Cybercrime DB

Zero-Day Exploit Marketplace Operators Prosecuted

Two prosecutions expose how exploit brokers source, resell, and deploy zero-day tools.

Editor at Large · · 8 min read
Cover illustration for “Zero-Day Exploit Marketplace Operators Prosecuted”
hacker arrests and indictments · August 30, 2026 · 8 min read · 1,788 words

Two people got prosecuted this year for handling zero-day exploits, and together their cases lay out the entire exploit trade like an autopsy. One was an insider who stole tools and sold them to a Russian broker. The other was a spyware maker that lost a $167 million jury verdict for actually running the attacks itself. Read them side by side and you get a map of how this market works, where the law reaches, and where it very much does not.

What current pricing reveals about where the market has moved

Money talks, and right now it's shouting about phones. Brokers in this space have posted prices up to $7 million for a zero-click iOS exploit and up to $5 million for the Android equivalent, with Crowdfense among the more visible players setting public acquisition prices. Browser exploit chains run $3 million to $3.5 million, and the multi-stage chains that string several bugs together to get full device control can approach $10 million.

Crowdfense put $30 million behind a single acquisition program in 2024, making these figures a matter of public record. That is a serious line item.

Prices have climbed something like 44% year over year, and the reason is straightforward: vendors keep hardening their software, and bug-bounty programs keep competing for the same researchers who might otherwise sell to a broker. Google's entire bug-bounty payout across all of 2025 landed around $17 million. Total. For the whole year, across every bug reported to them. A single top-tier iOS chain from a broker can cost more than that.

The premium sits hardest on zero-click exploits, the ones that need no victim to click anything, tap anything, or make a single dumb decision. The attack arrives without a phishing link or a fake update prompt, just silence, then compromise. That's also the exact category of tool at the center of the Williams case below, which tells you something about why it mattered so much.

Diagram: What a Single Zero-Day Exploit Is Worth in 2025. Visualizes: Visualise the current acquisition price ladder for zero-day exploits, running from lowest to highest value.

Who is actually exploiting zero-days and what they are targeting

Google's Threat Intelligence Group tracked 90 zero-days getting exploited in 2025, up from 78 in 2024. That is a trend line that keeps going up.

Of the 42 exploits GTIG could attribute, 18 traced back to commercial surveillance vendors and 15 to state-sponsored espionage groups. China-linked groups alone accounted for at least 10 zero-days in 2025, making them the most active state-sponsored cluster in this year's attributed set.

The targeting splits cleanly by buyer type. State-backed groups went after edge devices, routers, and security appliances, the boring infrastructure that sits at the edge of a network and rarely gets patched fast. Commercial surveillance vendors stuck to phones and browsers, the stuff that gets a person's location, messages, and camera. Microsoft took the most hits among vendors, with 25 zero-days used against its products in 2025, followed by Google at 11 and Apple at 8.

North Korea muddies the picture a bit. Its operators run campaigns that blend old-school espionage with straight-up cryptocurrency theft, a reminder that "nation-state buyer" covers multiple motives and shopping lists. Add it all up and you get a buyer pool that's well-funded, patient, and often unable to build these tools in-house. That gap is exactly what brokers exist to fill.

How Peter Williams and Operation Zero exposed the broker's interior mechanics

Peter Williams had one of the best jobs in offensive security. He was a senior executive at Trenchant, the L3Harris subsidiary that builds exploit tools meant for exclusive sale to the U.S. government and a short list of allies. Privileged access doesn't get much more privileged than that.

Between 2022 and 2025, prosecutors say he walked at least eight zero-day exploits out the door on a portable external hard drive, moving material out of secure facilities in Sydney and Washington, D.C. He sold them to Operation Zero, a Russian broker that advertises its resale business openly, including sales to the Russian government, for $1.3 million in cryptocurrency.

The Justice Department's framing at sentencing didn't pull punches: Williams "made it possible for the Russian Broker to arm its clients with powerful cyber exploits that could be used against any manner of victim, civilian or military around the world." Nice work if you can get it, except for the part where it ends in federal prison.

What's more interesting for anyone trying to understand how this market actually functions is what happened after the sale. Operation Zero didn't just buy and sit on the tools; at least one of them got passed downstream to a South Korean broker before Williams even found out about it. That's a multi-hop resale chain, the kind of thing that makes tracking where a tool ends up almost impossible once it leaves the first buyer's hands. It also explains why brokers find insider theft so appealing: one trusted employee with a hard drive can deliver, for a fraction of the cost, tools that would otherwise take years and tens of millions of dollars to build from scratch.

What the sanctions against Operation Zero reveal about how brokers evade oversight

The U.S. State Department sanctioned Operation Zero under the Protecting American Intellectual Property Act. The PAIPA designation signals that the government was waiting for a case clean enough to apply the law to a foreign exploit broker.

Zelenyuk had already built a workaround. Jurisdiction-hopping isn't subtle once prosecutors lay it out in a filing, and the sanctions documents describe structures designed to keep doing business with buyers despite restrictions on Russian financial channels.

Here's the part that should stick with you: Operation Zero never hid. It advertises its services in plain sight. The legal exposure came from where the tools originated and who was buying them. U.S. Attorney Jeanine Pirro called the broker part of "the next wave of international arms dealers," and that phrase is doing real policy work. Exploit brokers are getting treated like arms dealers now, not software vendors with an unusual product line.

Williams, for his part, got 87 months in prison and three years of supervised release. Prosecutors put the damage to L3Harris at $35 million, and noted the scope of potential harm given how widely the targeted platforms are deployed.

How the NSO Group verdict draws a different boundary — operator liability, not just supply

If Williams is about theft and resale, NSO Group is about something further: what happens when the maker of the spyware sells the gun and pulls the trigger too.

In 2025, a U.S. jury awarded Meta substantial punitive damages in the tens of millions, plus $444,719 in compensatory damages, against NSO Group. It's the first time a commercial spyware company has faced accountability like this in a U.S. courtroom.

The exploit underneath it all was a zero-day in WhatsApp's voice calling feature, rated 9.8 out of 10 on the CVSS severity scale, about as bad as vulnerability scoring gets. NSO used it to deploy Pegasus through WhatsApp's own California-based servers, 43 times in May 2019, hitting more than 1,400 users.

The finding that actually mattered legally: the trial established that NSO's own infrastructure was used to deploy Pegasus, independently of the government customers buying the software. That detail collapsed the wall NSO had spent years building, the argument that customers control Pegasus and bear the responsibility for how it's used. The jury rejected it. NSO's own hands were on the keyboard, and that decided the case.

Compare the two. Williams got nailed for supply: stealing the tool and reselling it to a prohibited buyer. NSO got nailed for operation: running the attack infrastructure itself. Different legal theories, different facts, but together they shut down two of the main escape hatches brokers have relied on for years.

The grey zone that both cases leave unresolved

Both cases are, frankly, easy calls once you see the facts. Williams stole trade secrets. NSO's own servers reached into phones uninvited. Both cases leave the harder question open: what about a broker operating entirely within the law, in its own jurisdiction, selling to a government buyer it has actually vetted?

Crowdfense and other well-known brokers advertise their acquisition prices in public, put restrictions on who can buy, and operate under the legal frameworks of the countries they're based in. That activity remains unprosecuted and appears lawful as structured.

The PAIPA sanctions against Operation Zero are genuinely novel, but they're narrow by design. They target a Russian entity selling to adversary governments; they leave the broader export-controlled market untouched, where brokers sell to allied governments through channels the State Department has already approved.

Subscription models make this even murkier. A buyer gets access to a rotating library, a subscription to whatever's fresh that month, rather than a single named exploit. Once that buyer's own customer redistributes access downstream, tracing the exploit back to its origin becomes close to impossible. Civil cases against spyware vendors have been expanding across more countries and courts, but most settle, get dismissed, or drag on for years. All of that falls short of a deterrent that an active broker feels next quarter.

So prosecution exposes the machinery while leaving it running. The ecosystem keeps running in the space between clearly legal and clearly criminal, which is exactly where it's operated all along.

What this market structure means for defenders who have to account for it

None of this is academic if you're the one defending a network. The buyer taxonomy alone should shape how you think about threat models: state-sponsored groups go after edge devices, routers, and security appliances, while commercial surveillance vendors chase mobile and browser targets. Which one you should worry about most depends on who'd actually want access to what you're protecting.

The insider-threat lesson from Williams is a supply-chain risk, even though it obviously involves an employee who went rogue. Proprietary defensive tools turn into offensive weapons the moment access controls at a contractor or vendor fall short, and $35 million in assessed losses at L3Harris is the price tag for finding that out.

Multi-hop resale chains mean the same exploit can turn up in campaigns run by groups with no visible connection to where the tool came from. Empty attribution is a structural feature of how brokers move product. And the pricing itself is a signal worth reading: the premium on zero-click iOS and Android exploits tells you where vendors have actually made progress, since patch cadence and memory-safety work show up directly in what brokers are willing to pay.

There's real threat intelligence sitting in prosecution filings, sanctions designations, and civil court records, the kind that names actual infrastructure, transaction methods, and resale paths that a typical vendor advisory never mentions. Reading the legal record complements a threat feed by supplying the part of the picture no feed gives you.

Sources

  1. forklog.com
  2. brightdefense.com

More in hacker arrests and indictments