<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Natto Thoughts: i-SOON Leaks]]></title><description><![CDATA[This section examines the i-SOON leaks, analyzing the company’s connections to other state-linked contractors, its business model, tooling, network of prominent Chinese security researchers, and where the firm stands today.]]></description><link>https://www.nattothoughts.com/s/i-soon-leaks</link><image><url>https://substackcdn.com/image/fetch/$s_!t3eQ!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd0e4005-414e-4e49-9a9a-3b89d3e533f5_629x629.png</url><title>Natto Thoughts: i-SOON Leaks</title><link>https://www.nattothoughts.com/s/i-soon-leaks</link></image><generator>Substack</generator><lastBuildDate>Tue, 26 May 2026 08:56:44 GMT</lastBuildDate><atom:link href="https://www.nattothoughts.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Natto Thoughts]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[nattothoughts@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[nattothoughts@substack.com]]></itunes:email><itunes:name><![CDATA[Natto Team]]></itunes:name></itunes:owner><itunes:author><![CDATA[Natto Team]]></itunes:author><googleplay:owner><![CDATA[nattothoughts@substack.com]]></googleplay:owner><googleplay:email><![CDATA[nattothoughts@substack.com]]></googleplay:email><googleplay:author><![CDATA[Natto Team]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Indictments and Leaks: Different but Complementary Sources]]></title><description><![CDATA[A case study of the i-SOON indictment and leaks reveals that source information may vary but it is important to compare and evaluate information for unique insights.]]></description><link>https://www.nattothoughts.com/p/indictments-and-leaks-different-but</link><guid isPermaLink="false">https://www.nattothoughts.com/p/indictments-and-leaks-different-but</guid><dc:creator><![CDATA[Natto Team]]></dc:creator><pubDate>Wed, 02 Apr 2025 16:02:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!eT3Z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd8097d9b-2c1b-48d6-bcd8-a74aa98116db_875x969.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>After the public learned of the leaked documents from the Chinese Information security company i-SOON in February 2024, various media and analysts from the cyber security industry, including the Natto Team, seized the rare opportunity to <a href="https://nattothoughts.substack.com/p/i-soon-kicking-off-the-year-of-the">uncover</a> <a href="https://amp.theguardian.com/technology/2024/feb/23/huge-cybersecurity-leak-lifts-lid-on-world-of-chinas-hackers-for-hire">"the world of China&#8217;s hackers for hire"</a>. A year later, on March 5, 2025, the <a href="https://www.justice.gov/opa/pr/justice-department-charges-12-chinese-contract-hackers-and-law-enforcement-officers-global">US Department of Justice (US DoJ)</a> unsealed an indictment charging eight i-SOON employees and two officers of the Chinese Ministry of Public Security for alleged hacking activities from 2016 to 2023. The i-SOON indictment revealed further details on the company&#8217;s operation, particularly, how i-SOON actors coordinated with the Chinese Ministry of Public Security (MPS) and Ministry of State Security (MSS).</p><p>Indictments can be <a href="https://medium.com/katies-five-cents/cyber-indictments-and-threat-intel-why-you-should-care-6336a14bb527">valuable resources</a> for cyber threat intelligence (CTI) analysts: they provide insights into the activities, tactics, and infrastructure of threat actors, which can be used to improve threat detection and response capabilities. Indictments also identif&#8230;</p>
      <p>
