Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Anthropic Claude Haiku 5.5 Offers Enhanced Coding and Computer Vision
October 8, 2026
Elastic Patches Critical Data Interception Flaw in Kibana (CVE-2024-5268)
October 8, 2026
US Offers $10M Reward for APT41 Hacker Over COVID-19 Research Theft
October 8, 2026
Home/CyberSecurity News/US Offers $10M Reward for APT41 Hacker Over COVID-19 Research Theft
CyberSecurity News

US Offers $10M Reward for APT41 Hacker Over COVID-19 Research Theft

Key Takeaways The U.S. State Department is offering up to $10 million for information leading to the apprehension of Zhang Yu, a Chinese national. Zhang Yu is accused of involvement in...

David kimber
David kimber
October 8, 2026 4 Min Read
3 0

Key Takeaways

  • The U.S. State Department is offering up to $10 million for information leading to the apprehension of Zhang Yu, a Chinese national.
  • Zhang Yu is accused of involvement in state-sponsored cyberattacks targeting U.S. COVID-19 research institutions and critical infrastructure.
  • These attacks, linked to China’s Ministry of State Security, allegedly involved data theft from universities, immunologists, and virologists during a critical period of vaccine development.
  • Zhang is also connected to the widespread HAFNIUM campaign, which exploited Microsoft Exchange vulnerabilities to compromise over 12,700 U.S. organizations.

U.S. Offers $10M Reward for Chinese Hacker in COVID-19 Research Theft Case

The United States Department of State has announced a reward of up to $10 million for details concerning Zhang Yu, a Chinese national implicated in cyberattacks against American COVID-19 research efforts. The Rewards for Justice program is seeking intelligence on Zhang, his associates, and their illicit cyber operations, with potential for significant financial rewards and relocation assistance for individuals providing actionable information.

Table Of Content

  • Key Takeaways
  • U.S. Offers $10M Reward for Chinese Hacker in COVID-19 Research Theft Case
  • Targeting Critical COVID-19 Research
  • Links to the HAFNIUM Exchange Server Exploits
  • Legal Proceedings and Continued Pursuit
  • What You Should Do

U.S. authorities contend that Zhang operated under the direction of the Shanghai State Security Bureau, an arm of China’s Ministry of State Security. The FBI Cyber Division emphasized this reward, drawing parallels to the ongoing case against Zhang’s alleged co-conspirator, Xu Zewei, who is currently in U.S. custody.

Targeting Critical COVID-19 Research

According to the Justice Department’s case summary, the alleged intrusions spanned from February 2020 to June 2021. Initial targets included American universities, as well as immunologists and virologists actively engaged in developing COVID-19 vaccines, treatments, and diagnostic tools. Investigators assert that intelligence officers not only directed these hacking operations but also received regular updates on their progress.

Court filings detail a specific timeline of events. Around February 19, 2020, Xu allegedly informed an officer from the Shanghai State Security Bureau that he had successfully breached a research university located in the Southern District of Texas. Just three days later, the officer reportedly instructed Xu to gain access to particular mailboxes belonging to researchers focused on COVID-19 studies.

Prosecutors state that Xu subsequently reported having successfully exfiltrated the contents of these mailboxes. This detail is crucial, as it indicates actual data theft rather than mere attempts to compromise research systems. However, the publicly available summary does not identify the specific university involved or enumerate every document that was stolen.

Links to the HAFNIUM Exchange Server Exploits

The investigation further connects Zhang and Xu to the widespread HAFNIUM campaign, which targeted Microsoft Exchange Servers. Beginning in late 2020, prosecutors allege that this group exploited critical vulnerabilities within Exchange to infiltrate email systems. Microsoft publicly disclosed this campaign in March 2021, leading to the rapid release of patches, detection tools, and official government guidance.

After gaining unauthorized access, the hackers reportedly deployed web shells—scripts that enable remote server control. This level of access allowed them to search and steal data from mailboxes. At one targeted law firm, investigators discovered that the attackers had searched for terms such as “Chinese sources,” “MSS,” and “HongKong.”

The FBI estimates that the broader HAFNIUM campaign compromised over 12,700 U.S. organizations. It is important to note that this figure represents the overall campaign and not a confirmed count of COVID-19 research victims or organizations specifically breached by Zhang himself.

Legal Proceedings and Continued Pursuit

Xu was arrested by Italian authorities in Milan on July 3, 2025, following a request from Washington. He was extradited to the U.S. on April 25, 2026, and made his initial appearance in federal court in Houston on April 27. Zhang, however, remains at large. Both individuals face charges in a nine-count indictment; these allegations do not constitute proof of guilt.

Earlier investigations by Cyber Security News identified Shanghai Powerock as Xu’s employer and Shanghai Firetech as Zhang’s, revealing insights into the alleged contractor network supporting these operations and their patents for data collection tools. However, these patent findings do not confirm which specific tools were utilized in the described intrusions.

The Justice Department highlights that China often uses private companies to mask its involvement in cyber espionage, and that these breaches can inadvertently create openings for other, financially motivated threat actors to exploit compromised systems.

The Rewards for Justice program directs potential sources to its official Tor-based reporting channel for submitting information regarding foreign state-sponsored cyber activities. The program’s guidelines indicate that eligible informants may receive support for relocation and payments in cryptocurrency.

What You Should Do

  • Organizations should ensure all Microsoft Exchange Servers are fully patched and updated, specifically addressing the vulnerabilities exploited by the HAFNIUM campaign.
  • Implement robust multi-factor authentication (MFA) across all critical accounts, especially for researchers and personnel involved in sensitive projects.
  • Regularly audit email server logs and network traffic for indicators of compromise (IOCs) related to web shells or unusual data exfiltration.
  • Educate employees, particularly those in research and development, about phishing attempts and social engineering tactics commonly used by state-sponsored actors.
  • Maintain comprehensive backups of critical data, isolated from the network, to facilitate recovery in the event of a breach.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitHackerPatchSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical Double Counter Bot Vulnerability Exposes Discord User Data

Next Post

Elastic Patches Critical Data Interception Flaw in Kibana (CVE-2024-5268)

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Attackers Hijack .gh, .sl, .as Domain Registries for Rogue HTTPS Certificates
October 7, 2026
CyberXero Blends AI Tools Claude Code, PentAGI with Cobalt Strike for Attacks
October 7, 2026
CrowdStrike, AWS, NVIDIA Expand Cybersecurity Startup Accelerator
October 7, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us