Alleged Silk Typhoon Hacker Extradited to US
The hacker was allegedly involved in Hafnium campaigns that targeted Exchange server flaws and in attacks against COVID-19 research institutions.

The hacker was allegedly involved in Hafnium campaigns that targeted Exchange server flaws and in attacks against COVID-19 research institutions.
April 28, 2026 | 3 min read

A hacker who allegedly launched attacks on behalf of the prolific Silk Typhoon state-sponsored Chinese espionage group has been extradited from Italy to the U.S.
According to the Justice Department, Xu Zewei, 34, of the People’s Republic of China (PRC), appeared on Monday in the U.S. District Court in Houston. Xu is facing a nine-count indictment linked to his reported involvement in intrusions between February 2020 and June 2021. Some of these attacks have been linked to activity by Silk Typhoon (also known as Hafnium), which has been around since 2021 and is known for targeting thousands of computers globally. Other operations targeted U.S. research related to COVID-19 during the pandemic.
“Today, Xu Zewei will stand in a federal courtroom to answer for crimes that struck at the heart of American science and security — allegedly stealing COVID-19 research from our universities when the world needed it most,” said Acting U.S. Attorney John G.E. Marck for the Southern District of Texas, in a statement on Monday.
The U.S. government has typically issued indictments and charges against various individuals behind cyberattacks (including one against Xu in March 2025). But it’s far less common to see actual arrests, particularly because these individuals live in so-called safe haven countries, and are even working on behalf of their government, as is the case here.
Xu worked for a company called Shanghai Powerock Network, which conducted hacks on behalf of the PRC government. According to court documents, his actions were directed by officers of the PRC’s Ministry of State Security’s (MSS) Shanghai State Security Bureau (SSSB). These are both PRC intelligence services that control PRC’s domestic counterintelligence, non-military foreign intelligence, and aspects of the PRC’s political and domestic security.
Xu allegedly targeted several U.S.-based universities, immunologists, and virologists that were researching COVID-19 vaccines and treatments in early 2020. For example, Xu targeted a research university located in the Southern District of Texas on February 22, 2020, accessing specific email accounts that belonged to virologists and immunologists and reporting the stolen intelligence to officers in the SSSB.
In late 2020, Xu also worked a campaign that exploited multiple Microsoft Exchange Server flaws, as part of a massive attack that was later exposed by Microsoft. The campaign left hundreds of webshells on U.S.-based computers running Exchange by the end of 2021, leading the DoJ to announce a court-authorized operation to remediate the vulnerable computers.
“Among the victims of Xu’s alleged exploitation of Microsoft Exchange Server were another university located in the Southern District of Texas and a law firm with offices worldwide, including in Washington, D.C.,” according to the Justice Department. “After exploiting computers running Microsoft Exchange Server, Xu and his co-conspirators installed web shells on them to enable their remote administration. The indictment alleges that these web shells were specific to HAFNIUM actors at the time. As with the earlier COVID-19 research intrusions, Xu and Zhang worked together on the HAFNIUM intrusions, under the supervision and direction of SSSB officers.”
Xu faces multiple federal charges—including wire fraud, computer intrusion, and identity theft offenses—that together carry potential prison sentences ranging from two to 20 years per count, depending on the charge. Xu is being charged along with Zhang Yu, 44, who is also a PRC national and who remains at large.
April 28, 2026 | 3 min read
Lindsey O’Donnell-Welch is an award-winning journalist who strives to shed light on how security issues impact not only businesses and defenders on the front line, but also the daily lives of consumers.