News Room
16
Share
criticalZero-Day Exploits

Zero-Day Weaponization: APT Groups Exploit Unpatched Vulnerabilities in East Asia

Advanced Persistent Threat (APT) groups in East Asia are increasingly exploiting zero-day vulnerabilities, leading to critical security breaches. This briefing examines recent activities, targeted sectors, and the role of exploit brokers in facilitating these attacks.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Zero-Day Weaponization: APT Groups Exploit Unpatched Vulnerabilities in East Asia for ₿ 0.10 BTC. Contact us.

06 March 2026Last updated 06 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
APT
Geography:
East Asia
Confidence:
Confirmed
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Introduction

In recent years, Advanced Persistent Threat (APT) groups in East Asia have intensified their exploitation of zero-day vulnerabilities, leading to significant security breaches across various sectors. Zero-day vulnerabilities are previously unknown flaws in software or hardware that attackers can exploit before developers release patches. The weaponization of these vulnerabilities has become a critical concern, with state-sponsored actors leveraging them for cyber espionage, data theft, and disruption of critical infrastructure.

APT Groups and Zero-Day Exploitation

Several APT groups in East Asia have been identified as active exploiters of zero-day vulnerabilities:

  • APT-C-39 (CIA): This group has extensively exploited zero-day vulnerabilities in cyber espionage operations against China and other nations. In 2024, APT-C-39 targeted key units related to cutting-edge technologies in China's aviation, aerospace, and materials science sectors, stealing sensitive technological information and research data. (globaltimes.cn)

  • Ricochet Chollima (APT 37): A North Korean state-sponsored hacking group, Ricochet Chollima has been involved in operations against financial institutions and the industrial sector in other countries. They have also engaged in attacks against Japan, Vietnam, Hong Kong, the Middle East, Russia, and the United States. (en.wikipedia.org)

  • Red Apollo (APT 10): A Chinese state-sponsored cyberespionage group, Red Apollo has operated since 2006, targeting aerospace, engineering, and telecom firms, as well as governments considered rivals to China. (en.wikipedia.org)

  • Volt Typhoon: Operated by the Chinese government, Volt Typhoon has been active since at least mid-2021, primarily targeting United States critical infrastructure. The group focuses on espionage, data theft, and credential access, often exploiting zero-day vulnerabilities to gain unauthorized access. (en.wikipedia.org)

Targeted Sectors and Impact

APT groups have targeted a wide range of sectors in East Asia, including:

  • Government Agencies: Attacks on government entities aim to steal sensitive information and disrupt operations.

  • Critical Infrastructure: Sectors such as telecommunications, energy, and transportation have been targeted to cause disruption and gather intelligence.

  • Financial Institutions: Cyber espionage campaigns against financial organizations seek to steal financial data and intellectual property.

  • Technology and Research Institutions: Attacks on tech firms and research institutions aim to steal intellectual property and gain a competitive advantage.

Exploit Brokers and Zero-Day Vulnerabilities

Exploit brokers play a significant role in the zero-day ecosystem by acquiring and selling vulnerabilities to various actors, including state-sponsored groups. In February 2026, the U.S. Department of the Treasury sanctioned Sergey Sergeyevich Zelenyuk and his company, Matrix LLC (doing business as Operation Zero), for acquiring and distributing cyber tools harmful to U.S. national security. Operation Zero traded in exploits, including at least eight proprietary cyber tools created for the exclusive use of the U.S. government, which were stolen from a U.S. company. (home.treasury.gov)

Conclusion

The weaponization of zero-day vulnerabilities by APT groups in East Asia poses a critical threat to regional and global cybersecurity. The involvement of exploit brokers in facilitating these attacks underscores the need for enhanced international cooperation and robust cybersecurity measures to detect, mitigate, and prevent such sophisticated cyber threats.

Highlights:

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo