Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
enforcement-actiontrade-export-controlcybercrime-service-ecosysteminsider-threat-incident

Ex-L3Harris Trenchant executive jailed as US sanctions Russian zero-day broker Operation Zero

Updated 3mo agoFirst seen Feb 24, 202617 sources

A former L3Harris executive, Peter Williams, was sentenced to 87 months (about seven years) in U.S. federal prison after pleading guilty to theft of trade secrets tied to the removal and sale of at least eight zero-day exploit components/cyber tools from Trenchant (L3Harris’ specialized unit supplying exploits to the U.S. government and select allies). Prosecutors said the stolen materials were intended for restricted government use; Williams allegedly leveraged his access over several years, received about $1.3 million in cryptocurrency, and the theft was estimated to have caused $35 million in losses to the contractor. Court reporting also noted Williams’ prior service with Australia’s signals intelligence community and that Trenchant traces back to L3Harris’ acquisition of Australian exploit-focused firms.

The U.S. Treasury’s OFAC simultaneously imposed sanctions on Operation Zero—a St. Petersburg-based Russian exploit brokerage—and its founder Sergey Zelenyuk, citing national security risks from acquiring and reselling zero-days and related tooling that could enable ransomware or other malicious activity. U.S. officials said Operation Zero obtained the stolen Trenchant tools and then resold them to unauthorized users, and multiple reports linked the sanctions action to the Williams case (where the buyer was previously anonymized in court as “Company 3”). Reporting also described Operation Zero’s public market for high-value mobile and app exploits (including past offers for Android, iOS, and Telegram), its marketing toward non-NATO customers and foreign intelligence services, and additional U.S. measures including State Department sanctions and action under the Protecting American Intellectual Property Act, plus sanctions on an affiliated UAE entity Special Technology Services (STS) and other associated parties.

Share:
Ex-L3Harris Trenchant executive jailed as US sanctions Russian zero-day broker Operation Zero
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
May 12, 20262mo ago

Restitution hearing in Williams case is scheduled

Court reporting said a further hearing on restitution in the Peter Williams case was set for May 12, 2026, to address financial recovery tied to the theft and sale of the stolen cyber tools.

Feb 24, 20264mo ago

Peter Williams is sentenced to 87 months in prison

On February 24, 2026, a U.S. court sentenced former L3Harris/Trenchant executive Peter Williams to 87 months in prison for stealing and selling eight trade-secret exploit tools to Operation Zero. The court also ordered forfeiture of proceeds and assets, and prosecutors said the theft caused about $35 million in losses.

U.S. sanctions Operation Zero and affiliated network

On February 24, 2026, the U.S. Treasury sanctioned Sergey Zelenyuk, Operation Zero/Matrix LLC, and associated individuals and entities, while the State Department designated Zelenyuk, Operation Zero, and UAE-based Special Technology Services. Officials described it as the first use of PAIPA sanctions tied to theft of U.S. trade-secret cyber tools.

Oct 29, 20258mo ago

Williams pleads guilty to theft of trade secrets

Peter Williams pleaded guilty to two counts of theft of trade secrets after U.S. investigators tied him to the theft and sale of at least eight exploit components from his employer to the Russian broker.

Jan 1, 20224y ago

Williams sells stolen exploits to Operation Zero for cryptocurrency

During 2022 to 2025, Williams sold at least eight stolen trade-secret exploit tools to Operation Zero under multiple arrangements, receiving about $1.3 million in cryptocurrency. U.S. authorities later said some of the tools were resold to at least one unauthorized user.

Peter Williams starts stealing Trenchant cyber tools

Between 2022 and 2025, Peter Williams allegedly stole proprietary zero-day exploit components and other cyber tools from Trenchant, an L3Harris unit whose capabilities were intended for U.S. government and allied use.

Jan 1, 20215y ago

Operation Zero begins operating as a Russian exploit broker

U.S. authorities said Matrix LLC, publicly operating as Operation Zero, began operating in 2021 as a St. Petersburg-based broker buying and reselling zero-days and spyware to non-NATO customers, including Russian government-linked buyers.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

36 LINKEDOpen in app
Threat actors
3 linked
Malware
2 linked
Affected products
9 linked
TelegramAndroidIphoneAndroidWindowsEsxiChatgptChatgptChrome
Organizations
22 linked
L3Harris TechnologiesTrenchantOperation ZeroAdvance Security SolutionsOPZeroSpecial Technology Services LLC FZMatrix LLCTelegramTinesLinchpin LabsSpecial Technology ServicesBleepingComputerTechCrunchOpenaiReutersBloombergCyberScoopTelegram Messenger Inc.Azimuth SecurityWynn ResortsUnnamed U.S. defense contractorAzimuth
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Ex-L3Harris Trenchant executive jailed as US sanctions Russian zero-day broker Operation Zero | Mallory