Natto Thoughts

Natto Thoughts

Chinese Threat Groups That Use Ransomware and Ransomware Groups That Use Chinese Names

Chinese threat groups are increasingly deploying ransomware for political reasons –but not all Chinese-named ransomware groups are Chinese

Natto Team's avatar
Natto Team
Oct 02, 2024
∙ Paid

Security experts have observed that the line between financially motivated criminal activities and politically motivated nation-state threat activities grows increasingly blurred. Some cybercrime operations mix state and criminal cyber threat activity; for example, North Korean state-sponsored threat actors launched cryptocurrency heists to “illicitly generate revenue for the country.” Further blurring the lines between states and criminals, the cybercriminal ecosystem is complex and constantly evolving. The Natto Team and others have explored this ecosystem, particularly in relation to ransomware. Various threat actors can be found on online underground discussion forums and marketplaces: cybercriminals who offer an array of specialized services, from pentesters and initial access brokers, to malware developers, to translators, ransom negotiators, and even government relations specialists. A thriving market in hackers-for-hire and ransomware-as-a-service makes it possible for even un…

User's avatar

Continue reading this post for free, courtesy of Natto Team.

Or purchase a paid subscription.
© 2026 Natto Thoughts · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture