Cybercrime DB

Zero-Day Vulnerability Attribution in Criminal Cases

Prosecutors struggle to prove who wrote and deployed zero-days in court.

Staff Writer · · 10 min read
Cover illustration for “Zero-Day Vulnerability Attribution in Criminal Cases”
hacker arrests and indictments · September 5, 2026 · 10 min read · 2,189 words

Zero-day attribution is a legal problem wearing a technical disguise. Prosecutors need to trace exploit development, deployment, and intent to a named person in a way that survives cross-examination, and that chain breaks far more often than it holds. Finding the exploit is straightforward compared to proving who touched it, and the record shows that link snapping again and again, long before anyone gets near a courtroom.

Intelligence attribution and legal attribution hold each other to different standards, and treating them as interchangeable is where most of these cases go sideways. A threat intel team can call a campaign "likely linked to a nation-state cluster" with moderate confidence and move on with the workday. A prosecutor making that same claim in front of a jury needs evidence. The inference that earns nods in a SOC briefing gets shredded by a defense attorney who only needs one question: how do you know it was him, and not someone using his tools?

Zero-day cases make this worse. The exploit itself is often the only artifact that exists early on, and its lineage gets scrubbed on purpose by the developer and again by the operator running it. "Who wrote the exploit," "who deployed it," and "who ordered it" are three separate questions, and each needs its own independent evidence. Borrowing proof from one link to cover another is the most common way these cases fall apart, and DFIR practice documents it as a recurring failure mode, not a rare one.

What the zero-day threat landscape actually looks like before prosecution begins

Google's Threat Intelligence Group (GTIG) counted 75 zero-days exploited in the wild in 2024. That's down from 98 in 2023, but still above the 63 recorded in 2022, so the four-year range sits somewhere between 60 and 100 a year. That looks like stability, but treat it as a floor, because plenty of zero-days never get discovered or publicly tied to anyone. The record is incomplete before an investigation even opens.

Enterprise products took a bigger share of the hits in 2024, 44%, up from 37% the year before. Security and networking appliances, the gear meant to guard the perimeter, accounted for more than 60% of that slice, according to analysis of 2024 zero-day targeting data. The lock on the door is the thing getting picked.

Mandiant's M-Trends 2024 report backs this up from a different angle: exploiting vulnerabilities overtook phishing as the most common entry point, showing up in 38% of investigated incidents. Credential theft used to be the default way in, but now it's a patchable flaw nobody patched fast enough.

What that means for prosecution is straightforward and uncomfortable. The attack surface is wide, the tooling behind it is sharp, and the window between disclosure and exploitation is often negative, meaning attackers use the flaw before the vendor even knows it exists. Evidence collection has to start before a patch does, which is exactly backwards from how most legal processes are built to work.

The three categories of zero-day actor and why each produces a different evidentiary problem

Nation-state espionage groups accounted for nearly 53% of attributed zero-day exploitation in 2024, 18 zero-days by GTIG's count. These cases carry the richest technical evidence and the least legal reach, because sovereignty is a wall no subpoena gets through. China-linked groups were among the busiest state actors, tied to at least 5 zero-days in 2024. North Korea sits in a stranger spot, also tied to 5, but blending espionage with financial motive. That hybrid actually helps prosecutors, since financial crime is a far easier case to build than espionage.

Commercial Surveillance Vendors, or CSVs, are their own animal, and they're the category worth worrying about most. Google tracks around 40 of them building and selling exploits to government buyers. The evidentiary problem comes in layers: the vendor who built it, the government that bought it, and the individual who ran it are three separate legal targets, often in three separate countries. Intellexa reportedly sold access to at least 8 governments. Each relationship needs its own paper trail, and no single prosecution catches all three actors at once. That's the business model working as designed.

Non-state financially motivated groups look, on paper, like the cleanest case to build, since proving a profit motive is a lot more straightforward than proving intelligence collection for a foreign government. But someone still has to trace where the exploit came from, and that step doesn't get easier just because the motive is obvious.

The CSV problem is getting worse. GTIG's 2024 assessment found these vendors actively tightening their own operational security. Tighter tradecraft for the seller means worse detection and attribution for everyone downstream.

How the Sichuan Silence indictment actually built its evidentiary chain

On December 10, 2024, the US unsealed an indictment against Guan Tianfeng, a Chinese national, for exploiting a zero-day in Sophos firewall devices back in 2020. The flaw was a SQL injection bug with a CVSS score of 9.8, about as severe as it gets, and it hit roughly 81,000 devices worldwide, including 36 protecting US critical infrastructure.

The chain built to support this indictment had several links, each doing separate work. First came the Asnarök Trojan, deployed through the vulnerability. Then, after Sophos patched the hole, came the pivot to Ragnarök ransomware. Then came the piece that actually made the case: a bug bounty submission about that exact vulnerability, traced back to researchers connected to Sichuan Silence's Double Helix Research Institute.

That bug bounty submission is the single most important artifact in the whole case, and it's worth sitting with why. It ties a named individual to specific knowledge of the vulnerability, before and during its exploitation. That kills the standard defense of "sure, someone found this bug, but you can't prove it was my client." Here, prosecutors can.

The FBI's Cyber Division treated this as a template, and the State Department backed a $10 million reward tied to it, which is not a subtle signal. Law enforcement also publicly credited Sophos's fast response for limiting the damage, which quietly established something bigger: the vendor as forensic witness. Expect that role to keep showing up in cases like this, because right now it's the only thing that's actually worked.

Where the NSO Group and Cellebrite cases show the chain breaking down

The WhatsApp lawsuit against NSO Group alleges a vulnerability in the messaging app was used to infect 1,400 devices with Pegasus spyware. It's one of only two active US cases involving Pegasus as of late 2024, which says something about how rare a case like this actually is.

