Advertisement · 728 × 90

Posts by Mei Danowski

Preview
Cybersecurity Strategy in China’s 15th Five-Year Plan China’s high-level cyber strategy for the next five years continues the effort to build a cyber superpower, outlining more detailed requirements

The Natto Team believes that understanding China’s cybersecurity strategy is essential for gaining clearer insight into cyber targeting originating from China.

www.nattothoughts.com/p/cybersecur...

1 week ago 7 4 0 1
Preview
The Tianfu Cup Returns Under MPS Leadership as AI Takes Center Stage After a two-year hiatus, the Tianfu Cup returns under MPS lead, combining AI-assisted vulnerability discovery and exploitation, a new competition track, and less transparency in vulnerability handling

The Tianfu Cup is back this year. See the analysis of the event by Eugenio @euben.bsky.social published today on Natto Thoughts.

www.nattothoughts.com/p/the-tianfu...

2 months ago 6 5 0 0
Preview
Provincial Tasking, Cross-Provincial Execution: A Case-Based Look at How China Scales Cyber Operations How decentralized MSS and MPS tasking and market-enabled, cross-provincial execution by commercial firms shape the scale of China’s cyber operations

We continue exploring provincial level’s involvement in cyber operations. See details in analysis by @euben.bsky.social

www.nattothoughts.com/p/provincial...

2 months ago 5 3 0 0
Preview
China’s 2025 Top 20 Cybersecurity Companies: Which “Dark Horses” Will Emerge to Prominence in 2026? Annual ranking reveals hyper-competitive, innovation-focused top performers – some familiar and some not so well known, with extensive government ties

Intense competition, rapid innovation, and strong state involvement define the overall trends in China’s cybersecurity industry for 2025. See our latest analysis

nattothoughts.substack.com/p/chinas-202...

3 months ago 3 4 0 0
Preview
The Many Arms of the MSS: Why Provincial Bureaus Matter in China’s Cyber Operations Provincial bureaus of the Chinese Ministry of State Security likely operate with their own tasking priorities, resources, and local ecosystems for cyber operations

In this post, @euben.bsky.social and the Natto Team assess that provincial bureaus of the Chinese Ministry of State Security likely operate with their own tasking priorities, resources, and local ecosystems for cyber operations.

nattothoughts.substack.com/p/the-many-a...

4 months ago 2 3 0 0
Post image

Researcher @sick.codes found a vulnerability in TCL TVs and reached out to TCL. What happened next?
New analysis from Natto Thoughts - how a single disclosure reshaped China’s approach to cybersecurity and control.

nattothoughts.substack.com/p/what-a-nar...

5 months ago 1 2 0 0
Preview
Beyond the Aliases: Decoding Chinese Threat Group Attribution and the Human Factor Examining the overlap between APT27, HAFNIUM, and Silk Typhoon through recent U.S. government disclosures, and why understanding the humans behind the keyboard is important for cyber defenders

The Natto Team explores how APT27, HAFNIUM, and Silk Typhoon highlight the complexities of tracking threat actors and their real-world identities and why understanding the humans behind the keyboard matters.

nattothoughts.substack.com/p/beyond-the...

5 months ago 1 1 0 0
Advertisement
Preview
Salt Typhoon: New Joint Advisory Offers a Beacon Through the Storm but Stirs Up New Questions Analysis of newly identified Salt Typhoon-linked companies casts light on the complex ecosystem of front companies and real businesses supporting Chinese state cyber operations

Our latest analysis digs into newly identified Salt Typhoon-linked companies, revealing the murky ecosystem of front firms and legitimate businesses that prop up Chinese state cyber operations.

A beacon of clarity? Or just more questions in the storm?

nattothoughts.substack.com/p/salt-typho...

7 months ago 5 2 0 0
Preview
Few and Far Between: During China’s Red Hacker Era, Patriotic Hacktivism Was Widespread—Talent Was Not Inside the small, elite circles that powered China’s massive hacker communities in the late 1990s and 2000s.

@euben.bsky.social Eugenio’s research explains the elite cyber talent paradox in China - “all people are soldiers” vs “extremely lean.”

