securitylab_nJuly 12, 2026🇷🇺Translated from Russian

NSA Revives Elite TAO Hacking Unit Behind Stuxnet and WannaCry to Accelerate Cyber Operations Against China and Adversaries

The U.S. National Security Agency has restored the original name Tailored Access Operations (TAO) to its premier cyber intrusion division as part of a major internal restructuring aimed at accelerating offensive operations against hostile nations, including China.

Until recently, the unit operated under the name Office of Computer Network Operations (CNO). The decision to revive the well-known TAO designation reverses part of the NSA21 reform launched in 2016, which had distributed offensive operations and intelligence collection across larger directorates and eliminated TAO as a standalone structure.

Former NSA employees noted that the previous reorganization failed to improve collaboration between developers and operators and instead created greater separation. The revival was overseen by Deputy NSA Director Tim Kosiba, who previously served in TAO. The updated organizational structure was presented to U.S. Defense Secretary Pete Hegseth during his visit to Fort Meade, home to both NSA and U.S. Cyber Command headquarters.

Starting next month, TAO will receive its own dedicated building within the Fort Meade complex. Former personnel believe that reuniting developers and operational teams will accelerate the preparation of cyber attacks and help discover new methods of penetrating highly protected networks, especially amid rapid advances in artificial intelligence.

TAO specializes in creating custom tools for covert access to foreign computer systems. These include malware, persistence mechanisms, and other specialized implants used in intelligence-gathering operations.

The unit has been linked to several high-profile cyber operations and tools. It played a role in developing Stuxnet, the sophisticated worm used to disrupt Iran’s nuclear enrichment program. TAO also became the focus of attention after the Shadow Brokers group leaked stolen NSA tools, including the EternalBlue exploit.

EternalBlue was later weaponized in the WannaCry ransomware attack of 2017, which spread to approximately 150 countries and affected around 200,000 organizations worldwide.

Around the same period, former NSA contractor Harold Martin, who worked in TAO between 2012 and 2015, was accused of storing a massive collection of classified materials at his home. In 2019 he was sentenced to nine years in prison, although investigators never proved he had shared the stolen information with others.

Related articles

Security NEXTState-Sponsored & APT

Russian State-Supported Group LAUNDRY BEAR Exploits Zero-Day CVE-2025-66376 in Zimbra Collaboration Suite

Synacor’s Zimbra Collaboration Suite was targeted in a zero-day campaign by the Russian state-backed threat actor known as LAUNDRY BEAR. The stored cross-site scripting flaw in the webmail stylesheet handler allowed attackers to steal past emails simply by having victims view a specially crafted HTML message. No user interaction beyond opening the email was required for JavaScript execution in the browser. On 23 July 2026, sixteen countries including the United States, European nations and Australia issued a joint advisory signed by twenty-seven agencies such as NSA, FBI and CISA. The vulnerability received CVE-2025-66376 and a CVSS v3.1 base score of 7.2, rated High. Analysts assess the campaign focused on intelligence collection against Western government and corporate targets.

安全客State-Sponsored & APT

Russian Intelligence Hijacks Exposed Security Cameras in Europe and Ukraine for Military Surveillance

Dutch intelligence agencies AIVD and MIVD have revealed that Russian military intelligence is systematically compromising internet-connected security cameras across Europe and Ukraine. The attackers scan for exposed devices using brand fingerprints, then log in with default passwords and outdated firmware without needing zero-day exploits. In Ukraine, live camera feeds are used not only for reconnaissance of military transport routes and weapon deliveries but also to directly support targeting of Ukrainian forces and equipment. Censys identified over 87,000 vulnerable cameras in the EU, NATO countries, and Ukraine, with more than 4,000 located in Ukraine alone. While the actual number of confirmed compromises is smaller, the cameras are strategically positioned along key military logistics routes. The agencies issued basic but critical recommendations including disabling public exposure, changing default credentials, and applying patches for known vulnerabilities such as CVE-2016-7407 and CVE-2021-39275.

securitylab_nState-Sponsored & APT

US Accuses Russian Cybersecurity Specialist D.O. of Void Blizzard Attacks on European Governments and US Companies, Kaspersky Ties Emerge

American authorities have charged Russian information security specialist D.O. with participating in cyberattacks by the Void Blizzard group, also known as Laundry Bear, targeting NATO-aligned European government agencies and at least 11 US companies since 2023. D.O., who previously held a senior position at one of Russia’s largest cybersecurity firms widely identified as Kaspersky, did not plead guilty during a court hearing in Boston. The US Department of Commerce banned the company’s software in 2024 over national security concerns, while European agencies had issued similar warnings earlier. Prosecutors also linked D.O. to a Nizhny Novgorod IT company where he served as deputy director from 2024, although his earlier Kaspersky employment was confirmed through salary records and a former colleague rather than the indictment itself. D.O. graduated from Bauman Moscow State Technical University with a degree in information security, an institution previously flagged by European journalists as a potential training ground for state-linked operatives. Experts note that movement between commercial cybersecurity roles and intelligence structures occurs across countries, but D.O.’s guilt remains to be proven in court.

安全客State-Sponsored & APT

Iranian State-Sponsored Hackers Unveil Cavern C2 Framework: Multi-Format .NET Compilation Bypasses All Security Detection Tools

In July 2026, Check Point Research exposed Cavern Manticore, an Iranian MOIS-linked APT group, actively targeting Israeli IT providers and government entities with a sophisticated modular C2 framework called Cavern (also known as Cav3rn). Unlike previous Iranian groups that rely on public tools, this actor built an entirely custom .NET-based framework deliberately compiled into three incompatible binary formats—pure IL, mixed-mode C++/CLI, and .NET 8 Native AOT—to force analysts to maintain multiple reverse-engineering toolchains and dramatically increase operational costs. The framework achieves near-zero detection rates on VirusTotal by avoiding traditional obfuscation and instead weaponizing compilation formats themselves, with modules running in isolated AppDomains that leave no persistent artifacts. Attackers gain initial access through compromised RMM solutions such as SysAid, abusing legitimate update mechanisms to sideload the Cavern Agent disguised as uxtheme.dll via a WinDirStat DLL side-loading chain. Communication uses XOR encryption with Base64 encoding, fixed Edge User-Agent strings, custom headers, and a unique protocol syntax, while supporting hot updates and aggressive cleanup. The campaign coincides with parallel operations by MuddyWater against regional targets, highlighting Iran’s coordinated escalation in cyberspace and the growing threat of supply-chain trust abuse against MSPs and RMM platforms worldwide.