tools

Inside Operation Zero: The Exploit Market and 5 Alternatives

Operation Zero is a US-sanctioned Russian exploit broker. Learn what it does, its published prices, and 5 vulnerability intelligence alternatives for 2026.

Juanma Juanma · 1789666359 · 14 min read · 2
Operation Zero alternatives

A sanctioned broker, a real market, and five legal options.

If you are searching for Operation Zero alternatives to build a vulnerability intelligence program, the first thing to understand is that Operation Zero is a sanctioned entity. In February 2026, the U.S. Department of the Treasury and Department of State jointly designated Operation Zero, its CEO Sergey Zelenyuk, the firm's Russian legal entity Matrix LLC, and its UAE-registered affiliate Special Technology Services LLC FZ under the Protecting Americans' Data from Foreign Adversaries Act (PAIPA) — the first time that statute was applied against a commercial exploit broker. Interaction with a designated entity by U.S. persons is prohibited by law.

This article is for CISOs and security directors who need to understand the exploit brokerage market — what it is, where a Russian-state-aligned player sits within it — and then choose vulnerability intelligence platforms that are both legal and defensively oriented. Operation Zero does not sell defensive products. The analysis below is market education, not a purchasing guide for its services.

The exploit broker market is real, lightly regulated outside the United States, and consequential enough that any serious vulnerability management conversation needs a working model of it. The five alternatives here — DarkEye, Zerodium, HackerOne, Bugcrowd, and Recorded Future — give security teams timely, actionable intelligence about vulnerabilities and exposures through approaches that are legal and accessible to Western organisations.

What Operation Zero Actually Does

Operation Zero (opzero.ru) describes itself as "the only official Russian zero-day purchase platform." Its business model is acquisition-and-resale: it purchases fully functional, unreported zero-day exploits from independent security researchers and resells them exclusively to Russian government agencies and Russian private organisations. It does not offer defensive products, vulnerability scanning, threat intelligence feeds, or SIEM integrations. Its entire value proposition is on the offensive side of the market.

To qualify for purchase, exploits must meet a narrow technical bar. Operation Zero does not accept proof-of-concept code, partial implementations, or previously reported vulnerabilities — every submission must be original, fully weaponized, and unreported. This reflects the end-buyer's requirement for immediately deployable capability rather than a research finding that needs further engineering.

The firm openly markets to Russian government buyers and states its clientele is limited to Russian organisations. That policy, combined with the February 2026 PAIPA designation, makes the firm inaccessible to Western organisations on two independent grounds: stated seller policy and U.S. sanctions law.

Under the Hood: Russia's State-Aligned Position in the Exploit Market

The exploit brokerage market has existed in various forms since the early 2000s. Brokers sit between independent vulnerability researchers who discover bugs and end buyers who want access to those bugs before vendors patch them. The commercial rationale for researchers is straightforward: coordinated disclosure bug bounties are measured in the thousands of dollars; exploit brokers pay multiples of millions for the same finding. For government buyers, the broker model offers speed, deniability, and access to researchers who will not engage with government procurement processes directly.

Operation Zero's distinctive position in this market is explicit state alignment. Where most commercial brokers maintain studied neutrality about end-buyer identity, Operation Zero publicly discloses that it sells to Russian government and Russian private sector buyers. The February 2026 PAIPA designation alleged that the firm purchased eight zero-day exploits stolen from Trenchant, a subsidiary of U.S. defense contractor L3Harris — an allegation that, if accurate, illustrates how state-aligned brokers fit into broader intelligence collection operations rather than purely commercial vulnerability markets.

PAIPA was enacted to restrict the transfer of sensitive data and capabilities to foreign adversaries, and its application to Operation Zero was the first use of the statute against a commercial technology intermediary. The designation covers the firm, its CEO (Sergey Zelenyuk), its Russian legal entity (Matrix LLC), and its UAE-registered entity (Special Technology Services LLC FZ) — the full corporate structure, not only its Russian components.

Where It Fits in a Security Program

It does not. This section exists because "where does it fit" is the right question to ask about any vendor under evaluation, and the honest answer here is: nowhere in a Western enterprise or public-sector security program.

Operation Zero sells offensive capability to a defined, restricted buyer set. It has no monitoring product, no threat intelligence feed, no exposure database, no SIEM integration, and no API that a defender would consume. Even setting aside the PAIPA designation entirely, it would have no function in a defensive security program because it produces no defensive outputs.

