U.S. Treasury Imposes Sanctions on Russian Exploit Broker Network
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) on Tuesday announced sanctions against Russian national Sergey Sergeyevich Zelenyuk and his company Operation Zero, along with several associates and affiliated firms. This action represents the first time the Protecting American Intellectual Property Act has been invoked to target a network that used cryptocurrency to purchase and resell stolen U.S. government cyber tools.
According to the Treasury, Zelenyuk operated from St. Petersburg, building a business that acquired and sold “exploits”—tools that exploit software vulnerabilities to gain unauthorized access or extract data. Among the exploits obtained by Operation Zero were at least eight proprietary cyber tools developed by a U.S. defense contractor exclusively for the U.S. government and select allies.
Stolen Tools Source: Insider Theft by Former Employee
These tools were stolen by Australian national Peter Williams, a former employee of the contractor, between 2022 and 2025. Williams sold them to Operation Zero in exchange for millions of dollars in cryptocurrency. He pleaded guilty in October 2025 to two counts of theft of trade secrets following an investigation by the Department of Justice and the FBI. Treasury Secretary Scott Bessent said, “If you steal U.S. trade secrets, we will hold you accountable.” The sanctions were issued under Executive Order 13694, as amended, which targets malicious cyber-enabled activities that threaten U.S. national security, foreign policy, or economic stability. Separately, the State Department imposed sanctions under the Protecting American Intellectual Property Act, marking its first use against foreign actors engaged in significant theft of U.S. trade secrets.
Multiple Sanctioned Entities and Links to Trickbot Ransomware Group
In addition to Zelenyuk and Operation Zero, the Treasury designated Marina Evgenyevna Vasanovich (identified as Zelenyuk's assistant), Special Technology Services LLC FZ (a UAE-based tech firm controlled by Zelenyuk), and two individuals who provided material support: Azizjon Makhmudovich Mamashoyev and Oleg Vyacheslavovich Kucherov. The Treasury described Kucherov as a suspected member of the Trickbot cybercrime group, a malware operation linked to ransomware attacks against U.S. government agencies and healthcare providers.
Operation Zero advertised bounties worth millions of dollars in crypto for exploits targeting widely used U.S.-built operating systems and encrypted messaging platforms. The Treasury said the firm did not disclose discovered vulnerabilities to affected software companies but instead sought to sell them to customers in non-NATO countries, including foreign intelligence services.
Role of Cryptocurrency and Absence of Blockchain-Specific Designations
While the Treasury noted that cryptocurrency facilitated the transactions for the stolen tools, it did not publish specific crypto wallet addresses or impose blockchain-specific sanctions. This indicates that the U.S. continues to rely on traditional financial sanctions tools while incorporating cryptocurrency payment patterns into investigations and charges, underscoring the growing importance of crypto in cybercrime enforcement.