#Cybersecurity #TalentPipeline #CyberOperations

nattothoughts.substack.com/p/few-and-fa...

8 months ago 2 2 0 0
Post image

Microsoft is probing whether a MAPP leak let Chinese hackers exploit a SharePoint vuln pre-patch.

In this new piece for Natto,
@dakotaindc.bsky.social, @meidanowski.bsky.social & I dig into:
🏛️ China's vuln reporting rules
📉 Which firms joined/left MAPP since 2018
⚠️ The risks today’s members pose

8 months ago 12 4 1 0
Preview
HAFNIUM-Linked Hacker Xu Zewei: Riding the Tides of China’s Cyber Ecosystem How one man’s career reveals the interconnected web of China’s state security apparatus, cybersecurity firms, and strategic industries

Natto Thoughts examines HAFNIUM-linked hacker Xu Zewei and reveals ties between China’s state security agencies, cybersecurity firm and strategic industries.
nattothoughts.substack.com/p/hafnium-li...

8 months ago 3 2 0 0
Preview
Butian Vulnerability Platform: Forging China's Next Generation of White Hat Hackers From 'Trouser Belt Project' to 'Patching the Sky': Qi An Xin’s Butian platform serves as cradle for nurturing new talent and smelter for refining seasoned hackers’ skills

What does China’s top vulnerability mining platform’s white hat elite growth system like? What are the capabilities needed to be an expert white hat hacker?

nattothoughts.substack.com/p/butian-vul...

9 months ago 0 1 0 0
Preview
Defense-Through-Offense Mindset: From a Taiwanese Hacker to the Engine of China’s Cybersecurity Industry The belief that offense enables defense in cyberspace, first rooted in China’s 1990s hacker culture, has since permeated the country’s cyber ecosystem

To defend, one must first know how to attack” (未知攻,焉知防). This mindset, popularized by a Taiwanese hacker Lin in the 1990s, spread from China's red hackers to CTF teams. Today, it powers China's cyber industry.

New piece for @nattothoughts.bsky.social

nattothoughts.substack.com/p/defense-th...

10 months ago 6 3 1 1
Preview
From Humble Beginnings: How a Vocational College Became a Vulnerability Powerhouse Qingyuan Polytechnic's focus on vulnerability studies highlights China's continued efforts in gathering vulnerability resources

The Natto Team explores the development of China's vulnerability research and discovery skills, starting from the vocational college level.

Thanks to @euben.bsky.social @dakotaindc.bsky.social Kristin Del Rosso for their previous research on the topic

nattothoughts.substack.com/p/when-a-voc...

10 months ago 11 7 0 1
Preview
From the World of “Hacker X Files” to the Whitewashed Business Sphere Jiang Jintao’s journey from hacker to infosec entrepreneur illustrates the blend of ambition, skill, and changes in China's cybersecurity industry

The Natto Team continues finding stories of Chinese hackers fascinating as they reveal the motivations behind cyber operations and the evolution of China's information security industry.

nattothoughts.substack.com/p/stories-of...

11 months ago 5 5 0 2
Preview
Ransom-War and Russian Political Culture: Trust, Corruption, and Putin's Zero-Sum Sovereignty Recent Western government revelations about EvilCorp flesh out how Russian ransomware actors and the Russian government use each other to navigate a world they perceive as dangerous.

This Natto Thoughts analysis was originally published last October. With new notes and updates added, we thought it is still relevant today to understand Russian ransomware actors and Russian political culture.

nattothoughts.substack.com/p/ransom-war...

11 months ago 2 1 0 0
Preview
Wars without Gun Smoke: China Plays the Cyber Name-and-Shame Game on Taiwan and the U.S. China’s security services have called out hackers of an alleged “Internet Army of Taiwan Independence” and of the U.S. National Security Agency, signaling an increasingly confrontational approach

In this piece with @nattothoughts.bsky.social's @meidanowski.bsky.social, we dug into China’s two naming-and-shaming campaigns over the past 30 days—targeting alleged Taiwanese and U.S. hackers amid escalating geopolitical tensions.

nattothoughts.substack.com/p/wars-witho...