          <a href="https://www.nattothoughts.com/p/indictments-and-leaks-different-but">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Where is i-SOON Now?]]></title><description><![CDATA[i-SOON&#8217;s business struggles after the leak reflect the cruel reality of China&#8217;s hacker-for-hire industry]]></description><link>https://www.nattothoughts.com/p/where-is-i-soon-now</link><guid isPermaLink="false">https://www.nattothoughts.com/p/where-is-i-soon-now</guid><dc:creator><![CDATA[Natto Team]]></dc:creator><pubDate>Wed, 05 Mar 2025 17:17:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2ff67c1-175e-4f63-9b4d-3122aafc1d59_1920x1080.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<pre><code>One hour before we were going to publish this post, US Department of Justice unsealed an <a href="https://www.justice.gov/opa/media/1391901/dl">indictment</a> charging eight i-SOON employees and highlighting the importance of companies like i-SOON in China's cyberthreat landscape.</code></pre><p>Cyber threats from China have never stopped evolving; analysts grapple with who <a href="https://www.infosecurity-magazine.com/news/chinese-silver-fox-backdoors/">Silver Fox</a> is and why they targeted Chinese-speakers, or who was using <a href="https://www.trendmicro.com/fr_fr/research/25/b/updated-shadowpad-malware-leads-to-ransomware-deployment.html">Shadowpad malware deploying ransomware</a> and what their motivations were. To understand these new developments, we need to keep in mind the dynamics and constraints that Chinese cyberthreat actors face. For this, the i-SOON leaks remain crucial.</p><p>After over a year, the Natto Team continues to discover that the <a href="https://nattothoughts.substack.com/p/i-soon-kicking-off-the-year-of-the">i-SOON leaks</a> &#8211; product marketing white papers, compromised data samples, chat logs among employees and clients, screenshots and images of business operations from the Chinese information security company i-SOON &#8211; are a gift that keeps on giving. For example, the recent Natto Thoughts&#8217; <a href="https://nattothoughts.substack.com/p/the-pangu-teamios-jailbreak-and-vulnerability">post</a> from <a href="https://www.linkedin.com/in/eugenio-benincasa-07a9517a/">Eugenio Beninicasa</a> dug&#8230;</p>
      <p>
          <a href="https://www.nattothoughts.com/p/where-is-i-soon-now">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The Pangu Team—iOS Jailbreak and Vulnerability Research Giant: A Member of i-SOON’s Exploit-Sharing Network ]]></title><description><![CDATA[A year after the i-SOON leaks, a deep dive into the Pangu Team reveals new insight into the relationships between elite vulnerability researchers and government-contracted hackers]]></description><link>https://www.nattothoughts.com/p/the-pangu-teamios-jailbreak-and-vulnerability</link><guid isPermaLink="false">https://www.nattothoughts.com/p/the-pangu-teamios-jailbreak-and-vulnerability</guid><dc:creator><![CDATA[Eugenio Benincasa]]></dc:creator><pubDate>Wed, 19 Feb 2025 17:01:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0Sut!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62a387f7-8ca7-4813-b379-ac669485e513_951x533.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This week marks the one-year anniversary of the i-SOON leaks<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>&#8212;files, chat logs, and images exposing the company's eight-year espionage effort targeting <a href="https://www.washingtonpost.com/world/2024/02/21/china-hacking-leak-documents-isoon/">at least 20</a> foreign governments for China&#8217;s government agencies. Since then, threat intelligence reports, U.S. indictments and sanctions have uncovered additional contractors linked to Chinese state-sponsored operations, such as Integrity Tech (&#21271;&#20140;&#27704;&#20449;&#33267;&#35802;&#31185;&#25216;&#26377;&#38480;&#20844;&#21496;) and Sichuan Silence (&#22235;&#24029;&#26080;&#22768;&#20449;&#24687;&#25216;&#26415;), covered by the Natto Team in reports <a href="https://nattothoughts.substack.com/p/flax-typhoon-linked-company-integrity">1</a>, <a href="https://nattothoughts.substack.com/p/sichuan-silence-information-technology">2</a>, and <a href="https://nattothoughts.substack.com/p/sichuan-silence-information-technology-fe9">3</a>. All these firms appeared in the i-SOON leaks at some point, revealing a tightly connected network of business partners, competitors, clients, and exploit brokers.</p><p>Other actors, such as the Pangu Team (&#30424;&#21476;&#22242;&#38431;) (Pangu), were also mentioned in the leaks. Known as <a href="https://web.archive.org/web/20240530180909/https://www.sohu.com/a/481289655_99975515">one of China&#8217;s top</a> white-hat hacker groups specializing in mobile system and application security, Pangu has gained global recognition since 2014 for its groundbreaking iOS jailbreaks<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>&#8212;downloaded tens of millions of times&#8212;and its <a href="https://ethz.ch/content/dam/ethz/special-interest/gess/cis/center-for-securities-studies/pdfs/cyber-report-2024-from-vegas-to-chengdu.pdf">performance in hacki&#8230;</a></p>
