/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Kaspersky Lab profiles Volodya, one of the most prolific Windows exploit developers, who has sold zero-days to criminal gangs and state-backed APTs

Catalin Cimpanu / ZDNet :

ZDNet Catalin Cimpanu

Context & Ripple Effects

Kaspersky Lab has spent months documenting how Windows exploits move through the espionage ecosystem: last November it flagged multiple cyber-espionage groups exploiting the same Windows escalation-of-privilege zero-day before Microsoft patched it, and in April it reported that roughly 70% of the attacks its products detected in Q4 2018 targeted Office vulnerabilities. Profiling Volodya adds the supply side to that picture — identifying one of the individual developers whose work feeds both criminal gangs and state-backed APTs.

First-order effects

  • Volodya's customers — criminal gangs and state-backed APT groups — gain a reliable source of Windows exploits without needing in-house vulnerability research capability.
  • Defenders on the receiving end, including Kaspersky's own customer base, face the same exploit code reused across otherwise unrelated threat actors, complicating attribution and prioritization.

Second-order effects

  • The broker model explains patterns Kaspersky has already observed, such as several distinct espionage groups deploying the same Windows zero-day before Microsoft's fix — one developer's output amplifying many buyers at once.
  • Microsoft faces pressure to shorten its patch cycle for privilege-escalation flaws, since a single brokered exploit can reach multiple APTs simultaneously rather than staying within one operation.

Third-order effects

  • If the pattern holds, the zero-day market keeps stratifying into professional intermediaries like Volodya on the supply side and well-funded state demand on the other — consistent with FireEye's later tally linking dozens of zero-days to state-sponsored operations and with boutique shops like Azimuth Security selling to Five Eyes agencies.
  • As brokers blur the line between criminal and state buyers, attribution based on tooling alone becomes less reliable, pushing defenders and governments toward tracking exploit provenance rather than malware signatures.

The trend: Windows zero-day exploitation is consolidating around professional brokers who sell the same research to criminal gangs and state-backed APTs alike, turning individual bugs into multi-group threats.