Check Point Research said a prolific exploit developer tracked as Volodya supplied Windows kernel local privilege escalation (LPE) code that appeared in both financially motivated malware and state-linked intrusion sets. By analyzing coding fingerprints in exploit modules, researchers tied more than 10 Windows LPE exploits to the same author, including at least five believed to have been used as zero-days between 2015 and 2019. The attribution began with a CVE-2019-0859 exploit recovered during incident response and expanded through recurring implementation traits such as a reusable elevate(target_pid) API, use of HMValidateHandle for kernel leaks, and token-stealing techniques based on scanning PsList with arbitrary read/write primitives.

Get the actors, campaigns, and ATT&CK mapping behind it.
12 events from the most recent confirmed update back to the earliest known activity.
Check Point published research attributing more than 10 Windows kernel local privilege escalation exploits to the developer Volodya using code fingerprinting. The report concluded that Volodya sold exploit modules to both crimeware and APT customers and documented recurring implementation traits across exploits from 2015 to 2019.
Check Point reported that CVE-2019-1458 was found in malware attributed to Operation WizardOpium, although its sample did not match the in-the-wild zero-day exploit described by Kaspersky. The exploit was still included in the set attributed to Volodya.
Check Point said CVE-2019-1132 was attributed to Buhtrap based on matching technical details and a PDB path containing volodimir_65, and assessed it as likely a Volodya zero-day. The researchers had not found the sample themselves.
Check Point's research began from an incident response case involving a small 64-bit executable used by malware to exploit CVE-2019-0859 on a victim machine. The sample included a leftover PDB path referencing cve-2019-0859, indicating real-world exploitation rather than a public proof of concept.
Check Point reported that CVE-2018-8641 was found in Magniber samples and noted that Kaspersky independently attributed the exploit to Volodya. The content anchors this event to 2018 only.
Check Point assessed CVE-2017-0263 as a zero-day used by APT28 and attributed the exploit's development to Volodya. The content provides only the year for this event.
Check Point reported that CVE-2017-0001 was used as a one-day in operations attributed to Turla and was later reused by Ursnif. The exploit was attributed to Volodya through fingerprinting.
FireEye published research on a threat actor leveraging a Windows zero-day exploit in payment card data attacks. Check Point later assessed CVE-2016-0167 as one of the zero-days attributable to Volodya.
Check Point said CVE-2016-7255 was attributable to APT28 and was later used by Ursnif, Dreambot, GandCrab, Cerber, and Maze. The exploit was also assessed as one of Volodya's zero-days.
Check Point attributed CVE-2016-0040 and CVE-2016-0165 to Volodya in its retrospective clustering of exploit samples. No more precise date is given in the content beyond the year.
Check Point later attributed CVE-2015-2546 to the exploit developer Volodya as part of a broader cluster of Windows kernel local privilege escalation exploits. The content anchors this event only to the year implied by the CVE identifier and attribution list.
Kaspersky previously reported that BuggiCorp, later identified as Volodya, advertised a Windows zero-day for sale on the Exploit[.]in forum with a starting price of $95,000. The reference does not provide a specific date for the advertisement.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
research.checkpoint.com
Open sourcefireeye.com
Open sourcefireeye.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.