Free tools Windows power users keep installed
One-click scans. No signup required.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
On February 24, 2026, the U.S. Treasury Department sanctioned Russian exploit broker Operation Zero, its owner Sergey Zelenyuk, and people and companies Treasury says were connected to its network. The U.S. alleges the broker acquired and redistributed at least eight proprietary cyber tools stolen by a former employee of a U.S. company. The State Department separately invoked the Protecting American Intellectual Property Act against Zelenyuk, Operation Zero, and a UAE-based affiliate.
The action blocks property within U.S. jurisdiction and generally bars U.S. persons from transactions with designated parties. It is a sanctions action, not a criminal conviction of Zelenyuk or Operation Zero. The separate criminal case was against former employee Peter Williams, who pleaded guilty to trade-secret theft.
What happened
The Treasury Department’s Office of Foreign Assets Control (OFAC) designated Sergey Sergeyevich Zelenyuk, Matrix LLC—identified as doing business as Operation Zero—and five associated individuals and entities. Treasury said Operation Zero acquired at least eight proprietary cyber tools originally developed for the exclusive use of the U.S. government and selected allies, then sold the stolen tools to at least one unauthorized user. Treasury’s announcement does not identify the tools, the unauthorized user, or a confirmed attack in which they were used.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11On the same day, the State Department imposed sanctions under the Protecting American Intellectual Property Act (PAIPA) on Zelenyuk, Operation Zero, and Special Technology Services LLC FZ (STS), a UAE-based company Treasury says Zelenyuk controlled. Treasury described this as the first use of PAIPA to impose sanctions.
#1 Best Overall
The action followed the criminal case against Williams, a former employee of the U.S. company whose tools were stolen. Treasury says Williams pleaded guilty on October 29, 2025, to two counts of theft of trade secrets. Secondary reporting identifies him as an Australian former general manager of L3Harris’s Trenchant unit and reports that he was sentenced to 87 months in prison. Those details are reported by BleepingComputer and SecurityWeek; Treasury’s release itself does not name the employer or give the sentence.
How the alleged theft unfolded
- Since 2021: Treasury says Operation Zero has operated as an exploit broker from St. Petersburg.
- 2022–2025: Williams allegedly stole proprietary cyber tools from his employer and sold them to Operation Zero. Treasury says he received millions of dollars in cryptocurrency; secondary reports put the amount at about $1.3 million.
- October 29, 2025: Williams pleaded guilty to two trade-secret theft counts.
- February 24, 2026: Treasury and State announced sanctions against the broker network. Secondary reporting says Williams was sentenced that day.
The sequence links an alleged insider theft to a broker and its associated network. It does not, on the public record described in Treasury’s release, establish that every stolen tool was deployed, identify every buyer, or show that the tools were sold directly to the Russian government.
What Operation Zero is—and what an exploit broker does
Operation Zero is the public-facing name of Matrix LLC, the legal entity OFAC identified. Treasury describes the business as a Russian exploit broker, active since 2021 and based in St. Petersburg. It says the company offers large bounties for exploits affecting widely used software, including U.S.-built operating systems and encrypted messaging applications, and does not disclose acquired exploits to the affected vendors.
An exploit broker buys, develops, aggregates, or sells code and techniques that take advantage of software vulnerabilities. A zero-day exploit targets a vulnerability for which a patch may not yet be available—or which the vendor may not know about. Such tools can be used in legitimate security research or government operations, but they can also enable surveillance, unauthorized access, data theft, or other harmful activity. The central issue in this case is not simply that exploits were traded: the U.S. alleges that proprietary tools were stolen from their creator and resold despite being intended for restricted government and allied use.
Treasury says Operation Zero publicly claimed it would sell exploits only to customers in non-NATO countries. It also says the broker sought to sell exploits to foreign intelligence agencies and that its customers could use the tools for ransomware or other malign activity. These are U.S. government assertions, not proof that every customer was an intelligence service or that a particular government used the stolen tools. “Non-NATO” does not by itself mean “Russian.”
