Volodya, also known as Volodimir and previously BuggiCorp, is a prolific Windows exploit developer and broker active since at least 2015. The actor is associated with the development and sale of Windows local privilege escalation exploits, including multiple zero-days and one-days, to both cyber-espionage operators and financially motivated cybercrime groups. Public reporting has linked Volodya to exploits for CVE-2015-2546, CVE-2016-0040, CVE-2016-0165, CVE-2016-0167, CVE-2016-7255, CVE-2017-0001, CVE-2017-0263, CVE-2018-8641, CVE-2019-0859, CVE-2019-1132, and CVE-2019-1458, with several assessed as zero-days at the time of use. Volodya appears to operate primarily as a specialist exploit supplier rather than a malware operator. The actor’s tooling was repeatedly embedded by downstream customers in crimeware and espionage operations, and later versions were sold as external utilities exposing a stable API for privilege escalation. A recurring implementation pattern is a function that elevates a specified process to SYSTEM privileges, indicating a reusable commercialization model for integration into third-party malware. Customers linked to Volodya’s exploits include APT28, Turla, Buhtrap, Ursnif, Dreambot, GandCrab, Cerber, Magniber, and Maze. Technically, Volodya is characterized by consistent exploit engineering choices across samples. Reported fingerprints include frequent use of HMValidateHandle-derived kernel leaks, token-swapping via PsList scanning using arbitrary read/write primitives, lightweight operating-system fingerprinting, and repeated stability-oriented behaviors such as delayed execution at startup. The actor’s exploits generally focus on post-compromise privilege escalation rather than initial intrusion, enabling malware operators to obtain SYSTEM-level execution after code execution on a host. Volodya has also been described as developing one-day exploits for patched vulnerabilities and reliable exploits for older unpatched systems. Volodya has been tied to both state-linked and criminal use cases. CVE-2016-7255 and CVE-2017-0263 were associated with APT28 activity, while other Volodya-linked exploits were later reused by banking malware, ransomware, and exploit-kit operators. Magnitude exploit kit activity has also been linked to a Volodya-attributed elevation-of-privilege exploit. The actor is therefore notable as an example of a commercial exploit developer whose work crossed the boundary between espionage and cybercrime ecosystems. Available reporting indicates the actor is fluent in Russian and likely of Ukrainian origin, but attribution below the country level remains unconfirmed. The dominant pattern is financially motivated sale of exploit capability to multiple customer types.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Another exploit developer used as a comparison point throughout the research; also sold Windows LPE exploits and had overlapping customers with PlayBit.
Windows kernel local privilege escalation exploit developer and seller whose exploits were used by both crimeware and APT groups; the research attributes more than 10 Windows LPE exploits, including multiple zero-days, to this actor.
A prolific exploit writer attributed as the developer of the CVE-2018-8641 privilege-escalation exploit used by Magnitude; described as selling zero-days to both APT groups and criminals.
A prolific exploit developer and zero-day seller who sold Windows zero-days and one-day exploits to multiple cyber-espionage groups and cybercrime gangs.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.