HomeSecurityHow zero-day exploits are sold on the black market

How zero-day exploits are sold on the black market

Zero -day exploits are one of the most valuable and dangerous “currencies” in the world of cybersecurity. They are software vulnerabilities that are unknown to the manufacturer at the time they are exploited, which leaves systems, organizations, and governments exposed. Behind these exploits there is an entire underground economy, with buying and selling that resembles a stock market more than illegal activity.

zero-day exploits

What are zero-day exploits and why are they valuable?

A zero-day exploit exploits a security flaw that has not yet been discovered or patched by the manufacturer. The term “zero-day” refers to the fact that the developer has zero days to react. This makes such exploits extremely effective, as they bypass antivirus, EDR systems, and traditional defense mechanisms.

See also: Serious bug in Broadcom software allows WiFi denial of service

Their value comes precisely from their “invisibility.” A zero-day exploit can offer complete control over target systems, access to sensitive data , or the ability to install persistent malware without being immediately noticed.

The underground market for zero-days

The sale of zero-day exploits does not happen on random forums. There is a multi-layered market that is divided into "gray" and outright illegal zones. In some cases, exploit brokers , operating legally on paper, but selling vulnerabilities to governments or state intelligence agencies.

On the black market, transactions typically take place in closed dark web forums or encrypted communication platforms. Access requires invitations, a history of trust, and often previous successful transactions. There, zero-days are advertised with technical details, verified proof-of-concepts, and clear terms of use.

How zero-day exploits are sold on the black market

Who buys zero-day exploits?

The buyers are not only cybercriminals. The list includes government agencies, cyber espionage groups, but also organized criminal networks specializing in ransomware or financial fraud. A zero-day for Windows, Android or popular enterprise platforms can cost from tens of thousands to millions of dollars, depending on its severity and credibility.

See also: Critical vulnerability in ServiceNow allows privilege escalation

Exploits that allow remote code execution without user interaction, as well as those targeting browsers, VPNs, and cloud services, are in particular demand.

From discovery to sale

The chain usually starts with security researchers, either independent or members of underground communities. Some choose the path of responsible disclosure, earning rewards through bug bounty programs. Others, however, knowing that the black market pays many times more, choose to sell the vulnerability silently.

Once a zero-day is released for sale, it goes through quality checks. Buyers require proof that it works on specific versions of software and that it hasn't already been disclosed. In many cases, the exploit is sold exclusively to one buyer to maintain its value.

How zero-day exploits are sold on the black market

How are they used in practice?

Zero-days are often the first step in complex attacks. They are used for initial penetration, installing backdoors , or privilege escalation. In highly targeted attacks, such as espionage or sabotage, they can remain active for months without being detected.

Once a vulnerability is known and patched, its value plummets. That's why attackers try to maximize profit and benefit before it's made public.

See also: CISA: Gogs vulnerability in KEV Catalog

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

What does this mean for the defense?

The existence of a thriving zero-day market shows that defense cannot rely solely on signatures and patches. Behavioral detection, privilege minimization, and continuous monitoring are critical tools.

As zero-day exploits continue to be sold and evolved, the battle between attackers and defenders becomes a race of endurance and speed. In the world of cybersecurity, the unknown remains the most dangerous weapon.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS