News Room
16
Share
mediumZero-Day Exploits

Zero-Day Weaponization: APT Groups Exploit Unpatched Vulnerabilities in East Asia

Advanced Persistent Threat (APT) groups in East Asia are increasingly exploiting zero-day vulnerabilities, highlighting the critical need for robust cybersecurity measures.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Zero-Day Weaponization: APT Groups Exploit Unpatched Vulnerabilities in East Asia for ₿ 0.10 BTC. Contact us.

25 March 2026Last updated 25 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Medium
Actor Type:
APT
Geography:
East Asia
Confidence:
Confirmed
CVE:
CVE-2024-38178
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Introduction

In recent years, Advanced Persistent Threat (APT) groups in East Asia have demonstrated a growing capability to exploit zero-day vulnerabilities—previously unknown flaws in software that lack patches. This trend underscores the escalating sophistication of cyber threats in the region and the imperative for organizations to enhance their cybersecurity defenses.

Exploitation of Zero-Day Vulnerabilities

Zero-day vulnerabilities are highly coveted by cyber adversaries due to their potential to bypass traditional security measures. APT groups, often state-sponsored, have been observed leveraging these vulnerabilities to infiltrate systems and achieve their objectives.

For instance, in November 2025, the Chinese state-sponsored APT group "Bronze Butler" exploited a zero-day vulnerability in the Lanscope endpoint management tool to compromise Japanese organizations. Lanscope is widely used across Japan, making it a significant target for cyber attackers. (darkreading.com)

Similarly, in October 2024, the North Korean APT group APT37, also known as RedEyes, exploited a zero-day vulnerability in Internet Explorer (CVE-2024-38178) to conduct a supply chain attack. This attack targeted an advertising agency, demonstrating the group's ability to weaponize unpatched vulnerabilities for initial access. (securityweek.com)

Exploit Broker Transactions

The trade of zero-day exploits has become a lucrative market, with brokers acting as intermediaries between vulnerability discoverers and buyers. These brokers often operate in private networks or the dark web, facilitating the sale of exploits to cybercriminals, nation-states, or organizations. Prices for zero-day exploits vary depending on the severity and target, with high-profile vulnerabilities fetching large sums. (atera.com)

In February 2026, the U.S. government sanctioned Russian exploit broker Operation Zero and its founder, Sergey Sergeyevich Zelenyuk, for acquiring and distributing cyber exploits harmful to national security. Between 2022 and 2025, Operation Zero acquired eight zero-day exploits stolen by Peter Williams, a former executive of a U.S. defense contractor. (securityweek.com)

Implications for East Asia

The exploitation of zero-day vulnerabilities by APT groups in East Asia poses significant risks to organizations in the region. The ability to weaponize unpatched flaws allows these groups to infiltrate systems undetected, leading to potential data breaches, intellectual property theft, and disruption of critical services.

Recommendations

To mitigate the risks associated with zero-day vulnerabilities, organizations in East Asia should consider the following measures:

  • Regular Software Updates: Implement a robust patch management process to ensure timely application of security updates.

  • Network Segmentation: Divide networks into segments to limit the lateral movement of attackers within the system.

  • Intrusion Detection Systems: Deploy advanced intrusion detection and prevention systems to identify and respond to suspicious activities promptly.

  • Employee Training: Conduct regular cybersecurity awareness training to educate staff about phishing attacks and other social engineering tactics.

Conclusion

The increasing weaponization of zero-day vulnerabilities by APT groups in East Asia highlights the evolving nature of cyber threats. Organizations must adopt comprehensive cybersecurity strategies to defend against these sophisticated attacks and protect their assets and data.

Highlights:

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo