Tailored Access Operations (TAO) is the National Security Agency’s elite offensive cyber and computer network exploitation unit, historically responsible for penetrating foreign computer networks to collect intelligence in support of U.S. national security objectives. It is a U.S. government cyber espionage organization rather than a criminal or ransomware actor, and its dominant mission has been foreign intelligence collection against overseas targets. TAO has also been referred to as TAO and, during part of an organizational restructuring, as the Office of Computer Network Operations before the historic TAO name was restored. TAO is widely regarded as one of the most capable cyber operators in existence. Its mission set includes developing and deploying custom intrusion capabilities, including bespoke software tools and implants, to gain access to foreign systems and maintain covert collection. Reported intelligence priorities have included terrorist financial networks, international money-laundering and drug operations, the readiness of foreign militaries, and the internal political dynamics of potential adversaries. Former officials have described the unit as highly automated at scale while still able to conduct tailored operations against hardened targets. The unit has been associated with advanced tradecraft including initial access, persistence, post-exploitation, privilege escalation, defense evasion, reconnaissance, and spoofing or false-flagging of activity to obscure attribution. TAO has also been linked to the development of custom offensive tooling and to high-profile U.S. cyber operations, including reported involvement in Stuxnet against Iran’s nuclear program. Public attention to TAO increased significantly after the Shadow Brokers leak exposed stolen NSA offensive tooling, some of which was later repurposed by other actors in destructive and criminal campaigns. TAO operates within the broader U.S. intelligence and defense ecosystem and has had operational relationships with other agencies, including reported support from CIA cyber elements in some espionage operations. Its activities are best understood as state-directed cyber espionage and access operations conducted on behalf of the United States.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
NSA offensive cyber operations unit focused on developing and deploying bespoke capabilities to penetrate foreign networks for espionage and sabotage operations.
Used as an illustrative example of a highly capable state cyber actor whose relevance depends on intent, not capability alone.
An elite NSA hacking unit referenced as conducting cyber espionage by breaking into computer networks, with CIA support mentioned via the Technology Management Office.
A secretive NSA unit conducting cyber espionage and computer network exploitation to steal electronic data at rest from foreign targets worldwide for intelligence gathering.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.