News Room
16
Share
highZero-Day Exploits

Ransomware Groups in East Asia Intensify Exploitation of Zero-Day Vulnerabilities

Ransomware groups in East Asia are increasingly leveraging zero-day vulnerabilities to infiltrate networks, with notable incidents involving Akira and Volt Typhoon.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Ransomware Groups in East Asia Intensify Exploitation of Zero-Day Vulnerabilities for ₿ 0.10 BTC. Contact us.

07 March 2026Last updated 07 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
High
Actor Type:
Ransomware Group
Geography:
East Asia
Confidence:
Confirmed
CVE:
CVE-2025-31324, CVE-2025-42999
Source:
Raptor Cyber Intelligence
Read Time:
5 min

In early 2026, ransomware groups in East Asia have escalated their exploitation of zero-day vulnerabilities, leading to significant security breaches across various sectors. This trend underscores the evolving tactics of cybercriminals and the critical need for robust cybersecurity measures.

Akira Ransomware Group's Exploitation of Zero-Day Vulnerabilities

The Akira ransomware group, which emerged in March 2023, has rapidly become one of the most prolific ransomware-as-a-service (RaaS) operations by the end of 2025. By January 2024, Akira affiliates had attacked over 250 organizations, amassing approximately $42 million in ransom proceeds. A significant portion of these attacks involved exploiting zero-day vulnerabilities in public-facing servers. In August 2025, reports indicated that Akira attackers were exploiting a zero-day vulnerability in SonicWall SSL VPN devices, enabling them to pivot directly from these devices to domain controllers within hours of an initial breach. (security.com)

Volt Typhoon's Targeting of Critical Infrastructure

Volt Typhoon, an advanced persistent threat (APT) group attributed to the Chinese government, has been active since at least mid-2021. This group primarily targets critical infrastructure in the United States, focusing on espionage, data theft, and credential access. Volt Typhoon is known for its meticulous approach to avoid detection, with campaigns designed to sabotage critical communications infrastructure between the U.S. and Asia during potential future crises. (en.wikipedia.org)

Exploitation of SAP NetWeaver Vulnerabilities

In May 2025, two ransomware groups and several Chinese APTs were observed exploiting two critical vulnerabilities in SAP NetWeaver: CVE-2025-31324 and CVE-2025-42999. These flaws, with CVSS scores of 10 and 9.1 respectively, affected the Visual Composer development server component, allowing remote attackers to execute arbitrary code without authentication. In-the-wild attacks began in January 2025, with threat actors deploying webshells for follow-up activities. SAP released patches for these vulnerabilities in April and May 2025. (securityweek.com)

Increased Zero-Day Exploitation by State-Sponsored Actors

Reports from 2023 indicate that threat groups with ties to nation-states were the primary exploiters of zero-day vulnerabilities, accounting for 80% of such exploits. Chinese state-sponsored cyber espionage groups were particularly active, responsible for over 50% of the zero-day exploits that year. This trend highlights the strategic importance of zero-day vulnerabilities in cyber operations and the need for enhanced defensive measures. (scworld.com)

Implications and Recommendations

The increasing use of zero-day vulnerabilities by ransomware groups in East Asia poses significant risks to organizations worldwide. To mitigate these threats, organizations should:

  • Implement Comprehensive Patching Protocols: Regularly update systems and applications to address known vulnerabilities promptly.

  • Enhance Network Monitoring: Deploy advanced intrusion detection systems to identify and respond to suspicious activities swiftly.

  • Conduct Regular Security Audits: Perform thorough assessments to identify potential vulnerabilities and strengthen defenses.

By adopting these measures, organizations can bolster their resilience against the evolving tactics of ransomware groups and other cyber adversaries.

Highlights:

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo