Felons Running a Zero-Day Broker: What It Means
The KrebsOnSecurity report on convicted felons operating a zero-day broker exposes a known-vendor problem in offensive security. Here's the practical read.
When the Threat Is Inside the Ecosystem
The offensive security ecosystem has a known-vendor problem, and the people running the startup at the center of the KrebsOnSecurity report “Felons, Fraudsters Flog Offensive Cybersecurity Startup” knew it before they incorporated. This post is not a summary of Krebs’s reporting. It is an analysis of what the underlying facts mean for practitioners on both sides of the house, and what you can do about it.
The Structural Problem the Report Exposes
The startup in question was publicly dangling millions of dollars for zero-days in popular software. That alone is a signal. The legitimate zero-day acquisition market is small, relationship-driven, and intensely reputation-dependent. A new entrant waving large dollar figures publicly is either extremely well-capitalized and legitimately connected, or it is performing capital it does not have to attract researchers who do have exploitable material.
The Krebs investigation confirms the latter: the principals are convicted felons whose prior ventures included fake intelligence companies and an AI-based lobbying platform operated under assumed names. That pattern—serial identity obfuscation across multiple fraudulent ventures—is not opportunistic. It is methodological. These operators identified a sector where OSINT hygiene among buyers and researchers is inconsistent enough to exploit, and they built around that gap.
Why the Zero-Day Market Is a High-Value Target for Fraud
Established brokers like Zerodium have published acquisition prices and reputational histories researchers can verify. Government vulnerability equities processes are opaque, but they operate within bureaucratic structures that impose at least nominal accountability.
The mid-tier and emerging broker space is murkier. Researchers selling into that space often do so through intermediaries, under NDAs, with delayed payment structures. The information asymmetry strongly favors the buyer. A researcher who delivers a working exploit for a critical vulnerability and receives no payment has limited legal recourse—because the transaction may sit in a gray area, and because publicizing the dispute exposes the researcher to scrutiny they want to avoid.
The Atlantic Council’s 2017 report “Buyers, Sellers, and the Emerging Market for Cyber Vulnerabilities” documented this structural opacity and flagged the information asymmetry as a systemic risk. Nearly a decade later, those structural conditions have not materially improved—which is exactly what the Krebs report demonstrates.
For the operators in this case, the setup is close to ideal: claim deep pockets, solicit valuable research, exploit the reputational and legal ambiguity that prevents defrauded researchers from going public, and use assumed identities to delay or prevent attribution. The assumed-name pattern is particularly significant from an OSINT standpoint—it signals the operators anticipated their real identities would be disqualifying and structured the operation to defeat basic corporate records searches.
The Identity Obfuscation Angle: An OSINT View
Assumed names in a corporate context are a known tradecraft indicator associated with fraud, intelligence operations, and organized crime—sometimes all three. The key question is not whether assumed names were used, but how the obfuscation was structured and what verification methods would have surfaced it.
Standard OSINT due diligence on a cybersecurity vendor or broker covers:
- Corporate registry cross-referencing: Registered agents, incorporation dates, and officer names across multiple state and national registries. Assumed names frequently reuse real addresses or phone numbers that link back to prior entities.
- Domain and infrastructure history: WHOIS history, hosting provider overlap, and SSL certificate patterns connect nominally unrelated companies sharing infrastructure.
- Personnel graph analysis: LinkedIn and professional directory cross-referencing for biographical inconsistencies—employment gaps, credential claims that do not survive verification, institutional affiliations that cannot be confirmed.
- Adverse media and court records: PACER searches, state court records, and international criminal database queries for principals and known associates.
- Social graph mapping: Who vouches for these people? Who has co-invested, co-founded, or publicly associated with them? Fraudulent operators tend to have thin or quickly assembled professional networks that do not survive comparative analysis.
The assumed names in this case were sufficient to defeat casual due diligence. They were not sufficient to defeat the kind of sustained, multi-source investigation Krebs conducted. Detection is not impossible—it requires deliberate effort, not default trust.
What This Means for Offensive Security Practitioners
If you work in offensive security—red teaming, vulnerability research, exploit development—the immediate risk is transactional. A startup soliciting zero-days and run by people with a documented fraud pattern is a counterparty risk, not a reputational nuisance.
1. Treat unsolicited or newly-emerged zero-day brokers as high-risk counterparties by default. Run the same OSINT diligence you would apply to any unknown third party before disclosing research or entering a payment arrangement.
2. Verify principal identities independently. Do not rely on names in outreach materials. Cross-reference incorporation documents, conference speaking history, and professional network endorsements. The assumed-name pattern means the name on the website may be a dead end by design.
3. Understand the legal landscape before transacting. The Computer Fraud and Abuse Act and equivalent statutes elsewhere create liability exposure that varies based on the buyer’s actual legal standing and intended use. Transacting with a fraudulent entity does not insulate a researcher from downstream legal risk if the exploit is subsequently misused. Consult qualified counsel before any vulnerability sale transaction.
4. Use structured escrow and milestone-based payment terms. An entity that resists escrow has revealed something about its intentions.
What This Means for Defensive Security Practitioners
For defenders—threat intelligence analysts, SOC leads, security architects—the relevant risk is different but equally concrete.
The report describes a startup that was, at minimum, attempting to acquire functional exploits for widely-deployed software. Even if the principals never successfully acquired a single working zero-day, the attempt tells you:
- Actors at the intersection of far-right conspiracy networks and criminal fraud understand the value of offensive cyber capabilities and are motivated to acquire them, whether for financial, ideological, or influence-operation purposes.
- Fake intelligence companies are an active tradecraft pattern being used to establish credibility with targets who might otherwise apply appropriate skepticism.
- AI-based influence platforms operated under assumed names sit at the intersection of disinformation and operational security—a combination that belongs on any threat model for organizations in politically sensitive sectors.
For vendor risk teams, this is a case study in why standard vendor questionnaires are insufficient. A questionnaire sent to a company run under assumed names by convicted felons returns polished, false answers. The verification burden sits with your team’s OSINT capacity, not with the vendor’s self-reporting.
Recommended Actions
- Audit your vendor vetting procedures for cybersecurity tooling and intelligence service providers. If the process relies primarily on vendor-provided documentation, it will not catch this class of operator.
- Brief your vulnerability research team on the specific tradecraft patterns in the Krebs report: assumed names, fake intelligence company structures, AI-platform fronts.
- Add ideologically motivated fraud actors to your threat actor mapping if your organization operates in sectors those networks have targeted. The overlap between ideological motivation and criminal fraud tradecraft is a threat actor characteristic, not an anomaly.
- Integrate investigative security journalism into your threat picture. The Krebs report is a primary-source investigation, not optional reading.
The Gap Between Discoverable and Discovered
The offensive security industry has grown fast enough that its credentialing and vetting infrastructure has not kept pace. Anyone can register a company, build a professional-looking website, and start making acquisition offers. The reputational networks that should function as a quality filter—conference communities, researcher networks, established broker relationships—are not impermeable.
The Krebs investigation demonstrates that two operators with easily discoverable fraud histories and assumed identities got far enough into the market to generate serious coverage concern. What was discoverable and what was actually discovered are not the same thing—and that gap is the real vulnerability. It is an OSINT problem, not a technical one, and the patch is deliberate due diligence applied before the transaction, not after.