China's Strategic Use of Zero-Day Exploits in Cyber Operations
China has been actively leveraging zero-day vulnerabilities to advance its cyber espionage and strategic objectives, posing a medium-level threat in East Asia.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Medium
- Actor Type:
- Nation-State
- Geography:
- East Asia
- Confidence:
- High Confidence
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Introduction
As of April 2026, China has been actively leveraging zero-day vulnerabilities to advance its cyber espionage and strategic objectives, posing a medium-level threat in East Asia. Zero-day vulnerabilities—previously unknown flaws in software or hardware—are highly coveted in the cyber threat landscape due to their potential for exploitation without prior detection.
Exploitation of Zero-Day Vulnerabilities
In 2025, China-linked cyber actors, notably groups such as UNC5221 and UNC3886, have been observed targeting defense firms and military contractors by deploying zero-day exploits against edge devices to gain initial access. (darkreading.com) These groups have focused heavily on security appliances and edge devices to maintain persistent access to strategic targets. (forbes.com)
Exploit Broker Transactions
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has sanctioned a Russian firm, Matrix LLC (operating as "Operation Zero"), and its founder, Sergey Sergeyevich Zelenyuk, for the theft and resale of U.S. trade secret cyber tools. (sanctionsnews.bakermckenzie.com) This incident underscores the complex ecosystem of exploit brokers facilitating the transfer of zero-day vulnerabilities between state and non-state actors.
In-the-Wild Exploitation
The exploitation of zero-day vulnerabilities in the wild has been a significant concern. In 2025, 90 zero-day vulnerabilities were under active exploitation, with 43% targeting enterprise technology. (computerweekly.com) China has been a significant developer and user of zero-day exploits during this period. (forbes.com)
Conclusion
China's strategic use of zero-day vulnerabilities in cyber operations highlights the evolving nature of cyber threats in East Asia. The interplay between state-sponsored actors and exploit brokers complicates the cybersecurity landscape, necessitating enhanced vigilance and adaptive defense strategies.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



