A Russian zero-day seller, Operation Zero, is offering up to $4 million for exploits targeting the messaging app Telegram, with prices ranging from $500,000 to $4 million based on the type of exploit.
Exploit brokers like Operation Zero acquire or develop security vulnerabilities to sell at higher prices, with a focus on Telegram due to its popularity in Russia and Ukraine.
The public offer provides insight into Russia's zero-day market priorities, with Operation Zero possibly responding to demand from the Russian government for Telegram exploits.
Zero-days, unknown to software makers, are highly sought-after in the exploit market, offering hackers opportunities to target technology with minimal defense.
Remote code execution (RCE) exploits, particularly zero-click ones, are valuable for allowing control without interaction from the target, making them lucrative in the hacking realm.
Telegram's security has been criticized compared to competitors like WhatsApp and Signal, with concerns about encryption and visibility of conversations on Telegram's servers.
Operation Zero's pricing for Telegram exploits is seen as relatively low, possibly indicating plans for higher pricing upon resale to customers, according to industry experts.
The zero-day market has seen escalating prices, with a zero-day for WhatsApp reportedly costing up to $8 million, reflecting the increasing difficulty in hacking popular apps.
Operation Zero previously offered $20 million for iOS and Android hacking tools and currently offers $2.5 million for such bugs, showcasing the high-stakes and evolving nature of the exploit market.