U.S. Treasury Sanctions Russian Exploit Broker Network Using Crypto-Funded Cyber Theft, First Application of New IP Protection Law

U.S. Treasury Sanctions Russian Exploit Broker Network Using Crypto-Funded Cyber Theft, First Application of New IP Protection Law

N
News Editor 01
2026-07-02 18:45:14
The U.S. Treasury's Office of Foreign Assets Control (OFAC) sanctioned Russian national Sergey Zelenyuk and his company Operation Zero for purchasing stolen U.S. government proprietary cyber tools using cryptocurrency and reselling them to unauthorized buyers, including foreign intelligence services. The case involves at least eight specialized tools stolen by a former defense contractor employee Peter Williams between 2022 and 2025, who pleaded guilty in October 2025. The sanctions mark the first use of the Protecting American Intellectual Property Act, alongside Executive Order 13694. The Treasury also linked the network to the Trickbot ransomware group and highlighted the role of cryptocurrency in facilitating cross-border cybercrime, though no blockchain-specific designations were made.
U.S. TreasurysanctionsRussiaexploit brokerOperation Zerocryptocurrencycyber theftProtecting American Intellectual Property Act

U.S. Treasury Imposes Sanctions on Russian Exploit Broker Network

The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) on Tuesday announced sanctions against Russian national Sergey Sergeyevich Zelenyuk and his company Operation Zero, along with several associates and affiliated firms. This action represents the first time the Protecting American Intellectual Property Act has been invoked to target a network that used cryptocurrency to purchase and resell stolen U.S. government cyber tools.

According to the Treasury, Zelenyuk operated from St. Petersburg, building a business that acquired and sold “exploits”—tools that exploit software vulnerabilities to gain unauthorized access or extract data. Among the exploits obtained by Operation Zero were at least eight proprietary cyber tools developed by a U.S. defense contractor exclusively for the U.S. government and select allies.

Stolen Tools Source: Insider Theft by Former Employee

These tools were stolen by Australian national Peter Williams, a former employee of the contractor, between 2022 and 2025. Williams sold them to Operation Zero in exchange for millions of dollars in cryptocurrency. He pleaded guilty in October 2025 to two counts of theft of trade secrets following an investigation by the Department of Justice and the FBI. Treasury Secretary Scott Bessent said, “If you steal U.S. trade secrets, we will hold you accountable.” The sanctions were issued under Executive Order 13694, as amended, which targets malicious cyber-enabled activities that threaten U.S. national security, foreign policy, or economic stability. Separately, the State Department imposed sanctions under the Protecting American Intellectual Property Act, marking its first use against foreign actors engaged in significant theft of U.S. trade secrets.

Multiple Sanctioned Entities and Links to Trickbot Ransomware Group

In addition to Zelenyuk and Operation Zero, the Treasury designated Marina Evgenyevna Vasanovich (identified as Zelenyuk's assistant), Special Technology Services LLC FZ (a UAE-based tech firm controlled by Zelenyuk), and two individuals who provided material support: Azizjon Makhmudovich Mamashoyev and Oleg Vyacheslavovich Kucherov. The Treasury described Kucherov as a suspected member of the Trickbot cybercrime group, a malware operation linked to ransomware attacks against U.S. government agencies and healthcare providers.

Operation Zero advertised bounties worth millions of dollars in crypto for exploits targeting widely used U.S.-built operating systems and encrypted messaging platforms. The Treasury said the firm did not disclose discovered vulnerabilities to affected software companies but instead sought to sell them to customers in non-NATO countries, including foreign intelligence services.

Role of Cryptocurrency and Absence of Blockchain-Specific Designations

While the Treasury noted that cryptocurrency facilitated the transactions for the stolen tools, it did not publish specific crypto wallet addresses or impose blockchain-specific sanctions. This indicates that the U.S. continues to rely on traditional financial sanctions tools while incorporating cryptocurrency payment patterns into investigations and charges, underscoring the growing importance of crypto in cybercrime enforcement.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.