Operation Zero, also known as Matrix LLC, is a Russia-based exploit broker active since at least 2021 and run by Russian national Sergey Sergeyevich Zelenyuk from St. Petersburg. The organization publicly markets and acquires high-value zero-day exploits affecting widely used software, including U.S.-built operating systems, mobile platforms, and encrypted messaging applications, and is assessed to sell those capabilities to non-NATO customers, including the Russian government and other foreign customers. It does not disclose acquired vulnerabilities to affected vendors, positioning it as a commercial supplier of offensive cyber capability rather than a defensive research organization. Operation Zero has been linked to the acquisition and resale of stolen proprietary exploit components originally developed for exclusive U.S. government and allied use. U.S. authorities stated that the broker obtained at least eight such tools from a former employee of a U.S. defense contractor and resold them to at least one unauthorized downstream user. Reporting also associates the broker with the Coruna iOS exploit kit, which was suspected to have been acquired and then sold onward to multiple threat actors, including financially motivated cybercriminals. The organization has also been described as seeking to recruit hackers, cultivate relationships with foreign intelligence services, and expand operations through affiliated entities in the United Arab Emirates. Its activity centers on the trade and distribution of intrusion-enabling cyber tools that can support unauthorized access, device compromise, information theft, spyware deployment, and follow-on criminal or intelligence operations. Authorities have further alleged that Operation Zero pursued development of spyware and techniques to extract sensitive personal data from AI application users. Known associated entities and individuals include Matrix LLC, Special Technology Services LLC FZ, Marina Evgenyevna Vasanovich, Azizjon Makhmudovich Mamashoyev, Oleg Vyacheslavovich Kucherov, and Advance Security Solutions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Russian exploit broker suspected of acquiring the Coruna exploit kit and selling it to other threat actors, including cybercriminals.
Exploit broker network involved in theft and sale/trafficking of cyber exploits and stolen government cyber tools to overseas buyers.
Russia-based exploit brokerage that buys and sells zero-day exploits (including for widely used operating systems and encrypted messaging apps) and advertises sales to non-NATO customers; per the cited U.S. Treasury language, it has sought relationships with foreign intelligence agencies, recruited hackers via social media, and explored development of spyware and data-extraction capabilities. The content links Operation Zero to downstream use of exploits for ransomware and other malicious activity by customers.
Russian exploit brokerage operation acquiring and distributing high-value zero-day exploits (e.g., for Telegram, Android, iPhone) and seeking to sell them to non-NATO customers, including foreign intelligence agencies; also described as pursuing development of spyware and data-extraction capabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.