<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://en.bharatpedia.org/w/index.php?action=history&amp;feed=atom&amp;title=Tailored_Access_Operations</id>
	<title>Tailored Access Operations - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://en.bharatpedia.org/w/index.php?action=history&amp;feed=atom&amp;title=Tailored_Access_Operations"/>
	<link rel="alternate" type="text/html" href="https://en.bharatpedia.org/w/index.php?title=Tailored_Access_Operations&amp;action=history"/>
	<updated>2026-07-27T13:39:11Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.6</generator>
	<entry>
		<id>https://en.bharatpedia.org/w/index.php?title=Tailored_Access_Operations&amp;diff=430227&amp;oldid=prev</id>
		<title>Ajay Kumar: Created a new article</title>
		<link rel="alternate" type="text/html" href="https://en.bharatpedia.org/w/index.php?title=Tailored_Access_Operations&amp;diff=430227&amp;oldid=prev"/>
		<updated>2023-09-25T18:48:01Z</updated>

		<summary type="html">&lt;p&gt;Created a new article&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Short description|Unit of the U.S. National Security Agency}}&lt;br /&gt;
{{Infobox organization&lt;br /&gt;
| name = Tailored Access Operations&lt;br /&gt;
| logo = File:Tailored Access Operations logo.png&lt;br /&gt;
| logo_size = 165px&lt;br /&gt;
| abbreviation = TAO&lt;br /&gt;
| formation = {{circa}} 1997–2001{{ref|a}}&lt;br /&gt;
| type = [[Advanced persistent threat]]&lt;br /&gt;
| purpose = [[Cyberespionage]], [[cyberwarfare]]&lt;br /&gt;
| role = Cyberwarfare Intelligence Gathering&lt;br /&gt;
| motto = &lt;br /&gt;
| headquarters = [[Fort Meade]]&lt;br /&gt;
| region = [[United States]]&lt;br /&gt;
| methods = [[Zero-day (computing)|Zero-day]]s, [[spyware]]&lt;br /&gt;
| membership = &lt;br /&gt;
| leader_name =&lt;br /&gt;
| language = [[English language|English]]&lt;br /&gt;
| parent_organization = S3 Data Acquisition&lt;br /&gt;
| formerly = &lt;br /&gt;
}}&lt;br /&gt;
{{NSA surveillance}}&lt;br /&gt;
[[File:XKeyscore presentation from 2008.pdf|page=24|thumb|right|A reference to Tailored Access Operations in an [[XKeyscore]] slide]]&lt;br /&gt;
&lt;br /&gt;
The &amp;#039;&amp;#039;&amp;#039;Office of Tailored Access Operations&amp;#039;&amp;#039;&amp;#039; (&amp;#039;&amp;#039;&amp;#039;TAO&amp;#039;&amp;#039;&amp;#039;), now &amp;#039;&amp;#039;&amp;#039;Computer Network Operations&amp;#039;&amp;#039;&amp;#039;, and structured as &amp;#039;&amp;#039;&amp;#039;S32&amp;#039;&amp;#039;&amp;#039;,&amp;lt;ref&amp;gt;{{cite news|url=https://www.washingtonpost.com/world/national-security/nsa-employee-who-worked-on-hacking-tools-at-home-pleads-guilty-to-spy-charge/2017/12/01/ec4d6738-d6d9-11e7-b62d-d9345ced896d_story.html |title=NSA employee who worked on hacking tools at home pleads guilty to spy charge |first=Ellen |last=Nakashima |date=1 December 2017 |newspaper=[[The Washington Post]] |access-date=4 December 2017}}&amp;lt;/ref&amp;gt; is a [[cyber-warfare]] intelligence-gathering unit of the [[National Security Agency]] (NSA).&amp;lt;ref&amp;gt;{{Cite journal|last=Loleski|first=Steven|date=2018-10-18|title=From cold to cyber warriors: the origins and expansion of NSA&amp;#039;s Tailored Access Operations (TAO) to Shadow Brokers|url=https://dx.doi.org/10.1080/02684527.2018.1532627|journal=Intelligence and National Security|volume=34|issue=1|pages=112–128|doi=10.1080/02684527.2018.1532627|s2cid=158068358|issn=0268-4527}}&amp;lt;/ref&amp;gt; It has been active since at least 1998, possibly 1997, but was not named or structured as TAO until &amp;quot;the last days of 2000,&amp;quot; according to General [[Michael Hayden (general)|Michael Hayden]].&amp;lt;ref name=&amp;quot;Hayde2016&amp;quot;&amp;gt;{{cite book|last=Hayden|first=Michael V.|url=https://books.google.com/books?id=kjepCQAAQBAJ&amp;amp;q=last+days+of+2000|title=Playing to the Edge: American Intelligence in the Age of Terror|date=23 February 2016|publisher=Penguin Press|isbn=978-1594206566|access-date=1 April 2021}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;fp2013&amp;quot;&amp;gt;{{cite journal|last=Aid|first=Matthew M.|date=10 June 2013|title=Inside the NSA&amp;#039;s Ultra-Secret China Hacking Group|url=https://foreignpolicy.com/2013/06/10/inside-the-nsas-ultra-secret-china-hacking-group/|journal=Foreign Policy|access-date=11 June 2013}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite news|last=Paterson|first=Andrea|date=30 August 2013|title=The NSA has its own team of elite hackers|newspaper=The Washington Post|url=https://www.washingtonpost.com/blogs/the-switch/wp/2013/08/29/the-nsa-has-its-own-team-of-elite-hackers/?tid=d_pulse|access-date=31 August 2013}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
TAO identifies, monitors, infiltrates, and gathers intelligence on computer systems being used by entities foreign to the United States.&amp;lt;ref name=&amp;quot;Kingsbury&amp;quot;&amp;gt;{{cite web|last=Kingsbury|first=Alex|title=The Secret History of the National Security Agency|url=https://www.usnews.com/opinion/articles/2009/06/19/the-secret-history-of-the-national-security-agency|work=[[U.S. News &amp;amp; World Report]]|access-date=22 May 2013|date=June 19, 2009}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|last1=Kingsbury|first1=Alex|title=U.S. is Striking Back in the Global Cyberwar|url=https://www.usnews.com/news/articles/2009/11/18/us-is-striking-back-in-the-global-cyberwar|access-date=22 May 2013|first2=Anna |last2=Mulrine |date=November 18, 2009|work=[[U.S. News &amp;amp; World Report]]}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;Riley&amp;quot;&amp;gt;{{cite web|last=Riley|first=Michael|title=How the U.S. Government Hacks the World|url=http://www.businessweek.com/articles/2013-05-23/how-the-u-dot-s-dot-government-hacks-the-world|archive-url=https://web.archive.org/web/20130525063903/http://www.businessweek.com/articles/2013-05-23/how-the-u-dot-s-dot-government-hacks-the-world|url-status=dead|archive-date=May 25, 2013|work=[[Bloomberg Businessweek]]|access-date=23 May 2013|date=May 23, 2013}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=&amp;quot;Aid2010&amp;quot;&amp;gt;{{cite book|last=Aid|first=Matthew M.|title=The Secret Sentry: The Untold History of the National Security Agency|url=https://books.google.com/books?id=x_K2rb-OShMC&amp;amp;pg=PA311|access-date=22 May 2013|date=8 June 2010|publisher=Bloomsbury USA|isbn=978-1-60819-096-6|page=311}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==History==&lt;br /&gt;
{{see also|Signals intelligence}}&lt;br /&gt;
TAO is reportedly &amp;quot;the largest and arguably the most important component of the NSA&amp;#039;s huge Signals Intelligence Directorate (SID),&amp;lt;ref&amp;gt;{{Cite web|url=https://www.aclu.org/files/assets/eo12333/NSA/Signals%20Intelligence%20Directorate%20%28SID%29%20Management%20Directive%20422%20United%20States%20SIGINT%20System%20Mission%20Delegation.pdf|title=FOIA #70809 (released 2014-09-19)}}&amp;lt;/ref&amp;gt; consisting of more than 1,000 military and civilian computer hackers, intelligence analysts, targeting specialists, computer hardware and software designers, and electrical engineers&amp;quot;.&amp;lt;ref name=fp2013 /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Snowden leak===&lt;br /&gt;
A document leaked by former NSA contractor [[Edward Snowden]] describing the unit&amp;#039;s work says TAO has software templates allowing it to break into commonly used hardware, including &amp;quot;routers, switches, and firewalls from multiple product vendor lines&amp;quot;.&amp;lt;ref name=gellman-nakashima-2013&amp;gt;{{cite news|title=U.S. spy agencies mounted 231 offensive cyber-operations in 2011, documents show|url=https://www.washingtonpost.com/world/national-security/us-spy-agencies-mounted-231-offensive-cyber-operations-in-2011-documents-show/2013/08/30/d090a6ae-119e-11e3-b4cb-fd7ce041d814_story.html|access-date=7 September 2013|newspaper=The Washington Post|date=August 30, 2013|first1=Barton|last1=Gellman|first2=Ellen|last2=Nakashima|quote=Much more often, an implant is coded entirely in software by an NSA group called, Tailored Access Operations (TAO). As its name suggests, TAO builds attack tools that are custom-fitted to their targets. The NSA unit&amp;#039;s software engineers would rather tap into networks than individual computers because there are usually many devices on each network. Tailored Access Operations has software templates to break into common brands and models of &amp;quot;routers, switches, and firewalls from multiple product vendor lines,&amp;quot; according to one document describing its work.}}&amp;lt;/ref&amp;gt; TAO engineers prefer to tap networks rather than isolated computers, because there are typically many devices on a single network.&amp;lt;ref name=gellman-nakashima-2013 /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Organization==&lt;br /&gt;
&lt;br /&gt;
TAO&amp;#039;s headquarters are termed the &amp;#039;&amp;#039;Remote Operations Center&amp;#039;&amp;#039; (ROC) and are based at the NSA headquarters at [[Fort Meade, Maryland]]. TAO also has expanded to [[Hawaii Cryptologic Center|NSA Hawaii]] ([[Wahiawa]], Oahu), [[Georgia Cryptologic Center|NSA Georgia]] ([[Fort Gordon, Georgia|Fort Gordon]], Georgia), [[Texas Cryptologic Center|NSA Texas]] ([[Joint Base San Antonio]], Texas), and [[Colorado Cryptologic Center|NSA Colorado]] ([[Buckley Space Force Base]], Denver).&amp;lt;ref name=fp2013 /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* S321 – Remote Operations Center (ROC) In the &amp;#039;&amp;#039;&amp;#039;Remote Operations Center&amp;#039;&amp;#039;&amp;#039;, 600 employees gather information from around the world.&amp;lt;ref&amp;gt;{{cite web |url=http://blogs.computerworld.com/cybercrime-and-hacking/22321/secret-nsa-hackers-tao-office-have-been-pwning-china-nearly-15-years |title=Secret NSA hackers from TAO Office have been pwning China for nearly 15 years |publisher=Computerworld |date=2013-06-11 |access-date=2014-01-27 |url-status=dead |archive-url=https://web.archive.org/web/20140125123015/http://blogs.computerworld.com/cybercrime-and-hacking/22321/secret-nsa-hackers-tao-office-have-been-pwning-china-nearly-15-years |archive-date=2014-01-25 }}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|last=Rothkopf |first=David |url=https://foreignpolicy.com/articles/2013/06/10/inside_the_nsa_s_ultra_secret_china_hacking_group |title=Inside the NSA&amp;#039;s Ultra-Secret China Hacking Group |work=Foreign Policy |access-date=2014-01-27}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
* S323 – [[Data Network Technologies Branch]] (DNT) : develops automated spyware&lt;br /&gt;
** S3231 – Access Division (ACD)&lt;br /&gt;
** S3232 – Cyber Networks Technology Division (CNT)&lt;br /&gt;
** S3233 – &lt;br /&gt;
** S3234 – Computer Technology Division (CTD)&lt;br /&gt;
** S3235 – Network Technology Division (NTD)&lt;br /&gt;
* [[Telecommunications Network Technologies Branch]] (TNT) : improve network and computer hacking methods&amp;lt;ref&amp;gt;{{cite news|url=http://www.tagesanzeiger.ch/ausland/amerika/Die-Speerspitze-des-amerikanischen-Hackings/story/30196342 |title=Hintergrund: Die Speerspitze des amerikanischen Hackings - News Ausland: Amerika |newspaper=Tages-Anzeiger |publisher=tagesanzeiger.ch |access-date=2014-01-27}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
* Mission Infrastructure Technologies Branch: operates the software provided above&amp;lt;ref&amp;gt;{{Cite web |date=2013-06-11 |title=Inside the NSA&amp;#039;s Ultra-Secret Hacking Group |url=https://www.atlanticcouncil.org/blogs/natosource/inside-the-nsas-ultrasecret-hacking-group/ |access-date=2023-07-27 |website=Atlantic Council |language=en-US}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
* S328 – [[Access Technologies Operations Branch]] (ATO): Reportedly includes personnel seconded by the CIA and the FBI, who perform what are described as &amp;quot;off-net operations&amp;quot;, which means they arrange for CIA agents to surreptitiously plant eavesdropping devices on computers and telecommunications systems overseas so that TAO&amp;#039;s hackers may remotely access them from Fort Meade.&amp;lt;ref name=fp2013/&amp;gt; Specially equipped submarines, currently the [[USS Jimmy Carter|USS &amp;#039;&amp;#039;Jimmy Carter&amp;#039;&amp;#039;]],&amp;lt;ref&amp;gt;{{cite web|author=noahmax |url=http://defensetech.org/2005/02/21/jimmy-carter-super-spy/ |title=Jimmy Carter: Super Spy? |publisher=Defense Tech |date=2005-02-21 |access-date=2014-01-27|url-status=dead}}&amp;lt;/ref&amp;gt; are used to wiretap fibre optic cables around the globe.&lt;br /&gt;
