Chapter 1
The Digital Arms Race: Inside the Cyberweapons Market
In a world where we entrust our most intimate secrets to digital devices, a hidden war is unfolding. While we worry about terrorists and nuclear weapons, the most devastating attacks of our lifetime may come not from bombs but from code. Nicole Perlroth's meticulously researched expose has become required reading in Washington and Silicon Valley alike, with Bill Gates calling it "one of the most important books of our time." The book's chilling revelations about the global zero-day exploit market have prompted emergency meetings at the Pentagon and White House, while earning praise from figures ranging from Garry Kasparov to John Kerry. What makes this investigation so compelling is how it transforms an abstract digital threat into a visceral human story-revealing how our own government's pursuit of digital weapons has inadvertently created a marketplace that now threatens the very infrastructure upon which modern life depends.
Chapter 2
The Birth of a Shadow Industry
The story begins with a simple question that haunted the author after spending weeks examining Edward Snowden's leaked NSA documents in a windowless storage closet at the New York Times: Where did the NSA get all these digital "backdoors" into virtually every major technology product? The answer led her on a seven-year investigation into the murky world of zero-day exploits-software vulnerabilities unknown to manufacturers that allow hackers complete, invisible access to devices and networks.
In the early 2000s, a Texas entrepreneur named John Watters pioneered the first formal vulnerability marketplace through his company iDefense. His innovation was simple but revolutionary: pay hackers for finding software bugs, then sell that intelligence to subscribers who needed early warnings about security flaws. What began as a legitimate security service paying a few hundred dollars per bug soon attracted attention from government contractors willing to pay exponentially more-up to $150,000 for the same vulnerabilities-if sellers kept them secret.
"Coconspiring with the government to leave gaping holes in core technology used by your customers would destroy my business," Watters explained, rejecting these overtures. But the market forces he unleashed couldn't be contained. By 2005, the same bugs that once earned hackers $400 were commanding $4,000, and Watters sold iDefense to Verisign for $40 million-an extraordinary return on his $10 initial investment to acquire the company just three years earlier.
While Watters maintained ethical boundaries, others rushed to fill the void. A shadowy broker code-named "Sabien" began assembling teams to find and sell high-value exploits exclusively to intelligence agencies. "We provided the entire kill chain," he explained, describing how his team delivered complete digital espionage capabilities to government clients. Their most prized discoveries included exploits that could persist even if a computer was wiped and reinstalled, like one that infected video memory card firmware and another targeting HP printers that allowed agencies to capture documents before encryption.
As intelligence agencies worldwide recognized the internet's potential as an intelligence goldmine, the market expanded rapidly. Despite overall defense budget cuts in the 1990s, "cybersecurity" funding remained robust, though policymakers had limited understanding of how these funds were used. This created massive duplication as different agencies purchased the same exploits multiple times, sometimes at wildly different prices.
Chapter 3
The NSA's Digital Arsenal
Behind the public zero-day market lay an even more expansive arsenal of NSA exploits, available only to elite Tailored Access Operations (TAO) hackers. Their catalog of vulnerabilities granted entry into virtually every corner of the digital universe, from operating systems and browsers to hardware and infrastructure. The TAO unit, operating from a fortified facility in Fort Meade, Maryland, developed sophisticated tools that could penetrate everything from Windows systems to industrial control equipment, often maintaining persistent access for years without detection.
After 9/11, everything became fair game in the digital realm. The arrival of Google, Facebook, and especially the iPhone created unprecedented surveillance opportunities. Programs like "Snacks" visualized targets' entire social networks, mapping relationships, communications patterns, and behavioral profiles with stunning precision. "Where's My Node?" tracked movements between cell towers, creating detailed location histories accurate to within meters. The NSA developed specialized tools for each major platform - DROPOUTJEEP for iPhones, GOPHERSET for GSM phones, and WATERWITCH for radio frequency tracking.
By 2008, the NSA was removing human decision-making from operations, with the classified "Genie" program embedding implants in routers, switches, and computers worldwide. What began with 85,000 implants grew into plans for millions of automated insertions. These implants could lie dormant for years before being activated, giving the NSA instant access to targeted networks. The program cost $652 million annually and relied on sophisticated AI systems to manage the vast network of compromised devices.
