Zero-Day Weaponization: APT Groups Targeting Unpatched Vulnerabilities in the Middle East
Advanced Persistent Threat (APT) groups are increasingly exploiting zero-day vulnerabilities in the Middle East, leveraging unpatched exploits and engaging in exploit broker transactions to enhance their cyber operations.
Encrygma is selling the entire Full Cyber Weapon Research of Zero-Day Weaponization: APT Groups Targeting Unpatched Vulnerabilities in the Middle East for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Medium
- Actor Type:
- APT
- Geography:
- Middle East
- Confidence:
- Confirmed
- CVE:
- CVE-2026-21509, CVE-2026-21513, CVE-2025-33053
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Introduction
In early 2026, Advanced Persistent Threat (APT) groups have intensified their exploitation of zero-day vulnerabilities in the Middle East. These groups are leveraging unpatched exploits and engaging in exploit broker transactions to enhance their cyber operations.
Exploitation of Zero-Day Vulnerabilities
Zero-day vulnerabilities are previously unknown flaws in software that attackers can exploit before developers release patches. In 2025, 90 zero-day vulnerabilities were exploited in the wild, with nearly half targeting enterprise-grade technology. This trend underscores the growing sophistication of cyber adversaries. (cybersecuritydive.com)
APT groups such as APT28, Lotus Blossom, and TA-RedAnt (APT37) have been particularly active in weaponizing zero-day vulnerabilities. For instance, APT28 exploited Microsoft Office and MSHTML zero-day vulnerabilities (CVE-2026-21509, CVE-2026-21513) immediately after their disclosure, launching large-scale attacks against European military, government, and transportation agencies, as well as Ukrainian organizations. (asec.ahnlab.com)
In-the-Wild Exploitation in the Middle East
APT groups have also targeted entities in the Middle East using zero-day exploits. The Stealth Falcon APT group, for example, exploited a Microsoft RCE zero-day vulnerability (CVE-2025-33053) to compromise high-profile defense entities in the region. (darkreading.com)
Exploit Broker Transactions
The underground market for zero-day exploits has seen significant activity, with brokers acting as intermediaries between vulnerability discoverers and buyers. Between January 2023 and September 2024, Kaspersky identified 547 listings to buy and sell exploits targeting software vulnerabilities, with half involving zero-day and one-day vulnerabilities. (me-en.kaspersky.com)
In February 2026, the U.S. Department of the Treasury sanctioned Sergey Sergeyevich Zelenyuk and his company, Matrix LLC (doing business as Operation Zero), for acquiring and distributing cyber tools harmful to U.S. national security. Operation Zero had acquired at least eight proprietary cyber tools created for the exclusive use of the U.S. government and select allies, which were stolen from a U.S. company. (home.treasury.gov)
Conclusion
The weaponization of zero-day vulnerabilities by APT groups in the Middle East represents a significant escalation in cyber threats. The active exploitation of unpatched vulnerabilities and the involvement of exploit brokers in facilitating these attacks highlight the need for enhanced cybersecurity measures and international cooperation to mitigate these risks.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



