Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese Hacker Linked to Cyber Espionage Extradited to U.S.

Chinese Hacker Linked to Cyber Espionage Extradited to U.S.

Posted on April 28, 2026 By CWS

The United States has successfully extradited a Chinese citizen involved in one of the most significant state-backed cyber espionage campaigns. The individual, Xu Zewei, was brought from Italy to the U.S. where he appeared in a Houston court on April 27, 2026, facing multiple charges related to cyber intrusions.

Details of the Cyber Espionage Campaign

Xu, aged 34, is accused of orchestrating a series of cyberattacks between February 2020 and June 2021, a time that coincided with the COVID-19 pandemic. These operations were allegedly directed by the Shanghai State Security Bureau, part of China’s Ministry of State Security (MSS). Xu was employed by Shanghai Powerock Network Co. Ltd., a company described as facilitating these covert activities.

This strategic outsourcing to private firms is a documented approach by the Chinese state to obscure its involvement in cyber operations. The campaign, known in cybersecurity circles as Silk Typhoon, is linked to the broader HAFNIUM operation, which targeted over 12,700 U.S. entities.

Impact on U.S. Institutions and Response

Among the targets were U.S. universities and research institutions focused on COVID-19 vaccines and treatments. Xu reportedly breached the network of a university in Texas, later accessing and extracting data from researchers’ email accounts. The FBI, demonstrating its global reach, warned that similar perpetrators will face prosecution.

Xu’s co-defendant, Zhang Yu, remains at large, with the FBI urging public assistance in locating him. The FBI’s Houston Field Office leads the investigation, supported by national security prosecutors.

Technical Exploits and Legal Actions

In late 2020, Xu and his accomplices exploited vulnerabilities in Microsoft Exchange Server, a crucial email platform for many organizations. They installed web shells to maintain access, a method linked to HAFNIUM, allowing investigators to connect the dots. These activities targeted a second Texas university and a global law firm, emphasizing intelligence collection over financial motives.

The U.S. Justice Department, in April 2021, took action to remove numerous web shells from compromised systems. By July 2021, the U.S. and its allies officially attributed the HAFNIUM campaign to China’s MSS.

For further updates, follow our coverage on Google News, LinkedIn, and other platforms.

Cyber Security News Tags:Chinese hacker, COVID-19 research, cyber espionage, Cybercrime, Extradition, FBI, HAFNIUM, Microsoft Exchange Server, Ministry of State Security, national security, Shanghai Powerock, Silk Typhoon, U.S. Cybersecurity

Post navigation

Previous Post: Sevii Introduces Predictable AI Defense Costs
Next Post: Zero Trust Data Movement: The Overlooked Challenge

Related Posts

Hackers Breaking Internet with 7.3 Tbps and 4.8 Billion Packets Per Second DDoS Attack Hackers Breaking Internet with 7.3 Tbps and 4.8 Billion Packets Per Second DDoS Attack Cyber Security News
Authorities Dismantled AVCheck, a Tool For Testing Malware Against Antivirus Detection Authorities Dismantled AVCheck, a Tool For Testing Malware Against Antivirus Detection Cyber Security News
Hackers Actively Exploiting ArrayOS AG VPN Vulnerability to Deploy Webshells Hackers Actively Exploiting ArrayOS AG VPN Vulnerability to Deploy Webshells Cyber Security News
Securden Unified PAM Vulnerability Let Attackers Bypass Authentication Securden Unified PAM Vulnerability Let Attackers Bypass Authentication Cyber Security News
Tycoon 2FA Phishing Kit Exploits OAuth for Account Breaches Tycoon 2FA Phishing Kit Exploits OAuth for Account Breaches Cyber Security News
Astaroth Banking Malware Leveraging GitHub to Host Malware Configurations Astaroth Banking Malware Leveraging GitHub to Host Malware Configurations Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Ghostwriter Hackers Target Gmail with Phishing Emails
  • Cyberattack Uses Fake CAPTCHA to Deploy Malware
  • OnionDrop Campaign Delivers LegionLoader via gainmsg C2
  • GitGuardian Enhances Developer Security with New Endpoint Protection
  • Hackers Exploit Microsoft Teams to Mask Ransomware Traffic

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Ghostwriter Hackers Target Gmail with Phishing Emails
  • Cyberattack Uses Fake CAPTCHA to Deploy Malware
  • OnionDrop Campaign Delivers LegionLoader via gainmsg C2
  • GitGuardian Enhances Developer Security with New Endpoint Protection
  • Hackers Exploit Microsoft Teams to Mask Ransomware Traffic

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark