U.S. Offers $10 Million Reward for Chinese Hacker Who Tried to Steal COVID-19 Research

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


The U.S. Department of State is offering up to $10 million for information on Zhang Yu, a Chinese national accused of helping hackers target American COVID-19 research. The Rewards for Justice notice seeks details about Zhang, his associates, and their malicious cyber activities, with possible rewards and relocation for eligible sources.

U.S. authorities allege Zhang worked on behalf of the Shanghai State Security Bureau, part of China’s Ministry of State Security. The FBI Cyber Division highlighted the reward while pointing to the case against his alleged partner, Xu Zewei, who is now in U.S. custody.

Research Mailboxes Targeted

According to the Justice Department’s case summary, the alleged intrusions ran from February 2020 through June 2021. Early targets included U.S. universities, immunologists, and virologists working on COVID-19 vaccines, treatments, and testing. Investigators say intelligence officers directed the hacking and received reports about its progress.

The court documents describe a clear sequence. Around February 19, 2020, Xu allegedly told a Shanghai State Security Bureau officer that he had breached a research university in the Southern District of Texas. Three days later, the officer instructed him to access specific mailboxes belonging to researchers studying COVID-19.

Xu later reported that he had obtained the contents of those mailboxes, prosecutors say. This distinction matters: the case describes alleged data theft, not simply failed attempts to reach research systems. However, the public summary does not identify the university or detail every document taken.

The investigation also links Zhang and Xu to the HAFNIUM Microsoft Exchange Server hacking campaign. Beginning in late 2020, prosecutors allege, the group exploited Exchange vulnerabilities to break into email systems. Microsoft publicly disclosed the campaign in March 2021, prompting patches, detection tools, and government guidance.

After gaining access, the hackers allegedly installed web shells, scripts that let attackers control a server remotely. Such access allowed them to search and steal mailbox data. At a targeted law firm, investigators say the attackers searched for terms including “Chinese sources,” “MSS,” and “HongKong.”

The FBI says the wider HAFNIUM campaign compromised more than 12,700 U.S. organizations. That figure describes the broader campaign, not a confirmed count of COVID-19 research victims or organizations personally breached by Zhang.

Italian authorities arrested Xu in Milan on July 3, 2025, at Washington’s request. He was extradited on April 25, 2026, and appeared in federal court in Houston on April 27. Zhang remains wanted. Both face allegations in a nine-count indictment; the charges are not proof of guilt.

Cyber Security News previously examined Chinese companies linked to Xu and Zhang and their patents for data collection tools. That reporting identified Shanghai Powerock as Xu’s employer and Shanghai Firetech as Zhang’s, adding context to the alleged contractor network behind these operations. The patent findings do not establish which tools were used in these intrusions.

The Justice Department says China uses private companies to hide its role in hacking, while the resulting breaches can leave systems open to further attacks by unrelated, profit-driven threat actors.

Rewards for Justice directs sources to its official Tor-based reporting channel for information about foreign state-backed cyber activity. Its guidance says eligible sources may receive relocation support and cryptocurrency payments.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post U.S. Offers $10 Million Reward for Chinese Hacker Who Tried to Steal COVID-19 Research appeared first on Cyber Security News.