Sign in

Natto Thoughts

@nattothoughts.bsky.social
149 followers 14 following 36 posts

Cyber threat intelligence research and analysis from geopolitical, economic, social, cultural and linguistic perspectives. www.nattothoughts.com

PostsRepliesMedia
Natto Thoughts @nattothoughts.bsky.social · 17/06/2026
Understanding China’s strategic thinking of the “Taiwan issue” is essential for assessing the country’s possible strategies in both military conflict and cyberspace. www.nattothoughts.com/p/the-inevit...
nattothoughts.com
The Inevitability of Reunification: China’s View of Strategic Drivers for A Potential Taiwan Conflict
For China, Taiwan independence is a relic of the historical struggle between the Chinese people and foreign imperialists; peaceful unification would be ideal, but the use of force remains an option
011
Natto Thoughts @nattothoughts.bsky.social · 03/06/2026
This piece examines the cyber operations and contractors behind efforts targeting critics abroad whom viewed by the CCP as threats to Party control or security. www.nattothoughts.com/p/how-chinas...
nattothoughts.com
How China's Cyber Operations – and the Contractors Behind Them – Target Critics Abroad
State agencies and an ecosystem of private contractors use cyber capabilities and social engineering to locate, monitor, and harass critics living outside China
022
Natto Thoughts @nattothoughts.bsky.social · 20/05/2026
More than one million smart cameras and baby monitors across 118 countries were reportedly exposed through vulnerabilities linked to Chinese IoT firm Meari Technology. But the story is larger than a cybersecurity failure. www.nattothoughts.com/p/is-this-ch...
nattothoughts.com
Is This Chinese Company Watching the World to Train its AI?
The story of Meari Technology reveals how insecure-by-design IoT infrastructure, global surveillance exposure, and China’s tech ecosystem are converging into a new model of AI-enabled data power.
011
Natto Thoughts @nattothoughts.bsky.social · 06/05/2026
Why are Chinese companies obsessed with Palantir Technologies—and is a homegrown counterpart closer than it seems? Natto Thoughts examines China’s next generation of AI-enabled defense firms. www.nattothoughts.com/p/chasing-pa...
nattothoughts.com
Chasing Palantir: Inside China’s Obsession and the Rise of Its Next-Generation AI-enabled Defense Firms
Chinese companies face institutional barriers as they strive to emulate Palantir’s provision of AI-enabled military-industrial applications to governments
000
Natto Thoughts @nattothoughts.bsky.social · 22/04/2026
Where does China stand in AI-driven vulnerability discovery? One company claims its AI-aided bug discovery operates at a scale similar to that claimed for Claude Mythos. What does that actually look like? www.nattothoughts.com/p/where-is-c...
nattothoughts.com
Chinese Firm Claims AI-Driven Bug Discovery Near Claude Mythos Scale
Chinese companies could match the capabilities attributed to Claude Mythos within months, according to industry experts, reinforcing existing cyber offense asymmetries
000
Natto Thoughts @nattothoughts.bsky.social · 08/04/2026
The Natto Team believes that understanding China’s cybersecurity strategy is essential for gaining clearer insight into cyber targeting originating from China. www.nattothoughts.com/p/cybersecur...
nattothoughts.com
Cybersecurity Strategy in China’s 15th Five-Year Plan
China’s high-level cyber strategy for the next five years continues the effort to build a cyber superpower, outlining more detailed requirements
063
Natto Thoughts @nattothoughts.bsky.social · 12/03/2026
France hosts the EU’s densest cluster of cyber partnerships with Chinese defense-linked universities, raising exposure to dual-use knowledge transfer, EU funding access, and institutional influence. New Natto Thoughts’ piece from @euben.bsky.social www.nattothoughts.com/p/faux-amis-...
nattothoughts.com
Faux Amis: How France Stands Apart in Europe’s High-Risk University Cyber Partnerships with China
France hosts the EU’s densest cluster of cyber partnerships with Chinese defense-linked universities, raising exposure to dual-use knowledge transfer, EU funding access, and institutional influence
011
Natto Thoughts @nattothoughts.bsky.social · 25/02/2026
In our latest report, the Natto Team examines how state-affiliated entities—beyond the private sector—support China’s cyber ambitions. www.nattothoughts.com/p/chinas-nat...
nattothoughts.com
China’s National Research Center for Information Technology Security: Is It Part of the PLA Cyberspace Force?
