2026-06-06 is live. RBL, certificate, and uptime monitoring — now in public beta.

News

Chinese National Alleged Silk Typhoon Operator Sent to U.S. Over COVID‑19 Research Hacks


A Chinese citizen accused of belonging to the Silk Typhoon cyber unit has been extradited from Italy to face U.S. criminal charges. Authorities in Washington contend the suspect was involved in a series of intrusions against American institutions and government entities.

Xu Zewei, 34, was detained in July 2025 by Italian law enforcement and later transferred to U.S. custody. The indictment accuses him of conducting intrusions between February 2020 and June 2021, including a breach of systems at a Texas university that allegedly resulted in the theft of vaccine-related research tied to COVID-19.

Federal prosecutors have lodged nine charges against Xu, including multiple counts of wire fraud, conspiracy to damage and to obtain information from protected computers through unauthorized access, and an aggravated identity theft count.

The complaint asserts that Xu and a co-defendant, fellow Chinese national Zhang Yu, carried out the operations under the direction of the Ministry of State Security’s Shanghai State Security Bureau (SSSB). Some intrusions reportedly leveraged then-unpatched zero-day flaws in Microsoft Exchange Server - activity that Microsoft attributed to a cluster it dubbed Hafnium - enabling attackers to install web shells for remote control.

According to the indictment, Xu was employed by Shanghai Powerock Network Co. Ltd. at the time the alleged intrusions took place. The U.S. Department of Justice has described Powerock as one of several Chinese firms that acted as “enablers,” carrying out cyber operations on behalf of state actors.

Prosecutors say that in early 2020 the defendants focused on U.S. universities and researchers - immunologists and virologists - who were working on vaccines, treatments and diagnostic testing for COVID-19. The charges also allege that beginning in late 2020 the conspirators exploited vulnerabilities in Microsoft Exchange Server, a widely used platform for email, to gain access to victim systems.

Xu has consistently denied participating in state-directed hacking, asserting that his arrest resulted from mistaken identity. He was reportedly vacationing in Milan with his wife when taken into custody. Xu’s attorney told TechCrunch that his client entered a plea of not guilty at a recent court appearance.

Zhang Yu has not been apprehended and remains at large as authorities continue their investigation into the network of suspects and the campaigns tied to Silk Typhoon.

First published on April 28, 2026.
Last updated on April 28, 2026.