{"id":43942,"date":"2026-02-26T03:19:56","date_gmt":"2026-02-25T19:19:56","guid":{"rendered":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/02\/26\/us-sanctions-russian-exploit-broker-over-stolen-us-cyber-tools\/"},"modified":"2026-02-26T03:19:56","modified_gmt":"2026-02-25T19:19:56","slug":"us-sanctions-russian-exploit-broker-over-stolen-us-cyber-tools","status":"publish","type":"post","link":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/02\/26\/us-sanctions-russian-exploit-broker-over-stolen-us-cyber-tools\/","title":{"rendered":"US Sanctions Russian Exploit Broker Over Stolen US Cyber Tools"},"content":{"rendered":"\n<p>The United States government has launched a crackdown on a global network accused of stealing and selling sensitive <a href=\"https:\/\/hackread.com\/5-cyber-tools-2020-business-needs-keep-safe\/\" target=\"_blank\" data-type=\"post\" data-id=\"74978\" rel=\"noreferrer noopener\">cyber tools<\/a> used for national security. In a move announced on Tuesday, February 24<sup>th<\/sup>, the Department of the Treasury placed sanctions on Sergey Sergeyevich Zelenyuk and his Russian firm, Matrix LLC, better known in the industry as Operation Zero.<\/p>\n<p>The Treasury Department\u2019s <a href=\"https:\/\/home.treasury.gov\/news\/press-releases\/sb0404\" target=\"_blank\" rel=\"noreferrer noopener\">press release<\/a> identifies this group as an &#8220;exploit broker.&#8221; To put it simply, an exploit is a specific method or piece of code that takes advantage of a flaw in a computer program, allowing a user to gain secret access to a device, steal data, or take over a system entirely.<\/p>\n<p>Investigation revealed that Zelenyuk has been running this operation since 2021, offering millions of pounds in rewards to hackers who can find weaknesses in American software and encrypted messaging apps.<\/p>\n<h3><strong>The Cost of Betrayal<\/strong><\/h3>\n<p>The case involves the theft of eight proprietary <a href=\"https:\/\/hackread.com\/2025-top-osint-tools-take-on-open-source-intel\/\" target=\"_blank\" rel=\"noreferrer noopener\">cyber tools<\/a>. These were not just any programs; they were created for the exclusive use of the US government and its allies. These tools were stolen from an American company by an insider named Peter Williams.<\/p>\n<p>Williams, a 39-year-old Australian national, pleaded guilty on 29 October 2025 to stealing these trade secrets. He was sentenced to 87 months in prison for selling these secrets. The Department of Justice also <a href=\"https:\/\/www.justice.gov\/opa\/pr\/former-general-manager-us-defense-contractor-sentenced-87-months-selling-stolen-trade\" target=\"_blank\" rel=\"noreferrer noopener\">announced<\/a> his sentencing on February 24th, revealing that he used his senior position at a US defence contractor to auction off these capabilities to a Russian bidder for personal gain. Along with his prison term, the court ordered him to give up $1.3 million, cryptocurrency, and various luxury items, including a house and expensive watches<\/p>\n<p>It is worth noting that Williams sold the stolen tools to Operation Zero in exchange for millions of dollars paid in cryptocurrencies. The <a href=\"https:\/\/hackread.com\/u-s-treasury-sanctions-isis-cybersecurity-experts\/\" target=\"_blank\" rel=\"noreferrer noopener\">Treasury Department<\/a> noted that the group then sold these sensitive tools to at least one unauthorised user, and beyond traditional software, the group also sought to develop ways to extract private data from people using <a href=\"https:\/\/hackread.com\/harnessing-ai-proactive-threat-intelligence-cyber-defense\/\" target=\"_blank\" data-type=\"link\" data-id=\"https:\/\/hackread.com\/harnessing-ai-proactive-threat-intelligence-cyber-defense\/\" rel=\"noreferrer noopener\">artificial intelligence<\/a> applications.<\/p>\n<figure>\n<div>\n<blockquote data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">BREAKING: US just sanctioned a network of exploit brokers trafficking in stolen US hacking tools<\/p>\n<p>First-ever use of <a href=\"https:\/\/twitter.com\/hashtag\/PIPA?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">#PIPA<\/a> (Protecting American Intellectual Property Act) by <a href=\"https:\/\/twitter.com\/USTreasury?