The educational value is market context. Understanding what exploit brokers pay and which actors are acquiring capabilities helps threat intelligence teams model the offensive landscape their adversaries operate within. If a mobile exploit commands $2.5 million on the open market, the attack surface deserves proportional defensive attention — that is the framing through which this article examines Operation Zero's published pricing.

What Operation Zero Costs

Operation Zero publishes a pricing page at opzero.ru/en/prices (opzero.ru, 2026). This level of price transparency is unusual in the exploit broker market, and the published prices are the highest documented acquisition rates for most categories — a fact worth acknowledging analytically because it reflects real market dynamics and genuine competitive positioning, not puffery.

Published bounty prices as of 2026:

Mobile exploits: Android full-chain zero-click remote code execution, $2,500,000; iOS full-chain zero-click RCE, $2,000,000; iMessage, Signal, or WhatsApp zero-click RCE, $1,500,000; WhatsApp RCE (non-zero-click), $1,000,000.

Virtualisation: VMware ESXi or Microsoft Hyper-V virtual machine escape, $1,000,000; ESXi VM escape standalone, $500,000.

Desktop browsers: Chrome RCE, $500,000; Microsoft Edge RCE, $400,000; Microsoft Outlook RCE, $250,000.

Server software: Apache or IIS RCE, $500,000; nginx RCE, $300,000.

Basebands: Up to $500,000 per submission.

Network infrastructure: Cisco, Fortinet, Citrix, Sonicwall, and Huawei enterprise routers, up to $100,000; consumer routers, up to $50,000.

Security software: Antivirus software exploits, $50,000.

For comparison: Zerodium's published Signal RCE bounty in 2026 is approximately $500,000 — Operation Zero's $1,500,000 rate is roughly three times higher (zerodium.com, 2026). At the mobile full-chain tier both brokers publish $2,500,000, but Operation Zero's mid-tier messaging and server rates consistently exceed Zerodium's published schedule.

Where Operation Zero Is Strong — and Where Teams Look Elsewhere

Genuinely strong: Operation Zero posts the highest documented exploit acquisition prices on the public broker market for most categories, and its pricing transparency is real. The page publishes specific dollar amounts, specific platform targets, and specific technical requirements — a combination of specificity not standard among brokers, most of which operate on invitation or referral only. For a researcher in a jurisdiction where selling to this firm is legal, the published prices represent the best-documented public offer available.

Where Western teams look elsewhere: On every dimension that matters for a Western enterprise or public-sector security program, Operation Zero is inaccessible. The PAIPA designation makes engagement by U.S. persons illegal regardless of intent, structure, or intermediary. The firm's stated buyer policy excludes Western organisations on its own, independent of sanctions. There is no defensive product to procure, integrate, or analyse. And the capability it sells is offensive — participating in this market as a buyer, where legal, adds to an adversary capability rather than a defender's visibility.

The alternatives in the next section are defensive or dual-use platforms that a Western security team can legally procure, integrate, and operate.

The 5 Best Operation Zero Alternatives in 2026

The following platforms address what a vulnerability intelligence program actually needs from the defender's side: dark web exposure data, structured bug discovery in your own systems, or curated threat intelligence on exploitation in the wild. They serve different workflows — the "who should pick what" section maps that directly.

1. DarkEye

DarkEye is a dark-web and OSINT intelligence group specialising in ransomware exposure, breach data, infostealer logs, and leaked access. Where most dark web monitoring tools return credential hits against a domain watchlist, DarkEye's architectural distinction is what happens after collection: it correlates emails, passwords, social accounts, crypto wallets, phone numbers, physical-world data, and content extracted from leaked documents — PDFs, image archives, mail exports — into unified identity profiles. That document-level processing matters operationally, because the exposure that ends a career or triggers a breach notification is typically inside a spreadsheet in a ransomware dump rather than in a credential combolist. Over a petabyte of dark-web data has been processed on this model.

The service portfolio covers Dark Monitor (continuous dark web surveillance), Domain Identity Tracker (supply-chain and executive credential exposure), Automation Platform (dark web intelligence combined with OSINT investigative workflows), Leak Analysis (post-breach forensics with a seven-day delivery commitment), consultancy, and training programmes. Tooling includes HaveIBeenRansom as the search layer, Breach.House as the crawler, Connector as the OSINT investigation panel, and Dark Manager for compliance workflows. Delivery is via secure dashboard, encrypted PDF report, or direct API integration into an existing SIEM or SOAR stack.

DarkEye sells no offensive capability. Its position as the first alternative here reflects the underlying need that drives security programs toward vulnerability intelligence: knowing what adversaries hold and where your exposure sits before it is weaponised against you. Check our DarkEye solutions here

2. Zerodium

Zerodium is the closest Western structural equivalent to Operation Zero — a commercial exploit broker purchasing zero-day exploits from researchers and reselling them to government clients. It is U.S.-registered, operates under U.S. law, and serves NATO-aligned government buyers. Published 2026 acquisition prices reach $2,500,000 for Android or iOS zero-click full-chain exploits, $1,500,000 for WhatsApp or iMessage zero-click RCE, and $200,000–$400,000 for desktop browser RCE (zerodium.com, 2026). Like Operation Zero, Zerodium produces no defensive product. The distinction that matters for Western buyers: Zerodium is not sanctioned, and its buyer base is Western government customers, not Russian state agencies.

3. HackerOne

HackerOne is the largest managed bug bounty platform by active researcher count and disclosed vulnerability volume. Where exploit brokers buy bugs for offensive deployment, HackerOne channels findings back to the vendor that can patch them — the opposite economic direction. Programmes span public and private bug bounties, vulnerability disclosure policies (VDPs), and penetration testing. Platform access starts from $29/month; Starter managed bug bounty from $20,000/year; enterprise contracts are custom-priced. Researcher payouts range from nominal amounts for informational findings to over $1,000,000 for critical vulnerabilities (hackerone.com, 2026). It is the right choice when an organisation needs to find bugs in its own systems before adversaries sell them.

4. Bugcrowd

Bugcrowd is HackerOne's closest structural competitor — a managed crowdsourced security platform covering bug bounties, vulnerability disclosure, penetration testing, and attack surface management. Its Crowdcontrol platform starts from $35/month per asset; managed bug bounty programmes start from $25,000/year; enterprise engagements are custom-priced (bugcrowd.com, 2026). Bugcrowd's differentiation tends to land in programme management flexibility and its researcher network composition, and the two platforms are frequently shortlisted together. Like HackerOne, it is a defensive platform — the intelligence it produces flows toward the organisation procuring the programme, reducing attack surface rather than selling it.

5. Recorded Future

Recorded Future is an enterprise threat intelligence platform with vulnerability intelligence as a dedicated module. For organisations that need to understand how vulnerabilities are being discussed, traded, and exploited in criminal and state-sponsored communities — without running their own broker or bounty programme — its module provides structured data on CVE exploitation timelines, patch priority analysis, and underground-forum monitoring for early-stage disclosures. Pricing is quote-only; enterprise vulnerability intelligence module contracts are reported in the $50,000–$500,000/year range (third-party, 2026). Appropriate for SOC and threat intelligence teams that need analyst-ready data rather than a researcher marketplace.

