including Cisco and Dell, have subsequently made public statements denying that they insert such back doors into their products.<ref>{{cite web |last=Farber |first=Dan |url=http://news.cnet.com/8301-1009_3-57616334-83/nsa-reportedly-planted-spyware-on-electronics-equipment/ |title=NSA reportedly planted spyware on electronics equipment &#124; Security & Privacy |publisher=CNET News |date=2013-12-29 |access-date=2014-01-18 |archive-date=2014-01-25 |archive-url=https://web.archive.org/web/20140125021735/http://news.cnet.com/8301-1009_3-57616334-83/nsa-reportedly-planted-spyware-on-electronics-equipment/ |url-status=live }}</ref> Microsoft provides advance warning to the NSA of vulnerabilities it knows about, before fixes or information about these vulnerabilities is available to the public; this enables TAO to execute so-called zero-day attacks.<ref>{{cite web |last=Schneier |first=Bruce |url=https://www.theatlantic.com/technology/archive/2013/10/how-the-nsa-thinks-about-secrecy-and-risk/280258/ |title=How the NSA Thinks About Secrecy and Risk |work=The Atlantic |date=2013-10-04 |access-date=2014-01-18 |archive-date=2014-01-10 |archive-url=https://web.archive.org/web/20140110160927/http://www.theatlantic.com/technology/archive/2013/10/how-the-nsa-thinks-about-secrecy-and-risk/280258/ |url-status=live }}</ref> A Microsoft official who declined to be identified in the press confirmed that this is indeed the case, but said that Microsoft cannot be held responsible for how the NSA uses this advance information.<ref>{{cite web |last=Riley |first=Michael |url=https://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-to-swap-data-with-thousands-of-firms.html |title=U.S. Agencies Said to Swap Data With Thousands of Firms |publisher=Bloomberg |date=2013-06-14 |access-date=2014-01-18 |archive-date=2015-01-12 |archive-url=https://web.archive.org/web/20150112075940/http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-to-swap-data-with-thousands-of-firms.html |url-status=live }}</ref>

=== Stuxnet === {{Main|Stuxnet}} Stuxnet is a computer worm discovered on June 17, 2010. Its objective were SCADA systems and is responsible of damaging Iran's Nuclear Program after being installed on a computer in the Nuclear Facility of Natanz on 2009. Made in collaboration by the United States' TAO and Israel's NCSA in Operation Olympic Games.<ref>This section was copied from the Stuxnet article, for references, see there.</ref> thumb|Illustration of how Stuxnet works.|left|306x306px

=== TREASUREMAP === {{Main|Operation Treasure Map}} "Bad guys are everywhere, good guys are somewhere" is the slogan of the operation which sought to map out the entire internet. Its objective was having the "capability for building a near real-time, interactive map of the global internet. [...] Any device, anywhere, all the time". Its plan was to monitor the "Logical Network Layer" aswell as the "Physical Network Layer" and the "Geographical Layer" under it. Mapping the traffic of the entire internet through IPv4 and IPv6 addresses, DNS, the traceroute, by country and by geographical data. It is unknown if the mission came to fruition after it being leaked among the files Snowden published on 2013.<ref>{{Cite web |title=NSA/CSS Threat Operations Center, TREASURE MAP: Bad guys are everywhere, good guys are somewhere!, undated. TS//SI//REL TO USA, FVEY {{!}} National Security Archive |url=https://nsarchive.gwu.edu/document/22626-document-01-nsa-css-threat-operations-center |access-date=2026-05-30 |website=nsarchive.gwu.edu}}</ref><ref>{{Cite web |title=Treasure Map Presentation |url=https://theintercept.com/document/treasure-map-presentation/ |access-date=2026-05-30 |website=The Intercept |language=en-US}}</ref> thumb|Operation TreasureMap description slide.|290x290px

=== Huawei infiltration === The NSA focused on collecting information on the former Chinese president Hu Jintao, the Chinese Ministry of Commerce, banks and telecom companies, but did a special effort in centring the operation on the massive Chinese technology company Huawei.<ref name=":7">{{Cite AV media |url=https://www.youtube.com/watch?v=aQNgelm7JeE |title=How the NSA Hacked Huawei: Operation Shotgiant |date=2025-07-17 |last=Cybernews |access-date=2026-05-31 |via=YouTube}}</ref>

It started on 2009, with Operation "'''''ShotGiant'''''" given the importance of Huawei in the Chinese tech sphere and its role as an enemy to the United State to form a monopoly on telecommunications; the agency infiltrated the company with a special team that obtained a list of 1.400 clients and internal documents regarding their engineering training and the use of Huawei products.<ref>{{Cite news |last=Sanger |first=David E. |last2=Perlroth |first2=Nicole |date=2014-03-22 |title=N.S.A. Breached Chinese Servers Seen as Security Threat |url=https://www.nytimes.com/2014/03/23/world/asia/nsa-breached-chinese-servers-seen-as-spy-peril.html |access-date=2026-05-31 |work=The New York Times |language=en-US |issn=0362-4331}}</ref><ref name=":8">{{Cite news |date=2014-03-22 |title=NSA Spied on Chinese Government and Networking Firm Huawei |url=https://www.spiegel.de/international/world/nsa-spied-on-chinese-government-and-networking-firm-huawei-a-960199.html |access-date=2026-05-31 |work=Der Spiegel |language=en |issn=2195-1349}}</ref> left|thumb|292x292px|"Why We Care Slide" in Operation ''ShotGiant''. Not only did they collect the archive of emails, they also acquired the source code for several products. They infiltrated along key spots in Huawei's Shenzhen network, where they could intercept all the networks traffic since January 2009. The objective was to find any form of government involvement, but the same internal documents showed that was not the case.<ref name=":8" />

The operation was made by direct orders by the White House's Intelligence Coordinator and the FBI.<ref>{{Cite web |date=2023-09-20 |title=US spy agency ‘hacked Huawei HQ’: China confirms Snowden leak |url=https://www.scmp.com/news/china/politics/article/3235174/us-spy-agency-nsa-hacked-huawei-hq-china-confirms-snowden-leak |access-date=2026-05-31 |website=South China Morning Post |language=en}}</ref><ref name=":8" />

The agency also stated in a document that "the structures of the intelligence community were not apt to handle issues that combine economic, counterintelligence, military influence and telecommunications infrastructure in just one entity."<ref name=":8" />

The information was also used to understand the functioning and structure of the enterprise, since China has been focused on scoping out US companies, thus upping the tech standard that used to be set by the US, as well as controlling the flux of internet information.<ref name=":7" /><ref name=":8" />

=== Mexico-Brazil infiltration === thumb|259x259px|Internal Operation WhiteTamale background slide. During the 2000s the office surveilled the Mexican president's email, in an operation named "'''''FlatLiquid'''''" that was labelled fulfilled on May 2010, it is reported how "TAO successfully exploited a key mail server in the Mexican Presicencia domain within the Mexican Presidential network to gain first-ever access to President Felipe Calderón's public email account." This domain was also being used by the cabinet and contained "diplomatic, economic and leadership communications which continue to provide insight into Mexico's political system and internal stability." being labelled as a "lucrative source." It is also reported by Brazil's TV Globo that the agency conducted surveillance of presidential candidate Enrique Peña Nieto and his close circle on summer 2012.<ref name=":10">{{Cite news |last=Glüsing |first=Jens |last2=Poitras |first2=Laura |last3=Rosenbach |first3=Marcel |last4=Stark |first4=Holger |date=2013-10-20 |title=NSA Hacked Email Account of Mexican President |url=https://www.spiegel.de/international/world/nsa-hacked-email-account-of-mexican-president-a-928817.html |access-date=2026-05-31 |work=Der Spiegel |language=en |issn=2195-1349}}</ref>

Several documents show how Mexico and Brazil are not interests, they are the two most important countries to surveil according to a classified list of intelligence priorities by the NSA declassified by the White House, in which the interests of each country is categorized from 1 to 5, 1 being high priority, and 5 being low: Drug trafficking was number 1, the country's leadership, economic stability, military capabilities, human rights and international commerce were labelled a 3, and counterespionage a 4. Brazil has similar spots, but their nuclear program was the top priority. The White House had its sights set on Brazil's president, Dilma Rousseff and her advisors, as well as the communications of Petrobras, to have the upper hand in the US' economic interests.<ref name=":10" />

