Ransomware Groups in South Asia Exploit Zero-Day Vulnerabilities
Ransomware groups in South Asia are increasingly exploiting zero-day vulnerabilities to infiltrate networks, with Clop and Akira leading these attacks.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Medium
- Actor Type:
- Ransomware Group
- Geography:
- South Asia
- Confidence:
- Confirmed
- CVE:
- CVE-2023-0669
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
In early 2026, ransomware groups in South Asia have intensified their exploitation of zero-day vulnerabilities, leading to significant security breaches across various sectors. Notably, the Clop and Akira ransomware groups have been at the forefront of these attacks, utilizing unpatched exploits to infiltrate networks and demand substantial ransoms.
Clop Ransomware Group
The Clop group has been particularly active, leveraging zero-day vulnerabilities to maximize the impact of their attacks. In 2023, Clop exploited a zero-day vulnerability in the GoAnywhere MFT secure file transfer tool, breaching over 130 organizations. This vulnerability, identified as CVE-2023-0669, allowed attackers to execute remote code on unpatched instances of GoAnywhere MFT with exposed administrative consoles. (en.wikipedia.org)
In 2025, Clop targeted the MOVEit Transfer software, exploiting a zero-day vulnerability to access sensitive data from multiple organizations. This attack underscored Clop's strategy of targeting widely used software to achieve rapid and extensive access. (en.wikipedia.org)
Akira Ransomware Group
The Akira ransomware group, operating as a Ransomware-as-a-Service (RaaS) platform, has also been active in exploiting zero-day vulnerabilities. In August 2025, reports indicated that Akira affiliates were exploiting a zero-day vulnerability in SonicWall SSL VPN devices. This vulnerability allowed attackers to pivot directly from the compromised devices to domain controllers within hours, facilitating rapid lateral movement within networks. (security.com)
Exploit Broker Transactions
The demand for zero-day vulnerabilities has led to a thriving market among exploit brokers. In March 2025, a Russian exploit broker known as "Operation Zero" offered up to $4 million for vulnerabilities in the Telegram messaging app. This highlights the lucrative nature of zero-day exploits and the lengths to which threat actors will go to acquire them. (techcrunch.com)
Impact and Mitigation
The exploitation of zero-day vulnerabilities by ransomware groups has resulted in a significant increase in cyberattacks. Between Q1 2022 and Q1 2023, there was a 143% increase in total ransomware victims, largely attributed to the abuse of zero-day and one-day vulnerabilities. (akamai.com)
Organizations are advised to implement robust security measures, including regular patching of software, network segmentation, and continuous monitoring for unusual activities. Additionally, maintaining up-to-date backups and developing comprehensive incident response plans are crucial steps in mitigating the risks associated with zero-day exploitations.
The evolving tactics of ransomware groups underscore the necessity for organizations to remain vigilant and proactive in their cybersecurity strategies to defend against sophisticated attacks leveraging zero-day vulnerabilities.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



