The National Security Agency (NSA) is a United States signals intelligence and cyber operations organization widely associated with advanced offensive cyber capabilities. Public reporting and historical disclosures have linked the NSA to sophisticated hardware implants and covert access tooling, including the COTTONMOUTH family, reflecting mature capabilities in stealthy access, persistence, and post-exploitation. The agency is commonly characterized as a top-tier state cyber operator with the ability to conduct long-term, technically complex operations against high-value targets. Recent public allegations by China’s Ministry of State Security accuse the NSA of conducting long-term covert cyber operations against China’s National Time Service Center beginning in 2022. Those allegations claim exploitation of mobile messaging-service vulnerabilities to compromise staff devices, theft of sensitive information, use of stolen credentials to access internal systems, reconnaissance of internal networks, and later deployment of a cyberwarfare platform against precision timing infrastructure. The same allegations describe concealment through forged certificates, encryption, and globally distributed infrastructure. These claims remain allegations and were not publicly substantiated with evidence in the reporting. Taken together, the NSA is best understood as a U.S. state cyber actor focused primarily on intelligence collection and strategic access. Reported and alleged tradecraft includes initial access through vulnerability exploitation, credential theft, reconnaissance, persistence, defense evasion, and post-exploitation against strategically significant targets, including critical infrastructure and government-linked entities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Alleged to have exploited vulnerabilities in messaging services of a foreign mobile phone brand to steal sensitive information from the Chinese National Time Center.
Allegedly conducting long-term, highly covert cyber operations against China’s National Time Service Center, including compromising staff mobile devices, stealing sensitive data, and attempting to infiltrate internal networks. The operations reportedly escalated in 2023 with the deployment of a new cyberwarfare platform targeting high-precision timing networks.
The NSA is accused of conducting cyber-espionage operations against China’s National Time Service Center, targeting sensitive data and critical infrastructure related to national timekeeping. The operations reportedly involved exploiting mobile phone vulnerabilities, credential theft, network infiltration, and deployment of a cyber warfare platform with multiple tools for data theft and disruption.
Allegedly conducted a cyber attack against China's National Time Service Center, targeting critical timekeeping infrastructure that supports communications, finance, power, transportation, defense, and other sectors. The operation reportedly involved exploiting an SMS vulnerability to compromise mobile devices of staff and steal sensitive data, with the potential to disrupt national and international time services.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.