Monday, August 3, 2026

Policy & Regulation

U.S. sanctions Russian zero-day broker Operation Zero

The U.S. Treasury sanctioned Russian broker Operation Zero and its affiliates for acquiring and reselling at least eight proprietary cyber tools stolen from a U.S. defense contractor.

U.S. sanctions Russian zero-day broker Operation Zero

On Tuesday, the U.S. government announced sanctions against two companies that acquire and resell zero-day exploits—security vulnerabilities in software that are unknown to the developer—as well as their founders and associates. The U.S. Treasury’s Office of Foreign Assets Control (OFAC) targeted Operation Zero, a Russian firm launched in 2021, and UAE-based Advance Security Solutions. According to the Treasury, Operation Zero acquired at least eight proprietary cyber tools stolen from a U.S. company and sold them to an unauthorized user. Operation Zero, which claims to work exclusively with the Russian government and local organizations, previously made headlines in 2023 by offering up to $20 million for zero-days in Android devices and iPhones, and up to $4 million for exploits in Telegram.

The Treasury’s announcement confirms that Operation Zero was the unspecified Russian broker involved in the case of Peter Williams, a former employee of U.S. defense contractor L3Harris. In October, Williams pleaded guilty to selling at least eight of the company’s exploits to an unspecified Russian broker. Williams served as the general manager at Trenchant, an L3Harris subsidiary that develops hacking and surveillance tools for the U.S. government and its partners in the Five Eyes—an intelligence alliance of Australia, Canada, New Zealand, the United Kingdom, and the United States.

Alongside Operation Zero, the U.S. government sanctioned several affiliated individuals and entities under a 2022 federal law targeting significant thefts of trade secrets. These include:

  • Sergey Zelenyuk: The founder of Operation Zero, whom officials accused of selling exploits to foreign intelligence agencies.
  • Special Technology Services: An affiliate company based in the United Arab Emirates.
  • Marina Evgenyevna Vasanovich: Zelenyuk’s assistant.
  • Oleg Vyacheslavovich Kucherov: A Russian national associated with the company who is suspected of being a member of the prolific ransomware gang TrickBot. OFAC stated that Operation Zero’s customers “could use the tools to launch ransomware attacks or engage in other malign activities.”
  • Azizjon Makhmudovich Mamashoyev: An associate who allegedly founded Advance Security Solutions, another sanctioned UAE-based broker that offered up to $20 million for smartphone exploits. However, a person operating an Advance Security Solutions’ chat account reported that Mamashoyev is not the founder of the company.

Why it matters

This action formalizes the link between a U.S. defense contractor’s internal security breach and the trade in zero-day exploits, signaling a crackdown on brokers who facilitate state-aligned cyber threats.