On September 16, 2026, a Wall Street Journal headline proclaimed, “How a Chinese Hacking Firm Tapped AI to Supercharge Cyber-Spying: Internal company materials show AI being used to make stolen foreign government data digestible for police, targeting Russia, Pakistan and others.” It described a nearly 10-gigabyte (GB) leak of data purportedly from Chinese cybersecurity company Zhengzhou Zhirong Network Technology Company (郑州智荣网络有限公司), also known as ZRON. Describing the leak’s contents – documents apparently stolen from government agencies in countries such as Russia, the Philippines, and Pakistan, as well as internal ZRON chats and marketing materials – the Wall Street Journal expressed tentative confidence in the trove’s authenticity, noting, “many of the documents align closely with public events.” The documents portray ZRON as one of many Chinese firms competing to provide their country’s government with not just access to stolen data but also “AI-driven systems to organize and analyze it,” the Wall Street Journal noted.
By then, the leaked ZRON data had been quietly circulating among global cybersecurity researchers for several months, ever since a Chinese dark-web participant posted a sample and offered the full dataset for sale in June 2026. A few reports on ZRON had appeared between June and September, when the WSJ article appeared. For example, in July 2026 researcher NetAskari found evidence of ZRON as offering “an information acquisition and processing pipeline seemingly designed for foreign espionage operations.”
The Natto Team is well-positioned to analyze this leak in the context of China’s ecosystem of commercial hackers for hire—that is, for-profit cybersecurity companies. When a massive leak of internal documents from the Chinese information security company i-SOON appeared in February 2024, the Natto Team had already had i-SOON on its radar for that company’s connections to the APT41 network. The Natto Team conducted an in-depth analysis of the leak, cross-checking it against our research findings, examining threat actors’ tactics, techniques, and procedures (TTPs), and, most importantly, seeking to understand the motivations and intentions of those behind the keyboard. (See the Natto Team’s i-SOON leak research here, here, here, here and here.) The Natto Team also covered a November 2025 leak involving the elite Chinese cybersecurity firm Knownsec.
The Natto Team is now reviewing the ZRON dataset in similar depth. We plan to publish a three-report series on the ZRON leak. In this first post, we offer our initial observations on the leak. First, we evaluate the sources of the leaked data. Next, we cross-check Chinese-language open-source information about ZRON, including its products and services, against the contents of the leaked data. Finally, we examine leaked chat logs to analyze the relationship between the commercial hacking industry and the government, comparing the ecosystem they reveal with the one depicted in the i-SOON leak more than three years earlier. In subsequent posts, we will look at who does and does not buy ZRON’s products and will flag some other intriguing features of the leaked dataset.
Natto Thoughts is a reader-supported publication. To receive new posts and support the Natto Team’s work, consider becoming a free or paid subscriber.
Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.
Enroll Now and Save 10%: Coupon Code MWNEWS10
Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.
<p>
<a href="https://www.nattothoughts.com/p/the-zron-leak-part-1-what-has-endured" rel="noreferrer" target="_blank">
Read more
</a>
</p>