The NSA not only spied the president and his cabinet, in a parallel operation named "'''''WhiteTamale'''''", during August 2009, the agency gained access to the emails of various high-ranking secretariats of the Public Security Secretariat, which helped them to understand the functioning of the cartels and to have "better diplomatic talking points". In one year, 260 classified reports were made so the United States government could make better diplomatic gatherings and international investments.<ref name=":10" /><ref name=":11">{{Cite web |last=Louv |first=Jason |date=2014-02-25 |title=La NSA de EU tiene una oficina en México |url=https://www.vice.com/es/article/la-nsa-de-eu-tiene-una-oficina-en-mexico/ |access-date=2026-05-31 |website=VICE |language=es}}</ref><ref name=":9" /> thumb|Operation Whitetamale Presentation. The agency determined the intrusions as a "tremendous success", where "these TAO accesses into several Mexican government agencies are just the beginning -- we intend to go much further against this important target," and the divisions were "poised for future successes." These operations were mainly made from the NSA's Headquarters in San Antonio, Texas, but there would also be secret spying stations within the US embassies in Mexico City and Brasilia.<ref name=":10" />

The operation was made in coordination with the CIA, with the name "''Special Collection Service''", where "the teams have at their disposal a wide array of methods and high-tech equipment that allow[s] them to intercept all forms of electronic communication. The NSA conducts its surveillance of telephone conversations and text messages transmitted through Mexico's cell phone network under the internal code ''''''EveningEasel'''''<nowiki/>'." Brasilia's communication interception works in a similar way.<ref name=":10" />

Given the Mexican presidential elections of 2012, they amplified the intensity and reach of their operations, because even though they were inside the president's network, they still knew little of Peña Nieto, the candidate assured to win. Washington was confused in regards to him, since he had conflicting positions, he, on the one hand, preached about changing the security policy of his predecessor, demilitarizing, ending the War against the cartels, and funding social prograns, but in the other, he personally assured the White House that there would be no changes in the policies made by Calderón.<ref name=":10" /><ref name=":11" /> thumb|Operation WhiteTamale slide. Following this the NSA approved an unusual type of espionage, a structural one, where during two weeks of early summer 2012, the specialized unit focused on monitoring every piece of information related to Peña Nieto's telecommunications and 9 of his close associates; according to a presentation dated on June 2012, they used a software called "DishFire" in which they could input every contact and related data to be automatically organised to show the most important ones, putting them in a data bank. In total, 85.489 sent and received messages were intercepted, finding a "needle in a haystack in a repeatable and efficient way".<ref name=":10" />

This revelation caused uproar and policy changes in Brazil. In Mexico, nothing of the sort, just press releases denouncing the illegality of the actions, issuing their trust on due process to those who may have abused their power and an internal investigation that led nowhere.<ref name=":10" /><ref>{{Cite web |last= |first= |date=2013-10-22 |title=El gobierno de México abre una investigación interna por espionaje de EU |url=https://expansion.mx/nacional/2013/10/22/el-gobierno-de-mexico-abre-una-investigacion-interna-por-espionaje-de-eu |access-date=2026-05-31 |website=Expansión |language=es}}</ref>

==See also== * Advanced persistent threat * Cyberwarfare in the United States * Equation Group * Magic Lantern (software) * MiniPanzer and MegaPanzer * PLA Unit 61398 * Stuxnet * Syrian Electronic Army * Unit 8200 * WARRIOR PRIDE

==References== {{reflist|30em}}

==External links== * [https://www.spiegel.de/international/world/the-nsa-uses-powerful-toolbox-in-effort-to-spy-on-global-networks-a-940969-3.html Inside TAO: Documents Reveal Top NSA Hacking Unit] * [https://www.theguardian.com/world/2013/dec/29/der-spiegel-nsa-hacking-unit-tao NSA 'hacking unit' infiltrates computers around the world – report] * [https://williamaarkin.wordpress.com/2013/09/03/nsa-tailored-access-operations/ NSA Tailored Access Operations] * [https://www.wired.com/threatlevel/2013/09/nsa-router-hacking/ NSA Laughs at PCs, Prefers Hacking Routers and Switches] * [https://www.nytimes.com/2014/01/15/us/nsa-effort-pries-open-computers-not-connected-to-internet.html N.S.A. Devises Radio Pathway Into Computers] * [https://theintercept.com/snowden-sidtoday/5987439-getting-the-ungettable-intelligence-an-interview/ Getting the 'Ungettable' Intelligence: An Interview with TAO's Teresa Shea]

{{National Security Agency}}

Category:Computer surveillance Category:Cyberwarfare in the United States Category:Hacker groups Category:National Security Agency