      <p>
          <a href="https://www.nattothoughts.com/p/the-pangu-teamios-jailbreak-and-vulnerability">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[i-SOON Toolkit: What is “TZ”?]]></title><description><![CDATA[Network investigation and reconnaissance work is so critical for the Chinese Public Security bureaus that it needs a code name, &#8220;TZ.&#8221;]]></description><link>https://www.nattothoughts.com/p/i-soon-toolkit-what-is-tz</link><guid isPermaLink="false">https://www.nattothoughts.com/p/i-soon-toolkit-what-is-tz</guid><dc:creator><![CDATA[Natto Team]]></dc:creator><pubDate>Wed, 24 Apr 2024 16:01:07 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/eaec9d05-f097-402b-8693-2bb036ead8ed_354x166.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The Natto Team and many other cyber threat intelligence (CTI) analysts have seized the rare opportunity presented by the leak of Chinese hacker-for-hire company i-SOON&#8217;s internal messages. The leaked materials allow us to <a href="https://www.recordedfuture.com/attributing-i-soon-private-contractor-linked-chinese-state-sponsored-groups">cross-examine past research findings</a> ; <a href="https://harfanglab.io/en/insidethelab/isoon-leak-analysis/">explore</a> threat actors&#8217; tactics, techniques and procedures (TTPs); and <a href="https://nattothoughts.substack.com/p/i-soon-leak-unanswered-questions">probe</a> the motivations and intents of Chinese threat actors. The Natto Team has found one aspect of i-SOON leaked documents that has not been discussed much. This is &#8220;TZ&#8221;, two letters in the Latin alphabet, likely an acronym. It appears more than 80 times across the <a href="https://www.washingtonpost.com/world/2024/02/21/china-hacking-leak-documents-isoon/">over 570 leaked documents</a>, including chat logs, product marketing white papers, compromised data samples, screenshots and images. What does TZ stand for? Interestingly, no explanation can be found through the documents. Even i-SOON&#8217;s product marketing whitepaper, Integrated Combat Platform (&#19968;&#20307;&#21270;&#20316;&#25112;&#24179;&#21488;), mentioned TZ 17 times, but it did not explain what TZ stood for or meant. It sounds as if TZ was a c&#8230;</p>
      <p>
          <a href="https://www.nattothoughts.com/p/i-soon-toolkit-what-is-tz">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[i-SOON Leak: Unanswered Questions and What Now? ]]></title><description><![CDATA[Chinese hackers&#8217; lax operations security; why Chinese officials have to rely on contractors; why i-SOON might not fear blowback from the leak; and how the name-and-shame strategy seems to be failing.]]></description><link>https://www.nattothoughts.com/p/i-soon-leak-unanswered-questions</link><guid isPermaLink="false">https://www.nattothoughts.com/p/i-soon-leak-unanswered-questions</guid><dc:creator><![CDATA[Natto Team]]></dc:creator><pubDate>Wed, 27 Mar 2024 18:00:31 GMT</pubDate><enclosure url="https://images.unsplash.com/photo-1588662886318-6b48b48143f6?