CSIDB logo
Threat actor

National Security Agency

Attribution profile

Type
Nation State
Location
United States of America
Known incidents
3 incidents
First seen
2014-01-28
Last seen
2022-09-11
Updated
2026-07-31 08:06
Aliases
3 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known publicly as the National Security Agency (NSA) also operates under the alias “No Such Agency” and is based in the United States of America. Public attributions and official statements consistently link the actor to the U.S. intelligence community, establishing a clear state nexus rather than a criminal consortium. The actor’s identity is reinforced by references to specific personnel such as Rob Joyce, the director of cybersecurity at the NSA, and by the use of malware historically associated with the agency, including tools exposed in the Shadow Brokers leaks.

Targeting patterns observed in reported incidents include military‑affiliated research institutions in China, government personnel and diplomatic staff using iOS devices, and broad user bases of popular mobile applications such as Angry Birds. Strategic objectives described in the sources emphasize the collection of sensitive information and the exploitation of communications platforms for intelligence gathering, with occasional references to actions that could endanger critical infrastructure or serve as protest vectors. No explicit mention of financial gain appears in the provided material, focusing instead on espionage‑related goals.

Noted tactics, techniques, and procedures involve the deployment of zero‑click iMessage exploits that deliver malware capable of executing code without user interaction, collecting system and user data, and then removing traces while lacking persistence mechanisms. The actor has also been linked to the use of front companies and fictitious identities to register domain names and SSL certificates, as well as to DNS tampering that redirects traffic to spoofed pages for defacement or surveillance purposes. Malware families referenced are those historically tied to the NSA through the Shadow Brokers disclosures, and initial access vectors described include iMessage zero‑click exploits and manipulation of advertising networks or DNS infrastructure. Representative campaigns cited are the alleged 2022 intrusion of Northwestern Polytechnical University, the 2019 iPhone zero‑click iMessage operation, and the 2014 Angry Birds website defacement incident tied to surveillance concerns.

Incidents

Attributed incidents are available to members.

3 incidents
CSIDB