




During the investigation of the cyberattack against Northwestern Polytechnical University (NPU), a leading Chinese aviation university, China has successfully extracted multiple samples of the spyware named SecondDate, and with the collaborative efforts of partners in various countries, the real identity of the US' National Security Agency (NSA) personnel responsible for launching the cyberattack on NPU has been successfully identified, Global Times learnt from National Computer Virus Emergency Response Center (CVERC) and Chinese internet security company 360 on Thursday.


In June 2022, NPU issued a public statement stating that it had been subjected to a cyberattack, with a hacker organization from overseas attempting to steal relevant data.

Afterwards, China successfully detected the mastermind behind this cyberattack was the Office of Tailored Access Operations (TAO, Code S32) under the Data Reconnaissance Bureau (Code S3) of the Information Department (Code S) of NSA.


According to internal documents exposed by the group "Shadow Brokers," SecondDate is a cyber weapon developed by the NSA. It is primarily deployed on target network boundary devices such as gateways, firewalls, and edge routers. It covertly monitors cyber traffic and, as needed, selectively redirects, intercepts, and manipulates specific network sessions.



The latest information shows that the CVERC and the company 360, during the investigation of this cyberattack case, have successfully extracted multiple samples of the spyware and identified the true identity of the NSA personnel behind this cyber "spying" case.


The subsequent technical analysis revealed that the involved spyware is a highly advanced cyber espionage tool. The developers must have a very deep understanding of cyber technology, especially network firewall technology. It is equivalent to installing a set of content filtering firewalls and proxy servers on the target network devices, allowing the attacker to completely take control of the target network devices and the network traffic passing through them. This enables the attacker to carry out long-term theft on other hosts and users in the target network, and serve as a "forward base" for delivering more cyberattack weapon toward target network at any time.


The spyware concerned is usually used in conjunction with various firewall and router vulnerability exploitation tools of TAO. After successful vulnerability exploitation and obtaining the corresponding permissions, it is implanted into the target device. The control of spyware is divided into server-side and control-side. The server-side is deployed on the target network boundary devices such as gateways, firewalls, or edge routers, and it monitors and filters all traffic in real-time through underlying drivers. The control-side triggers the activation mechanism by sending specially crafted packets, and the server-side parses the reconnect IP address from the activation packet and initiates a connection, then choose any target within the network to carry out a man-in-the-middle attack according to actual needs.

The network connection uses the UDP protocol, and the communication is encrypted throughout. The communication port is random. The control-side can remotely configure the working mode of the server-side and the target of hijacking.


According to relevant sources, Chinese side and its industry partners have conducted technical investigations worldwide. Through tracing, they have discovered hidden spyware and its derivative versions in thousands of network devices spread across multiple countries and regions. They have also found jump servers remotely controlled by the NSA in countries and regions including Germany, Japan, South Korea, India, and China's Taiwan region.

"With the strong collaboration of partners in multiple countries, we have made significant breakthroughs and have successfully identified the true identity of the NSA personnel responsible for launching cyberattacks against NPU."

此次我方对 “间谍”软件样本的成功提取,并展开溯源,进一步表明中国防范抵御美国政府网络攻击和维护全球网络安全的决心,这种将美国政府实施网络犯罪的细节昭告世界的做法也证明中国具备“看得见”的网络技术基础,可以更有力地帮助本国和他国感知风险、看见威胁、抵御攻击,将具有国家背景的黑客攻击暴露在阳光下。

The successful extraction and tracing of the spyware sample further demonstrates China's determination to prevent and defend against US government-backed cyberattacks and safeguard global cyber security. This practice of revealing the details of cyber crimes launched by the US government to the world also proves that China has a "visible" foundation in cyber technology, which can effectively assist our country and other nations in perceiving risks, identifying threats, and resisting attacks, thereby exposing state-sponsored hacker attacks to the public.


Relevant sources have told the Global Times that the real identities of individuals involved in NSA's cyberattacks will be disclosed through the media in due course. It is believed that this will once again draw global attention to the US government's indiscriminate cyberattacks on other countries.


China Daily精读计划来了!

推 荐 阅 读




华人神探李昌钰翻车,被判伪造证据!无辜男子34年冤狱背后,竟是惊天大阴谋?自主研发!西工大为水下无人潜航器戴上AI眼镜……听,教育早新闻来了AI伦理边界:西工大李学龙团队探索人工智能伦理计算早报|官方回应“北极鲶鱼事件调查结果不公开”;iPhone 14价格不降反涨;央行降准0.25个百分点;网攻西工大黑客身份已锁定西工大提出全新「群聊式」无人机控制框架!类人对话交互、主动环境感知、自主实体控制卫网君:清华震撼世人的EUV光刻厂方案?让子弹再飞一会儿;网攻西工大的神秘黑客身份已被锁定;美持续炒作对华科技制裁,效果适得其反新证据!网攻西工大的神秘黑客,身份已被锁定→关注!华裔神探李昌钰遭控,涉嫌伪造谋杀案证据!面临支付天价赔偿金…动物世界,镜头前的它美国政府“默默公布”UFO证据!战机被神秘球体骚扰甩不掉(图)干细胞疗法新突破!哈佛大学医学院:干细胞疗法为恢复眼部视力提供新证据,I期试验成果喜人!西工大新技术亮相了,千米海底能潜伏60天!伏击航母不在话下斩断“隔空猥亵”隐秘黑手就让我们彼此相爱吧 (Let’s love each other instead )突破!西工大仿生飞行器续航再破世界纪录……听,教育早新闻来了【老键曲库】Landscape in the mist theme这个世界就是个草台班子!这场世纪狗血大审判就是最新证据慢阻肺早诊早治,2023又添哪些新证据?利好来袭!华为、中兴突传重磅,1.8万亿资产全线飙升!美国神秘黑客身份锁定,什么情况?JAMA Ophthalmol|最新证据表明视力丧失或与痴呆症发生直接相关暗物质不存在?无暗物质宇宙模型又获新证据;“室温超导”科学家学术不端论文被撤稿,并将面临调查 | 环球科学要闻美方网攻西工大再添新证!“二次约会”软件是关键网攻西工大的神秘黑客,身份已被锁定!最新:武汉地震监测中心被网攻“幕后黑手”已锁定墨西哥展出疑似“外星生物”遗骸、美方网攻西工大再添新证、李在明绝食15天等丨今日天下谁挑战了白垩纪恐龙霸主地位?科学家发现新证据→希腊圣德米特里圣教堂(Holy Church of Saint Demetrius),列入世界遗产网攻西工大黑客身份被锁定!JAMA Ophthalmol | 最新证据表明视力丧失或与痴呆症发生直接相关战国故事《定风波》卷二(16):魂萦新证据!网攻西工大的黑客身份被锁定→手握美国核弹数据的黑客去世了,他后半生竟然全在反黑客。美高梅遭西方黑客网攻勒索 赌城ATM停摆酒店房卡失灵美国知名鉴识专家李昌钰被控伪造谋杀案证据!恐赔偿数千万美元网攻西工大的黑客身份被锁定!这款软件是网络间谍武器→