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHx3aGF0JTIwbm93fGVufDB8fHx8MTcxMTU1NjA0NXww&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>It has been over a month after the massive leak of i-SOON, a Chinese information security company, revealed the operations of China&#8217;s hacker-for-hire industry. We have seen many insightful reports about the i-SOON leak, analyzing i-SOON&#8217;s <a href="https://harfanglab.io/en/insidethelab/isoon-leak-analysis/">commercial offering</a>; diving deeply into i-SOON&#8217;s company culture, &#8220;<a href="https://apnews.com/article/chinese-hacking-leak-documents-surveillance-spying-6276e8662ddf6f2c1afbae994d8b3aa2">fueled by influence, alcohol and sex</a>&#8221;; and utilizing analysis of competing hypothesis (ACH) to assess <a href="https://blog.bushidotoken.net/2024/02/lessons-from-isoon-leaks.html">who was responsible for the i-SOON leak</a>. However, there are still many unanswered questions related to the leak and what it all means in terms of understanding Chinese threat groups, conducting threat analysis and preventing or mitigating future attacks. While the Natto Team has received many inquiries from the media and discussed the leak with experts from the industry, we would like to present these unanswered questions and our think-out-loud <a href="https://nattothoughts.substack.com/">Natto Thoughts</a> for the community to explore further.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1588662886318-6b48b48143f6?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHx3aGF0JTIwbm93fGVufDB8fHx8MTcxMTU1NjA0NXww&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1588662886318-6b48b48143f6?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHx3aGF0JTIwbm93fGVufDB8fHx8MTcxMTU1NjA0NXww&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1588662886318-6b48b48143f6?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHx3aGF0JTIwbm93fGVufDB8fHx8MTcxMTU1NjA0NXww&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1588662886318-6b48b48143f6?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHx3aGF0JTIwbm93fGVufDB8fHx8MTcxMTU1NjA0NXww&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1588662886318-6b48b48143f6?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHx3aGF0JTIwbm93fGVufDB8fHx8MTcxMTU1NjA0NXww&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1588662886318-6b48b48143f6?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHx3aGF0JTIwbm93fGVufDB8fHx8MTcxMTU1NjA0NXww&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080" width="568" height="378.6666666666667" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1588662886318-6b48b48143f6?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHx3aGF0JTIwbm93fGVufDB8fHx8MTcxMTU1NjA0NXww&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:4282,&quot;width&quot;:6423,&quot;resizeWidth&quot;:568,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;text&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="text" title="text" srcset="https://images.unsplash.com/photo-1588662886318-6b48b48143f6?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHx3aGF0JTIwbm93fGVufDB8fHx8MTcxMTU1NjA0NXww&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1588662886318-6b48b48143f6?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHx3aGF0JTIwbm93fGVufDB8fHx8MTcxMTU1NjA0NXww&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1588662886318-6b48b48143f6?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHx3aGF0JTIwbm93fGVufDB8fHx8MTcxMTU1NjA0NXww&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1588662886318-6b48b48143f6?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHwyfHx3aGF0JTIwbm93fGVufDB8fHx8MTcxMTU1NjA0NXww&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@timmossholder">Tim Mossholder</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><h1>Operations Security</h1><p><em><strong>Why do i-SOON and similar companies &#8230;</strong></em></p>
      <p>
          <a href="https://www.nattothoughts.com/p/i-soon-leak-unanswered-questions">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[i-SOON Operations: A View from Kazakhstan]]></title><description><![CDATA[Leak shows Kazakhstan&#8217;s cyber-vulnerability and its importance to China as economic partner and haven for Uyghurs]]></description><link>https://www.nattothoughts.com/p/i-soon-operations-a-view-from-kazakhstan</link><guid isPermaLink="false">https://www.nattothoughts.com/p/i-soon-operations-a-view-from-kazakhstan</guid><dc:creator><![CDATA[Natto Team]]></dc:creator><pubDate>Wed, 13 Mar 2024 16:01:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c49f20a-97aa-41ce-bfe3-9b35c4d0bd5d_1600x1133.