/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Mandiant: one-third of all hacker groups exploiting zero-days in 2021 were financially motivated criminals as opposed to government-backed cyberespionage groups

Patrick Howell O'Neill / MIT Technology Review :

MIT Technology Review Patrick Howell O'Neill

Context & Ripple Effects

Mandiant's predecessor FireEye spent the 2010s framing zero-days as a state weapon: its global tracking of exploits from 2012 to 2019 tied the use of 55 zero-days to state-sponsored operations. The new 2021 finding — that a third of groups exploiting zero-days were financially motivated criminals — marks a break from that picture.

The shift fits the broader arc in the coverage: China's state hacking already increasingly relies on private-sector hackers, and criminal crews like Lapsus$ have shown that commodity-grade intrusions can hit weaknesses neither spies nor ransomware gangs had prioritized. Mandiant's data suggests top-tier exploits are no longer the exclusive province of espionage.

First-order effects

  • Mandiant's incident-response clients can no longer assume a zero-day intrusion means a nation-state actor — triage, attribution and disclosure decisions now have to weigh criminal motive, with different legal and insurance implications.
  • Financially motivated crews now compete in the same exploit market as intelligence agencies, putting upward pressure on zero-day prices and squeezing defenders who budget for state-grade attacks only.

Second-order effects

  • Exploit brokers and vulnerability researchers gain a second deep-pocketed buyer class: where espionage stockpiles exploits quietly, criminal buyers monetize them fast through ransomware and extortion, changing how quickly discovered flaws burn out.
  • The monetization channels the coverage documents — from concentrated cryptocurrency-theft operations to extortion campaigns — give criminal groups the revenue to justify zero-day spend that was previously uneconomic.

Third-order effects

  • If the pattern holds, the zero-day economy structurally splits into two demand curves — state stockpiling and criminal monetization — eroding the assumption that exploit capability maps to geopolitical actors and complicating export-control and disclosure policy built around that assumption.
  • Defenders and insurers will increasingly price risk on capability rather than motive, pushing the industry toward treating any zero-day use as financially motivated until proven otherwise — a reversal of two decades of attribution doctrine.

The trend: Zero-day exploitation is shifting from a near-monopoly of state-sponsored espionage groups toward a mixed state-and-criminal market, with financially motivated buyers becoming a structural share of demand.

Discussion

  • @adam_k_levin Adam Levin on x
    “In terms of threat actors, China tops the list with eight zero-days used in cyberattacks in 2021, followed by Russia which used two, and North Korea with one.” https://www.bleepingcomputer.com/ ...
  • @mandiant @mandiant on x
    In 2021, Mandiant Threat Intelligence identified 80 #zerodays exploited in the wild, which is more than double the previous record volume in 2019. Read our latest blog post to learn more 👇 https://www.mandiant.com/...
  • @niallfirth Niall Firth on x
    Zero-days used to be mostly used by rich nation state-backed hacking groups. Not any more. @HowellONeill explains why. https://www.technologyreview.com/ ...
  • @nsa_csdirector Rob Joyce on x
    Threats to critical infrastructure remain very real. Russian state-sponsored and cybercriminal groups may target CIKR networks in the U.S. and globally, including attempting destructive actions. Prioritize our top mitigations to be prepared. https://www.nsa.gov/...