NASA's Office of Inspector General disclosed that Chinese national Song Wu allegedly conducted a years-long spear-phishing and impersonation campaign to obtain sensitive aerospace and defense-related software, source code, and other controlled technical information from NASA personnel, other U.S. government agencies, universities, and private companies. U.S. authorities said the operation ran from 2017 through 2021 and relied on fraudulent emails and false identities, with Wu posing as U.S. engineers, friends, and colleagues to persuade victims to share restricted data in violation of export control laws.
The U.S. Department of Justice charged Wu in September 2024 with wire fraud and aggravated identity theft, and the FBI has since placed him on its Most Wanted list. Investigators identified him as an engineer at the Aviation Industry Corporation of China (AVIC) and assessed the stolen software as having both industrial and military applications, including advanced tactical missile development and aerodynamic weapons design, underscoring the campaign's significance for U.S. national security and the defense industrial base.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
NASA's Office of Inspector General disclosed details of the alleged Chinese phishing operation, including its targeting of NASA personnel and the FBI's assessment that the stolen software had industrial and military applications.
Following the charges, Song Wu remained at large and was added to the FBI's Most Wanted list in connection with the alleged theft of sensitive aerospace and defense-related technical information.
In September 2024, the U.S. Department of Justice charged Song Wu, an engineer identified as working for AVIC, with wire fraud and aggravated identity theft for the alleged phishing and impersonation scheme.
From January 2017 through December 2021, Song Wu allegedly conducted a multi-year spear-phishing and impersonation campaign targeting NASA employees, other U.S. government agencies, universities, and private companies to obtain export-controlled aerospace and defense software and source code.
The Manhattan U.S. Attorney and FBI announced charges against seven individuals for allegedly engineering a sophisticated internet fraud scheme that infected millions of computers worldwide and manipulated the internet advertising business.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcemalwarebytes.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcefbi.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.