NSA Revives Elite TAO Hacking Unit Behind Stuxnet and WannaCry to Accelerate Cyber Operations Against China and Adversaries
The U.S. National Security Agency has restored the original name Tailored Access Operations (TAO) to its premier cyber intrusion division as part of a major internal restructuring aimed at accelerating offensive operations against hostile nations, including China.
Until recently, the unit operated under the name Office of Computer Network Operations (CNO). The decision to revive the well-known TAO designation reverses part of the NSA21 reform launched in 2016, which had distributed offensive operations and intelligence collection across larger directorates and eliminated TAO as a standalone structure.
Former NSA employees noted that the previous reorganization failed to improve collaboration between developers and operators and instead created greater separation. The revival was overseen by Deputy NSA Director Tim Kosiba, who previously served in TAO. The updated organizational structure was presented to U.S. Defense Secretary Pete Hegseth during his visit to Fort Meade, home to both NSA and U.S. Cyber Command headquarters.
Starting next month, TAO will receive its own dedicated building within the Fort Meade complex. Former personnel believe that reuniting developers and operational teams will accelerate the preparation of cyber attacks and help discover new methods of penetrating highly protected networks, especially amid rapid advances in artificial intelligence.
TAO specializes in creating custom tools for covert access to foreign computer systems. These include malware, persistence mechanisms, and other specialized implants used in intelligence-gathering operations.
The unit has been linked to several high-profile cyber operations and tools. It played a role in developing Stuxnet, the sophisticated worm used to disrupt Iran’s nuclear enrichment program. TAO also became the focus of attention after the Shadow Brokers group leaked stolen NSA tools, including the EternalBlue exploit.
EternalBlue was later weaponized in the WannaCry ransomware attack of 2017, which spread to approximately 150 countries and affected around 200,000 organizations worldwide.
Around the same period, former NSA contractor Harold Martin, who worked in TAO between 2012 and 2015, was accused of storing a massive collection of classified materials at his home. In 2019 he was sentenced to nine years in prison, although investigators never proved he had shared the stolen information with others.
Related articles
HoneyMyte APT Deploys Kernel-Level CoolClient Backdoor Disguised as Microsoft Defender
The Chinese-speaking APT group HoneyMyte has deployed an updated version of its CoolClient backdoor in espionage operations targeting government and private organizations in Russia, Myanmar, Mongolia, Pakistan, and India. The new variant operates at the Windows kernel level using a signed driver, allowing it to hide processes, files, registry entries, and network activity while evading detection. Attackers first abuse PlugX to add exclusions for Microsoft Defender, then drop a fake Windows Defender directory containing the renamed Sangfor binary defender.exe and the malicious libngs.dll. A scheduled task ensures persistence by launching the fake defender.exe with high privileges on system startup. Kaspersky GReAT researchers note that the kernel-mode capabilities significantly increase the backdoor’s stealth and survivability compared to its previous user-mode implementation. The campaign demonstrates sophisticated living-off-the-land techniques combined with legitimate software abuse.
Lazarus Group Exploits Windows Kernel Zero-Day CVE-2026-68820 to Deploy FudModule Rootkit
The North Korean Lazarus APT group has been actively exploiting a zero-day vulnerability in the Windows kernel to escalate privileges to SYSTEM level and install the FudModule rootkit. The flaw, tracked as CVE-2026-68820, resides in the afd.sys driver responsible for network functions and socket management. Microsoft released a patch for the issue on August 11. The attacks form part of the ongoing Operation Dream Job campaign, which uses fake job offers to target professionals in defense, aerospace, and aviation sectors. Victims in Brazil, Europe, and India are tricked into opening malicious PDF viewers or prepared files that deliver the MISTPEN downloader. Once initial access is obtained, the zero-day exploit elevates privileges, allowing FudModule to tamper with Windows telemetry and weaken EDR solutions as well as Smart App Control.
Iranian Hackers Disable Safety Alarms in US Industrial Control Systems
Iranian threat actors have been compromising internet-exposed industrial controllers across the United States since at least March 2026, modifying alarm and safety shutdown logic in critical infrastructure. The campaign has targeted government organizations and operators in the water, wastewater, and energy sectors, resulting in operational disruptions and financial losses. Attackers focus on devices with insecure remote access, weak credentials, or default configurations rather than exploiting zero-day vulnerabilities. Targeted hardware includes Rockwell CompactLogix and Micro850 controllers, Schneider BMX P34 and Modicon M340 PLCs, and Siemens S7-1200 models. Operators use rented foreign infrastructure and legitimate programming software to download, alter, and re-upload control logic projects. In at least one case, malicious code maintained normal operations while introducing instructions that bypassed safe operational limits and altered data displayed on HMI and SCADA interfaces. The tactics closely resemble prior activity attributed to the CyberAv3ngers group linked to Iran’s Islamic Revolutionary Guard Corps, though direct attribution remains unconfirmed.
Russian State-Supported Group LAUNDRY BEAR Exploits Zero-Day CVE-2025-66376 in Zimbra Collaboration Suite
Synacor’s Zimbra Collaboration Suite was targeted in a zero-day campaign by the Russian state-backed threat actor known as LAUNDRY BEAR. The stored cross-site scripting flaw in the webmail stylesheet handler allowed attackers to steal past emails simply by having victims view a specially crafted HTML message. No user interaction beyond opening the email was required for JavaScript execution in the browser. On 23 July 2026, sixteen countries including the United States, European nations and Australia issued a joint advisory signed by twenty-seven agencies such as NSA, FBI and CISA. The vulnerability received CVE-2025-66376 and a CVSS v3.1 base score of 7.2, rated High. Analysts assess the campaign focused on intelligence collection against Western government and corporate targets.