News Room
16
Share
mediumZero-Day Exploits

Zero-Day Weaponization: APT Groups Exploit Unpatched Vulnerabilities in East Asia

Advanced Persistent Threat (APT) groups in East Asia are increasingly exploiting zero-day vulnerabilities, targeting critical infrastructure and enterprise systems. This trend underscores the evolving cyber threat landscape and the need for enhanced security measures.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Zero-Day Weaponization: APT Groups Exploit Unpatched Vulnerabilities in East Asia for ₿ 0.10 BTC. Contact us.

24 March 2026Last updated 24 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Medium
Actor Type:
APT
Geography:
East Asia
Confidence:
Confirmed
CVE:
CVE-2024-7262
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Introduction

In recent years, Advanced Persistent Threat (APT) groups in East Asia have intensified their exploitation of zero-day vulnerabilities—previously unknown flaws in software that lack patches. This strategic shift allows attackers to infiltrate systems undetected, posing significant risks to critical infrastructure and enterprise environments.

APT Groups and Zero-Day Exploitation

APT groups are state-sponsored or highly organized entities that conduct prolonged, targeted cyberattacks. In East Asia, several such groups have been identified leveraging zero-day vulnerabilities:

  • APT-C-60: A South Korea-aligned cyberespionage group, APT-C-60, weaponized a remote code execution vulnerability in WPS Office for Windows (CVE-2024-7262) to target East Asian countries. The group utilized a deceptive spreadsheet document to exploit the vulnerability, delivering a custom backdoor named SpyGlace. (eset.com)

  • Lazarus Group: A North Korean state-sponsored actor, the Lazarus Group, has been observed exploiting one-day vulnerabilities—flaws that have been publicly disclosed and patched but not yet widely implemented. This approach allows them to target systems before organizations can apply necessary updates. (cybersecuritynews.com)

Exploit Broker Transactions

The market for zero-day exploits has seen significant activity, with brokers facilitating the sale and purchase of these vulnerabilities:

  • Operation Zero: A Russia-based exploit broker, Operation Zero, has been sanctioned by the U.S. government for acquiring and reselling zero-day exploits. Between 2022 and 2025, they acquired eight zero-day exploits stolen from a U.S. defense contractor executive, paying $1.3 million in cryptocurrency. (securityweek.com)

  • Market Dynamics: Between January 2023 and September 2024, Kaspersky identified 547 listings on dark web forums and Telegram channels for buying and selling exploits targeting software vulnerabilities. Approximately half of these involved zero-day and one-day vulnerabilities, with remote code execution exploits averaging $100,000. (me-en.kaspersky.com)

Implications and Recommendations

The exploitation of zero-day vulnerabilities by APT groups and the active market for these exploits highlight the critical need for robust cybersecurity measures:

  • Proactive Defense: Organizations should implement comprehensive security assessments to identify and patch vulnerabilities before they can be exploited.

  • Monitoring and Response: Continuous monitoring of digital assets and the dark web can help detect and mitigate emerging threats.

  • Collaboration: Sharing threat intelligence and collaborating with cybersecurity firms can enhance the collective defense against sophisticated cyberattacks.

Conclusion

The increasing weaponization of zero-day vulnerabilities by APT groups in East Asia underscores a dynamic and evolving cyber threat landscape. Organizations must adopt proactive and comprehensive security strategies to safeguard against these advanced and persistent threats.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo