We've heard many times about hackers stealing data and selling it online. This time, something different is happening. ZDNet revealed in a report that a hacker is selling zero-day vulnerabilities to various hacker groups. In fact, this has been happening for the last three years. The groups that buy the vulnerabilities are well-known and are mainly espionage groups. Some of them are known as Advanced Persistent Threats (APTs).
Among the APT groups that are clients of the hacker is the Russian espionage group Fancy Bear.
The hacker selling the vulnerabilities, known by the pseudonym "Volodya", is quite popular in the hacking world. He has sold zero-day vulnerabilities in the past.
Back then, he had the nickname “BuggiCorp.” BuggiCorp had posted an ad on a public forum for the sale of a zero-day vulnerability and had shocked the whole world, since it was the first time something like this had happened.
The director of Kaspersky Lab 's Global Research and Analysis Team (GReAT) , said that his team had been monitoring Volodya's activity since 2015.
The director says Volodya is probably of Ukrainian origin. He speaks fluent Russian, but his name, which comes from Volodimir, is Ukrainian.
Volodya is also associated with the CVE-2019-0859, another zero-day vulnerability found in Microsoft Windows. The vulnerability was discovered by Kaspersky and a patch has been released to fix it.
Volodya is focused on selling these vulnerabilities. Their price can reach up to $200,000. It is very likely that he has a team with him, who has been helping him for the past three years.
It seems that spy are willing to pay large sums of money to acquire vulnerabilities and carry out attacks. So as this continues, the number of hackers selling bugs will increase.
