Zero-Day Weaponization: Ransomware Groups Exploit Unpatched Vulnerabilities in East Asia
Ransomware groups in East Asia are increasingly exploiting zero-day vulnerabilities, leading to significant cyber threats. This briefing examines recent incidents, actor tactics, and the role of exploit brokers.
Encrygma is selling the entire Full Cyber Weapon Research of Zero-Day Weaponization: Ransomware Groups Exploit Unpatched Vulnerabilities in East Asia for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- High
- Actor Type:
- Ransomware Group
- Geography:
- East Asia
- Confidence:
- Confirmed
- CVE:
- CVE-2025-31324, CVE-2025-42999, CVE-2025-53770, CVE-2025-29824
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 6 min
In recent years, ransomware groups in East Asia have intensified their exploitation of zero-day vulnerabilities, leading to significant cyber threats across the region. Zero-day vulnerabilities are previously unknown flaws in software that attackers can exploit before developers release patches. The weaponization of these vulnerabilities has become a critical concern for cybersecurity professionals.
Recent Incidents in East Asia
In May 2025, two ransomware groups and several Chinese Advanced Persistent Threats (APTs) were observed exploiting critical vulnerabilities in SAP NetWeaver, tracked as CVE-2025-31324 and CVE-2025-42999. These flaws allowed remote code execution without authentication, enabling attackers to deploy web shells for follow-up activities. The exploitation of these vulnerabilities was ongoing since January 2025, with targeted attacks against critical infrastructure networks in the UK, US, and Saudi Arabia. (securityweek.com)
Additionally, in November 2025, Chinese state-sponsored actors exploited a zero-day vulnerability in Microsoft SharePoint, identified as CVE-2025-53770, to compromise government and private sector networks across multiple continents, including Africa, South America, the Middle East, and Europe. The flaw, patched in July 2025, allowed unauthenticated remote code execution on on-premise SharePoint servers and was weaponized months before disclosure. (criticalstart.com)
Actor Tactics and Techniques
Ransomware groups in East Asia have demonstrated sophisticated tactics in exploiting zero-day vulnerabilities. For instance, the Chinese APT group known as Chaya_004 targeted vulnerable SAP NetWeaver instances, deploying web shells for network discovery and application mapping, likely in preparation for lateral movement. This approach highlights the group's focus on thorough reconnaissance before executing malicious payloads. (securityweek.com)
Another notable example is the exploitation of the Windows Common Log File System (CLFS) vulnerability, CVE-2025-29824, by ransomware groups such as Storm-2460. This flaw allowed attackers to escalate privileges and deploy malware like PipeMagic, typically used to deploy ransomware. The exploitation of this vulnerability was observed in attacks targeting sectors including IT, real estate, finance, and retail across various countries. (securityweek.com)
Role of Exploit Brokers
Exploit brokers play a significant role in the cyber threat landscape by acquiring and distributing zero-day vulnerabilities. In February 2026, the U.S. Department of the Treasury sanctioned Sergey Sergeyevich Zelenyuk and his company, Matrix LLC (doing business as Operation Zero), for acquiring and distributing cyber tools harmful to U.S. national security. Operation Zero traded in exploits, including at least eight proprietary cyber tools stolen from a U.S. company, and offered rewards for exploits targeting U.S.-built software. (home.treasury.gov)
The activities of exploit brokers like Operation Zero underscore the complex ecosystem of cyber threats, where vulnerabilities are commodified and sold to the highest bidder, often facilitating attacks by various threat actors.
Conclusion
The weaponization of zero-day vulnerabilities by ransomware groups in East Asia represents a high-level threat to global cybersecurity. The sophisticated tactics employed by these groups, coupled with the involvement of exploit brokers, necessitate a coordinated and proactive response from cybersecurity professionals and organizations worldwide. Continuous monitoring, timely patching, and comprehensive threat intelligence sharing are essential to mitigate the risks associated with zero-day exploits.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