Even as the U.S. warned allies about Chinese backdoors in Huawei equipment, the NSA had already penetrated Huawei's headquarters through Operation Shotgiant. The agency stole source code, mapped internal networks, and planted backdoors in Huawei products. The operation, conceived in 2007, initially aimed to uncover ties between Huawei and the People's Liberation Army but expanded into a comprehensive infiltration campaign. The NSA gained access to Huawei's internal emails, including communications from founder Ren Zhengfei, and developed plans to exploit Huawei products globally, particularly in countries actively avoiding American technology.
By 2017, NSA implants were embedded in networks across six continents, with many actively collecting data while others remained dormant until needed. The agency had compromised everything from underwater cables to satellite systems. In the post-9/11 rush for total information awareness, few questioned the implications if these operations were discovered. No one considered the potential blowback on American tech companies or the moral hazard of compromising the same technologies Americans relied on for banking, healthcare, and critical infrastructure. The NSA's answer was more secrecy and compartmentalization, operating under the dangerous assumption that they were smarter than everyone else and their operations would never be exposed.
Chapter 4
Crossing the Digital Rubicon
In 2007, President Bush confronted an escalating crisis at Iran's Natanz nuclear enrichment facility, a heavily fortified underground complex discovered through satellite imagery. After diplomatic efforts spanning three years had failed to halt Iran's uranium enrichment program, and with military strikes potentially triggering a catastrophic Middle East conflict, Bush faced mounting pressure from Israeli Prime Minister Ehud Olmert, whose military was actively preparing for unilateral airstrikes.
NSA Director Keith Alexander presented a revolutionary third option during a classified Situation Room meeting. He proposed leveraging the NSA's sophisticated digital infiltration capabilities to sabotage Iran's nuclear program from within. At Tennessee's Oak Ridge National Laboratory, engineers had meticulously constructed an exact replica of Natanz's enrichment system, including the specific Pakistani-designed P-1 centrifuges Iran had acquired through A.Q. Khan's nuclear proliferation network. Alexander's detailed plan involved compromising the Siemens S7-315 programmable logic controllers (PLCs) that regulated these delicate machines, which needed to spin at precisely 63,000 rpm to enrich uranium.
The operation, codenamed "Olympic Games," marked an unprecedented collaboration between five major agencies: the NSA's Tailored Access Operations unit, Israel's elite Unit 8200, CIA's Operations Directorate, Mossad's Caesarea division, and U.S. national energy laboratories. The technical challenges were immense - the code needed to operate undetected for months while causing centrifuges to self-destruct in ways that would appear as random mechanical failures to Iranian engineers.
The attack's execution required extraordinary precision. Since Natanz's critical systems were air-gapped, initial penetration likely came through human intelligence - either a compromised contractor or unwitting employee introducing an infected USB drive. The resulting worm was unprecedented in complexity: a 500KB package containing seven zero-day exploits worth millions on the black market. It was programmed to target only PLCs controlling exactly 164 centrifuges - matching Natanz's known configuration of centrifuge cascades.
The worm's sophistication reflected years of intelligence gathering. It would passively monitor normal operations for thirteen days, recording typical sensor readings. Then it alternated between commanding the centrifuges to spin at damaging 1,410 Hz frequencies and dramatically slowing them to 2 Hz, all while feeding technicians' monitors false data showing normal operations. By 2009, the attack had destroyed nearly 25% of Iran's enrichment capability, eliminating 2,000 of their 8,700 centrifuges.
During the presidential transition, Bush personally briefed Obama on Olympic Games in the Oval Office, emphasizing its strategic importance. While Obama continued and even accelerated the program, he expressed deep concerns about unleashing the first true cyberweapon of mass destruction - essentially opening Pandora's box. His fears materialized in June 2010 when the worm escaped Natanz's confines, spreading to computers worldwide. Security researchers who discovered it named it "Stuxnet," eventually tracing its sophisticated code back to American and Israeli origins, though both governments maintained official silence.
Chapter 5
The Mercenaries: Selling Digital Weapons to the Highest Bidders
As the zero-day market matured, a new breed of mercenary hackers emerged who sold their skills to the highest bidders in the largely unregulated cyberweapons market. Unlike earlier security researchers motivated primarily by intellectual curiosity, these newer players were driven by profit and operated with few ethical constraints.
Sinan Eren's background shaped his complex relationship with hacking. Growing up Kurdish in Turkey during intense persecution, he witnessed his father shot by police and saw thousands of Kurds "disappear." At Istanbul Technical University, he created early warning systems when secret police entered campus, defaced government websites, and hacked university officials' emails to expose their complicity in crackdowns.
After escaping to Silicon Valley, Eren joined Dave Aitel at Immunity, developing zero-day exploits. Their business thrived training government contractors, but Eren faced a moral crisis when forced to train a Turkish general - the same military persecuting his people. Eventually, the ethical compromises became unbearable, and Eren left to start his own company with stricter customer standards, only working with governments in "upper right quadrants" of human rights records.
The zero-day market was attracting an increasingly mercenary breed of brokers with little concern for ethics or discretion. The Grugq, a South African hacker living in Thailand, flaunted his wealth in Forbes photoshoots. Luigi and Donato from Malta openly advertised exploits for American industrial control systems. Singapore's Thomas Lim sold cyber weapons to governments lacking technical skills but flush with cash. Chaouki Bekrar, the self-styled "Wolf of Vuln Street," taunted tech giants while selling their vulnerabilities to unknown governments.
By 2013, the market had exploded to $5 billion from virtually nothing a decade earlier. Nearly every nation except Antarctica had entered the trade. Israel, Britain, Russia, India, and Brazil matched U.S. government prices, while Malaysia and Singapore joined the buying frenzy.
Perhaps the most sophisticated player in this market was NSO Group, an Israeli company founded by graduates of Intelligence Unit 8200. Their flagship product, Pegasus, could transform smartphones into comprehensive spy devices, capturing calls, texts, emails, contacts, GPS data, social media conversations, and even activate microphones and cameras for surveillance.
Unlike competitors, NSO had perfected "zero-click infection" - the ability to hack phones without requiring targets to click malicious links. They charged premium prices - $500,000 installation fee plus $650,000 to hack just ten phones, with additional targets costing hundreds of thousands more.
Despite NSO's claims of only selling to democratic governments for criminal and terrorism investigations, their technology was used to target Mexican nutritionists supporting a soda tax, anti-corruption activists, journalists critical of President Pena Nieto, and even their family members. When confronted with evidence of abuse, NSO executives deflected responsibility: "When you're selling AK-47s, you can't control how they'll be used once they leave the loading docks."
Chapter 6
The Resistance: Silicon Valley Awakens
The Chinese hack of Google in December 2009, dubbed "Aurora," became Silicon Valley's wake-up call. When a Google intern detected an unusual digital "blip" triggering security alarms, it soon metastasized into the most sophisticated cyberattack Google had ever faced. The hackers had sent Google employees in Beijing a malicious chat message containing a zero-day exploit for Internet Explorer.
The investigation revealed the hackers were targeting Google's source code - the crown jewels of any tech company. Unlike short-term targets like credit card information, source code is the raw matter that tells devices and apps how to behave, and manipulating it can create invisible backdoors. The attackers specifically targeted Gmail accounts belonging to Chinese dissidents.
In a historic move, Google publicly attributed the attack to China in January 2010 and announced it would no longer censor search results on Google.cn, effectively withdrawing from the Chinese market. This marked the first time an American company publicly called out China for cyber theft.
The attack transformed Google's approach to security. "The attack was proof that serious actors-nation-states-were doing these things, not just kids," explained Heather Adkins, Google's security director. The company began a comprehensive security overhaul while embarking on a mission to harden not just Google but the entire internet from within.
Google tapped into the global hacker community by offering financial incentives for discovering vulnerabilities. Their bug bounty program quickly expanded beyond Chromium to cover YouTube, Gmail and other services, eventually raising maximum rewards to $31,337 (a nod to "eleet" hackers). The program attracted diverse participants worldwide who used bounties to transform their lives, buy homes, fund startups, and support charities.
Facebook soon followed, led by self-proclaimed hacker Mark Zuckerberg. When Dutch hackers Michiel Prins and Jobert Abma demonstrated they could take over all Facebook accounts, COO Sheryl Sandberg immediately printed their email and rushed it to security head Alex Rice. Within two years, Facebook had paid $1.5 million to researchers for 687 bugs, 41 of which could have severely compromised the platform.
Microsoft took longer to embrace bug bounties. Katie Moussouris, Microsoft's hacker outreach lead, faced the Herculean task of convincing executives to pay hackers despite concerns about competing with government prices and creating perverse incentives. After collecting two years of data showing declining bug reports, and with the Snowden leaks creating a crisis of trust for tech companies, Microsoft finally launched a bounty program in June 2013.
The Snowden revelations in 2013 pushed tech companies into full battle mode, especially after leaks revealed the NSA and GCHQ were directly hacking Google and Yahoo's data centers. A hand-scribbled diagram with a triumphant smiley face emoji drove Google engineers into fury, with one declaring "Fuck these guys." In response, companies sealed every crack and implemented stronger encryption. Google's security chief Eric Grosse was clear about his mission: "No hard feelings, but my job is to make their job hard."
Chapter 7
When America's Weapons Boomerang Back
In August 2016, amid the DNC leaks and Russian election interference, a mysterious Twitter account @shadowbrokerss appeared, claiming to have hacked the NSA and offering to auction its cyberweapons online. Security experts quickly confirmed these were authentic NSA tools-"the keys to the kingdom" that could break into government agencies and corporate networks worldwide.
The Shadow Brokers released their most damaging leak on April 14, 2017 - twenty of the NSA's most coveted zero-day exploits, including the powerful "EternalBlue" that could invisibly penetrate millions of Windows machines. Despite Microsoft having quietly patched the vulnerabilities a month earlier, hundreds of thousands of unpatched systems remained vulnerable.
The first sign that America's cyberweapons were boomeranging back came on May 12, 2017, when nearly fifty British hospitals were hit by ransomware attacks. Within 24 hours, the ransomware dubbed "WannaCry" had infected 200,000 organizations across 150 countries. The attacks spread with unprecedented speed because they utilized EternalBlue, the stolen NSA exploit.
Just six weeks later, an even more destructive attack struck. What researchers initially thought was Petya ransomware was actually a far more sophisticated attack dubbed NotPetya. Using two stolen NSA tools-EternalBlue and EternalRomance-plus the password-stealing MimiKatz exploit, the attack spread globally after Russian hackers compromised a Ukrainian tax software company. Unlike genuine ransomware, NotPetya's encryption couldn't be reversed; it was designed purely for destruction.
What Russia likely intended as a targeted attack on Ukraine quickly spread worldwide, paralyzing Merck, DLA Piper, FedEx, Maersk shipping, hospitals, and even Cadbury's chocolate factory in Tasmania. The damage ultimately reached $10 billion, making it history's most destructive cyberattack.
Three years after the NSA lost control of its tools, EternalBlue had become a permanent fixture in cyberattacks on American towns and cities. In Allentown, Pennsylvania, malware spread across city networks, wiping police databases and freezing surveillance systems. By May 2019, Baltimore was hit with ransomware that disrupted essential services and cost $18 million in damages.
When journalists reported EternalBlue's involvement, the NSA denied responsibility through careful wordsmithing, infuriating Microsoft executives who were cleaning up the aftermath nationwide. Former NSA Director Michael Rogers showed no remorse, comparing the situation to Toyota not being responsible when someone weaponizes their trucks-an analogy Microsoft executives vehemently rejected, noting exploits were "already bombs."
Chapter 8
The Gathering Storm: Our Vulnerable Future
By 2020, the situation had become increasingly precarious, with foreign adversaries deeply embedded throughout American networks and critical infrastructure systems. Between 2019-2020, over 600 American towns, cities and counties were crippled by sophisticated ransomware attacks, generating billions for Russian cybercriminals. The demands escalated dramatically - from initial hundreds of dollars to multimillion-dollar extortion attempts. Notable attacks included Baltimore ($76 million in damages), Atlanta ($17 million to recover), and smaller cities like Lake City, Florida, which paid $460,000 in Bitcoin to recover their systems.
Intelligence officials found it "inconceivable" that the Kremlin wasn't aware of these criminal operations, given their scale and sophistication. Through detailed forensic analysis, they discovered Russian cybercriminals were meticulously following Putin's explicit rule against hacking inside Russia - their malware contained sophisticated code that specifically avoided computers with Cyrillic keyboard settings or IP addresses originating from former Soviet states. In several high-profile cases, cybercrime leaders weren't just working with Russian intelligence - they were active FSB agents operating under official cover, using criminal enterprises as a facade for state-sponsored operations.
"There's a pax mafiosa between the Russian regime and its cyber cartels," explained Tom Kellermann, head of cybersecurity strategy at VMware. "Russia's cybercriminals are treated as a national asset who provide the regime free access to victims of ransomware and financial crime. And in exchange, they get untouchable status, operating freely from luxury apartments in Moscow and St. Petersburg."
Meanwhile, Russian hackers had achieved something even more alarming - penetrating America's nuclear infrastructure. In July 2017, the DHS and FBI issued an urgent alert that Russian operatives had breached Wolf Creek, a 1200-megawatt nuclear power plant in Burlington, Kansas. Forensic analysis revealed they weren't just conducting espionage - they were methodically mapping networks for a potential future attack, compromising engineers with direct access to critical reactor controls. Similar intrusions were later discovered at multiple other nuclear facilities across the country.
Under General Paul Nakasone's leadership, U.S. Cyber Command began "defending forward," implementing a more aggressive strategy that included planting crippling malware inside Russian systems with unprecedented depth and sophistication. This was designed as an unmistakable message: if Russia dared to activate their implants in American infrastructure, the U.S. would immediately reciprocate with devastating consequences. The strategy included establishing persistent presence in adversary networks and conducting preemptive disruption of hacking infrastructure before it could be used against U.S. targets. While many national security experts viewed these counterattacks as long overdue deterrence, others worried that explicitly targeting civilian infrastructure, even as a defensive measure, would legitimize power grids and other critical systems as acceptable military targets, potentially escalating future conflicts into dangerous new territory.
Chapter 9
Securing Our Digital Future
For years, intelligence agencies justified concealing digital vulnerabilities as critical to national security. But this reasoning ignores our interconnected reality - vulnerabilities that affect one affect all. While America's cyber capabilities were initially far ahead (the "NOBUS" principle - "nobody but us"), that advantage has eroded.
We must lock down the code at the foundation level. Nobody will invest in securing higher layers if our basic foundations remain weak. While we can't rebuild the internet or replace the world's code, we can significantly raise barriers for cybercriminals and hostile nations. Our economy currently rewards those first to market with the most features, but speed has always been security's enemy.
We need to fundamentally rethink our machines' architecture by identifying and compartmentalizing critical systems from non-critical ones. As cybersecurity entrepreneur Casey Ellis says, "build it like it's broken" - companies must assume compromise and limit the potential damage radius. Apple's app sandboxing demonstrates this approach, significantly raising costs for attackers.
Our elections cannot be conducted online under any circumstances. Despite pandemic-driven experiments with online voting in several states, security experts consistently demonstrate these systems can be hacked. If academics can manipulate these systems to elect their chosen candidates, so can foreign adversaries.
The United States needs to reestablish a national cybersecurity coordinator position that was eliminated in 2018. While regulation alone won't solve our cybersecurity problems, mandating basic security requirements for critical infrastructure operators would significantly improve resilience.
The United States must use its immense spending power to create an arms race for the common good, having spawned the cyberarms market for vulnerabilities. We should consider tax credits for secure software development, expand bug bounty programs beyond federal networks to critical infrastructure, and create a Project Zero-style initiative deploying top hackers to find and patch vulnerabilities.
The government's offensive exploitation programs have worsened the trust deficit. Though Rob Joyce released details about the Vulnerabilities Equities Process (VEP) in 2017, the NSA's handling of EternalBlue - holding a severe vulnerability in widely-used software for five years - contradicted the VEP's stated principles. Despite claims that zero-days are held only "for a limited time," evidence from Shadow Brokers leaks showed the NSA kept critical vulnerabilities for years.
These cybersecurity challenges may seem impossible, but America has overcome existential threats before by mobilizing our scientific community, government, industry, and citizens. Writing during the COVID-19 pandemic, Perlroth sees parallels in our unpreparedness: inadequate testing, protective gear, warning systems, and recovery plans apply to both domains. We don't have to wait for "the Big One" to take action. As Greg McManus's t-shirt read: SOMEONE SHOULD DO SOMETHING.