1 year ago 8 5 1 0
Advertisement
Preview
Indictments and Leaks: Different but Complementary Sources A case study of the i-SOON indictment and leaks reveals that source information may vary but it is important to compare and evaluate information for unique insights.

A case study of the i-SOON indictment and leaks reveals that source information may vary but it is important to compare and evaluate information for unique insights.

nattothoughts.substack.com/p/indictment...

1 year ago 5 4 0 0
Preview
Zhou Shuai: A Hacker’s Road to APT27 US-sanctioned, allegedly APT27-associated actor Zhou Shuai represents a group of Chinese elite hackers who have become an important resource for Chinese state cyber operations.

A recent research from Natto Thoughts about US-sanctioned, allegedly APT27-associated actor. #apt27

nattothoughts.substack.com/p/zhou-shuai...

1 year ago 5 2 0 0
Preview
Where is i-SOON Now? i-SOON’s business struggles after the leak reflect the cruel reality of China’s hacker-for-hire industry

As the Natto Team was going to publish this piece, US Department of Justice unsealed an indictment charging eight i-SOON employees and highlighting the importance of companies like i-SOON in China's cyberthreat landscape.

nattothoughts.substack.com/p/where-is-i...

1 year ago 4 3 0 0
Post image

We appreciate that more and more threat intelligence researchers value the importance of cultural component in APT research. @techy.detectionengineering.net

1 year ago 6 2 0 0
Preview
The Pangu Team—iOS Jailbreak and Vulnerability Research Giant: A Member of i-SOON’s Exploit-Sharing Network A year after the i-SOON leaks, a deep dive into the Pangu Team reveals new insight into the relationships between elite vulnerability researchers and government-contracted hackers

One year after the I-SOON leaks, we still found more things that were not clear to us before. @euben.bsky.social ‘s Pangu team analysis gives more insights into China’s cyber operations.

nattothoughts.substack.com/p/the-pangu-...

1 year ago 2 1 0 0
Preview
Chasing Chengdu404, Sichuan Silence....and NoSugar Technology !? On the ground research on US sanctioned cyber security companies in China.

We are glad to see that some curious minds like us want to find out more about Chinese APTs associated companies in reality. They actually paid a visit to them.

substack.com/home/post/p-...

1 year ago 3 2 0 0
Preview
Sichuan Silence Information Technology and Guan Tianfeng: Your Criminal Our Hero Even before DeepSeek's debut sparked pride among Chinese netizens, US sanctions on Sichuan Silence developer Guan Tianfeng triggered online vows to "march forward" in cyberpower competition

Even before DeepSeek's debut sparked pride among Chinese netizens, US sanctions on Sichuan Silence developer Guan Tianfeng triggered online vows to "march forward" in cyberpower competition.

nattothoughts.substack.com/p/sichuan-si...

1 year ago 4 2 0 0
Preview
Salt Typhoon: the Other Shoe Has Dropped, but Consternation Continues Sichuan Juxinhe, directly involved in the Salt Typhoon cyber operations, resembles a front company of the Chinese Ministry of State Security

The other shoe has finally dropped, but we still need more intrusion details to defend against the threats.
#salttyphoon #apt

nattothoughts.substack.com/p/salt-typho...

1 year ago 4 3 0 1

No, it doesn’t look like

1 year ago 1 0 0 0
Advertisement

Can I have some rest on the weekend? 😊

1 year ago 1 0 1 0
Post image

It is Sichuan not Chengdu

1 year ago 2 0 1 1
Preview
Chengdu: Teahouses, Hotpots, Universities and … Hackers Chengdu’s leisure lifestyle, education and talent resources have contributed to the city becoming a hacking hub

Kick off 2025 with a spicy hotpot - why has Chengdu become a hub for hacking?

nattothoughts.substack.com/p/chengdu-te...

1 year ago 4 0 0 1
1000 subscribers. You did it. Natto Thoughts has  its first thousand subscribers. Nattothoughts.substack.com

1000 subscribers. You did it. Natto Thoughts has its first thousand subscribers. Nattothoughts.substack.com

Thank you for your support. The Natto Team appreciates it.

1 year ago 7 2 0 2