HAFNIUM , the Chinese cyberespionage group that rocked the cybersecurity world in 2021, is back in the spotlight with a dramatic development: the U.S. State Department is offering a reward of up to $ 10 million for information leading to the identification or capture of Zhang Yu , a Chinese national accused of involvement in the infamous Microsoft Exchange Server attacks . Zhang remains at large, and the case highlights once again how China uses private companies to conceal its role in cyber operations.

The U.S. State Department's Rewards for Justice program , which has paid out more than $250 million to more than 125 people since 1984 , has officially announced the reward for Zhang. According to The Hacker News, Zhang is wanted for his alleged role in " malicious cyber activities against critical U.S. infrastructure ."
Also charged with Zhang is Xu Zewei , who was arrested in Milan in July 2025 at the request of the US and extradited to the United States in April 2026. Brett Leatherman , assistant director of the FBI 's Cyber Division , said that Xu " is one of many contractors the Chinese government uses to conceal its involvement in cyber operations ."
See also: Silk Typhoon: Hacker extradited to the US for “COVID espionage”
HAFNIUM and ProxyLogon: The attack that changed the data
HAFNIUM was publicly disclosed on March 2 , 2021 , when Microsoft disclosed four critical zero-day vulnerabilities in Microsoft Exchange Server — a set of vulnerabilities that became known as ProxyLogon . These vulnerabilities affected only on-premises installations of Exchange Server (versions 2013, 2016, and 2019 ), not Exchange Online. The most critical of these was CVE-2021-26855 , a Server-Side Request Forgery (SSRF) vulnerability that allowed an attacker to send specially crafted requests to Exchange Server without requiring authentication. The remaining three vulnerabilities — CVE-2021-26857 (insecure deserialization), CVE-2021-26858 , and CVE-2021-27078 (arbitrary file write) — were used in combination to achieve a complete system compromise.
The exploit chain followed specific steps: first, the attacker exploited CVE-2021-26855 to bypass authentication, then used the remaining vulnerabilities to gain elevated privileges, and finally installed a web shell on the server. Through this web shell, attackers could execute commands, access mailboxes , steal credentials, and move laterally within the network. The FBI estimates that the HAFNIUM in total compromised more than 12,700 organizations in the US.
It is worth noting that the attack began as a targeted espionage operation, but after the vulnerabilities were publicly disclosed, other groups — both state and criminal — began exploiting the same vulnerabilities, turning the case into a global mass breach event. This case is often compared to Log4Shell and WannaCry as examples of how quickly a disclosed vulnerability in widely used software can escalate into a global security crisis.

HAFNIUM, Zhang Yu and Chinese cyber businesses
According to the indictment, Zhang Yu held the position of director at Shanghai Firetech Information Science and Technology, a Shanghai-based company. He allegedly performed duties assigned to him by the Shanghai State Security Bureau, a branch of China’s Ministry of State Security (MSS), overseeing the cyberattacks of other Firetech employees and coordinating activities with Xu Zewei. Xu Zewei, in turn, allegedly worked for a second company, Shanghai Powerock Network, which the Justice Department describes as one of several “front companies” that carry out cyberattacks on behalf of the Chinese government.
See also: Microsoft Exchange: Critical vulnerability allows access to other users' mailboxes
The indictment describes two series of attacks. The first, in early 2020 , targeted U.S. universities and scientists working on vaccines, treatments, and diagnostics for COVID-19 . The second, from late 2020 , exploited vulnerabilities in Microsoft Exchange Server in a campaign later dubbed HAFNIUM . The victims included two Texas universities and an international law firm with a Washington office. On January 30, 2021 , Xu allegedly informed Zhang that he had breached the network of a Texas university. Microsoft is now tracking the HAFNIUM group under the new name Silk Typhoon .
In July 2021, the US and its allies officially announced that the HAFNIUM campaign was carried out by hackers affiliated with MSS. This case highlights the difficulty of attributing cyberattacks solely based on technical indicators: multiple actors can use the same exploit chain, web shells, infrastructure, or stolen credentials. The attribution in this case is based on a combination of malware analysis, infrastructure, victimology, intelligence reports, and evidence from US law enforcement.
Practical measures to protect against HAFNIUM-type attacks
The HAFNIUM highlighted three critical cybersecurity lessons. First, online exposure was crucial: Exchange servers accessible from the public internet could be remotely attacked via the SSRF. Second, installing security patches was not enough after a breach — organizations had to investigate for web shells, stolen credentials, and persistence mechanisms. Third, mass exploitation followed the targeted attack: once the vulnerabilities became public, attackers unrelated to HAFNIUM began scanning and compromising vulnerable systems.
For organizations managing on-premises Exchange servers, the recommendations are clear: immediately install updates or retire vulnerable versions, use Microsoft, rotate credentials, review mailbox forwarding rules, and enable multi-factor authentication (MFA) for all administrators. In addition, capturing and centrally storing logs — IIS, Exchange, Windows events, firewall — on an immutable platform is essential for early detection of suspicious activity. Organizations should also actively look for web shells in Exchange directories, unusual schedule tasks, and suspicious PowerShell activity.
See also: UNC5792: $10 million reward for information on Russian hackers
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The Zhang Yu and HAFNIUM is a reminder that state-sponsored cyberattacks are not an abstract threat — they have specific names, front companies, and victims. International cooperation to prosecute those responsible, as demonstrated by the extradition of Xu Zewei, sends a strong message of deterrence, even if Zhang remains a fugitive. The $10 million offered by the Rewards for Justice reflects the seriousness with which the United States treats Chinese cyber operations and its determination to hold those responsible accountable.