Under “Two signboards” arrangement, the NITSC offers services to public, Party, government, and military entities, under the guise of a civilian name.
000
Natto Thoughts @nattothoughts.bsky.social · 12/02/2026
The Tianfu Cup is back this year. See the analysis of the event by Eugenio @euben.bsky.social published today on Natto Thoughts. www.nattothoughts.com/p/the-tianfu...
nattothoughts.com
The Tianfu Cup Returns Under MPS Leadership as AI Takes Center Stage
After a two-year hiatus, the Tianfu Cup returns under MPS lead, combining AI-assisted vulnerability discovery and exploitation, a new competition track, and less transparency in vulnerability handling
065
Natto Thoughts @nattothoughts.bsky.social · 28/01/2026
We continue exploring provincial level’s involvement in cyber operations. See details in analysis by @euben.bsky.social www.nattothoughts.com/p/provincial...
nattothoughts.com
Provincial Tasking, Cross-Provincial Execution: A Case-Based Look at How China Scales Cyber Operations
How decentralized MSS and MPS tasking and market-enabled, cross-provincial execution by commercial firms shape the scale of China’s cyber operations
053
Natto Thoughts @nattothoughts.bsky.social · 14/01/2026
Intense competition, rapid innovation, and strong state involvement define the overall trends in China’s cybersecurity industry for 2025. See our latest analysis nattothoughts.substack.com/p/chinas-202...
nattothoughts.substack.com
China’s 2025 Top 20 Cybersecurity Companies: Which “Dark Horses” Will Emerge to Prominence in 2026?
Annual ranking reveals hyper-competitive, innovation-focused top performers – some familiar and some not so well known, with extensive government ties
033
Natto Thoughts @nattothoughts.bsky.social · 06/01/2026
From attack–defense thinking to vulnerability research and exposed threat actors, we explored key aspects of China’s cyber ecosystem in 2025. nattothoughts.substack.com/p/a-look-bac...
nattothoughts.substack.com
A Look Back at the Top 5 Natto Thoughts Reports in 2025
From attack–defense thinking to vulnerability research and exposed threat actors, we explored key aspects of China’s cyber ecosystem
000
Natto Thoughts @nattothoughts.bsky.social · 16/12/2025
In this post, @euben.bsky.social and the Natto Team assess that provincial bureaus of the Chinese Ministry of State Security likely operate with their own tasking priorities, resources, and local ecosystems for cyber operations. nattothoughts.substack.com/p/the-many-a...
nattothoughts.substack.com
The Many Arms of the MSS: Why Provincial Bureaus Matter in China’s Cyber Operations
Provincial bureaus of the Chinese Ministry of State Security likely operate with their own tasking priorities, resources, and local ecosystems for cyber operations
023
Natto Thoughts @nattothoughts.bsky.social · 03/12/2025
The Natto Team examines the leaked incident from Knownsec’s perspective to explore the role that elite Chinese cybersecurity companies play in building the country’s cyber capabilities. nattothoughts.substack.com/p/knownsec-t...
nattothoughts.substack.com
Knownsec: The King of Vulnerability Missed Three Vulnerabilities of Its Own
The leak incident involving Chinese cybersecurity firm Knownsec shows the company’s seemingly transparent crisis management strategy and underscores its position in the industry, but mysteries remain.
011
Natto Thoughts @nattothoughts.bsky.social · 19/11/2025
In this Natto Thoughts' piece, with Eugenio Benincasa (@euben.bsky.social), we look into China's attack-defense labs and their role in operationalizing cyber capability for commercial purposes and state-linked cyber operations. nattothoughts.substack.com/p/chinas-cyb...
nattothoughts.substack.com
China’s Cybersecurity Companies Advancing Offensive Cyber Capabilities Through Attack-Defense Labs
Private-sector attack-defense labs form a core pillar of how China builds, sustains, and operationalizes cyber capability for commercial purposes and state-linked cyber operations.
