Zero-Day Weaponization: Nation-State Actors and the Exploit Broker Ecosystem
An analysis of nation-state actors' use of zero-day vulnerabilities and the exploit broker market, focusing on recent developments in North America.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Medium
- Actor Type:
- Nation-State
- Geography:
- North America
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Zero-day vulnerabilities—flaws in software unknown to the vendor and lacking a patch—pose significant risks to cybersecurity. Nation-state actors have increasingly weaponized these vulnerabilities, often acquiring them through exploit brokers, to advance their strategic objectives.
Exploitation by Nation-State Actors
In 2025, nation-state actors were responsible for exploiting 12 out of 42 unique zero-day vulnerabilities, as reported by the Google Threat Intelligence Group (GTIG). Chinese state-sponsored groups led this activity, with seven known vulnerabilities exploited, followed by Russia and North Korea, each with two. (scworld.com)
A notable example is the exploitation of a Microsoft zero-day vulnerability by the North Korean state-sponsored group, Kimsuky. This vulnerability was used to target organizations in North America, Europe, Asia, South America, and Australia, affecting sectors such as government, financial, telecommunications, military, and energy. (cybersecuritydive.com)
The Role of Exploit Brokers
Exploit brokers act as intermediaries between vulnerability discoverers and buyers, including nation-state actors. These brokers acquire zero-day vulnerabilities and sell them to the highest bidder, often government agencies or intelligence services. The U.S. Department of the Treasury has sanctioned Russian exploit broker Sergey Sergeyevich Zelenyuk and his company, Matrix LLC (also known as Operation Zero), for acquiring and distributing cyber tools harmful to U.S. national security. (home.treasury.gov)
In March 2025, Operation Zero offered up to $4 million for zero-day exploits targeting the Telegram messaging app, highlighting the lucrative nature of the exploit market. (techcrunch.com)
Implications for North America
The weaponization of zero-day vulnerabilities by nation-state actors poses a medium-level threat to North American cybersecurity. The involvement of exploit brokers in facilitating these activities underscores the need for enhanced vigilance and proactive defense measures. Organizations should prioritize patch management, conduct regular security assessments, and collaborate with cybersecurity agencies to mitigate the risks associated with zero-day exploits.
Understanding the dynamics between nation-state actors and exploit brokers is crucial for developing effective cybersecurity strategies. By staying informed about these developments, organizations can better prepare and defend against sophisticated cyber threats.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Critical GitLab Path Traversal Vulnerability (CVE-2026-85706) Under Active Exploitation

Critical GitLab Path Traversal (CVE-2026-85706) Under Active Exploitation Following Disclosure

