Natto Thoughts's Avatar

Natto Thoughts

@nattothoughts.bsky.social

Cyber threat intelligence research and analysis from geopolitical, economic, social, cultural and linguistic perspectives.

105 Followers  |  10 Following  |  17 Posts  |  Joined: 04.12.2024  |  1.5992

Latest posts by nattothoughts.bsky.social on Bluesky

Post image

Microsoft is probing whether a MAPP leak let Chinese hackers exploit a SharePoint vuln pre-patch.

In this new piece for Natto,
@dakotaindc.bsky.social, @meidanowski.bsky.social & I dig into:
๐Ÿ›๏ธ China's vuln reporting rules
๐Ÿ“‰ Which firms joined/left MAPP since 2018
โš ๏ธ The risks todayโ€™s members pose

31.07.2025 16:44 โ€” ๐Ÿ‘ 5    ๐Ÿ” 3    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
HAFNIUM-Linked Hacker Xu Zewei: Riding the Tides of Chinaโ€™s Cyber Ecosystem How one manโ€™s career reveals the interconnected web of Chinaโ€™s state security apparatus, cybersecurity firms, and strategic industries

Natto Thoughts examines HAFNIUM-linked hacker Xu Zewei and reveals ties between Chinaโ€™s state security agencies, cybersecurity firm and strategic industries.
nattothoughts.substack.com/p/hafnium-li...

23.07.2025 16:20 โ€” ๐Ÿ‘ 2    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

1/ Chinaโ€™s cyber capabilities didnโ€™t start top-down, they started with raw hacking talent. The new CSS/ETH report "Before Vegas" traces how informal talent shaped Chinaโ€™s cyber ecosystem, moving from online forums to industry leaders (link in thread).

21.07.2025 08:11 โ€” ๐Ÿ‘ 14    ๐Ÿ” 8    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Pick Your Innovation Path in AI: Chinese Edition Chinaโ€™s advances in AI show the effects of a state approach of โ€œintroduce, digest, absorb, re-innovateโ€ and years of debate on the balance between market-driven innovation and state-led development

How has China advanced its AI development to its current state? No single innovation path in AI can be considered definitive.

nattothoughts.substack.com/p/debating-c...

10.07.2025 19:14 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Butian Vulnerability Platform: Forging China's Next Generation of White Hat Hackers From 'Trouser Belt Project' to 'Patching the Sky': Qi An Xinโ€™s Butian platform serves as cradle for nurturing new talent and smelter for refining seasoned hackersโ€™ skills

What does Chinaโ€™s top vulnerability mining platformโ€™s white hat elite growth system like? What are the capabilities needed to be an expert white hat hacker?

nattothoughts.substack.com/p/butian-vul...

25.06.2025 18:24 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

We often questioned how they achieved their current status regarding China developing its cyber offensive capabilities. The Natto Team appreciates @euben.bsky.social for investigating the origin of the defense-through-offense approach.

11.06.2025 16:53 โ€” ๐Ÿ‘ 2    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
From Humble Beginnings: How a Vocational College Became a Vulnerability Powerhouse Qingyuan Polytechnic's focus on vulnerability studies highlights China's continued efforts in gathering vulnerability resources

The Natto Team explores the development of China's vulnerability research and discovery skills, starting from the vocational college level.

Thanks to @euben.bsky.social @dakotaindc.bsky.social Kristin Del Rosso for their previous research on the topic

nattothoughts.substack.com/p/when-a-voc...

28.05.2025 16:46 โ€” ๐Ÿ‘ 11    ๐Ÿ” 7    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Preview
From the World of โ€œHacker X Filesโ€ to the Whitewashed Business Sphere Jiang Jintaoโ€™s journey from hacker to infosec entrepreneur illustrates the blend of ambition, skill, and changes in China's cybersecurity industry

The Natto Team continues finding stories of Chinese hackers fascinating as they reveal the motivations behind cyber operations and the evolution of China's information security industry.

nattothoughts.substack.com/p/stories-of...

14.05.2025 16:22 โ€” ๐Ÿ‘ 5    ๐Ÿ” 5    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 2
Preview
Ransom-War and Russian Political Culture: Trust, Corruption, and Putin's Zero-Sum Sovereignty Recent Western government revelations about EvilCorp flesh out how Russian ransomware actors and the Russian government use each other to navigate a world they perceive as dangerous.

This Natto Thoughts analysis was originally published last October. With new notes and updates added, we thought it is still relevant today to understand Russian ransomware actors and Russian political culture.

nattothoughts.substack.com/p/ransom-war...

02.05.2025 04:54 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Wars without Gun Smoke: China Plays the Cyber Name-and-Shame Game on Taiwan and the U.S. Chinaโ€™s security services have called out hackers of an alleged โ€œInternet Army of Taiwan Independenceโ€ and of the U.S. National Security Agency, signaling an increasingly confrontational approach

In this piece with @nattothoughts.bsky.social's @meidanowski.bsky.social, we dug into Chinaโ€™s two naming-and-shaming campaigns over the past 30 daysโ€”targeting alleged Taiwanese and U.S. hackers amid escalating geopolitical tensions.

nattothoughts.substack.com/p/wars-witho...

