U.S. Offers $10 Million Reward for Chinese Hacker Behind Alleged COVID-19 Research Cyberattacks
The U.S. offers up to $10 million for information on Zhang Yu, accused of COVID-19 research cyberattacks.
The U.S. State Department's Rewards for Justice program is offering up to $10 million for information on Zhang Yu, a Chinese national accused of cyberattacks on American COVID-19 research under direction of the Shanghai State Security Bureau. Prosecutors say intrusions from February 2020 to June 2021 targeted universities and researchers, and that alleged partner Xu Zewei was extradited from Italy and appeared in Houston federal court on April 27, 2026. Investigators also connect both men to the HAFNIUM campaign, which exploited Microsoft Exchange, installed web shells, and which the FBI says compromised more than 12,700 U.S. organizations. The nine-count indictment contains allegations, and both defendants are presumed innocent.
- Rewards for Justice offers up to $10 million for Zhang Yu.
- Alleged MSS-directed theft targeted U.S. COVID-19 research in 2020-2021.
- Co-defendant Xu Zewei was extradited from Italy and arraigned in Houston.
- Both are linked to HAFNIUM Exchange intrusions affecting 12,700-plus U.S. organizations.
Full article515 words · extracted from gbhackers.com · click to collapse
The U.S. Department of State is offering a reward of up to $10 million for information regarding Zhang Yu, a Chinese national accused of participating in cyberattacks that targeted American COVID-19 research.
This initiative, part of the Rewards for Justice program, seeks information about Zhang, his associates, and their malicious cyber activities.
Zhang is alleged to have operated under the direction of the Shanghai State Security Bureau, which is part of China’s Ministry of State Security. His alleged partner, Xu Zewei, was extradited from Italy and appeared in federal court in Houston on April 27, 2026. Zhang, however, remains at large.
Reward for Chinese Hacker
According to the Justice Department, the cyber intrusions occurred between February 2020 and June 2021. Early targets included American universities and researchers, specifically immunologists and virologists studying coronavirus vaccines, treatments, and testing. Prosecutors allege that intelligence officers supervised the operations and received progress reports.
On February 19, 2020, Xu allegedly informed an intelligence officer that he had compromised a research university in the Southern District of Texas.
Just three days later, the officer instructed him to access specific email accounts belonging to researchers engaged in COVID-19 studies. Xu subsequently reported that he had successfully obtained the contents of the researchers’ mailboxes.
This indicates data theft rather than attempted access. However, the public case summary does not disclose the university’s name or provide a complete list of the stolen research.
Investigators also connect Zhang and Xu to the HAFNIUM campaign, which began in late 2020 when the attackers exploited vulnerabilities in Microsoft Exchange Server to compromise organizational email systems. Microsoft publicly disclosed this campaign in March 2021.
After gaining access, the attackers allegedly installed web shells, server-side scripts that enable remote administration. This access facilitated mailbox searches and the theft of information. At one targeted international law firm, prosecutors claimed that the intruders searched for terms such as “Chinese sources,” “MSS,” and “Hong Kong.”
The FBI attributes more than 12,700 compromised U.S. organizations to the broader HAFNIUM campaign. However, this figure does not confirm the specific COVID-19 research victims or systems that Zhang personally breached. Despite patches and detection guidance, hundreds of web shells remained active on affected American Exchange servers by late March 2021.
Xu allegedly worked for Shanghai Powerock Network. Previous Cyber Security News reports have identified Shanghai Firetech as Zhang’s employer and have examined patents for intrusive data-collection technologies. These patents do not establish which specific tools were used during the intrusions.
The Justice Department says China’s contractor ecosystem obscures government involvement while leaving compromised systems vulnerable to exploitation by other actors. The nine-count indictment contains allegations, and both defendants are presumed innocent until proven guilty.
The Rewards for Justice program offers a Tor-based reporting channel for information about foreign government-directed cyberattacks against U.S. critical infrastructure. Eligible sources of information may receive relocation assistance and cryptocurrency reward payments.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.