Ransomware Groups in East Asia Intensify Exploitation of Zero-Day Vulnerabilities
Ransomware groups in East Asia are increasingly leveraging zero-day vulnerabilities to infiltrate networks, with notable incidents involving Akira and Volt Typhoon.
Encrygma is selling the entire Full Cyber Weapon Research of Ransomware Groups in East Asia Intensify Exploitation of Zero-Day Vulnerabilities for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- High
- Actor Type:
- Ransomware Group
- Geography:
- East Asia
- Confidence:
- Confirmed
- CVE:
- CVE-2025-31324, CVE-2025-42999
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
In early 2026, ransomware groups in East Asia have escalated their exploitation of zero-day vulnerabilities, leading to significant security breaches across various sectors. This trend underscores the evolving tactics of cybercriminals and the critical need for robust cybersecurity measures.
Akira Ransomware Group's Exploitation of Zero-Day Vulnerabilities
The Akira ransomware group, which emerged in March 2023, has rapidly become one of the most prolific ransomware-as-a-service (RaaS) operations by the end of 2025. By January 2024, Akira affiliates had attacked over 250 organizations, amassing approximately $42 million in ransom proceeds. A significant portion of these attacks involved exploiting zero-day vulnerabilities in public-facing servers. In August 2025, reports indicated that Akira attackers were exploiting a zero-day vulnerability in SonicWall SSL VPN devices, enabling them to pivot directly from these devices to domain controllers within hours of an initial breach. (security.com)
Volt Typhoon's Targeting of Critical Infrastructure
Volt Typhoon, an advanced persistent threat (APT) group attributed to the Chinese government, has been active since at least mid-2021. This group primarily targets critical infrastructure in the United States, focusing on espionage, data theft, and credential access. Volt Typhoon is known for its meticulous approach to avoid detection, with campaigns designed to sabotage critical communications infrastructure between the U.S. and Asia during potential future crises. (en.wikipedia.org)
Exploitation of SAP NetWeaver Vulnerabilities
In May 2025, two ransomware groups and several Chinese APTs were observed exploiting two critical vulnerabilities in SAP NetWeaver: CVE-2025-31324 and CVE-2025-42999. These flaws, with CVSS scores of 10 and 9.1 respectively, affected the Visual Composer development server component, allowing remote attackers to execute arbitrary code without authentication. In-the-wild attacks began in January 2025, with threat actors deploying webshells for follow-up activities. SAP released patches for these vulnerabilities in April and May 2025. (securityweek.com)
Increased Zero-Day Exploitation by State-Sponsored Actors
Reports from 2023 indicate that threat groups with ties to nation-states were the primary exploiters of zero-day vulnerabilities, accounting for 80% of such exploits. Chinese state-sponsored cyber espionage groups were particularly active, responsible for over 50% of the zero-day exploits that year. This trend highlights the strategic importance of zero-day vulnerabilities in cyber operations and the need for enhanced defensive measures. (scworld.com)
Implications and Recommendations
The increasing use of zero-day vulnerabilities by ransomware groups in East Asia poses significant risks to organizations worldwide. To mitigate these threats, organizations should:
-
Implement Comprehensive Patching Protocols: Regularly update systems and applications to address known vulnerabilities promptly.
-
Enhance Network Monitoring: Deploy advanced intrusion detection systems to identify and respond to suspicious activities swiftly.
-
Conduct Regular Security Audits: Perform thorough assessments to identify potential vulnerabilities and strengthen defenses.
By adopting these measures, organizations can bolster their resilience against the evolving tactics of ransomware groups and other cyber adversaries.
Highlights:
- Ransomware Groups, Chinese APTs Exploit Recent SAP NetWeaver Flaws - SecurityWeek, Published on Wednesday, May 14
- Threat actors linked to nation-states exploited zero-days the most in 2022 | SC Media, Published on Monday, March 20
- Zero-day exploits hit enterprises faster and harder | CSO Online, Published on Thursday, March 05
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