** S3283 – Expeditionary Access Operations (EAO)&lt;br /&gt;
** S3285 – Persistence Division&lt;br /&gt;
&lt;br /&gt;
===Virtual locations===&lt;br /&gt;
Details&amp;lt;ref&amp;gt;https://www.eff.org/files/2014/04/09/20140312-intercept-the_nsa_and_gchqs_quantumtheory_hacking_tactics.pdf (slide 8)&amp;lt;/ref&amp;gt; on a program titled QUANTUMSQUIRREL indicate NSA ability to masquerade as any routable IPv4 or IPv6 host.&amp;lt;ref&amp;gt;{{Cite journal|last=Dealer|first=Hacker|title=Dealer, Hacker, Lawyer, Spy: Modern Techniques and Legal Boundaries of Counter-cybercrime Operations|journal=The European Review of Organised Crime}}&amp;lt;/ref&amp;gt; This enables an NSA computer to generate false geographical location and personal identification credentials when accessing the Internet utilizing QUANTUMSQUIRREL.&amp;lt;ref&amp;gt;{{cite web|url=https://firstlook.org/theintercept/document/2014/03/12/nsa-gchqs-quantumtheory-hacking-tactics/ |title=The NSA and GCHQ&amp;#039;s QUANTUMTHEORY Hacking Tactics |publisher=firstlook.org |date=2014-07-16 |access-date=2014-07-16}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Leadership ===&lt;br /&gt;
From 2013 to 2017,&amp;lt;ref&amp;gt;{{cite news |last1=Landler |first1=Mark |date=April 10, 2018 |title=Thomas Bossert, Trump&amp;#039;s Chief Adviser on Homeland Security, Is Forced Out |work=New York Times |url=https://www.nytimes.com/2018/04/10/us/politics/tom-bossert-trump-homeland-security.html |access-date=March 9, 2022}}&amp;lt;/ref&amp;gt; the head of TAO was [[Rob Joyce]], a 25-plus year employee who previously worked in the NSA&amp;#039;s [[Information Assurance Directorate]] (IAD). In January 2016, Joyce had a rare public appearance when he gave a presentation at the Usenix’s Enigma conference.&amp;lt;ref&amp;gt;{{cite web|publisher=The Register|url=https://www.theregister.com/2016/01/28/nsas_top_hacking_boss_explains_how_to_protect_your_network_from_his_minions/|title=NSA&amp;#039;s top hacking boss explains how to protect your network from his attack squads|date=January 28, 2016|first=Iain |last=Thomson}}&amp;lt;/ref&amp;gt;[[File:QUANTUMSQUIRREL.jpg|thumb|[[QUANTUMSQUIRREL]] image from an NSA presentation explaining the QUANTUMSQUIRREL IP host spoofing ability|alt=&amp;quot;Truly covert infrastructure, be any IP in the world.&amp;quot;]]&lt;br /&gt;
&lt;br /&gt;
==NSA ANT catalog==&lt;br /&gt;
{{Main|NSA ANT catalog}}&lt;br /&gt;
The [[NSA ANT catalog]] is a 50-page [[Classified information|classified]] document listing technology available to the [[United States]] [[National Security Agency|National Security Agency (NSA)]] Tailored Access Operations (TAO) by the Advanced Network Technology (ANT) Division to aid in cyber surveillance. Most devices are described as already operational and available to US nationals and members of the [[Five Eyes]] alliance. According to &amp;#039;&amp;#039;[[Der Spiegel]]&amp;#039;&amp;#039;, which released the catalog to the public on December 30, 2013, &amp;quot;The list reads like a mail-order catalog, one from which other NSA employees can order technologies from the ANT division for tapping their targets&amp;#039; data.&amp;quot;&amp;lt;!--&amp;lt;ref name=Applebaum /&amp;gt;&amp;lt;ref name=Hathaway /&amp;gt;&amp;lt;ref name=Condliffe /&amp;gt;&amp;lt;ref name=Edwards /&amp;gt;&amp;lt;ref name=LeMonde /&amp;gt;&amp;lt;ref name=Satter /&amp;gt;&amp;lt;ref name=Hardawar /&amp;gt;&amp;lt;ref name=Kain /&amp;gt;&amp;lt;ref name=Zetter /&amp;gt;--&amp;gt; The document was created in 2008.&amp;lt;ref name=See_NSA-ANT-catalog&amp;gt;This section copied from [[NSA ANT catalog]]; see there for sources&amp;lt;/ref&amp;gt; &lt;br /&gt;
Security researcher [[Jacob Appelbaum]] gave a speech at the [[Chaos Communications Congress]] in [[Hamburg]], [[Germany]], in which he detailed techniques that the simultaneously published &amp;#039;&amp;#039;Der Spiegel&amp;#039;&amp;#039; article he coauthored disclosed from the catalog.&amp;lt;ref name=See_NSA-ANT-catalog /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===QUANTUM attacks===&lt;br /&gt;
