Breaking
Live threat feed May 19, 2026 | 11:51 UTC
4110 CVEs This Month
6 Actively Exploited
2 Ransomware Activity
18 Breaches YTD
Threat Investigation Portal
Investigate an IOC in the live graph workspace.
Investigate IOC
Cybersecurity News

Chinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks

Chinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks

Xu Zewei, a Chinese national accused of membership in the Silk Typhoon hacking group, was extradited from Italy to the United States. He faces allegations of orchestrating cyberattacks targeting American government agencies and organizations between 2020 and 2021, during the COVID-19 pandemic.

What happened

Italian authorities arrested Xu Zewei in July 2025 due to his alleged connection with Silk Typhoon, a Chinese state-sponsored hacking collective. The U.S. sought his extradition based on accusations that he conducted cyberattacks against American entities, including government agencies and organizations involved in COVID-19 research and response efforts.

These cyberattacks reportedly occurred between February 2020 and June 2021, a period critical to pandemic-related research. Following legal proceedings, Xu was extradited to the U.S. to face charges related to these activities.

Why it matters

The extradition underscores increasing international cooperation in prosecuting cybercriminals connected to state-sponsored threat groups. Cyberattacks on research entities and government agencies during the pandemic period represent significant threats to national security and public health infrastructure.

Preventing unauthorized access to sensitive COVID-19 information and related research is critical as such attacks can undermine trust, disrupt critical response measures, and compromise intellectual property. This case highlights ongoing challenges in attributing and responding to cyber activity linked to nation-state actors.

What security teams should do

Organizations involved in sensitive research or government operations should maintain vigilant monitoring for signs of intrusion associated with advanced persistent threats like Silk Typhoon. Implementing robust incident response protocols and ensuring secure communication channels are essential.

Security teams are advised to stay updated on threat intelligence regarding tactics attributed to state-sponsored groups targeting pandemic-related information and incorporate recommended mitigations from cybersecurity authorities.

Key technical details

While specific techniques used by Xu Zewei or Silk Typhoon in these attacks have not been detailed in the available information, Silk Typhoon is known as a state-sponsored threat group attributed to China. Their operations have historically included cyber-espionage campaigns targeting intellectual property and sensitive data.

The attacks identified occurred over a prolonged timeframe from early 2020 through mid-2021, spanning an important phase of the COVID-19 pandemic when research and government activities were critical.

Affected organizations/products

American organizations and government agencies involved in COVID-19 related efforts were specifically targeted by the alleged cyberattacks orchestrated by Xu Zewei, a member of the Silk Typhoon group.

Source attribution

https://thehackernews.com/2026/04/chinese-silk-typhoon-hacker-extradited.html

Thirumala Rao Padilam
Written by
Thirumala Rao Padilam
error: Content is protected !!