The ZRON Leak, Part 1 What has Endured and What is Evolving in China's Commercial Hacking Ecosystem Since the 2024 i-SOON Leak
The ZRON Leak, Part 1: What has Endured and What is Evolving in China’s Commercial Hacking Ecosystem Since the 2024 i-SOON Leak?
On September 16, 2026, a Wall Street Journal headline proclaimed, “How a Chinese Hacking Firm Tapped AI to Supercharge Cyber-Spying”. Internal company materials show AI being used to make stolen foreign government data digestible for police, targeting Russia, Pakistan, and others. This report described a nearly 10-gigabyte (GB) leak of data purportedly from the Chinese cybersecurity company Zhengzhou Zhirong Network Technology Company (郑州智荣网络有限公司), also known as ZRON. The leak’s contents include documents apparently stolen from government agencies in countries such as Russia, the Philippines, and Pakistan, as well as internal ZRON chats and marketing materials. The Wall Street Journal expressed tentative confidence in the trove’s authenticity, noting, “many of the documents align closely with public events.”
The leaked ZRON data had been quietly circulating among global cybersecurity researchers for several months, ever since a Chinese dark-web participant posted a sample and offered the full dataset for sale in June 2026. In July 2026, researcher NetAskari found evidence of ZRON offering “an information acquisition and processing pipeline seemingly designed for foreign espionage operations.”
The Natto Team is well-positioned to analyze this leak in the context of China’s ecosystem of commercial hackers for hire—that is, for-profit cybersecurity companies. When a massive leak of internal documents from the Chinese information security company i-SOON appeared in February 2024, the Natto Team had already had i-SOON on its radar for that company’s connections to the APT41 network. The Natto Team conducted an in-depth analysis of the leak, cross-checking it against their research findings, examining threat actors’ tactics, techniques, and procedures (TTPs). Additionally, the Natto Team also covered a November 2025 leak involving the elite Chinese cybersecurity firm Knownsec.
The Natto Team is now reviewing the ZRON dataset in similar depth and plans to publish a three-report series on the ZRON leak. In this first post, we offer our initial observations on the leak. We will examine leaked chat logs to analyze the relationship between the commercial hacking industry and the government, comparing the ecosystem they reveal with the one depicted in the i-SOON leak more than three years earlier. In subsequent posts, we will look at who does and does not buy ZRON’s products and will flag some other intriguing features of the leaked dataset.
To read the complete article see: Read full article
🚀 Stay tuned for more updates on this evolving story!