[[File:NSA quantum cat.jpg|thumb|[[Lolcat]] image from an NSA presentation explaining in part the naming of the QUANTUM program|alt=&amp;quot;I iz in ur space-time continuum, upsetting all your gravity and quantums and stuffs.&amp;quot;]]&lt;br /&gt;
[[File:NSA QUANTUMTHEORY.jpg|thumb|NSA&amp;#039;s QUANTUMTHEORY overview slide with various codenames for specific types of attack and integration with other NSA systems]]&lt;br /&gt;
&lt;br /&gt;
The TAO has developed an attack suite they call QUANTUM. It relies on a compromised [[router (computing)|router]] that duplicates internet traffic, typically [[HTTP]] requests, so that they go both to the intended target and to an NSA site (indirectly). The NSA site runs FOXACID software which sends back exploits that load in the background in the target [[web browser]] before the intended destination has had a chance to respond (it&amp;#039;s unclear if the compromised router facilitates this race on the return trip). Prior to the development of this technology, FOXACID software made [[spear-phishing]] attacks the NSA referred to as spam. If the browser is exploitable, further permanent &amp;quot;implants&amp;quot; (rootkits etc.) are deployed in the target computer, e.g. OLYMPUSFIRE for Windows, which gives complete remote access to the infected machine.&amp;lt;ref&amp;gt;{{cite web|url=https://www.spiegel.de/netzwelt/netzpolitik/quantumtheory-wie-die-nsa-weltweit-rechner-hackt-a-941149.html |title=Quantumtheory: Wie die NSA weltweit Rechner hackt |work=Der Spiegel |date=2013-12-30 |access-date=2014-01-18}}&amp;lt;/ref&amp;gt; This type of attack is part of the [[man-in-the-middle attack]] family, though more specifically it is called [[man-on-the-side attack]]. It is difficult to pull off without controlling some of the [[Internet backbone]].&amp;lt;ref name=&amp;quot;Schneier&amp;quot;&amp;gt;{{cite web |url= https://www.schneier.com/blog/archives/2013/10/how_the_nsa_att.html |first=Bruce |last=Schneier |title=How the NSA Attacks Tor/Firefox Users With QUANTUM and FOXACID |publisher=Schneier.com |date=2013-10-07 |access-date=2014-01-18}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
There are numerous services that FOXACID can exploit this way. The names of some FOXACID modules are given below:&amp;lt;ref&amp;gt;{{cite web|author=Fotostrecke |url=https://www.spiegel.de/fotostrecke/nsa-dokumente-so-knackt-der-geheimdienst-internetkonten-fotostrecke-105326-11.html |title=NSA-Dokumente: So knackt der Geheimdienst Internetkonten |work=Der Spiegel |date=2013-12-30 |access-date=2014-01-18}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{Div col|colwidth=20em}}&lt;br /&gt;
* [[Alibaba Group|alibaba]]ForumUser&lt;br /&gt;
* [[doubleclick]]ID&lt;br /&gt;
* [[rocketmail]]&lt;br /&gt;
* [[hi5]]&lt;br /&gt;
* [[Hotmail]]ID&lt;br /&gt;
* [[LinkedIn]]&lt;br /&gt;
* [[Mail.Ru|mailruid]]&lt;br /&gt;
* [[MSN|msnMail]]Token64&lt;br /&gt;
* [[Tencent QQ|qq]]&lt;br /&gt;
* [[Facebook]]&lt;br /&gt;
* [[simbar]]id&lt;br /&gt;
* [[Twitter]]&lt;br /&gt;
* [[Yahoo]]&lt;br /&gt;
* [[Gmail]]&lt;br /&gt;
* [[YouTube]]&lt;br /&gt;
{{Div col end}}&lt;br /&gt;
&lt;br /&gt;
By collaboration with the British [[Government Communications Headquarters]] (GCHQ) ([[MUSCULAR (surveillance program)|MUSCULAR]]), Google services could be attacked too, including [[Gmail]].&amp;lt;ref&amp;gt;{{cite web |url=https://www.spiegel.de/fotostrecke/nsa-dokumente-so-knackt-der-geheimdienst-internetkonten-fotostrecke-105326-12.html |title=NSA-Dokumente: So knackt der Geheimdienst Internetkonten |work=Der Spiegel |date=2013-12-30 |access-date=2014-01-18}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Finding machines that are exploitable and worth attacking is done using analytic databases such as [[XKeyscore]].&amp;lt;ref&amp;gt;{{cite news|url=https://arstechnica.com/tech-policy/2013/08/nsas-internet-taps-can-find-systems-to-hack-track-vpns-and-word-docs/|title=NSA&amp;#039;s Internet taps can find systems to hack, track VPNs and Word docs|author=Gallagher, Sean|date=August 1, 2013|access-date=August 8, 2013}}&amp;lt;/ref&amp;gt; A specific method of finding vulnerable machines is interception of [[Windows Error Reporting]] traffic, which is logged into XKeyscore.&amp;lt;ref name=&amp;quot;spiegel1&amp;quot;&amp;gt;{{cite web|url=https://www.spiegel.de/international/world/the-nsa-uses-powerful-toolbox-in-effort-to-spy-on-global-networks-a-940969-2.html |title=Inside TAO: Targeting Mexico |work=Der Spiegel |date=2013-12-29 |access-date=2014-01-18}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