WhatsApp is arguing its claim under the Computer Fraud and Abuse Act, using the trespass theory from Van Buren v. United States (2021). A win here gives other spyware victims a legal path to follow, sure, but notice how long it's taken just to get a civil claim this far, with no criminal conviction anywhere in sight. NSO Group was sanctioned by the US and EU back in 2021 and is still operating today. Sanctions fall well short of prosecution, and that gap is exactly where CSV accountability keeps stalling out.

The Cellebrite case shows the same pattern from a different angle. Researchers documented exploit chains built by Cellebrite and used by government security services against civil society targets. The forensic evidence held up fine. Accountability remains unresolved: the question of whether responsibility lies with the government that deployed the tool or the company that built it has no clean answer, and none is coming soon.

There's a partial win worth flagging: Intellexa's principals were convicted in Greece, part of what's been called the "accountability turn" running from 2024 into 2026. But partial outcomes are the norm here, not the exception. The CSV business model is built specifically to split the exploit developer, the platform seller, and the deploying government into separate legal entities across separate jurisdictions. Each layer needs its own prosecution, in its own country, under its own laws. That's the whole point of the system.

The technical evidence types that courts can actually evaluate

MITRE ATT&CK, which catalogs a large number of threat groups and techniques, gives prosecutors and expert witnesses a shared vocabulary for describing attacker behavior. It's useful for establishing a pattern, but useless for establishing identity. Conflating the two is where weak cases start.

Structured analytic frameworks for intrusion analysis are the current practitioner standard for turning raw indicators into judgments that hold up under scrutiny. What survives the jump from intelligence to evidence: infrastructure tied to named registrants, code-signing certificates linked to real legal entities, financial transactions connecting an exploit purchase to its deployment, and documentary artifacts like the Sichuan Silence bug bounty submission.

What falls apart under cross-examination, almost every time, is attribution built solely on code similarity or shared tooling. Tools get sold, tools get leaked, and tools get reused on purpose, specifically to muddy attribution. Pointing at similar code and saying "same author" is an argument that falls short of proof, and any defense attorney worth the retainer knows exactly how to make that gap visible to a jury.

The distinction between activity, identity, and attribution is the exact point where most cases collapse the moment they move from an intel briefing into a courtroom. AI-assisted attribution tools that combine TTPs, indicators, and context can sharpen group-level attribution, sure, but courts want explainability. A model that spits out a confidence score with no visible reasoning behind it amounts to a hunch with better math.

GTIG documented the North Korean group APT45 running large volumes of iterative prompts through AI systems to analyze vulnerability disclosures and validate proof-of-concept exploits. The significance is speed: the same work, done faster, at higher volume, by fewer people.

Recent security research treats AI-assisted criminal exploit development as a structurally different problem than the manual version, and that framing matters. Security programs built around manual exploit development, tuned to catch known vulnerabilities exploited weeks or months after disclosure, are aimed at a threat that's already changed shape by the time the program catches up.

Here's the evidentiary catch. AI-assisted development strips out a lot of the stylistic fingerprints that code similarity analysis depends on. An exploit built with heavy AI assistance bears no stylistic resemblance to any individual's prior work. As that fingerprint fades, infrastructure and financial trails carry more of the weight. The investigation shifts focus to the operational footprint around the code: who paid for what, who ran which server, when.

Forescout's Vedere Labs measured a 46% jump in zero-day exploitation in the first half of 2025 alone, and 41% of the vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog that year were zero-days. Volume is climbing right as attribution gets harder, which is about the worst combination this field could ask for. The justice system's clock hasn't sped up to match it either: the Sophos indictment landed four years after the exploitation happened, and four years is not built for a threat whose development cycle shrinks by the month.

What a defensible attribution standard actually requires, from first artifact to indictment

The full chain runs in order: vulnerability discovery (who found it, and when), exploit development (who actually built the weaponized version), deployment (who ran the infrastructure), intent (what the targeting pattern says about the purpose), and identity (who, in the legal sense, is on the hook). Each link needs its own proof. Borrowing certainty from the link next door is the most common crack a defense attorney finds and pries open, and it's avoidable if investigators treat each link as its own case from day one.

Private vendors have become load-bearing parts of this chain, and that's the actual takeaway here. The Sophos model, forensic telemetry, patch timelines, and bug bounty records turned into prosecution exhibits, is the template most likely to get copied going forward, because it's the only one that's produced a clean conviction. The CSV accountability gap, where the exploit developer, the platform seller, and the deploying government each answer to a different court in a different country, requires multilateral legal agreements that remain absent, with no serious sign of progress.

The practical lesson is blunt: attribution good enough for an intelligence briefing has to be rebuilt from the ground up to survive a courtroom, and what survives that rebuild is almost always financial and operational evidence, with technical fingerprinting playing only a supporting role. The cases that worked, Sichuan Silence being the cleanest example, worked because a private company preserved and handed over forensic evidence that law enforcement had no way to collect on its own. The cases that stalled, NSO Group and Cellebrite among them, stalled because no equivalent artifact ever surfaced to tie the technical trail to an actual name. That's the pattern worth remembering: better paperwork from the right company at the right moment drives outcomes more reliably than better malware analysis. Cyberou, a content studio that covers exactly this intersection of threat intelligence and legal accountability for cybersecurity audiences, publishes regularly on how attribution evidence gets built and tested.

Sources

  1. brightdefense.com
  2. labs.cloudsecurityalliance.org
  3. minimus.io
  4. deepstrike.io
  5. cloud.google.com
  6. natlawreview.com

More in hacker arrests and indictments