In short
- Treasury Department sanctions alleged that Sergey Sergeyevich Zelenyuk and Operation Zero operated as a Russian network of operators.
- According to regulators, the sanctions are the first actions under the new sanctions law on trade secrets.
- The stolen ‘tools’ were built for the exclusive use of the US government.
The U.S. Treasury Department said Tuesday it has imposed sanctions on a Russian exploit broker accused of selling stolen U.S. government cyber tools.
The sanctions targeted Sergei Sergeyevich Zeleniuk and his St. Petersburg-based company Matrix LLC, also known as ‘Operation Zero’.
The sanctions mark the first use of the Protecting American Intellectual Property Act to address the theft and sale of digital trade secrets, the Office of Foreign Assets Control said.
“Zelenyuk and Operation Zero traffic in ‘exploits,’ pieces of code or techniques that exploit vulnerabilities in a computer program to enable users to gain unauthorized access, steal information, or take control of an electronic device,” OFAC said in a statement statement on Tuesday.
Operation Zero would then award bounties to anyone who provided exploits for U.S.-built software, OFAC added.
The Treasury Department also imposed sanctions on Oleg Vyacheslavovich Kucherov, a suspected member of the Trickbot cybercrime gang, and Marina Evgenyevna Vasanovich, described as Zelenyuk’s assistant.
Launched in 2021, Operation Zero has offered millions of dollars in bounties for vulnerabilities in operating systems and encrypted messaging applications.
Operation Zero did not hide the rewards, many of which were openly published on X. One premium item in November offered the maximum $500,000 for an exploit targeting Apple’s iOS 26. A March 2025 bounty offered maximum $4 million for Telegram “full chain” exploits.
Operation Zero’s customers are “exclusively Russian private and government organizations,” for those looking to purchase “research, products and software code in the field of offensive security,” according to a rough translation of the company’s website.
“Zero-day acquisition is a popular and common practice in many countries today,” the company says in the FAQ. “It is not only much more lucrative than working with bug bounties and vendors, but also more secure,” adding that a researcher working with Operation Zero does not have to trade privacy and security for money.
Operation Zero stole at least eight proprietary “cyber tools” developed for the exclusive use of the U.S. government and select allies, according to the Treasury Department.
The US Department of State reported this in a separate letter on Tuesday statement that the action follows a Justice Department and FBI investigation into Peter Williams, an Australian citizen and former employee of a U.S. defense contractor, who allegedly stole “eight zero-day exploits” between 2022 and 2025.
“These components were intended to be sold exclusively to the US government and select allies, the State Department said. “He sold these exploits to Operation Zero in exchange for $1.3 million in crypto payments.” Williams pleaded guilty last October to two counts of trade secret theft.
The Treasury Department said the Russian company has also been working to develop spyware and AI-based tools to extract personally identifiable information and other sensitive data. It has also used social media to recruit hackers and build relationships with foreign intelligence services.
The Treasury Department and Operation Zero did not immediately respond Decode requests for comments.
Daily debriefing Newsletter
Start every day with today’s top news stories, plus original articles, a podcast, videos and more.