The FBI’s Operation Winter SHIELD has been linked to the long-running response to the 2021 Microsoft Exchange exploitation campaign attributed to HAFNIUM (also tracked as Silk Typhoon), which expanded from targeted intrusions into a mass compromise of roughly 88,000 internet-facing servers worldwide. Researchers observed web shells implanted across organizations including utilities, government entities, managed service providers, and police departments, creating broad opportunities for follow-on exploitation by both the original operators and copycat actors.
According to reporting on the case, the FBI—working with Department of Justice authorization under Rule 41 and through a Unified Coordination Group—remotely removed malicious web shells from vulnerable Exchange servers as part of the disruption effort. The broader investigation later led to the 2025 arrest and extradition of alleged HAFNIUM co-conspirator Xu Zewei, while U.S. authorities continued related cybercrime infrastructure takedowns in 2025 and 2026 targeting phishing, proxy, and bulletproof hosting services.

TTPs, infrastructure, and targeting history in one profile.
17 events from the most recent confirmed update back to the earliest known activity.
Through mid-June 2026, the FBI reported 87 arrests, 137 indictments, 145 disruptions, and 11 dismantlements. The figures were cited as current-year enforcement results.
Operation Riptide was described as an accelerated 60-day FBI campaign launched in June under Executive Order 14390 and the White House Cyber Strategy for America. The source frames it as part of intensified disruption efforts against cybercrime infrastructure.
The FBI stated that it completed at least a dozen extraditions of cyber actors in the first half of 2026. The source does not provide exact dates for the individual extradition actions.
Alleged HAFNIUM co-conspirator Xu Zewei was arrested in Milan in early July 2025 on a provisional warrant. The arrest was coordinated between the FBI and Italy's Polizia Postale.
The FBI reported that in 2025 its cyber teams made 197 arrests, secured 158 convictions, unsealed 345 indictments, conducted 261 disruptions, and completed 26 extraditions. These figures were presented as part of broader cybercrime enforcement activity.
The phishing-as-a-service platform Outsider was described as operating since 2023. It was later tied to more than 8,000 phishing domains, about 3.87 million stolen credit cards, and roughly $1.9 billion in global losses.
On July 19, 2021, the United States, the European Union, NATO, and other allied governments publicly accused China of malicious cyber activity and tied China's Ministry of State Security-linked hackers to the 2021 Microsoft Exchange server intrusion. The coordinated attribution marked a major multinational diplomatic condemnation of China's role in the campaign.
Microsoft announced a one-click mitigation tool for on-premises Exchange servers to help customers apply mitigations against the ongoing exploitation campaign. The tool was published as part of Microsoft's March 2021 response to the Exchange attacks.
Shadowserver reported that 21,248 Microsoft Exchange servers appeared compromised with a Babydraco web shell following exploitation of recently patched Exchange flaws. It also observed on March 26 attempts to install the backdoor at /owa/auth/babydraco.aspx and, on some hosts, a PowerShell script downloading a secondary payload from 159.65.136[.]128.
A Unified Coordination Group was convened through the U.S. National Security Council, and the Department of Justice authorized use of a Rule 41 warrant to support remote remediation. The FBI Houston Division then removed malicious web shells from vulnerable servers at scale to stop both the original intrusion set and copycat exploitation.
Huntress, CrowdStrike, and other security researchers split the victim list and directly contacted affected organizations, which included utilities, governments, MSSPs, and police departments. The effort showed that manual notification could not scale fast enough to the number of compromised organizations.
By gaining cloned access to adversary infrastructure with hosting-provider and law-enforcement coordination, Huntress confirmed the Exchange intrusion had grown far beyond limited targeting. Huntress tracked real-time logs across more than 80,000 victims, and the campaign resulted in about 88,000 backdoored servers worldwide.
Security researchers observed a wave of exploitation against on-premises Microsoft Exchange servers in 2021. The campaign was later attributed to the Chinese state-sponsored group HAFNIUM, also known as Silk Typhoon.
The FBI, Lumen Technologies, and Google's Threat Intelligence Group dismantled NetNut, a residential proxy platform used by foreign actors to route traffic through U.S. residential IP addresses. No explicit event date is given in the source.
The FBI worked with Google and Lumen Technologies to take down domains associated with the Outsider phishing-as-a-service platform. The source does not explicitly anchor the takedown to a specific date.
The FBI published a reference page for Operation Winter SHIELD. The provided material does not include operational details beyond the existence of the operation and its publication by the FBI.
After his arrest in Italy, Xu Zewei was extradited to Houston to face charges related to the HAFNIUM case. The source does not provide a specific date for the extradition.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
huntress.com
Open sourcefbi.gov
Open sourcewashingtonpost.com
Open sourcekrebsonsecurity.com
Open sourceshadowserver.org
Open sourcemsrc-blog.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.