Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
state-sponsored-espionageenforcement-actioneducation-sector-threatactively-exploited-vulnerability

Italy Extradites Alleged HAFNIUM Hacker Xu Zewei to the United States

Updated 2mo agoFirst seen Apr 27, 202616 sources

Italian authorities extradited Chinese national Xu Zewei to the United States over allegations that he took part in a Chinese state-backed hacking campaign linked to HAFNIUM, also tracked as Silk Typhoon. U.S. prosecutors say Xu and co-defendant Zhang Yu conducted intrusions between February 2020 and June 2021 on behalf of China’s Ministry of State Security and the Shanghai State Security Bureau, including efforts to steal COVID-19 vaccine and research data from U.S. universities and researchers. Xu was arrested at Milan’s Malpensa Airport on a U.S. warrant, later transferred to U.S. custody, and is now being held in Houston; he denies the allegations and claims mistaken identity.

The indictment also ties Xu to the mass exploitation of previously unknown Microsoft Exchange vulnerabilities that began in March 2021, a campaign U.S. authorities say hit more than 60,000 U.S. entities and successfully compromised over 12,700 organizations. Prosecutors allege the victims included defense contractors, law firms, think tanks, universities, and infectious disease researchers, making the case one of the most prominent efforts to bring an alleged Chinese state-linked hacker into U.S. custody. If convicted on all charges, Xu faces up to 77 years in prison.

Share:
Italy Extradites Alleged HAFNIUM Hacker Xu Zewei to the United States
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Apr 27, 20262mo ago

Xu Zewei makes first U.S. court appearance in Texas

After being extradited from Italy, Xu Zewei made his first appearance in the U.S. District Court for the Southern District of Texas. The appearance followed the Justice Department's announcement of charges tied to the alleged HAFNIUM/Silk Typhoon espionage campaign.

Chinese national extradited to US for pandemic-era Silk Typhoon attacks | CyberScoop

Xu Zewei is extradited to the United States and held in Houston

By April 27, 2026, Xu Zewei had been extradited from Italy to the United States and was being held in Houston to face charges tied to the alleged China-backed hacking campaign.

Italy moves to extradite Xu Zewei to the United States

Italian authorities initiated extradition proceedings to send Xu Zewei to the U.S. over cyber-espionage charges tied to the alleged 2020-2021 hacking campaign.

Jul 1, 20251y ago

Italian police arrest Xu Zewei at Milan Malpensa Airport

Italian authorities arrested Xu Zewei in July 2025 at Milan's Malpensa Airport on a U.S. warrant and seized his documents and devices.

Jun 1, 20215y ago

Alleged Chinese state-backed intrusion campaign ends

According to the indictment, the charged hacking activity involving Xu Zewei and Zhang Yu ran from February 2020 until June 2021.

Mar 1, 20215y ago

HAFNIUM allegedly starts exploiting Microsoft Exchange zero-days

Beginning in March 2021, prosecutors say the operators attributed to HAFNIUM, later tracked as Silk Typhoon, exploited previously unknown Microsoft Exchange vulnerabilities in a broad campaign. The activity allegedly affected more than 60,000 U.S. entities and successfully compromised more than 12,700 organizations.

Feb 1, 20206y ago

Xu Zewei and Zhang Yu allegedly begin targeting COVID-19 research

U.S. prosecutors allege that Xu Zewei and co-defendant Zhang Yu began intrusions in February 2020 against U.S. universities and researchers to steal COVID-19 vaccine and related research on behalf of Chinese state security services.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

14 LINKEDOpen in app
Threat actors
1 linked
Organizations
12 linked
Microsoft CorporationShanghai Powerock NetworkPulse SecureShanghai Firetech Information Science and Technology CompanyShanghai Powerock Network Co., Ltd.TechCrunchBleepingComputerFlashpointRecorded FutureCyberScoopSecurity AffairsShanghai GTA Semiconductor Ltd
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.