US Offers $10M Reward for APT41 Hacker Over COVID-19 Research Theft
Key Takeaways The U.S. State Department is offering up to $10 million for information leading to the apprehension of Zhang Yu, a Chinese national. Zhang Yu is accused of involvement in...
Key Takeaways
- The U.S. State Department is offering up to $10 million for information leading to the apprehension of Zhang Yu, a Chinese national.
- Zhang Yu is accused of involvement in state-sponsored cyberattacks targeting U.S. COVID-19 research institutions and critical infrastructure.
- These attacks, linked to China’s Ministry of State Security, allegedly involved data theft from universities, immunologists, and virologists during a critical period of vaccine development.
- Zhang is also connected to the widespread HAFNIUM campaign, which exploited Microsoft Exchange vulnerabilities to compromise over 12,700 U.S. organizations.
U.S. Offers $10M Reward for Chinese Hacker in COVID-19 Research Theft Case
The United States Department of State has announced a reward of up to $10 million for details concerning Zhang Yu, a Chinese national implicated in cyberattacks against American COVID-19 research efforts. The Rewards for Justice program is seeking intelligence on Zhang, his associates, and their illicit cyber operations, with potential for significant financial rewards and relocation assistance for individuals providing actionable information.
Table Of Content
U.S. authorities contend that Zhang operated under the direction of the Shanghai State Security Bureau, an arm of China’s Ministry of State Security. The FBI Cyber Division emphasized this reward, drawing parallels to the ongoing case against Zhang’s alleged co-conspirator, Xu Zewei, who is currently in U.S. custody.
Targeting Critical COVID-19 Research
According to the Justice Department’s case summary, the alleged intrusions spanned from February 2020 to June 2021. Initial targets included American universities, as well as immunologists and virologists actively engaged in developing COVID-19 vaccines, treatments, and diagnostic tools. Investigators assert that intelligence officers not only directed these hacking operations but also received regular updates on their progress.
Court filings detail a specific timeline of events. Around February 19, 2020, Xu allegedly informed an officer from the Shanghai State Security Bureau that he had successfully breached a research university located in the Southern District of Texas. Just three days later, the officer reportedly instructed Xu to gain access to particular mailboxes belonging to researchers focused on COVID-19 studies.
Prosecutors state that Xu subsequently reported having successfully exfiltrated the contents of these mailboxes. This detail is crucial, as it indicates actual data theft rather than mere attempts to compromise research systems. However, the publicly available summary does not identify the specific university involved or enumerate every document that was stolen.
Links to the HAFNIUM Exchange Server Exploits
The investigation further connects Zhang and Xu to the widespread HAFNIUM campaign, which targeted Microsoft Exchange Servers. Beginning in late 2020, prosecutors allege that this group exploited critical vulnerabilities within Exchange to infiltrate email systems. Microsoft publicly disclosed this campaign in March 2021, leading to the rapid release of patches, detection tools, and official government guidance.
After gaining unauthorized access, the hackers reportedly deployed web shells—scripts that enable remote server control. This level of access allowed them to search and steal data from mailboxes. At one targeted law firm, investigators discovered that the attackers had searched for terms such as “Chinese sources,” “MSS,” and “HongKong.”
The FBI estimates that the broader HAFNIUM campaign compromised over 12,700 U.S. organizations. It is important to note that this figure represents the overall campaign and not a confirmed count of COVID-19 research victims or organizations specifically breached by Zhang himself.
Legal Proceedings and Continued Pursuit
Xu was arrested by Italian authorities in Milan on July 3, 2025, following a request from Washington. He was extradited to the U.S. on April 25, 2026, and made his initial appearance in federal court in Houston on April 27. Zhang, however, remains at large. Both individuals face charges in a nine-count indictment; these allegations do not constitute proof of guilt.
Earlier investigations by Cyber Security News identified Shanghai Powerock as Xu’s employer and Shanghai Firetech as Zhang’s, revealing insights into the alleged contractor network supporting these operations and their patents for data collection tools. However, these patent findings do not confirm which specific tools were utilized in the described intrusions.
The Justice Department highlights that China often uses private companies to mask its involvement in cyber espionage, and that these breaches can inadvertently create openings for other, financially motivated threat actors to exploit compromised systems.
The Rewards for Justice program directs potential sources to its official Tor-based reporting channel for submitting information regarding foreign state-sponsored cyber activities. The program’s guidelines indicate that eligible informants may receive support for relocation and payments in cryptocurrency.
What You Should Do
- Organizations should ensure all Microsoft Exchange Servers are fully patched and updated, specifically addressing the vulnerabilities exploited by the HAFNIUM campaign.
- Implement robust multi-factor authentication (MFA) across all critical accounts, especially for researchers and personnel involved in sensitive projects.
- Regularly audit email server logs and network traffic for indicators of compromise (IOCs) related to web shells or unusual data exfiltration.
- Educate employees, particularly those in research and development, about phishing attempts and social engineering tactics commonly used by state-sponsored actors.
- Maintain comprehensive backups of critical data, isolated from the network, to facilitate recovery in the event of a breach.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.