Zero-Day Weaponization: Ransomware Groups Exploit Unpatched Vulnerabilities in East Asia
Ransomware groups in East Asia are increasingly exploiting zero-day vulnerabilities, leading to critical threats and significant financial losses.
Encrygma is selling the entire Full Cyber Weapon Research of Zero-Day Weaponization: Ransomware Groups Exploit Unpatched Vulnerabilities in East Asia for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- East Asia
- Confidence:
- Confirmed
- CVE:
- CVE-2025-31324, CVE-2025-42999
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
In recent years, ransomware groups in East Asia have intensified their exploitation of zero-day vulnerabilities, leading to critical threats and substantial financial losses. Zero-day vulnerabilities are previously unknown flaws in software that attackers can exploit before developers release patches. The exploitation of these vulnerabilities has become a prevalent tactic among cybercriminals, particularly ransomware groups targeting organizations in East Asia.
Exploitation of Zero-Day Vulnerabilities
Ransomware groups have increasingly targeted zero-day vulnerabilities to gain unauthorized access to systems and deploy malicious payloads. For instance, in October 2025, the Chinese state-sponsored advanced persistent threat (APT) group known as "Bronze Butler" exploited a zero-day vulnerability in the Lanscope Endpoint Manager, a widely used endpoint management tool in Japan. This exploitation allowed the attackers to execute arbitrary commands with SYSTEM privileges on compromised systems, leading to the deployment of backdoors and unauthorized access to sensitive information. (darkreading.com)
Similarly, in May 2025, multiple Chinese APTs and ransomware groups exploited two critical vulnerabilities in SAP NetWeaver, tracked as CVE-2025-31324 and CVE-2025-42999. These vulnerabilities, with CVSS scores of 10 and 9.1 respectively, affected the Visual Composer development server component and allowed remote attackers to execute arbitrary code without authentication. The exploitation of these flaws led to the deployment of web shells, facilitating further malicious activities within targeted organizations. (securityweek.com)
Financial Implications and Exploit Broker Transactions
The financial impact of zero-day exploitation is significant. In August 2023, Akamai Technologies reported a 143% increase in total ransomware victims between Q1 2022 and Q1 2023, attributing this surge to the rampant abuse of zero-day and one-day vulnerabilities. The report also highlighted that ransomware groups are increasingly targeting the exfiltration of files, making unauthorized extraction or transfer of sensitive information the primary source of extortion. (akamai.com)
The market for zero-day exploits has also seen significant activity. Between January 2023 and September 2024, Kaspersky Digital Footprint Intelligence identified 547 listings to buy and sell exploits targeting software vulnerabilities, with half involving zero-day and one-day vulnerabilities. The average price for remote code execution exploits was around $100,000, indicating the high value placed on such exploits in the cybercriminal ecosystem. (me-en.kaspersky.com)
Mitigation Strategies
To mitigate the risks associated with zero-day exploitation, organizations should implement a multi-layered security approach. This includes regular patch management to address known vulnerabilities, network segmentation to limit the spread of attacks, and continuous monitoring to detect unusual activities. Additionally, investing in advanced threat detection systems and conducting regular security audits can help identify and address potential vulnerabilities before they are exploited.
In conclusion, the weaponization of zero-day vulnerabilities by ransomware groups in East Asia presents a critical threat to organizations in the region. The increasing sophistication of these attacks underscores the need for robust cybersecurity measures and proactive threat intelligence to safeguard sensitive information and maintain operational integrity.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



