Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
U.S. Offers Reward for Info on Chinese Hacker in COVID-19 Case

U.S. Offers Reward for Info on Chinese Hacker in COVID-19 Case

Posted on October 8, 2026 By CWS

The U.S. Department of State has announced a reward of up to $10 million for information leading to the capture of Zhang Yu, a Chinese national implicated in cyberattacks targeting American COVID-19 research. This initiative, part of the Rewards for Justice program, seeks insights into Zhang’s activities and connections, promising potential rewards and relocation for those providing eligible information.

Alleged Ties to Chinese Security

Zhang is accused of collaborating with the Shanghai State Security Bureau, under China’s Ministry of State Security. The FBI’s Cyber Division has emphasized this reward while noting the ongoing case against his alleged accomplice, Xu Zewei, currently detained in the U.S.

The cyber intrusions, detailed by the Justice Department, reportedly spanned from February 2020 to June 2021. Initial targets included American universities and researchers in the fields of vaccines and treatments for COVID-19. Intelligence officials are believed to have directed these hacking efforts, monitoring their progression closely.

Details of the Cyber Attacks

According to court filings, on February 19, 2020, Xu allegedly informed an officer from the Shanghai State Security Bureau about breaching a university in Texas. Shortly thereafter, he was instructed to access specific email accounts of researchers involved in COVID-19 studies.

Prosecutors claim that Xu successfully extracted data from these accounts, marking a clear case of data theft rather than mere attempted breaches. However, the public records do not disclose the university’s identity or the specific documents obtained.

Connection to HAFNIUM Campaign

The investigation also links Zhang and Xu to the HAFNIUM hacking campaign targeting Microsoft Exchange Servers. Starting in late 2020, this group allegedly exploited server vulnerabilities to infiltrate email systems, as publicly revealed by Microsoft in March 2021. This led to the release of patches and guidance for affected systems.

Using these vulnerabilities, hackers reportedly installed web shells, enabling remote server control. At one law firm, attackers searched emails for terms like “Chinese sources” and “MSS.” The FBI reports that this campaign affected over 12,700 U.S. organizations, though not all were related to COVID-19 research.

Xu was apprehended in Milan on July 3, 2025, and extradited to the U.S. where he appeared in Houston federal court on April 27, 2026. Zhang remains at large, with both facing charges in a nine-count indictment, which are not yet proven in court.

Broader Implications and Future Outlook

Prior reporting by Cyber Security News highlighted Chinese companies tied to Xu and Zhang, with patents for data collection tools linked to Shanghai Powerock and Shanghai Firetech. These insights shed light on the contractor network potentially facilitating these hacks.

The Justice Department asserts that China often utilizes private firms to obscure its involvement in cyber activities, with such breaches potentially exposing systems to further attacks by independent threat actors.

The Rewards for Justice program invites tipsters to use its Tor-based reporting channel, offering possible relocation and cryptocurrency payments for useful information on state-sponsored cyber activities.

Cyber Security News Tags:Chinese hacker, COVID-19 research, Cybersecurity, FBI, HAFNIUM, Microsoft Exchange, Shanghai State Security, U.S. reward, Xu Zewei, Zhang Yu

Post navigation

Previous Post: Compromised Tensorlake npm Package Delivers Credential-Stealing Malware
Next Post: Leading ASPM Platforms of 2026: A Comprehensive Overview

Related Posts

Aembit Introduces Identity and Access Management for Agentic AI Aembit Introduces Identity and Access Management for Agentic AI Cyber Security News
OpenClaw’s Rise Exposes Vulnerability Tracking Challenges OpenClaw’s Rise Exposes Vulnerability Tracking Challenges Cyber Security News
Critical Telegram Desktop Bug Exposed Chat Data Critical Telegram Desktop Bug Exposed Chat Data Cyber Security News
15 Best Docker Monitoring Tools in 2025 15 Best Docker Monitoring Tools in 2025 Cyber Security News
Threat Actors Widely Abuse .COM TLD to Host Credential Phishing Website Threat Actors Widely Abuse .COM TLD to Host Credential Phishing Website Cyber Security News
Link11 Launches Technical Hub in Lisbon for Enhanced Security Link11 Launches Technical Hub in Lisbon for Enhanced Security Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Oracle Health Data Breach Exposes 20 Million Records
  • U.S. Offers $10 Million Reward for Tips on Cyber Suspect Zhang Yu
  • Leading ASPM Platforms of 2026: A Comprehensive Overview
  • U.S. Offers Reward for Info on Chinese Hacker in COVID-19 Case
  • Compromised Tensorlake npm Package Delivers Credential-Stealing Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Oracle Health Data Breach Exposes 20 Million Records
  • U.S. Offers $10 Million Reward for Tips on Cyber Suspect Zhang Yu
  • Leading ASPM Platforms of 2026: A Comprehensive Overview
  • U.S. Offers Reward for Info on Chinese Hacker in COVID-19 Case
  • Compromised Tensorlake npm Package Delivers Credential-Stealing Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark