Tailored Access Operations (TAO) is a specialized offensive cyber and foreign-network exploitation unit of the United States National Security Agency (NSA). Established in the early 1990s, it conducts cyber espionage and supports U.S. national-security and covert operations. The unit was subsequently renamed the Office of Computer Network Operations (CNO), before the NSA restored the Tailored Access Operations name. TAO develops and deploys custom intrusion tools, exploits, and software implants tailored to foreign targets. Its operations establish covert access to computer systems and maintain intelligence-collection capabilities for months or years. Its tradecraft includes automated data collection, exfiltration, and concealment of intrusion activity. Intelligence objectives include foreign military readiness, political developments among potential adversaries, terrorist financial networks, international money laundering, and drug-trafficking operations. TAO combines operators, developers, and analysts to support targeted intelligence collection. It has collaborated with the CIA on network intrusions for espionage and contributed to the development of Stuxnet, the cyber weapon used to sabotage Iran’s nuclear program. Its dominant mission is intelligence collection rather than financially motivated cybercrime or ransomware.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An elite NSA hacking organization expected to be assigned to the NSA's new Global Intelligence mission center as part of the agency reorganization.
The NSA's secretive elite hacking unit is holding a reunion for former members as part of an effort to rebuild the unit.
NSA offensive cyber-operations unit conducting intrusions into foreign computer networks for intelligence collection and deploying persistent espionage implants. The unit also helped develop Stuxnet and is seeking to recruit former personnel following workforce attrition.
The NSA's named offensive hacking unit is used as a workforce comparison to support the article's argument that intelligence collection and analysis require substantially more institutional manpower than technical intrusion capabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.