- Updated: February 24, 2026
- 6 min read
US Treasury Sanctions Russian Zero‑Day Broker and UAE Affiliate Over Exploit Trade
US Treasury Sanctions on Russian Zero‑Day Broker and UAE Affiliate: National Security Risks Unveiled
The U.S. Treasury’s Office of Foreign Assets Control (OFAC) has sanctioned Russian zero‑day broker Operation Zero, its founder Sergey Zelenyuk, and a United Arab Emirates affiliate, citing the theft of U.S. defense‑contractor exploits and the threat these tools pose to national security, foreign policy, and the economy.

Overview of the Treasury Sanctions
On 24 February 2026, OFAC announced a coordinated set of sanctions targeting two companies that specialize in acquiring and reselling zero‑day exploits, as well as the individuals who run them. The action marks the first time the U.S. government has directly named a zero‑day broker as a national‑security threat. The sanctions freeze any U.S. assets, prohibit American persons from dealing with the listed entities, and add them to the Specially Designated Nationals (SDN) list.
The primary targets are:
- Operation Zero, a Russian firm founded in 2021.
- Founder Sergey Zelenyuk, accused of selling stolen exploits to foreign intelligence services.
- UAE‑based affiliate Special Technology Services and its associate Advance Security Solutions.
The Treasury justified the measures under a 2022 federal law that penalizes “significant thefts of trade secrets,” emphasizing that the stolen tools were originally created for exclusive use by the U.S. government and its Five‑Eyes allies.
Zero‑Day Market and Operation Zero
What is a zero‑day exploit?
A zero‑day is a software vulnerability unknown to the vendor at the time of discovery. Because no patch exists, attackers can exploit it with impunity until the flaw is disclosed and fixed. Zero‑days are the most valuable commodity in the cyber‑crime underground, fetching millions of dollars per vulnerability.
Operation Zero’s bounty model
Operation Zero gained notoriety in 2023 by publicly offering up to $20 million for Android and iPhone exploits and up to $4 million for Telegram vulnerabilities. The firm claims to work exclusively with the Russian government and local entities, but Treasury officials allege that its clientele includes foreign intelligence agencies and ransomware groups.
According to OFAC, the broker acquired “at least eight proprietary cyber tools” that were originally built for the U.S. defense contractor L3Harris. Those tools were stolen, repackaged, and sold to “unauthorized users,” a phrase that typically denotes state‑sponsored actors or criminal syndicates.
UAE Affiliate: Special Technology Services & Advance Security Solutions
The sanctions also encompass Special Technology Services, a Dubai‑registered company that acted as a regional sales channel for Operation Zero’s exploits. In parallel, the Treasury named Advance Security Solutions, allegedly founded by Azizjon Makhmudovich Mamashoyev, which offered similar high‑bounty programs for smartphone and desktop exploits.
Both entities are accused of facilitating the transfer of stolen U.S. cyber‑tools to “unauthorized users,” thereby breaching export‑control regulations and endangering critical infrastructure worldwide.
National Security Implications
Threat to U.S. defense contractors
The stolen exploits originated from a contractor that supplies the U.S. Department of Defense and the Five‑Eyes intelligence community. When such tools fall into hostile hands, they can be weaponized to infiltrate classified networks, exfiltrate sensitive data, or sabotage critical systems.
Enabling ransomware and espionage
Treasury officials warned that Operation Zero’s customers could use the tools to launch ransomware attacks, conduct cyber‑espionage, or develop bespoke spyware. The involvement of individuals linked to the notorious TrickBot ransomware gang further underscores the potential for large‑scale financial disruption.
Broader geopolitical fallout
By sanctioning a Russian broker and its UAE affiliate, the United States sends a clear signal to allied nations: the illicit trade in zero‑days will be treated as a matter of national security, not merely a criminal issue. This stance may prompt coordinated international actions, tighter export‑control regimes, and increased scrutiny of cyber‑risk supply chains.
Treasury Statement (Paraphrased)
“The individuals and entities sanctioned today have engaged in the theft of U.S. trade secrets and the illicit resale of zero‑day exploits that threaten our national security, foreign policy, and economic stability. Their activities enable foreign intelligence services and ransomware operators to compromise critical infrastructure and undermine the safety of American citizens.” – Office of Foreign Assets Control, U.S. Treasury
How Organizations Can Respond
For IT security analysts, policy makers, and cyber‑risk consultants, the sanctions highlight the urgency of strengthening defenses against zero‑day threats. Below are practical steps that can be taken immediately:
- Implement robust vulnerability‑management programs. Prioritize rapid patching of known flaws and adopt threat‑intelligence feeds that flag emerging zero‑day activity. Workflow automation studio can help orchestrate patch‑deployment pipelines.
- Leverage AI‑driven threat detection. Platforms like the Enterprise AI platform by UBOS use machine‑learning models to spot anomalous behavior indicative of zero‑day exploitation.
- Adopt secure software development lifecycles (SDLC). Integrate static and dynamic analysis tools early, and consider using the Web app editor on UBOS to embed security checks directly into code repositories.
- Educate staff on social‑engineering vectors. The Treasury noted that Zelenyuk recruited hackers via social media. Regular phishing simulations and awareness campaigns can reduce the risk of insider compromise.
- Utilize AI‑enhanced cyber‑threat intelligence. Tools such as the AI marketing agents can be repurposed to aggregate open‑source intel on zero‑day markets, providing early warnings.
- Review third‑party risk. Conduct due‑diligence on vendors that handle code or data that could be targeted by zero‑day exploits. The UBOS pricing plans include modules for continuous third‑party risk monitoring.
UBOS Resources for Cyber‑Resilience
Organizations looking to modernize their security posture can explore a range of UBOS solutions that align with the challenges highlighted by the Treasury sanctions:
- UBOS solutions for SMBs – affordable AI‑powered security automation.
- UBOS for startups – fast‑track AI integration without heavy upfront costs.
- UBOS portfolio examples – real‑world case studies of zero‑day detection and response.
- UBOS templates for quick start – pre‑built workflows for incident response, threat hunting, and compliance reporting.
- AI SEO Analyzer – while focused on SEO, its underlying language models can be repurposed for scanning code repositories for hidden vulnerabilities.
- AI Article Copywriter – generate clear internal documentation on security policies.
- AI Video Generator – create engaging security awareness videos for staff training.
Read the Full Story
For a comprehensive account of the Treasury’s action, see the original TechCrunch article.
Conclusion
The sanctions against Operation Zero, its founder, and the UAE affiliate underscore a growing recognition that zero‑day markets are not just a criminal concern but a strategic national‑security threat. By disrupting the supply chain of stolen exploits, the United States aims to protect critical infrastructure, safeguard defense‑contractor intellectual property, and deter foreign intelligence services from exploiting these tools.
Security leaders must treat zero‑day risk as a core component of their cyber‑risk strategy. Leveraging AI‑driven platforms like those offered by UBOS can accelerate detection, automate response, and ultimately reduce the attack surface that zero‑day brokers seek to exploit.
Ready to fortify your organization against the next zero‑day? Contact UBOS today and start building a resilient, AI‑powered security architecture.
Andrii Bidochko
CTO UBOS
Andrii Bidochko is an AI entrepreneur and researcher focused on AI agents, reinforcement learning, and autonomous systems. He writes about the technologies shaping the future of machine intelligence, from frontier models and agent architectures to real-world AI applications.