QUANTUM attacks launched from NSA sites can be too slow for some combinations of targets and services as they essentially try to exploit a [[race condition]], i.e. the NSA server is trying to beat the legitimate server with its response.&amp;lt;ref&amp;gt;{{cite web|author=Fotostrecke |url=https://www.spiegel.de/fotostrecke/qfire-die-vorwaertsverteidigng-der-nsa-fotostrecke-105358-14.html |title=QFIRE - die &amp;quot;Vorwärtsverteidigng&amp;quot; der NSA |work=Der Spiegel |date=2013-12-30 |access-date=2014-01-18}}&amp;lt;/ref&amp;gt; As of mid-2011, the NSA was prototyping a capability codenamed QFIRE, which involved embedding their exploit-dispensing servers in [[virtual machine]]s (running on [[VMware ESX]]) hosted closer to the target, in the so-called [[Special Collection Sites]] (SCS) network worldwide. The goal of QFIRE was to lower the latency of the spoofed response, thus increasing the probability of success.&amp;lt;ref&amp;gt;{{cite web |url=https://www.spiegel.de/fotostrecke/qfire-die-vorwaertsverteidigng-der-nsa-fotostrecke-105358-8.html |title=QFIRE - die &amp;quot;Vorwärtsverteidigng&amp;quot; der NSA |work=Der Spiegel |date=2013-12-30 |access-date=2014-01-18}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web |url=https://www.spiegel.de/fotostrecke/qfire-die-vorwaertsverteidigng-der-nsa-fotostrecke-105358-9.html |title=QFIRE - die &amp;quot;Vorwärtsverteidigng&amp;quot; der NSA |work=Der Spiegel |date=2013-12-30 |access-date=2014-01-18}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web |url=https://www.spiegel.de/fotostrecke/qfire-die-vorwaertsverteidigng-der-nsa-fotostrecke-105358-11.html |title=QFIRE - die &amp;quot;Vorwärtsverteidigng&amp;quot; der NSA |work=Der Spiegel |date=2013-12-30 |access-date=2014-01-18}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
COMMENDEER {{sic}} is used to commandeer (i.e. compromise) untargeted computer systems. The software is used as a part of QUANTUMNATION, which also includes the software vulnerability scanner VALIDATOR. The tool was first described at the 2014 [[Chaos Communication Congress]] by [[Jacob Appelbaum]], who characterized it as tyrannical.&amp;lt;ref&amp;gt;{{cite web |url=https://www.youtube.com/watch?v=b0w36GAyZIA#t=28m34s|title=&amp;quot;Chaos Computer Club CCC Presentation&amp;quot; at 28:34|website=[[YouTube]]}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=pwnage&amp;gt;{{cite news |last=Thomson |first=Iain |url=https://www.theregister.co.uk/2013/12/31/nsa_weapons_catalogue_promises_pwnage_at_the_speed_of_light |title=How the NSA hacks PCs, phones, routers, hard disks &amp;#039;at speed of light&amp;#039;: Spy tech catalog leaks |work=[[The Register]] |location=[[London]] |date=2013-12-31 |access-date=2014-08-15}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite news |last=Mick |first=Jason |url=http://www.dailytech.com/Tax+and+Spy+How+the+NSA+Can+Hack+Any+American+Stores+Data+15+Years/article34010.htm |title=Tax and Spy: How the NSA Can Hack Any American, Stores Data 15 Years |publisher=[[DailyTech]] |date=2013-12-31 |access-date=2014-08-15 |url-status=dead |archive-url=https://web.archive.org/web/20140824193107/http://www.dailytech.com/Tax+and+Spy+How+the+NSA+Can+Hack+Any+American+Stores+Data+15+Years/article34010.htm |archive-date=2014-08-24 }}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
QUANTUMCOOKIE is a more complex form of attack which can be used [[Tor (anonymity network)#Weaknesses|against Tor]] users.&amp;lt;ref&amp;gt;{{cite magazine|last=Weaver |first=Nicholas |url=https://www.wired.com/opinion/2013/11/this-is-how-the-internet-backbone-has-been-turned-into-a-weapon/ |title=Our Government Has Weaponized the Internet. Here&amp;#039;s How They Did It |magazine=Wired |date=2013-03-28 |access-date=2014-01-18}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Targets and collaborations==&lt;br /&gt;