010
Natto Thoughts @nattothoughts.bsky.social · 05/11/2025
Researcher @sick.codes found a vulnerability in TCL TVs and reached out to TCL. What happened next? New analysis from Natto Thoughts - how a single disclosure reshaped China’s approach to cybersecurity and control. nattothoughts.substack.com/p/what-a-nar...
012
Natto Thoughts @nattothoughts.bsky.social · 22/10/2025
The Natto Team explores how APT27, HAFNIUM, and Silk Typhoon highlight the complexities of tracking threat actors and their real-world identities and why understanding the humans behind the keyboard matters. nattothoughts.substack.com/p/beyond-the...
nattothoughts.substack.com
Beyond the Aliases: Decoding Chinese Threat Group Attribution and the Human Factor
Examining the overlap between APT27, HAFNIUM, and Silk Typhoon through recent U.S. government disclosures, and why understanding the humans behind the keyboard is important for cyber defenders
011
Natto Thoughts @nattothoughts.bsky.social · 10/09/2025
Our latest analysis digs into newly identified Salt Typhoon-linked companies, revealing the murky ecosystem of front firms and legitimate businesses that prop up Chinese state cyber operations. A beacon of clarity? Or just more questions in the storm? nattothoughts.substack.com/p/salt-typho...
nattothoughts.substack.com
Salt Typhoon: New Joint Advisory Offers a Beacon Through the Storm but Stirs Up New Questions
Analysis of newly identified Salt Typhoon-linked companies casts light on the complex ecosystem of front companies and real businesses supporting Chinese state cyber operations
052
Natto Thoughts @nattothoughts.bsky.social · 13/08/2025
@euben.bsky.social Eugenio’s research explains the elite cyber talent paradox in China - “all people are soldiers” vs “extremely lean.” #Cybersecurity #TalentPipeline #CyberOperations nattothoughts.substack.com/p/few-and-fa...
nattothoughts.substack.com
Few and Far Between: During China’s Red Hacker Era, Patriotic Hacktivism Was Widespread—Talent Was Not
Inside the small, elite circles that powered China’s massive hacker communities in the late 1990s and 2000s.
022
Reposted by Natto Thoughts
Eugenio Benincasa @euben.bsky.social · 31/07/2025
Microsoft is probing whether a MAPP leak let Chinese hackers exploit a SharePoint vuln pre-patch. In this new piece for Natto, @dakotaindc.bsky.social, @meidanowski.bsky.social & I dig into: 🏛️ China's vuln reporting rules 📉 Which firms joined/left MAPP since 2018 ⚠️ The risks today’s members pose
1114
Natto Thoughts @nattothoughts.bsky.social · 23/07/2025
Natto Thoughts examines HAFNIUM-linked hacker Xu Zewei and reveals ties between China’s state security agencies, cybersecurity firm and strategic industries. nattothoughts.substack.com/p/hafnium-li...
nattothoughts.substack.com
HAFNIUM-Linked Hacker Xu Zewei: Riding the Tides of China’s Cyber Ecosystem
How one man’s career reveals the interconnected web of China’s state security apparatus, cybersecurity firms, and strategic industries
032
Reposted by Natto Thoughts
Eugenio Benincasa @euben.bsky.social · 21/07/2025
1/ China’s cyber capabilities didn’t start top-down, they started with raw hacking talent. The new CSS/ETH report "Before Vegas" traces how informal talent shaped China’s cyber ecosystem, moving from online forums to industry leaders (link in thread).
