Hacktivist Groups in East Asia Intensify Zero-Day Exploitation Campaigns
Hacktivist groups in East Asia are increasingly leveraging zero-day vulnerabilities to target critical infrastructure, with a notable rise in exploit broker transactions facilitating these attacks.
Encrygma is selling the entire Full Cyber Weapon Research of Hacktivist Groups in East Asia Intensify Zero-Day Exploitation Campaigns for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- High
- Actor Type:
- Hacktivist
- Geography:
- East Asia
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
In early 2026, hacktivist groups in East Asia have escalated their use of zero-day vulnerabilities to compromise critical infrastructure, underscoring a significant shift in cyberattack methodologies. These groups are not only exploiting previously unknown software flaws but are also engaging in exploit broker transactions to acquire and disseminate these vulnerabilities, thereby enhancing their operational capabilities.
Zero-Day Exploitation Trends
Zero-day vulnerabilities—flaws in software that are unknown to the vendor and lack patches—have become a focal point for cyber attackers. In 2025, a total of 90 zero-day vulnerabilities were exploited in the wild, with nearly half targeting enterprise-grade technologies. This trend highlights the increasing sophistication and resourcefulness of threat actors, particularly hacktivist groups in East Asia. (tech.yahoo.com)
Notable Exploitation Campaigns
Hacktivist groups have been implicated in several high-profile exploitation campaigns:
-
Operation SyncHole: Attributed to the Lazarus Group, this campaign targeted South Korean organizations across various sectors, including software, IT, financial, semiconductor manufacturing, and telecommunications. The attackers employed a combination of watering hole strategies and exploitation of vulnerabilities in South Korean software, such as Cross Ex and Innorix Agent. (ics-cert.kaspersky.com)
-
SAP NetWeaver Exploitation: Chinese-linked advanced persistent threat (APT) groups exploited a zero-day vulnerability in SAP NetWeaver to target critical infrastructure in the UK, US, and Saudi Arabia. The attacks focused on sectors integral to public welfare and national security, including natural gas networks, water utilities, medical manufacturing, and oil and gas firms. (gbhackers.com)
Exploit Broker Transactions
The acquisition and sale of zero-day vulnerabilities have become a lucrative market, with exploit brokers acting as intermediaries between vulnerability discoverers and end-users. In February 2026, the U.S. Department of the Treasury sanctioned Sergey Sergeyevich Zelenyuk and his company, Matrix LLC (doing business as Operation Zero), for acquiring and distributing cyber tools harmful to U.S. national security. Operation Zero had previously offered substantial rewards for zero-day exploits targeting platforms like Telegram, indicating a growing trend of exploit brokers facilitating the dissemination of zero-day vulnerabilities. (home.treasury.gov)
Implications and Recommendations
The increasing exploitation of zero-day vulnerabilities by hacktivist groups in East Asia poses significant risks to global cybersecurity, particularly concerning critical infrastructure. The involvement of exploit brokers in facilitating these attacks further complicates the threat landscape. Organizations are advised to:
-
Enhance Vulnerability Management: Implement robust patch management processes to address known vulnerabilities promptly.
-
Monitor for Exploit Broker Activity: Stay informed about exploit broker transactions and assess the potential impact of newly discovered zero-day vulnerabilities.
-
Strengthen Incident Response Plans: Develop and regularly update incident response strategies to effectively address potential zero-day exploitations.
By proactively addressing these areas, organizations can better defend against the evolving threat posed by hacktivist groups leveraging zero-day vulnerabilities.
Highlights:
- Treasury Sanctions Exploit Broker Network for Theft and Sale of U.S. Government Cyber Tools | U.S. Department of the Treasury, Published on Monday, February 23
- Treasury sanctions Russian zero-day broker accused of buying exploits stolen from US defense contractor | TechCrunch, Published on Monday, February 23
- Chinese Hackers Exploit SAP NetWeaver Zero-Day Vulnerability to Target Critical Infrastructure, Published on Tuesday, May 13
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



