The NSA did it! Source of cyber attack on Chinese universities identified

Today (5th), National Computer Virus Emergency Response Center and 360 company respectively released investigation reports on Northwestern Polytechnical University suffering from overseas network attacks. The Specific Intrusion Operations Office (TAO) has carried out tens of thousands of malicious cyber attacks on network targets in my country over the years, controlled relevant network equipment, and was suspected of stealing high-value data.

In April this year, the Xi'an Public Security Bureau received a report of a cyber attack, and the information system of Northwestern Polytechnical University found traces of cyber attack.

Song Qiang, Deputy Director of the Information Construction and Management Office and Director of the Information Center of Northwestern Polytechnical University: Recently, our school system discovered a Trojan horse program, which attempted to illegally obtain permissions, which caused major risks to the normal work and life order of our school. Our school attaches great importance to network security and has reported the situation to the police.

Xi'an public security organs attached great importance to this, and immediately organized police force and network security technical experts to set up a joint task force to investigate the case. The National Computer Virus Emergency Response Center and 360 Company jointly formed a technical team and participated in the technical analysis of the case throughout the process. The technical team has successively extracted a variety of Trojan horse samples from multiple information systems and Internet terminals of Northwestern Polytechnical University, comprehensively used existing domestic data resources and analysis methods, and obtained the full support of partners from some countries in Europe and South Asia. The overall overview, technical characteristics, attack weapons, attack paths and attack sources of the relevant attack events have been fully restored. referred to as TAO).

This investigation also found that in recent years, the Specific Intrusion Operations Office (TAO) under the US National Security Agency (NSA) has carried out tens of thousands of malicious cyber attacks on network targets in China, controlling tens of thousands of networks Equipment, including: network servers, Internet terminals, network switches, telephone switches, routers, firewalls, etc., stole over 140GB of high-value data. After complex technical analysis and source tracing, the

joint technical team restored the process of Northwestern Polytechnical University's cyber attack and the stolen files, and mastered the specific intrusion operations office (TAO) under the US National Security Agency (NSA) on China's information network. Evidence pertaining to cyberattacks and data theft involving 13 individuals who directly launched cyberattacks against China in the U.S., and contracts signed by the U.S. National Security Agency (NSA) with U.S. telecommunications operators to create a cyberattack environment through cover companies More than 60 copies and more than 170 electronic documents.

Jin Qi, Deputy Director of Beilin Branch of Xi'an Public Security Bureau: At present, the joint task force has reported the relevant investigation results to the relevant state departments.

source | CCTV news

editor | Zhao Zeqin Xia Hong

proofreading | Zhang Yongqiong Wu Ziqi (internship)

reviewer | Liu Ying

Collection quickly! All 87 posters exclusive to artisans from great powers have been released!