In July 2015 the hacker Phineas Fisher dumped some 400 GB of Italian surveillance vendor Hacking Team's data, including internal emails. Among them, Kaspersky Lab's Costin Raiu found a 2013 negotiation in which exploit seller Vitaliy Toropov offered Hacking Team a Silverlight zero-day 'written 2.5 years ago' with 'all chances to survive further in next years' — evidence that an exploit with no patch and no public details might still be infecting systems, if Kaspersky could only find it.

Zero-days are usually found by accident, in the forensic aftermath of a breach. Raiu tried the opposite: profile the author. He pulled the proof-of-concept exploits Toropov had published to bug-bounty programs between 2011 and 2013, before his public disclosures dried up, and noticed three debugging strings that recurred across the files — leftovers developers routinely ship in compiled code without meaning to. In July he wrote them into a YARA rule and pushed it across Kaspersky's automatic exploit prevention tool and its customer-shared telemetry network, then waited.

Months passed with nothing. Then on 25 November 2015 a customer machine in the Middle East matched: a Silverlight remote-code-execution exploit built on code from Toropov's published calculator PoC. Hours later a second sample surfaced on VirusTotal, uploaded from Laos and compiled on 21 July — two weeks after the leaked emails went online. Kaspersky reported the vulnerability, and Microsoft shipped a 'critical' patch for the Silverlight BinaryReader bug in January 2016.

The leak was repurposed as an early-warning system: a stolen sales brochure told defenders which unseen exploit existed, roughly how old it was, and who had built it.

Authorship is a signature: exploit writers reuse their libraries, and debug code tends to survive into compiled binaries, so published PoCs can fingerprint private follow-up work.

The sensor network already existed: a YARA rule across Kaspersky's opt-in telemetry turned thousands of customer machines into tripwires without deploying anything new.

Defensive etiquette left the trace: the years Toropov spent responsibly disclosing bugs to bounty programs — with published PoCs — became the fingerprint of his undisclosed exploits.

Attack attribution works in reverse too: an author's habits are a signature. When you can't find the artifact, model its maker from what they've published and let your sensors wait for the match.

Kaspersky found no further samples, suggesting the buyer used the exploit surgically; Raiu estimated it was worth $20,000–$40,000 on the zero-day market. Toropov told WIRED the exploit 'is not mine' after examining the code, though he confirmed the PoC parts were his. Raiu called it the first time his team had succeeded in catching something it had planned to hunt, and noted the technique could now be turned on other sellers' public code. Microsoft's patch removed the specific threat; the method — fingerprint the author, then wait — stayed in the toolbox.

FOLLOW THE EVIDENCE

The sources

  1. Hacking Team's Leak Helped Researchers Hunt Down a Zero-Day wired.com