Suspected, alleged and confirmed targets of the Tailored Access Operations unit include national and international entities like [[China]],&amp;lt;ref name=&amp;quot;fp2013&amp;quot; /&amp;gt;  [[Northwestern Polytechnical University]].&amp;lt;ref&amp;gt;{{Cite news|url=https://www.bloomberg.com/news/articles/2022-09-05/china-accuses-us-of-repeated-hacks-on-polytechnic-university|title=China Accuses US of Repeated Hacks on Polytechnic University|newspaper=Bloomberg |date=September 5, 2022|via=www.bloomberg.com}}&amp;lt;/ref&amp;gt;, [[OPEC]],&amp;lt;ref&amp;gt;{{cite web|last=Gallagher |first=Sean |url=https://arstechnica.com/information-technology/2013/11/quantum-of-pwnness-how-nsa-and-gchq-hacked-opec-and-others/ |title=Quantum of pwnness: How NSA and GCHQ hacked OPEC and others |publisher=Ars Technica |date=2013-11-12 |access-date=2014-01-18}}&amp;lt;/ref&amp;gt; and [[Secretariat of Public Security (Mexico)|Mexico&amp;#039;s Secretariat of Public Security]].&amp;lt;ref name=&amp;quot;spiegel1&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The group has also targeted global communication networks via [[SEA-ME-WE 4]] – an optical fibre [[submarine communications cable]] system that carries telecommunications between Singapore, Malaysia, Thailand, Bangladesh, India, Sri Lanka, Pakistan, United Arab Emirates, Saudi Arabia, Sudan, Egypt, Italy, Tunisia, Algeria and France.&amp;lt;ref name=&amp;quot;pwnage&amp;quot; /&amp;gt; Additionally, [[National Defence Radio Establishment (Sweden)|Försvarets radioanstalt (FRA)]] in Sweden gives access to fiber optic links for QUANTUM cooperation.&amp;lt;ref&amp;gt;{{cite web|url=http://www.svt.se/ug/las-dokumenten-om-sverige-fran-edward-snowden |title=Läs dokumenten om Sverige från Edward Snowden - Uppdrag Granskning |publisher=SVT.se |access-date=2014-01-18}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=http://s3.documentcloud.org/documents/894386/legal-issues-uk-regarding-sweden-and-quantum.pdf |title=What You Wanted to Know |publisher=documentcloud.org |access-date=2015-10-03}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
TAO&amp;#039;s QUANTUM INSERT technology was passed to UK services, particularly to [[Government Communications Headquarters|GCHQ]]&amp;#039;s [[MyNOC]], which used it to target [[Belgacom]] and [[GPRS roaming exchange]] (GRX) providers like the [[Comfone]], [[Syniverse]], and Starhome.&amp;lt;ref name=&amp;quot;spiegel1&amp;quot; /&amp;gt; Belgacom, which provides services to the [[European Commission]], the [[European Parliament]] and the [[European Council]] discovered the attack.&amp;lt;ref&amp;gt;{{cite web |url=http://www.networkworld.com/news/2013/111113-british-spies-reportedly-spoofed-linkedin-275807.html |title=British spies reportedly spoofed LinkedIn, Slashdot to target network engineers |publisher=Network World |date=2013-11-11 |access-date=2014-01-18 |url-status=dead |archive-url=https://web.archive.org/web/20140115014135/http://www.networkworld.com/news/2013/111113-british-spies-reportedly-spoofed-linkedin-275807.html |archive-date=2014-01-15 }}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In concert with the [[CIA]] and [[FBI]], TAO is used to intercept laptops purchased online, divert them to secret warehouses where spyware and hardware is installed, and send them on to customers.&amp;lt;ref&amp;gt;{{cite web|url=http://www.spiegel.de/international/world/the-nsa-uses-powerful-toolbox-in-effort-to-spy-on-global-networks-a-940969-3.html |title=Inside TAO: The NSA&amp;#039;s Shadow Network |work=Der Spiegel |date=2013-12-29 |access-date=2014-01-27}}&amp;lt;/ref&amp;gt; TAO has also targeted internet browsers [[Tor (network)|Tor]] and [[Firefox]].&amp;lt;ref name=&amp;quot;Schneier&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