Operation Zero vs the Alternatives: Full Comparison

Platform Primary focus Core data Identity correlation Delivery / integrations Best for Pricing
Operation Zero Offensive exploit acquisition Fully weaponized zero-day exploits across mobile, server, browser, and network targets Not applicable — no defensive product No Western-accessible delivery; sells exclusively to Russian government and private organisations N/A — sanctioned entity; inaccessible to Western buyers by law and by firm policy Bounty/purchase prices per opzero.ru: Android full-chain zero-click $2.5M, iOS $2M, server exploits $250K–$500K, routers up to $100K (opzero.ru, 2026); inaccessible to Western buyers
DarkEye Dark web and OSINT intelligence Ransomware leaks, breach data, infostealer logs, leaked access; document-level extraction from PDF, image, and mail archives Unified identity profiles correlating email, social, wallet, phone, physical data, and leaked document content Secure dashboard, encrypted PDF report, SIEM/SOAR API Orgs needing dark-web exposure monitoring, post-breach forensics, supply-chain breach visibility, and identity-level attribution Custom quote; no public list price — scoped per deployment.
Zerodium Offensive exploit brokerage (Western government-aligned) Fully weaponized zero-day exploits across mobile, browser, and infrastructure targets Not applicable — no defensive product No public consumer product; government buyer direct engagement Western government agencies legally acquiring offensive capability under applicable legal frameworks Android/iOS zero-click full-chain up to $2.5M; browser RCE $200K–$400K; iMessage/WhatsApp zero-click $1.5M (zerodium.com, 2026)
HackerOne Bug bounty and vulnerability disclosure platform Researcher-submitted vulnerability reports across web, API, mobile, and infrastructure Not a primary platform feature Web platform; integrations with Jira, Slack, GitHub, SIEM, and enterprise ticketing systems Orgs finding and remediating bugs in their own systems via crowdsourced research From $29/month platform fee; Starter managed bounty from $20K/year; Enterprise custom (hackerone.com, 2026)
Bugcrowd Crowdsourced security and managed bug bounty Researcher-submitted vulnerability reports, attack surface data Not a primary platform feature Web platform; Jira, Slack, ServiceNow, and enterprise ticketing integrations Orgs wanting managed programme flexibility with researcher network depth and attack surface management From $35/month per asset; managed bounty from $25K/year; Enterprise custom (bugcrowd.com, 2026)
Recorded Future Enterprise threat intelligence CVE exploitation data, underground-forum intelligence, patch timing and priority analysis Organisation and threat-actor entity intelligence API, browser extension, Splunk, Microsoft Sentinel, and major SIEM integrations SOC and threat intel teams needing curated vulnerability intelligence without running a bounty programme Quote-only; enterprise $50K–$500K/year for vuln intel module (third-party, 2026)

Who Should Pick What

If your primary need is dark web exposure monitoring — leaked credentials, ransomware dump analysis, supply-chain breach visibility, post-breach forensics — DarkEye's document-level extraction and identity correlation covers ground that credential-only tools miss. Suitable for mid-market and enterprise organisations, including teams with attribution mandates.

If your organisation needs to find and fix bugs in its own systems — the choice is between HackerOne and Bugcrowd. Both are credible; selection comes down to researcher network fit and programme management overhead. Start with a managed programme tier if you lack dedicated triage capacity.

If your security operations team needs structured intelligence on active exploitation — when a CVE is being weaponized, by whom, at what stage — Recorded Future's vulnerability intelligence module delivers that without a researcher marketplace or broker relationship.

If your organisation is a Western government agency with a legal mandate to understand offensive capability — Zerodium is the legal, Western-aligned option within the exploit broker market. It is not a defensive product; acquisition engagements require legal review.

Operation Zero is not a viable option for any Western buyer. The PAIPA designation makes engagement by U.S. persons illegal. The firm's stated buyer policy excludes Western organisations independently of sanctions, and it produces no defensive product to integrate. This article covers it because understanding the market requires knowing its participants — not because interaction is possible or advisable.

The Bottom Line

The exploit broker market exists, pays prices that dwarf most bug bounty programmes, and now includes a state-aligned entrant under U.S. sanctions. Understanding that market is legitimate for CISOs building accurate threat models. Interacting with Operation Zero is not — it is illegal for U.S. persons, and the firm's stated policies exclude Western buyers regardless of the sanctions designation.

The five platforms here address the defensible version of the same need: timely intelligence about vulnerabilities and exposures affecting your environment. DarkEye covers dark-web exposure and identity-level correlation. Zerodium covers the offensive broker market for Western government buyers within applicable legal frameworks. HackerOne and Bugcrowd cover crowdsourced vulnerability discovery in your own systems. Recorded Future covers structured exploitation intelligence across the threat landscape.

Build your programme around what you need to defend.

Share //
Juanma

Darkeye Research Team

Juanma

Tracking ransomware crews, breach disclosures and the tooling that matters — field notes from the Darkeye desk.

Intel briefing

Get breach reports before they trend

Ransomware intel and breach disclosures in your inbox. Signal only, no noise.

Read next //

Have I Been Pwned Alternatives: 5 Platforms That Go Further
tools

Have I Been Pwned Alternatives: 5 Platforms That Go Further

HIBP tells you a breach happened. These five platforms answer what was taken, who has the data now, and what to do about it — with pricing for all six.

Juanma · 1789666358

Keep investigating //

Discussion (0)

Sign in to join the discussion

Share your take with the Darkeye community.

No comments yet. Be the first to weigh in.