A Chinese national accused of stealing COVID-19 research from U.S. universities and taking part in the China-linked Hafnium hacking campaign — the same group Microsoft now tracks as Silk Typhoon — has been extradited from Italy to face federal charges in Houston and was scheduled to appear before a U.S. magistrate for a detention hearing.
Federal prosecutors said Xu Zewei, 34, appeared in U.S. District Court in Houston on a nine-count indictment tied to alleged computer intrusions between February 2020 and June 2021. Xu was extradited on April 25 and remains in custody, according to the Justice Department. His detention hearing was scheduled for 10:30 a.m. before U.S. Magistrate Judge Richard W. Bennett.
Prosecutors allege Xu worked at the direction of officers from China’s Ministry of State Security and its Shanghai State Security Bureau while employed by Shanghai Powerock Network Co. Ltd., a company U.S. officials described as part of a broader network of private contractors used to conduct hacking operations for the Chinese government.
The indictment accuses Xu and co-defendant Zhang Yu, who remains at large, of targeting U.S. universities, immunologists and virologists conducting research into COVID-19 vaccines, treatments and testing during the early months of the pandemic. Prosecutors said Xu confirmed in February 2020 that he had compromised the network of a research university in the Southern District of Texas and later obtained the contents of researchers’ email mailboxes.
The Justice Department also tied Xu to the Hafnium campaign, the China-linked operation that exploited Microsoft Exchange Server vulnerabilities in 2021 and compromised thousands of systems worldwide. The FBI said the campaign affected more than 12,700 U.S. organizations. Among Xu’s alleged Exchange victims were a second Texas university and a global law firm with offices in Washington, D.C.
According to the indictment, once inside the law firm’s mailboxes, the operators ran searches for terms including “Chinese sources,” “MSS” and “HongKong,” offering a glimpse into the tasking behind the access.
The Actor Behind the Indictment
Hafnium is now better known to defenders as Silk Typhoon, the name Microsoft assigned the group when it migrated to its weather-themed taxonomy in 2023. By either name, it is one of the most active Chinese state-aligned actors currently operating.
Silk Typhoon was tied to the late-2024 breach of the U.S. Treasury Department, was observed exploiting an Ivanti Pulse Connect VPN zero-day, CVE-2025-0282, in January 2025, and has spent the last 18 months pivoting from on-premises Exchange exploitation toward IT supply-chain targets, including managed service providers, identity platforms and OAuth application abuse to exfiltrate mail, OneDrive and SharePoint data through Microsoft Graph. The 2021 Exchange campaign Xu is charged with helping run was the high-profile opening act; the group continued operating.
What makes Xu’s case unusual is not the targeting — it is the visibility into the apparatus behind it. Court documents and follow-on research from SentinelLabs describe a tiered Chinese contractor network in which Powerock sits in the middle layer: above lower-tier firms like i-Soon, the contractor whose internal documents leaked publicly in 2024, exposing unstable, low-paying subcontracts and poor morale; and below trusted MSS-aligned firms like Shanghai Firetech, the company tied to co-defendant Zhang Yu, which holds patents on close-access surveillance tooling.
The Justice Department’s own description of the model is blunt: Contractors “cast a wide net” to find vulnerable computers, exploit them on spec and sell whatever they find — much of it “of no interest to the PRC government and, therefore, sold to other third parties.” That economic logic helps explain why a single tasking order to steal vaccine research could produce 12,700 collateral victims.
Charges and Procedural Status
Xu faces charges including conspiracy to commit wire fraud, wire fraud, conspiracy to damage and obtain information from protected computers, unauthorized access, intentional damage to protected computers and aggravated identity theft. The wire fraud counts carry a maximum sentence of 20 years in prison, while other counts carry maximum penalties of five or 10 years. The aggravated identity theft charge carries a mandatory two-year sentence that must run consecutively to any other prison term.
“We have pursued this moment across years and continents,” Acting U.S. Attorney John G.E. Marck said in the Justice Department announcement, adding that prosecutors would “work to protect the American people.”
Why the Extradition Itself is the Story
The case also underscores a persistent challenge for U.S. cyber enforcement: Washington often identifies and indicts alleged state-sponsored hackers, but rarely gets them into an American courtroom. The APT41 indictees, the APT40 indictees and the i-Soon employees charged in March 2025 largely remain in China, where they face little risk of arrest or extradition.
Xu’s arrest in Milan changed those odds. Italian authorities — including the Polizia Postale, Italy’s national cyber police — detained him in July 2025 on a U.S. warrant, and Italy later approved his extradition. Reuters reported that Xu’s lawyer previously argued he was a victim of mistaken identity, while China’s Foreign Ministry accused the U.S. of political manipulation. The operational signal for Beijing’s contract-hacker workforce is clear: Third-country travel to any jurisdiction with a working U.S. extradition relationship is now a real risk, and the Justice Department is clearly working that angle.
“The extradition of Xu Zewei demonstrates the FBI’s reach extends well beyond U.S. borders,” said Brett Leatherman, assistant director of the FBI’s Cyber Division. “He is one of many contractors the Chinese government uses to obscure its hand in cyber operations.”
Defenders Takeaway
The indictment is a 2020-2021 story, but Silk Typhoon’s playbook has evolved. The group still favors internet-facing collaboration and edge infrastructure for initial access — Exchange in 2021, Citrix NetScaler in 2023, PAN-OS GlobalProtect in 2024 and Ivanti Pulse Connect in 2025 — and it has added cloud identity abuse. Patch cadence on edge devices, web shell hunting on Exchange and SharePoint, audit logging on mailbox access, and tight scrutiny of OAuth application consents and service principal credentials remain the controls that would have made Xu’s job harder five years ago and would make his successors’ jobs harder today.

Shaun Nichols is an IT news journalist. He has spent nearly 20 years covering the industry with a specialty in the cybersecurity