1158
Natto Thoughts @nattothoughts.bsky.social · 10/07/2025
How has China advanced its AI development to its current state? No single innovation path in AI can be considered definitive. nattothoughts.substack.com/p/debating-c...
nattothoughts.substack.com
Pick Your Innovation Path in AI: Chinese Edition
China’s advances in AI show the effects of a state approach of “introduce, digest, absorb, re-innovate” and years of debate on the balance between market-driven innovation and state-led development
021
Natto Thoughts @nattothoughts.bsky.social · 25/06/2025
What does China’s top vulnerability mining platform’s white hat elite growth system like? What are the capabilities needed to be an expert white hat hacker? nattothoughts.substack.com/p/butian-vul...
nattothoughts.substack.com
Butian Vulnerability Platform: Forging China's Next Generation of White Hat Hackers
From 'Trouser Belt Project' to 'Patching the Sky': Qi An Xin’s Butian platform serves as cradle for nurturing new talent and smelter for refining seasoned hackers’ skills
001
Natto Thoughts @nattothoughts.bsky.social · 11/06/2025
We often questioned how they achieved their current status regarding China developing its cyber offensive capabilities. The Natto Team appreciates @euben.bsky.social for investigating the origin of the defense-through-offense approach.
022
Natto Thoughts @nattothoughts.bsky.social · 28/05/2025
The Natto Team explores the development of China's vulnerability research and discovery skills, starting from the vocational college level. Thanks to @euben.bsky.social @dakotaindc.bsky.social Kristin Del Rosso for their previous research on the topic nattothoughts.substack.com/p/when-a-voc...
nattothoughts.substack.com
From Humble Beginnings: How a Vocational College Became a Vulnerability Powerhouse
Qingyuan Polytechnic's focus on vulnerability studies highlights China's continued efforts in gathering vulnerability resources
0127
Natto Thoughts @nattothoughts.bsky.social · 14/05/2025
The Natto Team continues finding stories of Chinese hackers fascinating as they reveal the motivations behind cyber operations and the evolution of China's information security industry. nattothoughts.substack.com/p/stories-of...
nattothoughts.substack.com
From the World of “Hacker X Files” to the Whitewashed Business Sphere
Jiang Jintao’s journey from hacker to infosec entrepreneur illustrates the blend of ambition, skill, and changes in China's cybersecurity industry
055
Natto Thoughts @nattothoughts.bsky.social · 02/05/2025
This Natto Thoughts analysis was originally published last October. With new notes and updates added, we thought it is still relevant today to understand Russian ransomware actors and Russian political culture. nattothoughts.substack.com/p/ransom-war...
nattothoughts.substack.com
Ransom-War and Russian Political Culture: Trust, Corruption, and Putin's Zero-Sum Sovereignty
Recent Western government revelations about EvilCorp flesh out how Russian ransomware actors and the Russian government use each other to navigate a world they perceive as dangerous.
021
Reposted by Natto Thoughts
Eugenio Benincasa @euben.bsky.social · 16/04/2025
In this piece with @nattothoughts.bsky.social's @meidanowski.bsky.social, we dug into China’s two naming-and-shaming campaigns over the past 30 days—targeting alleged Taiwanese and U.S. hackers amid escalating geopolitical tensions. nattothoughts.substack.com/p/wars-witho...
nattothoughts.substack.com
Wars without Gun Smoke: China Plays the Cyber Name-and-Shame Game on Taiwan and the U.S.
China’s security services have called out hackers of an alleged “Internet Army of Taiwan Independence” and of the U.S. National Security Agency, signaling an increasingly confrontational approach
185
Natto Thoughts @nattothoughts.bsky.social · 02/04/2025
A case study of the i-SOON indictment and leaks reveals that source information may vary but it is important to compare and evaluate information for unique insights. nattothoughts.substack.com/p/indictment...
nattothoughts.substack.com
Indictments and Leaks: Different but Complementary Sources
A case study of the i-SOON indictment and leaks reveals that source information may vary but it is important to compare and evaluate information for unique insights.
054
Natto Thoughts @nattothoughts.bsky.social · 19/03/2025
A recent research from Natto Thoughts about US-sanctioned, allegedly APT27-associated actor. #apt27 nattothoughts.substack.com/p/zhou-shuai...
nattothoughts.substack.com
Zhou Shuai: A Hacker’s Road to APT27
US-sanctioned, allegedly APT27-associated actor Zhou Shuai represents a group of Chinese elite hackers who have become an important resource for Chinese state cyber operations.
052
Natto Thoughts @nattothoughts.bsky.social · 05/03/2025
As the Natto Team was going to publish this piece, US Department of Justice unsealed an indictment charging eight i-SOON employees and highlighting the importance of companies like i-SOON in China's cyberthreat landscape. nattothoughts.substack.com/p/where-is-i...
nattothoughts.substack.com
Where is i-SOON Now?
i-SOON’s business struggles after the leak reflect the cruel reality of China’s hacker-for-hire industry
043
Natto Thoughts @nattothoughts.bsky.social · 28/02/2025
We appreciate that more and more threat intelligence researchers value the importance of cultural component in APT research. @techy.detectionengineering.net
062
Reposted by Natto Thoughts
Eugenio Benincasa @euben.bsky.social · 19/02/2025
If you’re familiar with iOS jailbreaking, then you’ve likely heard of the Pangu Team. 1y after the i-SOON leaks, my latest for @nattothoughts.bsky.social examines Pangu’s ties to i-SOON and the links b/w elite vuln researchers and govt-contracted hackers nattothoughts.substack.com/p/the-pangu-...
nattothoughts.substack.com
The Pangu Team—iOS Jailbreak and Vulnerability Research Giant: A Member of i-SOON’s Exploit-Sharing Network
A year after the i-SOON leaks, a deep dive into the Pangu Team reveals new insight into the relationships between elite vulnerability researchers and government-contracted hackers
01510
Natto Thoughts @nattothoughts.bsky.social · 18/02/2025
We are glad to see that some curious minds like us want to find out more about Chinese APTs associated companies in reality. They actually paid a visit to them. substack.com/home/post/p-...
substack.com
Chasing Chengdu404, Sichuan Silence....and NoSugar Technology !?
On the ground research on US sanctioned cyber security companies in China.
032
Natto Thoughts @nattothoughts.bsky.social · 06/02/2025
Even before DeepSeek's debut sparked pride among Chinese netizens, US sanctions on Sichuan Silence developer Guan Tianfeng triggered online vows to "march forward" in cyberpower competition. nattothoughts.substack.com/p/sichuan-si...
nattothoughts.substack.com
Sichuan Silence Information Technology and Guan Tianfeng: Your Criminal Our Hero
Even before DeepSeek's debut sparked pride among Chinese netizens, US sanctions on Sichuan Silence developer Guan Tianfeng triggered online vows to "march forward" in cyberpower competition
042
Natto Thoughts @nattothoughts.bsky.social · 22/01/2025
The other shoe has finally dropped, but we still need more intrusion details to defend against the threats. #salttyphoon #apt nattothoughts.substack.com/p/salt-typho...
nattothoughts.substack.com
Salt Typhoon: the Other Shoe Has Dropped, but Consternation Continues
Sichuan Juxinhe, directly involved in the Salt Typhoon cyber operations, resembles a front company of the Chinese Ministry of State Security
043
Natto Thoughts @nattothoughts.bsky.social · 17/12/2024
Thank you for your support. The Natto Team appreciates it.
1000 subscribers. You did it. Natto Thoughts has  its first thousand subscribers. Nattothoughts.substack.com
072
Natto Thoughts @nattothoughts.bsky.social · 11/12/2024
Natto Thoughts is honored to have guest contributor Eugenio Benincasa discussing China’s pubic opinion analysis systems and how Bluesky should outsmart them. @euben.bsky.social nattothoughts.substack.com/p/bluesky-sh...
nattothoughts.substack.com
Bluesky Should Outsmart China's Public Opinion Monitoring Tools to Safeguard Public Discourse
The Chinese government has leveraged public opinion analysis systems to target U.S. social media platforms to tamper with public discourse in the past. Will Bluesky be included? most likely yes.
031
Natto Thoughts @nattothoughts.bsky.social · 04/12/2024
The Natto Team follows up on the findings of Sophos' Pacific Rim reports and provides a deep dive into Sichuan Silence Information Technology company - a Chengdu-based jack-of-all-trades infosec company. nattothoughts.substack.com/p/sichuan-si...
nattothoughts.substack.com
Sichuan Silence Information Technology: Great Sounds are Often Inaudible
Formerly very public, Sichuan Silence has gone quiet since 2020; but as part of a circle of Chengdu-based jack-of-all-trades infosec companies, it serves the state in cyber-enabled operations
164