Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

US Sanctions Network of Exploit Brokers That Stole US Government Cyber Tools

On Fri, Feb 24, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated Russian national Sergey Sergeyevich Zelenyuk and his company, Matrix LLC, operating as Operation Zero, along with five associated individuals…

On Fri, Feb 24, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated Russian national Sergey Sergeyevich Zelenyuk and his company, Matrix LLC, operating as Operation Zero, along with five associated individuals and entities. These designations are due to their involvement in acquiring and distributing cyber tools detrimental to U.S. national security.

This action represents the first application of the Protecting American Intellectual Property Act (PAIPA) to impose sanctions on foreign entities profiting from the theft of American intellectual property.

Former executive at Trenchant, Peter Williams, leveraged his access between 2022 and 2025 to steal zero-day exploits intended for the U.S. government. He sold these to Operation Zero for $1.3 million in cryptocurrency, resulting in an estimated $35 million loss for Trenchant. Williams pleaded guilty on Wed, Oct 29, 2025, and was sentenced to 87 months in federal prison on Fri, Feb 24, 2026.

Since 2021, Operation Zero has functioned as an exploit broker, offering significant bounties for zero-day exploits targeting widely used software, including U.S. operating systems and applications. The organization does not disclose vulnerabilities to affected vendors and restricts its clientele to non-NATO countries, including Russia.

Operation Zero also focuses on developing spyware and techniques for extracting sensitive data from AI applications, recruiting hackers via social media.

Designated Person / Entity Role Basis

Sergey Zelenyuk Founder, Operation Zero Cyber-enabled activities threatening U.S. national security.

These designations are due to their involvement in acquiring and distributing cyber tools detrimental to U.S.
Anna Fields · Thehackingpost

Matrix LLC (Operation Zero) Russian exploit brokerage Acquisition and sale of stolen U.S. cyber tools.

Marina Evgenyevna Vasanovich Zelenyuk’s assistant Acting on behalf of Zelenyuk.

Special Technology Services LLC FZ (STS) UAE-based affiliate Controlled by Zelenyuk; sanctioned under PAIPA.

Oleg Vyacheslavovich Kucherov Suspected TrickBot member Material support to Zelenyuk.

Azizjon Makhmudovich Mamashoyev Operator, Advance Security Solutions Material support to Zelenyuk.

Advertisement

Advance Security Solutions UAE/Uzbekistan exploit brokerage Owned and controlled by Mamashoyev.

Oleg Kucherov is suspected to be part of the TrickBot cybercrime group, associated with ransomware attacks on U.S. government agencies and healthcare centers. OFAC had previously sanctioned TrickBot members in 2023.

All U.S.-held property and interests of these entities are blocked and must be reported to OFAC. Entities owned 50% or more by designated persons are similarly blocked, and U.S. persons are prohibited from engaging with those on the Specially Designated Nationals (SDN) list.

The Department of State issued parallel designations under PAIPA, marking the first use of this law against foreign exploit traders.

Treasury Secretary Scott Bessent emphasized the administration's commitment to using all legal instruments to protect American intellectual property and national security.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories