Kaspersky Lab profiles Volodya, one of the most prolific Windows exploit developers, who has sold zero-days to criminal gangs and state-backed APTs
Context & Ripple Effects
Kaspersky Lab has spent months documenting how Windows exploits move through the espionage ecosystem: last November it flagged multiple cyber-espionage groups exploiting the same Windows escalation-of-privilege zero-day before Microsoft patched it, and in April it reported that roughly 70% of the attacks its products detected in Q4 2018 targeted Office vulnerabilities. Profiling Volodya adds the supply side to that picture — identifying one of the individual developers whose work feeds both criminal gangs and state-backed APTs.
First-order effects
- Volodya's customers — criminal gangs and state-backed APT groups — gain a reliable source of Windows exploits without needing in-house vulnerability research capability.
- Defenders on the receiving end, including Kaspersky's own customer base, face the same exploit code reused across otherwise unrelated threat actors, complicating attribution and prioritization.
Second-order effects
- The broker model explains patterns Kaspersky has already observed, such as several distinct espionage groups deploying the same Windows zero-day before Microsoft's fix — one developer's output amplifying many buyers at once.
- Microsoft faces pressure to shorten its patch cycle for privilege-escalation flaws, since a single brokered exploit can reach multiple APTs simultaneously rather than staying within one operation.
Third-order effects
- If the pattern holds, the zero-day market keeps stratifying into professional intermediaries like Volodya on the supply side and well-funded state demand on the other — consistent with FireEye's later tally linking dozens of zero-days to state-sponsored operations and with boutique shops like Azimuth Security selling to Five Eyes agencies.
- As brokers blur the line between criminal and state buyers, attribution based on tooling alone becomes less reliable, pushing defenders and governments toward tracking exploit provenance rather than malware signatures.
The trend: Windows zero-day exploitation is consolidating around professional brokers who sell the same research to criminal gangs and state-backed APTs alike, turning individual bugs into multi-group threats.