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The massive February 16 2024 <a href="https://nattothoughts.substack.com/p/i-soon-kicking-off-the-year-of-the">leak</a> of materials from Chinese information security company i-SOON showed the company had compromised and stolen data from entities worldwide. The materials included charts with personal data on subscribers of several telecommunications companies in the Central Asian country of Kazakhstan. This oil- and mineral-rich country, formerly part of the Soviet Union and <a href="https://www.nature.com/articles/s41599-018-0125-5">flanked by Russia and China</a>, has pursued a <a href="https://www.sciencedirect.com/science/article/pii/S1879366515000032">multivector foreign policy</a>, nurturing good relations with a variety of countries. Current president Kassym-Jomart Tokayev, a former diplomat, reportedly speaks fluent Chinese, Russian, French and English, in addition to the Kazakh language (https://online.zakon[.]kz/Document/?doc_id=30100479). His family has discreet <a href="https://www.occrp.org/en/suisse-secrets/the-offshore-secrets-of-kazakhstans-president-tokayev">business ties to Russia</a>. Kazakhstan is a key transit country for Chinese exports to Europe. The Kazakh ethnic group, culturally Turkic, extends on both sides of the border with China and shares the Muslim religion and cultural similarities wit&#8230;</p>
      <p>
          <a href="https://www.nattothoughts.com/p/i-soon-operations-a-view-from-kazakhstan">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[i-SOON: Kicking off the Year of the Dragon with Good Luck … or Not]]></title><description><![CDATA[Chat logs in the i-SOON leak show China&#8217;s hacker-for-hire industry is subject to Chinese business culture: in the race for profits, survival depends on who you know and who you wine and dine with.]]></description><link>https://www.nattothoughts.com/p/i-soon-kicking-off-the-year-of-the</link><guid isPermaLink="false">https://www.nattothoughts.com/p/i-soon-kicking-off-the-year-of-the</guid><dc:creator><![CDATA[Natto Team]]></dc:creator><pubDate>Wed, 28 Feb 2024 17:25:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_66G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff02f0ff4-50d1-4783-8f87-c3c95cf3de9e_720x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On February 18, the first working day after a week-long Lunar New Year holiday, i-SOON, a Chinese information security company on which the Natto team <a href="https://nattothoughts.substack.com/p/i-soon-another-company-in-the-apt41">reported</a> last October, posted on its WeChat public account a red banner with the greeting &nbsp;&#24320;&#24037;&#22823;&#21513; (kai gong da ji), meaning&nbsp; &#8220;<a href="https://language.chinadaily.com.cn/a/201902/11/WS5c60f18da3106c65c34e8ab3.html">Good luck with your work throughout the new year</a>.&#8221; However, this first business day in the year of the Dragon was not so blessed for i-SOON. A massive leak &#8211; including i-SOON&#8217;s product marketing white papers, compromised data samples, chat logs among employees and clients, screenshots and images related to the company&#8217;s business operations from at least 2020 to 2022 &#8211; was <a href="https://web.archive.org/web/20240221060140/https://github.com/I-S00N/I-S00N/tree/main">posted on GitHub</a>. As of this writing, GitHub has taken down the leaked documents. The Associated Press <a href="https://apnews.com/article/china-cybersecurity-leak-document-dump-spying-aac38c75f268b72910a94881ccbb77cb">confirmed</a> the leak&#8217;s authenticity with two employees of i-SOON. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_66G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff02f0ff4-50d1-4783-8f87-c3c95cf3de9e_720x1280.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_66G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff02f0ff4-50d1-4783-8f87-c3c95cf3de9e_720x1280.png 424w, https://substackcdn.com/image/fetch/$s_!_66G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff02f0ff4-50d1-4783-8f87-c3c95cf3de9e_720x1280.png 848w, https://substackcdn.com/image/fetch/$s_!_66G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff02f0ff4-50d1-4783-8f87-c3c95cf3de9e_720x1280.png 1272w, https://substackcdn.com/image/fetch/$s_!