Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
The U.S. State Department has offered $10 million for information leading to the location of Zhang Yu, a Chinese national and director of Shanghai Firetech Information Science and Technology. The announcement, dated October 7, 2026, places Zhang at the center of the Hafnium campaign—the cyber-espionage operation that compromised thousands of Microsoft Exchange servers between 2020 and 2021 to steal COVID-19 research and sensitive data from U.S. entities. The stakes exceed the capture of a single hacker: Zhang remains a fugitive while his alleged accomplice, Xu Zewei, is already in custody in Houston after extradition from Italy last April.
- The $10 million reward ranks among the highest ever offered by the Rewards for Justice program for an individual APT operator
- Zhang Yu directed Shanghai Firetech, one of the private Chinese firms used as an operational front by the Ministry of State Security (MSS) and the Shanghai State Security Bureau (SSSB)
- Xu Zewei, arrested in Milan in July 2025 and extradited to the U.S. in April 2026, has admitted to compromising a university network in the Southern District of Texas
- According to the FBI, the Hafnium campaign targeted more than 60,000 U.S. entities and successfully victimized over 12,700
The Firetech Model: When Private IT Firms Become Intelligence Proxies
The Rewards for Justice dossier identifies Zhang Yu in terms that blend managerial and operational roles: director of Shanghai Firetech, yet also a figure who acted “at the behest of” the MSS and its Shanghai bureau. This dual capacity is no anomaly in Chinese operations; the U.S. Justice Department has described “a network of private companies and contractors in China” that identify vulnerable computers, exploit them, and sell the information “directly or indirectly to the PRC government.”
Shanghai Firetech and Shanghai Powerock, cited in the nine-count indictment, serve as a layer of plausible deniability. Zhang wore no uniform and signed no official memos; his executive title provided legal cover and access to technical infrastructure. The model, documented in DOJ investigations, exploits the proliferation of small and medium Chinese IT firms that operate on government contract without appearing as state entities.
Xu in Custody, Zhang on the Run: What Divides the Two Accomplices
The discrepancy between the fates of the two defendants is the political core of today’s announcement. Xu Zewei, 33, was arrested in Milan in July 2025 and extradited to the U.S. in April 2026. He is held at the Federal Detention Center in Houston and faces up to 77 years in prison if convicted on all counts. He has admitted to compromising a Texas university network, according to court documents cited by The Record.
Zhang Yu, by contrast, remains a fugitive. The dossier does not specify his current location or whether he uses aliases or alternative identities. His absence fuels two readings that are not mutually exclusive: structural protection by Chinese authorities, or the failure of international investigative infrastructure to track an operator who may never have left Chinese territory. Xu’s extradition proves the U.S. can extract defendants from allied countries; Zhang’s absence suggests the Chinese border remains, for now, impenetrable.
"Through HAFNIUM, the CCP targeted over 60,000 U.S. entities, successfully victimizing more than 12,700 in order to steal sensitive information" Brett Leatherman, assistant director of the FBI Cyber Division
The 2021 Technique: Four Zero-Days and the Exchange Chain
The 2021 Hafnium campaign exploited four zero-day vulnerabilities in on-premises Microsoft Exchange Server: CVE-2021-26855 (CVSS 9.1, critical), CVE-2021-26857 (CVSS 7.8, high), CVE-2021-26858 (CVSS 7.8, high), and CVE-2021-27065 (CVSS 7.8, high). According to Microsoft and Volexity, the techniques included authentication bypass, privilege escalation, deployment of ASPX web shells for persistent access, exfiltration of mailbox contents, and address book theft.
The indictment’s timeline spans February 2020 through June 2021: the first phase targeted COVID-19 research at universities and immunology institutes, the second expanded to law firms, defense contractors, think tanks, and NGOs. Microsoft confirmed that Exchange Online was not vulnerable; only on-premises installations were at risk—a detail that pushed many organizations toward cloud migration but left those with legacy infrastructure exposed.
Why It Matters
The brief does not specify remedial measures or operational actions for organizations. The dossier does not clarify whether the $10 million reward was announced in response to specific intelligence on Zhang’s whereabouts or as part of a broader “naming and shaming” strategy against individual Chinese APT operators.
The source does not detail Zhang’s specific technical contribution relative to Xu in the intrusions: whether Zhang managed coordination while Xu operated in the field, or whether both held overlapping operational roles. The dossier also does not indicate whether Zhang has left Chinese territory since June 2021, nor whether Chinese authorities have formally refused judicial cooperation.
The absence of a structured ZDI or GHSL advisory in the dossier limits technical granularity compared to other documented cases. Primary government sources (Rewards for Justice, DOJ, FBI) provide sufficient political-legal context for the main claim, but do not substitute a public forensic analysis of command-and-control infrastructure.
FAQ
What is the difference between Zhang Yu and Xu Zewei?
Xu was arrested in Italy and extradited; Zhang remains a fugitive. Both are charged in the same nine-count indictment for intrusions between February 2020 and June 2021, but Zhang held a managerial role at Shanghai Firetech while Xu appears more directly involved in field operations.
Is the $10 million reward the highest ever offered?
The dossier does not provide historical rankings for the Rewards for Justice program. The figure is among the highest documented for a single APT operator, but the source does not state it as an absolute record.
Have the 2021 Exchange vulnerabilities been patched?
Yes. Microsoft released patches in March 2021 for the four CVEs cited. However, the dossier does not provide updated data on how many on-premises installations remain vulnerable due to unapplied fixes.
Sources
- https://therecord.media/accused-hafnium-hacker-zhang-yu-10million-reward
- https://therecord.media/chinese-apt-targeted-exchange-servers-with-four-zero-days-microsoft-says
- https://therecord.media/chinese-national-arrested-italy-hafnium-covid
- https://therecord.media/chinese-hacker-italy-extradited
- https://rewardsforjustice.net/rewards/zhang-yu-sssb/
Information is based on cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.