Silk Typhoon: Chinese Hacker Extradited to the US for COVID-19 Espionage

Silk Typhoon: hacker cinese estradato negli USA per spionaggio COVID-19

A member of the Chinese state-sponsored hacking group Silk Typhoon has been extradited from Italy to the United States, facing charges related to the theft of COVID-19 research from American universities. The case stands as one of the most significant state-backed cyber espionage prosecutions in recent years.

Who Is Xu Zewei and What Did He Do?

The Hacker’s Profile and His State Backers

Xu Zewei, 34, operated as a contract hacker working for Shanghai Powerock Network Co. Ltd., a front company serving as a cover for China’s Ministry of State Security (MSS), specifically its Shanghai bureau. Through this arrangement, Xu carried out operations on behalf of Silk Typhoon, also known as HAFNIUM — a Chinese state-sponsored advanced persistent threat (APT) group whose primary focus is industrial and scientific espionage.

His campaign ran from February 2020 to June 2021, targeting immunology and virology researchers at the height of the global pandemic. The objective was unambiguous: steal cutting-edge research on COVID-19 vaccines, treatments, and diagnostic tests before Western institutions could fully exploit them.

Arrest and Extradition

Xu was arrested in Italy in July 2025 and subsequently extradited to the United States. His first court appearance is scheduled for April 27–28, 2026, in Houston, Texas. Co-defendant Zhang Yu remains at large, and US authorities are actively pursuing him.

The Scale of the Attacks: Over 60,000 Victims Worldwide

The HAFNIUM Campaign and Microsoft Exchange Exploits

Perhaps the most alarming dimension of this case is its sheer scale. Xu and his co-conspirators exploited zero-day vulnerabilities in Microsoft Exchange Server in what became known as the HAFNIUM campaign — a landmark cyber offensive that sent shockwaves through the global cybersecurity community.

Using these exploits, the group compromised more than 12,700 US-based entities, while the global victim count exceeds 60,000. Targets included Texas universities, a law firm, and thousands of other organizations worldwide. Beyond academic data, Silk Typhoon also set its sights on government agencies and public policy bodies, seeking strategic advantages across both scientific and geopolitical domains.

Formal Charges

The US Department of Justice has brought nine counts against Xu Zewei, including:

  • Wire fraud
  • Conspiracy to damage protected computer systems
  • Aggravated identity theft

If convicted on all counts, Xu faces significant prison time in the United States.

A Historic Milestone in the Fight Against Chinese Cyber Espionage

A Rare Precedent

The extradition of Chinese state-linked hackers to face US justice is extraordinarily rare. The most notable prior case dates to 2022, when Yanjun Xu, an MSS officer, was sentenced to 20 years in prison for espionage targeting the aerospace industry — the first-ever conviction secured through extradition. The case of Xu Zewei marks the second significant episode of its kind, signaling that the United States is ramping up legal pressure on Chinese cyber operatives. Nevertheless, the vast majority of state-sponsored hackers continue to operate beyond the reach of American law.

The Geopolitical Context: Healthcare Espionage During a Pandemic

The COVID-19 pandemic created an unprecedented opportunity for intelligence-gathering operations. MSS-linked groups dramatically escalated attacks against universities and research centers, targeting intellectual property of enormous strategic value. The biotech and academic sectors remain primary targets today — and the threat has not diminished since 2021. If anything, it has grown more sophisticated.

How to Defend Against Silk Typhoon and Similar Threats

Practical Guidance for CISOs and Security Leaders

Legal action alone is not enough. Organizations must take concrete defensive steps. Key priorities include:

  1. Immediate patching of critical vulnerabilities, especially on Exchange Server. Every hour of delay increases exposure.
  2. Zero-trust architecture: never grant implicit trust to any access request by default.
  3. Network segmentation for sensitive research data.
  4. Multi-factor authentication (MFA) across all email and web-facing servers.
  5. APT threat intelligence on groups like Silk Typhoon, integrated into SOC workflows.
  6. Regular penetration testing on internet-exposed systems.
  7. EDR solutions and active incident response retainers, with a specific focus on intellectual property protection.

Universities and biomedical research institutions in particular must recognize themselves as high-value targets. Investing in cybersecurity is not an overhead cost — it is a strategic safeguard for intellectual capital.

Sources: The Hacker News, LiveNow Fox, The Record


The Silk Typhoon case makes it starkly clear how critical it is for universities, research centers, and public organizations to have structured tools for securely sharing threat intelligence on state-sponsored APT groups. Platforms like IsacChain enable the distribution of indicators of compromise and attack tactics in an encrypted, blockchain-verified manner, while simultaneously ensuring automated NIS2 compliance as required under European regulation. In an environment where industrial and scientific espionage is on a steady upward trajectory, collaboration between ISACs and SOCs has become a decisive factor in organizational resilience. Discover how IsacChain can help your organization at www.isacchain.com