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@USTreasury<\/a>. <\/p>\n<p>Here&#39;s the wild backstory of how <a href=\"https:\/\/twitter.com\/opzero_en?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@opzero_en<\/a> got US-taxpayer funded exploits. 1\/ <a href=\"https:\/\/t.co\/5f1CytCTaO\">pic.twitter.com\/5f1CytCTaO<\/a><\/p>\n<p>&mdash; John Scott-Railton (@jsrailton) <a href=\"https:\/\/twitter.com\/jsrailton\/status\/2026380832085258734?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">February 24, 2026<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script> <\/div>\n<\/figure>\n<h3><strong>A Network of Global Associates<\/strong><\/h3>\n<p>The US Treasury\u2019s action also names several individuals and companies tied to the Russian broker. This includes Zelenyuk\u2019s assistant, Marina Evgenyevna Vasanovich, and a UAE-based firm called Special Technology Services (STS).<\/p>\n<p>The investigators also identified Azizjon Makhmudovich Mamashoyev and Oleg Vyacheslavovich Kucherov as key associates. Kucherov is a suspected member of the <a href=\"https:\/\/hackread.com\/tag\/Trickbot\/\" target=\"_blank\" data-type=\"post_tag\" data-id=\"5238\" rel=\"noreferrer noopener\">Trickbot<\/a> cybercrime gang, which has a history of attacking hospitals and government centres. Whereas Mamashoyev is also linked to a second brokerage firm, Advance Security Solutions, which operates in the UAE and Uzbekistan.<\/p>\n<div style='margin: 8px auto; text-align: center; display: block; clear: both;'> <script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-3675825324474978\"      crossorigin=\"anonymous\"><\/script>  <ins      style=\"display:inline-block;width:300px;height:250px\"      data-ad-client=\"ca-pub-3675825324474978\"      data-ad-slot=\"3421156210\"><\/ins> <script>      (adsbygoogle = window.adsbygoogle || []).push({}); <\/script><\/div>\n<p>Secretary of the Treasury Scott Bessent was clear about the government\u2019s stance, stating: &#8220;If you steal US trade secrets, we will hold you accountable.&#8221;<\/p>\n<p>These sanctions are the first ever issued under the <a href=\"https:\/\/www.state.gov\/releases\/office-of-the-spokesperson\/2026\/02\/protecting-americans-from-intellectual-property-theft\/\" target=\"_blank\" rel=\"noreferrer noopener\">Protecting American Intellectual Property Act.<\/a> As we know it, the goal is to freeze the group&#8217;s assets and block them from the global financial system to protect national security.<\/p>\n<div >\n<div>\n<div>\n<div>\n<h5> \t\t\t\t\t\t<a href=\"https:\/\/hackread.com\/author\/deeba\/\" rel=\"author\"> \t\t\t\t\t\t\tDeeba Ahmed\t\t\t\t\t\t<\/a> \t\t\t\t\t<\/h5>\n<div> \t\t\t\t\t\t\t<a href=\"https:\/\/hackread.com\/author\/deeba\/\" rel=\"author\"> \t\t\t\t\t\t\t\t<img src='https:\/\/secure.gravatar.com\/avatar\/9fefbe13a37a8aeb4620dfe89bb7feabd9433643ff382b6b882f27837a4cfb72?s=80&#038;d=mm&#038;r=g' srcset='https:\/\/secure.gravatar.com\/avatar\/9fefbe13a37a8aeb4620dfe89bb7feabd9433643ff382b6b882f27837a4cfb72?s=160&#038;d=mm&#038;r=g 2x' height='80' width='80' alt=\"US Sanctions Russian Exploit Broker Over Stolen US Cyber Tools\" \/>\t\t\t\t\t\t\t<\/a> \t\t\t\t\t\t<\/div>\n<div>\n<div> \t\t\t\t\t\t\t\tDeeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform\u2019s trusted coverage.\t\t\t\t\t\t\t<\/div>\n<div>\n<div> \t\t<a href=\"https:\/\/hackread.com\/author\/deeba\/\" target=\"\"> \t\t\tView Posts\t\t<\/a> \t<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The United States government has launched a crackdown o [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-43942","post","type-post","status-publish","format-standard","hentry","category-hackread"],"_links":{"self":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/43942","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/comments?post=43942"}],"version-history":[{"count":0,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/43942\/revisions"}],"wp:attachment":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/media?parent=43942"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/categories?post=43942"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/tags?post=43942"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}