Italian authorities extradited Chinese national Xu Zewei to the United States over allegations that he took part in a Chinese state-backed hacking campaign linked to HAFNIUM, also tracked as Silk Typhoon. U.S. prosecutors say Xu and co-defendant Zhang Yu conducted intrusions between February 2020 and June 2021 on behalf of China’s Ministry of State Security and the Shanghai State Security Bureau, including efforts to steal COVID-19 vaccine and research data from U.S. universities and researchers. Xu was arrested at Milan’s Malpensa Airport on a U.S. warrant, later transferred to U.S. custody, and is now being held in Houston; he denies the allegations and claims mistaken identity.
The indictment also ties Xu to the mass exploitation of previously unknown Microsoft Exchange vulnerabilities that began in March 2021, a campaign U.S. authorities say hit more than 60,000 U.S. entities and successfully compromised over 12,700 organizations. Prosecutors allege the victims included defense contractors, law firms, think tanks, universities, and infectious disease researchers, making the case one of the most prominent efforts to bring an alleged Chinese state-linked hacker into U.S. custody. If convicted on all charges, Xu faces up to 77 years in prison.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
After being extradited from Italy, Xu Zewei made his first appearance in the U.S. District Court for the Southern District of Texas. The appearance followed the Justice Department's announcement of charges tied to the alleged HAFNIUM/Silk Typhoon espionage campaign.
By April 27, 2026, Xu Zewei had been extradited from Italy to the United States and was being held in Houston to face charges tied to the alleged China-backed hacking campaign.
Italian authorities initiated extradition proceedings to send Xu Zewei to the U.S. over cyber-espionage charges tied to the alleged 2020-2021 hacking campaign.
Italian authorities arrested Xu Zewei in July 2025 at Milan's Malpensa Airport on a U.S. warrant and seized his documents and devices.
According to the indictment, the charged hacking activity involving Xu Zewei and Zhang Yu ran from February 2020 until June 2021.
Beginning in March 2021, prosecutors say the operators attributed to HAFNIUM, later tracked as Silk Typhoon, exploited previously unknown Microsoft Exchange vulnerabilities in a broad campaign. The activity allegedly affected more than 60,000 U.S. entities and successfully compromised more than 12,700 organizations.
U.S. prosecutors allege that Xu Zewei and co-defendant Zhang Yu began intrusions in February 2020 against U.S. universities and researchers to steal COVID-19 vaccine and related research on behalf of Chinese state security services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
16 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcetheregister.com
Open sourcetheregister.com
Open sourcegovinfosecurity.com
Open sourcedatabreaches.net
Open sourcebleepingcomputer.com
Open sourcetechcrunch.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.