16.04.2025 16:17 โ€” ๐Ÿ‘ 8    ๐Ÿ” 5    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Indictments and Leaks: Different but Complementary Sources A case study of the i-SOON indictment and leaks reveals that source information may vary but it is important to compare and evaluate information for unique insights.

A case study of the i-SOON indictment and leaks reveals that source information may vary but it is important to compare and evaluate information for unique insights.

nattothoughts.substack.com/p/indictment...

02.04.2025 17:13 โ€” ๐Ÿ‘ 5    ๐Ÿ” 4    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Zhou Shuai: A Hackerโ€™s Road to APT27 US-sanctioned, allegedly APT27-associated actor Zhou Shuai represents a group of Chinese elite hackers who have become an important resource for Chinese state cyber operations.

A recent research from Natto Thoughts about US-sanctioned, allegedly APT27-associated actor. #apt27

nattothoughts.substack.com/p/zhou-shuai...

19.03.2025 16:17 โ€” ๐Ÿ‘ 5    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Where is i-SOON Now? i-SOONโ€™s business struggles after the leak reflect the cruel reality of Chinaโ€™s hacker-for-hire industry

As the Natto Team was going to publish this piece, US Department of Justice unsealed an indictment charging eight i-SOON employees and highlighting the importance of companies like i-SOON in China's cyberthreat landscape.

nattothoughts.substack.com/p/where-is-i...

05.03.2025 17:32 โ€” ๐Ÿ‘ 4    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

We appreciate that more and more threat intelligence researchers value the importance of cultural component in APT research. @techy.detectionengineering.net

28.02.2025 03:05 โ€” ๐Ÿ‘ 6    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
The Pangu Teamโ€”iOS Jailbreak and Vulnerability Research Giant: A Member of i-SOONโ€™s Exploit-Sharing Network A year after the i-SOON leaks, a deep dive into the Pangu Team reveals new insight into the relationships between elite vulnerability researchers and government-contracted hackers

If youโ€™re familiar with iOS jailbreaking, then youโ€™ve likely heard of the Pangu Team.

1y after the i-SOON leaks, my latest for @nattothoughts.bsky.social examines Panguโ€™s ties to i-SOON and the links b/w elite vuln researchers and govt-contracted hackers

nattothoughts.substack.com/p/the-pangu-...

19.02.2025 17:07 โ€” ๐Ÿ‘ 16    ๐Ÿ” 10    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Chasing Chengdu404, Sichuan Silence....and NoSugar Technology !? On the ground research on US sanctioned cyber security companies in China.

We are glad to see that some curious minds like us want to find out more about Chinese APTs associated companies in reality. They actually paid a visit to them.

substack.com/home/post/p-...

18.02.2025 17:58 โ€” ๐Ÿ‘ 3    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Sichuan Silence Information Technology and Guan Tianfeng: Your Criminal Our Hero Even before DeepSeek's debut sparked pride among Chinese netizens, US sanctions on Sichuan Silence developer Guan Tianfeng triggered online vows to "march forward" in cyberpower competition

Even before DeepSeek's debut sparked pride among Chinese netizens, US sanctions on Sichuan Silence developer Guan Tianfeng triggered online vows to "march forward" in cyberpower competition.

nattothoughts.substack.com/p/sichuan-si...

06.02.2025 00:30 โ€” ๐Ÿ‘ 4    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Salt Typhoon: the Other Shoe Has Dropped, but Consternation Continues Sichuan Juxinhe, directly involved in the Salt Typhoon cyber operations, resembles a front company of the Chinese Ministry of State Security

The other shoe has finally dropped, but we still need more intrusion details to defend against the threats.
#salttyphoon #apt

nattothoughts.substack.com/p/salt-typho...

22.01.2025 17:45 โ€” ๐Ÿ‘ 4    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
1000 subscribers. You did it. Natto Thoughts has  its first thousand subscribers. Nattothoughts.substack.com

1000 subscribers. You did it. Natto Thoughts has its first thousand subscribers. Nattothoughts.substack.com

Thank you for your support. The Natto Team appreciates it.

17.12.2024 15:31 โ€” ๐Ÿ‘ 7    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 2
Preview
Bluesky Should Outsmart China's Public Opinion Monitoring Tools to Safeguard Public Discourse The Chinese government has leveraged public opinion analysis systems to target U.S. social media platforms to tamper with public discourse in the past. Will Bluesky be included? most likely yes.

Natto Thoughts is honored to have guest contributor Eugenio Benincasa discussing Chinaโ€™s pubic opinion analysis systems and how Bluesky should outsmart them. @euben.bsky.social nattothoughts.substack.com/p/bluesky-sh...

11.12.2024 18:24 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Sichuan Silence Information Technology: Great Sounds are Often Inaudible Formerly very public, Sichuan Silence has gone quiet since 2020; but as part of a circle of Chengdu-based jack-of-all-trades infosec companies, it serves the state in cyber-enabled operations

The Natto Team follows up on the findings of Sophos' Pacific Rim reports and provides a deep dive into Sichuan Silence Information Technology company - a Chengdu-based jack-of-all-trades infosec company.

nattothoughts.substack.com/p/sichuan-si...

04.12.2024 18:45 โ€” ๐Ÿ‘ 6    ๐Ÿ” 4    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@nattothoughts is following 10 prominent accounts