_66G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff02f0ff4-50d1-4783-8f87-c3c95cf3de9e_720x1280.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_66G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff02f0ff4-50d1-4783-8f87-c3c95cf3de9e_720x1280.png" width="526" height="935.1111111111111" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f02f0ff4-50d1-4783-8f87-c3c95cf3de9e_720x1280.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1280,&quot;width&quot;:720,&quot;resizeWidth&quot;:526,&quot;bytes&quot;:234172,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_66G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff02f0ff4-50d1-4783-8f87-c3c95cf3de9e_720x1280.png 424w, https://substackcdn.com/image/fetch/$s_!_66G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff02f0ff4-50d1-4783-8f87-c3c95cf3de9e_720x1280.png 848w, https://substackcdn.com/image/fetch/$s_!_66G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff02f0ff4-50d1-4783-8f87-c3c95cf3de9e_720x1280.png 1272w, https://substackcdn.com/image/fetch/$s_!_66G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff02f0ff4-50d1-4783-8f87-c3c95cf3de9e_720x1280.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>Source: i-SOON WeChat public account</em></figcaption></figure></div><p>As various media reports illustrated, the leak &#8220;<a href="https://therecord.media/china-commercial-hacking-industry-isoon-leaks">open(s) the lid on China&#8217;s commercial hacking industry</a>&#8221; and provides &#8220;<a href="https://amp.theguardian.com/technology/2024/feb/23/huge-cybersecurity-leak-lifts-lid-on-world-of-chinas-hackers-for-hire">unprecedented insight into t&#8230;</a></p>
      <p>
          <a href="https://www.nattothoughts.com/p/i-soon-kicking-off-the-year-of-the">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[i-SOON: Another Company in the APT41 Network]]></title><description><![CDATA[A lawsuit casts light on the ecosystem of IT companies related to Chengdu 404, the company allegedly behind Chinese state-sponsored hacking group APT41.]]></description><link>https://www.nattothoughts.com/p/i-soon-another-company-in-the-apt41</link><guid isPermaLink="false">https://www.nattothoughts.com/p/i-soon-another-company-in-the-apt41</guid><dc:creator><![CDATA[Natto Team]]></dc:creator><pubDate>Fri, 27 Oct 2023 02:00:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!4WzG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8b88094-6521-4bac-9ac4-1e77907bc727_925x354.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A recent court case in Chengdu, Sichuan Province, China has caught Natto Team&#8217;s attention because it involves a company that US officials have alleged to be linked with Chinese offensive hacking. This court case is an intellectual property dispute in which the company known as Chengdu 404 &#8211; which allegedly stands behind <a href="https://www.justice.gov/opa/pr/seven-international-cyber-defendants-including-apt41-actors-charged-connection-computer">Chinese state hacking operation known as APT41</a> &#8211; sued a company known as Sichuan i-SOON. &nbsp;The case, which pitted Chengdu Silingsi (404) Network Technology Company (&#25104;&#37117;&#24066;&#32902;&#38646;&#32902;&#32593;&#32476;&#31185;&#25216;&#26377;&#38480;&#20844;&#21496;) as the plaintiff against Sichuan i-SOON Information Technology Company(&#22235;&#24029;&#23433;&#27957;&#20449;&#24687;&#25216;&#26415;&#26377;&#38480;&#20844;&#21496;) as the defendant, centered on a software development contract dispute. As of this writing, there is no publicly available information about the case, except that it was scheduled to go to trial on October 17, 2023. The existence of this case suggests that Chengdu 404 and Sichuan i-SOON had a business relationship. A look at Sichuan i-SOON adds to our understanding of the ecosystem of IT companies in which Che&#8230;</p>
      <p>
          <a href="https://www.nattothoughts.com/p/i-soon-another-company-in-the-apt41">
              Read more
          </a>
      </p>
   ]]></content:encoded></item></channel></rss>