Hacktivist Exploitation of Zero-Day Vulnerabilities in North America
Hacktivist groups are increasingly leveraging zero-day vulnerabilities to target North American enterprises, exploiting unpatched CVEs and engaging in exploit broker transactions.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Medium
- Actor Type:
- Hacktivist
- Geography:
- North America
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Introduction
In recent years, the cyber threat landscape has witnessed a significant uptick in the exploitation of zero-day vulnerabilities by hacktivist groups targeting North American enterprises. These actors are increasingly leveraging unpatched Common Vulnerabilities and Exposures (CVEs) to infiltrate systems, often engaging in exploit broker transactions to acquire and disseminate these vulnerabilities.
Rise in Zero-Day Exploitation
The frequency of zero-day vulnerabilities exploited in the wild has been on the rise. In 2025, the Google Threat Intelligence Group reported 90 such vulnerabilities, with nearly half targeting enterprise-grade technology. This marks an all-time high, indicating a growing trend in the exploitation of previously unknown flaws. (cybersecuritydive.com)
Hacktivist Targeting of Critical Infrastructure
Hacktivist groups have been observed targeting critical infrastructure systems in North America. For instance, the China-linked actor UAT-8837 has been exploiting both known and zero-day vulnerabilities to gain initial access to organizations, primarily focusing on critical infrastructure sectors. (bleepingcomputer.com)
Exploit Broker Transactions
The trade of zero-day exploits has become a significant concern. In February 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) sanctioned the Russian zero-day broker "Operation Zero" and its founder, Sergey Zelenyuk, for acquiring and reselling highly sensitive cyber exploits stolen from a U.S. defense contractor. This incident underscores the role of exploit brokers in facilitating the dissemination of zero-day vulnerabilities to various threat actors, including hacktivist groups. (ubos.tech)
Implications for North American Enterprises
The exploitation of zero-day vulnerabilities by hacktivist groups poses significant risks to North American enterprises. These attacks can lead to unauthorized access, data exfiltration, and potential disruption of critical services. The involvement of exploit brokers in the trade of these vulnerabilities further complicates the threat landscape, making it challenging for organizations to defend against such sophisticated attacks.
Recommendations
To mitigate the risks associated with zero-day exploitation, organizations should:
-
Implement Robust Patch Management: Ensure timely application of security patches to known vulnerabilities to reduce the attack surface.
-
Enhance Threat Detection Capabilities: Deploy advanced monitoring tools to detect anomalous activities indicative of zero-day exploitation.
-
Engage in Threat Intelligence Sharing: Collaborate with industry peers and governmental agencies to share information on emerging threats and vulnerabilities.
-
Conduct Regular Security Audits: Perform comprehensive security assessments to identify and remediate potential vulnerabilities within the organization.
Conclusion
The increasing use of zero-day vulnerabilities by hacktivist groups targeting North American enterprises highlights the evolving nature of cyber threats. By understanding the dynamics of exploit broker transactions and implementing proactive security measures, organizations can better defend against these sophisticated attacks.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



