The U.S. Department of State is offering a reward of up to $10 million for information regarding Zhang Yu, a Chinese national accused of participating in cyberattacks that targeted American COVID-19 research.
This initiative, part of the Rewards for Justice program, seeks information about Zhang, his associates, and their malicious cyber activities.
Zhang is alleged to have operated under the direction of the Shanghai State Security Bureau, which is part of China’s Ministry of State Security. His alleged partner, Xu Zewei, was extradited from Italy and appeared in federal court in Houston on April 27, 2026. Zhang, however, remains at large.
According to the Justice Department, the cyber intrusions occurred between February 2020 and June 2021. Early targets included American universities and researchers, specifically immunologists and virologists studying coronavirus vaccines, treatments, and testing. Prosecutors allege that intelligence officers supervised the operations and received progress reports.
On February 19, 2020, Xu allegedly informed an intelligence officer that he had compromised a research university in the Southern District of Texas.
Just three days later, the officer instructed him to access specific email accounts belonging to researchers engaged in COVID-19 studies. Xu subsequently reported that he had successfully obtained the contents of the researchers’ mailboxes.
This indicates data theft rather than attempted access. However, the public case summary does not disclose the university’s name or provide a complete list of the stolen research.
Investigators also connect Zhang and Xu to the HAFNIUM campaign, which began in late 2020 when the attackers exploited vulnerabilities in Microsoft Exchange Server to compromise organizational email systems. Microsoft publicly disclosed this campaign in March 2021.
After gaining access, the attackers allegedly installed web shells, server-side scripts that enable remote administration. This access facilitated mailbox searches and the theft of information. At one targeted international law firm, prosecutors claimed that the intruders searched for terms such as “Chinese sources,” “MSS,” and “Hong Kong.”
The FBI attributes more than 12,700 compromised U.S. organizations to the broader HAFNIUM campaign. However, this figure does not confirm the specific COVID-19 research victims or systems that Zhang personally breached. Despite patches and detection guidance, hundreds of web shells remained active on affected American Exchange servers by late March 2021.
Xu allegedly worked for Shanghai Powerock Network. Previous Cyber Security News reports have identified Shanghai Firetech as Zhang’s employer and have examined patents for intrusive data-collection technologies. These patents do not establish which specific tools were used during the intrusions.
The Justice Department says China’s contractor ecosystem obscures government involvement while leaving compromised systems vulnerable to exploitation by other actors. The nine-count indictment contains allegations, and both defendants are presumed innocent until proven guilty.
The Rewards for Justice program offers a Tor-based reporting channel for information about foreign government-directed cyberattacks against U.S. critical infrastructure. Eligible sources of information may receive relocation assistance and cryptocurrency reward payments.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…