Government US Sanctions Russian Exploit Broker Operation Zero The broker acquired eight zero-day exploits from a US defense contractor executive jailed for his actions. By Ionut Arghire | February 26, 2026 (5:33 AM ET) Flipboard Reddit Whatsapp Whatsapp Email The US government this week announced sanctions against seven individuals and entities for the acquisition and distribution of cyber exploits harmful to national security. The Department of State designated Sergey Sergeyevich Zelenyuk as the owner of Russian exploit broker Operation Zero (Matrix LLC) and Special Technology Services LLC FZ (STS). Between 2022 and 2025, the State Department says, Operation Zero acquired eight zero-day exploits stolen by Peter Williams from his employer, likely Trenchant, a division of L3Harris. Williams, an Australian national, was sentenced to 87 months in prison in the US . According to State, the exploits were meant to be sold exclusively to the US government and allied government entities. Operation Zero paid $1.3 million in cryptocurrency for the cyber tools. Zelenyuk, the department says, is the director and sole owner of Operation Zero. He also established STS in the UAE to circumvent US sanctions on Russian bank accounts and to conduct business with entities in Asia and the Middle East. Concurrently, the Treasury Department’s Office of Foreign Assets Control (OFAC) announced sanctions against Zelenyuk, his companies, and four individuals and organizations associated with them. Advertisement. Scroll to continue reading. Operation Zero, OFAC says, has offered millions of dollars for zero-day exploits and sold them to customers in non-NATO countries, which have used them in ransomware attacks and other malicious activities. The office also says that, through Operation Zero, Zelenyuk sought to sell exploits to foreign intelligence agencies, to develop cyber intelligence systems such as spyware, and to recruit hackers to support its activities. Additionally, OFAC announced sanctions against Marina Evgenyevna Vasanovich, Zelenyuk’s assistant, Oleg Vyacheslavovich Kucherov, a suspected member of the Trickbot hacking group, and Azizjon Makhmudovich Mamashoyev, who previously worked with Operation Zero. OFAC also sanctioned Advance Security Solutions, an exploit broker and offensive cybersecurity company established by Mamashoyev, which operates in the UAE and Uzbekistan. Related: Google Disrupts Chinese Hackers Targeting Telecoms, Governments Related: Taiwan Security Firm Confirms Flaw Flagged by CISA Likely Exploited by Chinese APTs Related: China Revives Tianfu Cup Hacking Contest Under Increased Secrecy Related: UK Sanctions Russian and Chinese Firms Suspected of Being ‘Malign Actors’ in Information Warfare Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. More from Ionut Arghire Astelia Raises $35 Million for Exposure Management Ad Tech Company Optimizely Targeted in Cyberattack ‘Arkanix Stealer’ Malware Disappears Shortly After Debut New ‘Sandworm_Mode’ Supply Chain Attack Hits NPM GitHub Issues Abused in Copilot Attack Leading to Repository Takeover Anonymous Fénix Members Arrested in Spain Ukrainian Gets 5 Years in US Prison for Aiding North Korean IT Fraud Romanian Hacker Pleads Guilty to Selling Access to US State Network Latest News Trend Micro Patches Critical Apex One Vulnerabilities Cisco Patches Catalyst SD-WAN Zero-Day Exploited by Highly Sophisticated Hackers The Blast Radius Problem: Stolen Credentials Are Weaponizing Agentic AI Google Disrupts Chinese Hackers Targeting Telecoms, Governments SolarWinds Patches Four Critical Serv-U Vulnerabilities Medical Device Maker UFP Technologies Hit by Cyberattack Ex-US Defense Contractor Executive Jailed for Selling Exploits to Russia CarGurus Data Breach Impacts Over 12 Million Users Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Identity Under Attack: Why Every Business Must Respond Now February 11, 2026 Attendees will walk away with guidance for how to build robust identity defenses, unify them under a consistent security model, and ensure business operations move quickly without compromise. Register Virtual Event: Ransomware Resilience & Recovery 2026 Summit February 25, 2026 SecurityWeek’s 2026 Ransomware Summit will discuss a roadmap for defending the enterprise, from mitigating root causes to mastering recovery, giving security teams the critical insights needed to navigate and neutralize today’s ransomware extortion threats. Submit People on the Move Menlo Security has named Bill Robbins as Chief Executive Officer. Axonius has named a new CMO and a new AFS leader. Wealth management platform Envestnet announced the appointment of Rich Friedberg as CISO. More People On The Move Expert Insights How to Eliminate the Technical Debt of Insecure AI-Assisted Software Development Developers must view AI as a collaborator to be closely monitored, rather than an autonomous entity to be unleashed. Without such a mindset, crippling tech debt is inevitable. (Matias Madou) Security in the Dark: Recognizing the Signs of Hidden Information Security failures don’t always start with attackers, sometimes they start with missing truth. (Joshua Goldfarb) Living off the AI: The Next Evolution of Attacker Tradecraft Living off the AI isn’t a hypothetical but a natural continuation of the tradecraft we’ve all been defending against, now mapped onto assistants, agents, and MCP. (Etay Maor) Why We Can’t Let AI Take the Wheel of Cyber Defense The fastest way to squander the promise of AI is to mistake automation for assurance, and novelty for resilience. (Steve Durbin) The Upside Down is Real: What Stranger Things Teaches Us About Modern Cybersecurity To all those who are fighting the good fight in the world of cyber, keep collaborating to ensure our world never succumbs to the chaos of the Upside Down. (Nadir Izrael) Flipboard Reddit Whatsapp Whatsapp Email
This article details a sanctions action against a threat actor, not a specific software vulnerability. The threat is the illicit acquisition and sale of proprietary zero-day exploits stolen from a U.S. defense contractor by an insider, Peter Williams, who sold them to the Russian broker Operation Zero. These exploits were then marketed and sold to non-NATO countries and foreign intelligence agencies, where they have been used in activities including ransomware attacks. The U.S. Treasury and State Departments have sanctioned the broker, its owner, and associated entities and individuals in response.