US Puts $10 Million Bounty on Chinese Hacker Accused of Stealing COVID Research
The U.S. Department of State 2026-10-8 07:49:10 Author: thecyberexpress.com(查看原文) 阅读量:1 收藏

Who Is Zhang Yu

The U.S. Department of State’s Rewards for Justice (RFJ) program is offering up to $10 million for information on Zhang Yu, a Chinese national accused of hacking COVID-19 research at U.S. universities on behalf of China’s Ministry of State Security (MSS). U.S. officials also describe Zhang as a key figure in the HAFNIUM hacking campaign, which compromised thousands of computers worldwide.

His alleged partner, Xu Zewei, was arrested in Italy in July 2025 and extradited to the United States in April 2026. Zhang remains at large.

Who Is Zhang Yu

Zhang is a director at Shanghai Firetech Information Science and Technology Company, Ltd. U.S. officials say he worked at the direction of the MSS Shanghai State Security Bureau (SSSB). According to RFJ, the MSS and SSSB are Chinese intelligence services responsible for domestic counterintelligence, non-military foreign intelligence, and parts of the country’s political and domestic security.

Zhang Yu
Image Source: Rewards for Justice

The reward covers information leading to the identification or location of anyone who, while acting under the direction or control of a foreign government, takes part in malicious cyber activity against U.S. critical infrastructure in violation of the Computer Fraud and Abuse Act. The State Department says Zhang’s cyberattacks violated that law.

Zhang Yu and the COVID-19 Research Intrusions

Starting in early 2020, Zhang and Xu allegedly gained unauthorized access to COVID-19 research conducted by U.S.-based universities and leading immunologists and virologists in order to steal sensitive information. At the time, Xu was a general manager at Shanghai Powerock Network Co. Ltd.

Prosecutors say the two men carried out the hacks at the behest of the MSS and SSSB and reported back to supervising officers at the SSSB. In one instance, Xu allegedly confirmed to his handlers that he had compromised the network of a research university in the Southern District of Texas.

The HAFNIUM Campaign Linked to Zhang Yu

In 2021, Zhang and Xu allegedly exploited vulnerabilities in computers running Microsoft Exchange Server, software used to store and retrieve emails. These intrusions were part of the mass hacking campaign publicly known as HAFNIUM. Victims included a university and a law firm, both based in the United States.

A nine-count indictment unveiled by the Justice Department in 2025 accused both men of computer intrusions between February 2020 and June 2021, including the HAFNIUM campaign, which prosecutors described as indiscriminate.

The scale of the campaign was significant. Brett Leatherman, assistant director of the FBI’s Cyber Division, said in 2025 that through HAFNIUM, the Chinese Communist Party targeted more than 60,000 U.S. entities and successfully victimized more than 12,700 of them to steal sensitive information.

Zhang Yu Remains at Large as Partner Faces U.S. Charges

Xu was arrested by Italian authorities in July 2025 while on vacation in Milan. He was extradited to the United States in April 2026, while Zhang has not been apprehended.

According to RFJ, China uses an extensive network of private companies and contractors to hack and steal information in a way that hides the government’s involvement. Both men worked for private Shanghai firms while allegedly acting on behalf of state intelligence services.

RFJ is asking anyone with information on Zhang, his associates, or their malicious cyber activities to submit a tip through its Tor-based tip line. Rewards of up to $10 million are available for information that meets the program’s criteria.


文章来源: https://thecyberexpress.com/us-offers-10m-for-info-on-zhang-yu/
如有侵权请联系:admin#unsafe.sh