According to a 2013 article in &amp;#039;&amp;#039;[[Foreign Policy]]&amp;#039;&amp;#039;, TAO has become &amp;quot;increasingly accomplished at its mission, thanks in part to the high-level cooperation it secretly receives from the &amp;#039;big three&amp;#039; American telecom companies ([[AT&amp;amp;T]], [[Verizon]] and [[Sprint Corporation|Sprint]]), most of the large US-based Internet service providers, and many of the top computer security software manufacturers and consulting companies.&amp;quot;&amp;lt;ref name=&amp;quot;fp&amp;quot; /&amp;gt; A 2012 TAO budget document claims that these companies, on TAO&amp;#039;s behest, &amp;quot;insert vulnerabilities into commercial encryption systems, IT systems, networks and endpoint communications devices used by targets&amp;quot;.&amp;lt;ref name=&amp;quot;fp&amp;quot;&amp;gt;{{Cite web |last=Aid |first=Matthew M. |date=2013-10-15 |title=The NSA&amp;#039;s New Code Breakers |url=https://foreignpolicy.com/2013/10/15/the-nsas-new-code-breakers/ |access-date=2023-07-27 |website=Foreign Policy |language=en-US}}&amp;lt;/ref&amp;gt; A number of US companies, including [[Cisco]] and [[Dell]], have subsequently made public statements denying that they insert such back doors into their products.&amp;lt;ref&amp;gt;{{cite web|last=Farber |first=Dan |url=http://news.cnet.com/8301-1009_3-57616334-83/nsa-reportedly-planted-spyware-on-electronics-equipment/ |title=NSA reportedly planted spyware on electronics equipment &amp;amp;#124; Security &amp;amp; Privacy |publisher=CNET News |date=2013-12-29 |access-date=2014-01-18}}&amp;lt;/ref&amp;gt; [[Microsoft]] provides advance warning to the NSA of vulnerabilities it knows about, before fixes or information about these vulnerabilities is available to the public; this enables TAO to execute so-called [[zero-day attack]]s.&amp;lt;ref&amp;gt;{{cite web|last=Schneier |first=Bruce |url=https://www.theatlantic.com/technology/archive/2013/10/how-the-nsa-thinks-about-secrecy-and-risk/280258/ |title=How the NSA Thinks About Secrecy and Risk |work=The Atlantic |date=2013-10-04 |access-date=2014-01-18}}&amp;lt;/ref&amp;gt; A Microsoft official who declined to be identified in the press confirmed that this is indeed the case, but said that Microsoft cannot be held responsible for how the NSA uses this advance information.&amp;lt;ref&amp;gt;{{cite web|last=Riley |first=Michael |url=https://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-to-swap-data-with-thousands-of-firms.html |title=U.S. Agencies Said to Swap Data With Thousands of Firms |publisher=Bloomberg |date=2013-06-14 |access-date=2014-01-18}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==See also==&lt;br /&gt;
* [[Advanced persistent threat]]&lt;br /&gt;
* [[Cyberwarfare in the United States]]&lt;br /&gt;
* [[Equation Group]]&lt;br /&gt;
* [[Magic Lantern (software)]]&lt;br /&gt;
* [[MiniPanzer and MegaPanzer]]&lt;br /&gt;
* [[PLA Unit 61398]]&lt;br /&gt;
* [[Stuxnet]]&lt;br /&gt;
* [[Syrian Electronic Army]]&lt;br /&gt;
* [[Unit 8200]]&lt;br /&gt;
* [[WARRIOR PRIDE]]&lt;br /&gt;
&lt;br /&gt;
==References==&lt;br /&gt;
{{reflist|30em}}&lt;br /&gt;
&lt;br /&gt;
==External links==&lt;br /&gt;
* [https://www.spiegel.de/international/world/the-nsa-uses-powerful-toolbox-in-effort-to-spy-on-global-networks-a-940969-3.html Inside TAO: Documents Reveal Top NSA Hacking Unit]&lt;br /&gt;
* [https://www.theguardian.com/world/2013/dec/29/der-spiegel-nsa-hacking-unit-tao NSA &amp;#039;hacking unit&amp;#039; infiltrates computers around the world – report]&lt;br /&gt;
* [https://williamaarkin.wordpress.com/2013/09/03/nsa-tailored-access-operations/ NSA Tailored Access Operations]&lt;br /&gt;
* [https://www.wired.com/threatlevel/2013/09/nsa-router-hacking/ NSA Laughs at PCs, Prefers Hacking Routers and Switches]&lt;br /&gt;
* [https://www.nytimes.com/2014/01/15/us/nsa-effort-pries-open-computers-not-connected-to-internet.html N.S.A. Devises Radio Pathway Into Computers]&lt;br /&gt;
* [https://theintercept.com/snowden-sidtoday/5987439-getting-the-ungettable-intelligence-an-interview/ Getting the &amp;#039;Ungettable&amp;#039; Intelligence: An Interview with TAO&amp;#039;s Teresa Shea]&lt;br /&gt;
&lt;br /&gt;
{{National Security Agency}}&lt;br /&gt;
[[Category:Computer surveillance]]&lt;br /&gt;
[[Category:Cyberwarfare in the United States]]&lt;br /&gt;
[[Category:Hacker groups]]&lt;br /&gt;
[[Category:National Security Agency]]&lt;br /&gt;
[[Category:American advanced persistent threat groups]]&lt;br /&gt;
[[Category:Cybercrime in India]]&lt;br /&gt;
[[Category:Cyberwarfare in Iran]]&lt;/div&gt;</summary>
		<author><name>Ajay Kumar</name></author>
	</entry>
</feed>