Nation-State Actors Intensify Zero-Day Exploitation in North America
Nation-state actors are increasingly leveraging zero-day vulnerabilities to conduct high-impact cyber operations in North America, posing significant threats to critical infrastructure and national security.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- High
- Actor Type:
- Nation-State
- Geography:
- North America
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
In recent years, nation-state actors have escalated their use of zero-day vulnerabilities—previously unknown software flaws—to execute sophisticated cyber operations in North America. These exploits enable attackers to infiltrate systems undetected, often leading to data breaches, espionage, and disruption of critical services.
Emerging Threats and Exploitation Trends
A notable example is the Chinese-speaking hacking collective known as Storm-1175. This group has been observed rapidly exploiting both zero-day and n-day vulnerabilities to deploy ransomware, such as the Medusa variant, within days of initial access. Their targets include sectors like healthcare, education, professional services, and finance across the U.S., U.K., and Australia. Storm-1175's ability to chain multiple vulnerabilities enhances the effectiveness of their attacks, often before patches are available. (techradar.com)
The prevalence of zero-day exploits has been rising. In 2023, Mandiant tracked 97 unique zero-day vulnerabilities exploited in the wild, marking a 50% increase from the previous year. These exploits accounted for 38% of tracked intrusions, surpassing other initial infection vectors like phishing and stolen credentials. (techtarget.com)
The Role of Exploit Brokers
The market for zero-day exploits has become a focal point for nation-state actors seeking to acquire advanced cyber capabilities. Exploit brokers facilitate the sale and purchase of these vulnerabilities, often operating in the dark web. Between January 2023 and September 2024, Kaspersky identified 547 listings for exploits targeting software vulnerabilities, with half involving zero-day and one-day vulnerabilities. The average price for remote code execution exploits was around $100,000, reflecting the high value placed on such tools. (me-en.kaspersky.com)
A significant incident underscored the risks associated with exploit brokers. In February 2026, the U.S. Treasury sanctioned Russian zero-day broker "Operation Zero" and its founder, Sergey Zelenyuk, for acquiring and reselling highly sensitive cyber exploits stolen from a U.S. defense contractor. This marked the first time the U.S. government directly targeted a zero-day broker as a national security threat. (ubos.tech)
Implications for North American Cybersecurity
The increasing use of zero-day exploits by nation-state actors poses significant challenges to cybersecurity in North America. Traditional defense mechanisms, such as signature-based detection systems, are often ineffective against these unknown vulnerabilities. Organizations must adopt proactive security measures, including regular system updates, comprehensive monitoring, and threat intelligence sharing, to mitigate the risks associated with zero-day exploits.
In conclusion, the strategic use of zero-day vulnerabilities by nation-state actors represents a high-level threat to North American cybersecurity. The involvement of exploit brokers in facilitating these activities further complicates the threat landscape. A coordinated and proactive approach is essential to defend against these sophisticated cyber threats.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

CISA Adds Three Linux Kernel Vulnerabilities to KEV Catalog Amid Active Exploitation Reports

Google Patches Actively Exploited Android Zero-Day CVE-2026-58704 Affecting Pixel Devices

