Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
phishing-campaign-intelligencestate-sponsored-espionagegovernment-diplomatic-threatidentity-impersonation-fraud

Chinese Phishing Campaign Stole NASA and Defense Software Source Code

Updated 2mo agoFirst seen Apr 11, 20265 sources

NASA's Office of Inspector General disclosed that Chinese national Song Wu allegedly conducted a years-long spear-phishing and impersonation campaign to obtain sensitive aerospace and defense-related software, source code, and other controlled technical information from NASA personnel, other U.S. government agencies, universities, and private companies. U.S. authorities said the operation ran from 2017 through 2021 and relied on fraudulent emails and false identities, with Wu posing as U.S. engineers, friends, and colleagues to persuade victims to share restricted data in violation of export control laws.

The U.S. Department of Justice charged Wu in September 2024 with wire fraud and aggravated identity theft, and the FBI has since placed him on its Most Wanted list. Investigators identified him as an engineer at the Aviation Industry Corporation of China (AVIC) and assessed the stolen software as having both industrial and military applications, including advanced tactical missile development and aerodynamic weapons design, underscoring the campaign's significance for U.S. national security and the defense industrial base.

Share:
Chinese Phishing Campaign Stole NASA and Defense Software Source Code
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Apr 24, 20262mo ago

NASA OIG publicly discloses details of the campaign

NASA's Office of Inspector General disclosed details of the alleged Chinese phishing operation, including its targeting of NASA personnel and the FBI's assessment that the stolen software had industrial and military applications.

FBI adds Song Wu to Most Wanted list

Following the charges, Song Wu remained at large and was added to the FBI's Most Wanted list in connection with the alleged theft of sensitive aerospace and defense-related technical information.

Sep 1, 20242y ago

Song Wu charged with wire fraud and identity theft

In September 2024, the U.S. Department of Justice charged Song Wu, an engineer identified as working for AVIC, with wire fraud and aggravated identity theft for the alleged phishing and impersonation scheme.

Jan 1, 20179y ago

Chinese spear-phishing campaign targeted NASA and defense-related entities

From January 2017 through December 2021, Song Wu allegedly conducted a multi-year spear-phishing and impersonation campaign targeting NASA employees, other U.S. government agencies, universities, and private companies to obtain export-controlled aerospace and defense software and source code.

Nov 9, 201115y ago

Internet fraud scheme operators charged in Manhattan

The Manhattan U.S. Attorney and FBI announced charges against seven individuals for allegedly engineering a sophisticated internet fraud scheme that infected millions of computers worldwide and manipulated the internet advertising business.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Affected products
2 linked
LinkedinGmail
Organizations
4 linked
Aviation Industry Corporation of ChinaThe Hacker NewsMalwarebytesSecurity Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.