In a development that has brought global concerns about cyberwarfare and digital espionage, Italian authorities have arrested a Chinese national at Milan's Malpensa airport. Xu Zewei, is accused of participating in the state-backed cyberattack group Silk Typhoon – also known as Hafnium – which is behind serious incidents of digital espionage targeting US and international infrastructure.

The arrest took place on July 3, after his arrival from China (based on an international warrant issued by the United States). Xu is being held in Busto Arsizio, while the US authorities have already filed a formal extradition request to face the charges against him.
See also: Silk Typhoon hackers: Changing tactics and supply chain attacks
According to the ANSA, Xu is allegedly directly involved in attacks launched by Silk Typhoon during the COVID-19 pandemic, targeting research institutions, public health organizations and laboratories involved in vaccine development. The attacks were aimed at intercepting sensitive datarelated to vaccines, diagnostic tools and treatments.
Silk Typhoon has established itself as one of the most aggressive APT (Advanced Persistent Threat) groups, with activity extending beyond the pandemic. According to Microsoft, the group has now turned its attention to critical infrastructure and U.S. agencies, such as the Office of Foreign Assets Control (OFAC) and the Committee on Foreign Investment, in an effort to gain access to sensitive government data and financial information.
See also: USA: Chinese hackers Silk Typhoon behind the Treasury Department hack?
More recent analysis suggests that Silk Typhoon is evolving its methods, targeting remote management, cloud services , and critical supply chains, with the aim of penetrating broader customer ecosystems.

The arrest by Italian police shows a growing determination by European authorities to tackle cyber threats in a more systematic and coordinated manner. The Silk Typhoon hackers had clearly structured roles, targeted high-profile institutions and sought profit and notoriety in the cybercrime underworld.
See also: Chinese hackers target France via Ivanti zero-day vulnerabilities
The Xu case, beyond its legal aspects, highlights the growing tensions between the West and China in the field of cybersecurity, bringing into focus the use of digital attacks as a tool for geopolitical influence and espionage. Xu's possible extradition to the US is expected to test diplomatic balances and reignite international debates about the control of cyberspace.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
