Zero-Day Weaponization: Ransomware Groups Exploit Unpatched Vulnerabilities in Western Europe
Ransomware groups in Western Europe are increasingly exploiting zero-day vulnerabilities, leading to critical threats. This briefing examines recent incidents, actor tactics, and the role of exploit brokers.
Encrygma is selling the entire Full Cyber Weapon Research of Zero-Day Weaponization: Ransomware Groups Exploit Unpatched Vulnerabilities in Western Europe for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Western Europe
- Confidence:
- Confirmed
- CVE:
- CVE-2021-1675, CVE-2021-34527, CVE-2025-10035
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
In early 2026, ransomware groups in Western Europe have intensified their exploitation of zero-day vulnerabilities, posing significant threats to organizations across the region. Zero-day vulnerabilities are previously unknown flaws in software that attackers can exploit before developers release patches, often leading to severe security breaches.
Recent Exploitation Trends
Between January 2023 and September 2024, Kaspersky identified 547 listings on dark web forums and Telegram channels offering exploits targeting software vulnerabilities. Notably, half of these listings involved zero-day and one-day vulnerabilities, highlighting the lucrative market for such exploits. The average price for remote code execution vulnerabilities was approximately $100,000, indicating a thriving underground economy centered around these critical flaws. (me-en.kaspersky.com)
Notable Ransomware Groups and Their Tactics
Several ransomware groups have been active in exploiting zero-day vulnerabilities:
-
Clop: This Russian-speaking group has been responsible for high-profile attacks, including the exploitation of zero-day vulnerabilities in GoAnywhere MFT and MOVEit Transfer platforms. In January 2023, Clop claimed responsibility for breaching over 130 organizations by exploiting a zero-day vulnerability in GoAnywhere MFT, leading to significant data exfiltration. (en.wikipedia.org)
-
Vice Society: Known for targeting healthcare, educational, and manufacturing sectors, Vice Society has utilized vulnerabilities like PrintNightmare (CVE-2021-1675, CVE-2021-34527) to gain initial access to networks. Their attacks often involve data exfiltration and double extortion tactics, demanding ransoms to prevent data leaks. (en.wikipedia.org)
-
Storm-1175: This threat group has been linked to the exploitation of critical vulnerabilities in GoAnywhere MFT, deploying Medusa ransomware following successful compromises. The exploitation of CVE-2025-10035, a deserialization vulnerability, has been particularly impactful, affecting sectors such as healthcare, finance, and manufacturing. (linkedin.com)
Role of Exploit Brokers
Exploit brokers play a pivotal role in the cyber threat landscape by acquiring and distributing zero-day vulnerabilities. For instance, in February 2026, the U.S. Department of the Treasury sanctioned Sergey Sergeyevich Zelenyuk and his company, Matrix LLC (doing business as Operation Zero), for acquiring and distributing cyber tools harmful to U.S. national security. Operation Zero has been known to trade in exploits, including those targeting U.S.-built software, and has offered rewards for such vulnerabilities. (home.treasury.gov)
Implications for Organizations
The active exploitation of zero-day vulnerabilities by ransomware groups underscores the necessity for organizations to adopt a proactive cybersecurity posture. This includes implementing robust patch management processes, conducting regular security assessments, and fostering a culture of security awareness among employees. Given the critical nature of these threats, organizations should also collaborate with cybersecurity vendors and governmental agencies to stay informed about emerging vulnerabilities and effective mitigation strategies.
In conclusion, the weaponization of zero-day vulnerabilities by ransomware groups in Western Europe represents a critical and evolving threat. Continuous vigilance, timely response to security advisories, and comprehensive security measures are essential to mitigate the risks associated with these sophisticated cyberattacks.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