Who was sanctioned?
| Person or entity | What the U.S. says about the connection | Action described by Treasury |
|---|---|---|
| Sergey Sergeyevich Zelenyuk | Owner and operator of Operation Zero | OFAC designation; also named in the State Department’s PAIPA action |
| Matrix LLC, doing business as Operation Zero | The legal entity behind the broker’s public-facing name | OFAC designation; also named in the PAIPA action |
| Marina Evgenyevna Vasanovich | Identified by Treasury as Zelenyuk’s assistant | OFAC designation |
| Oleg Vyacheslavovich Kucherov | Described by OFAC as a suspected member of the Trickbot cybercrime group | OFAC designation |
| Azizjon Makhmudovich Mamashoyev | Previously connected to Operation Zero | OFAC designation |
| Advance Security Solutions | An exploit-brokerage and offensive-cybersecurity company created by Mamashoyev, with operations in the UAE and Uzbekistan | OFAC designation |
| Special Technology Services LLC FZ (STS) | A UAE-based company Treasury says Zelenyuk controlled | OFAC designation; also named in the PAIPA action |
The Trickbot connection is an association within the broader set of sanctioned targets. Treasury has linked Trickbot to malicious activity, including ransomware attacks against U.S. government entities, hospitals, and health-care centers. That does not establish that Operation Zero operated Trickbot or that its transactions involved the group.
Rank #3
Which laws and authorities did the U.S. use?
OFAC and Executive Order 13694, as amended. Treasury designated targets under Executive Order 13694, as amended by Executive Order 14306, citing cyber-enabled activity involving the misappropriation of intellectual property and other assets that could threaten U.S. national security, foreign policy, or economic interests. The OFAC action covers the individuals and entities listed above.
PAIPA. The State Department separately used the Protecting American Intellectual Property Act. The law provides for sanctions against people alleged to have knowingly engaged in, or benefited from, significant theft of U.S. trade secrets when the theft is reasonably likely to create a major national-security, foreign-policy, or economic threat. Treasury called this the first sanctions action under PAIPA. That is a notable use of an intellectual-property law as a sanctions tool, but it is not a criminal judgment against the people or businesses named.
What the sanctions mean in practice
For OFAC-designated persons, property and interests in property that are in the United States, or in the possession or control of U.S. persons, must generally be blocked. U.S. persons generally may not transact or deal with blocked persons unless an exemption or OFAC authorization applies. The restrictions can reach beyond banks: payments, contracts, consulting, software and hardware services, cloud services, brokering, investment, and providing goods or services for a designated party’s benefit may all require careful review.
Rank #4
OFAC’s 50 Percent Rule also matters: an entity owned, directly or indirectly and in aggregate, 50% or more by one or more blocked persons is itself treated as blocked, even if it has not been separately named on the sanctions list. A business relationship therefore cannot be cleared solely by checking the counterparty’s name; ownership and indirect dealings may matter too.
Violations can carry civil or criminal penalties. OFAC civil liability can apply on a strict-liability basis, meaning a violation may create exposure even without proof that the person knew the transaction was prohibited. The details depend on the activity, the parties, applicable rules, and any licenses or exemptions. Companies facing a potentially relevant transaction should consult current OFAC guidance and qualified sanctions counsel; this article is not legal advice. Designations and applicable authorizations can change after the announcement.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What remains undisclosed
Treasury has not publicly identified the eight or more tools by name, provided vulnerability identifiers or affected products, or identified the unauthorized user that received the tools. The public release also does not establish whether a stolen tool was used in a confirmed attack, disclose a full cryptocurrency transaction trail, or identify Operation Zero’s ultimate customers. It says the tools were sold to at least one unauthorized user; that is narrower than saying all tools were deployed or naming a state recipient.
Best Value
Nor does the designation itself mean the sanctions shut down Operation Zero. It restricts dealings with designated persons under U.S. jurisdiction and creates substantial compliance consequences for U.S.-linked counterparties, but the public announcement alone does not establish the company’s operational status elsewhere.
Why the case matters
It targets the supply chain, not only an end user. The action focuses on a broker accused of acquiring and redistributing stolen cyber capabilities, extending the policy response beyond operators of malware or victims of attacks.
It highlights insider risk. A trusted employee can become a route from restricted tools to outside buyers. For companies that develop offensive cyber capabilities, access controls, auditing, and protection of source code and trade secrets are part of the security perimeter—not just internal administrative concerns.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →It puts cryptocurrency into the procurement story without resolving the payment trail. Treasury says Williams was paid in cryptocurrency. That illustrates how digital assets can be used in high-value cyber-tool transactions, but the public release does not specify the coin, blockchain, wallets, intermediaries, or whether funds were frozen or traced.
It joins sanctions policy with trade-secret protection. The first PAIPA sanctions action, as Treasury characterizes it, suggests the U.S. is prepared to use sanctions in response to alleged foreign-linked exploitation of stolen intellectual property when national-security consequences are asserted. That is an interpretation of the action’s significance, not a separate official finding about the future scope of the law.
For organizations with U.S. exposure, the practical takeaway is to screen counterparties and beneficial owners against current sanctions lists, assess the 50 Percent Rule, review indirect transactions involving brokers and affiliates, and escalate deals involving exploit research or offensive cyber services—especially where a counterparty’s ownership, customers, or end use is unclear.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →

