Italy to Extradite Alleged Hafnium Hacker to US in Major Cyber-Espionage Case

Italy has approved the extradition of Xu Zewei, an alleged member of China's Hafnium APT group, to the US on charges of stealing COVID-19 research and mass enterprise hacking.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region4 min read
Illustration representing international cyber-espionage extradition case involving alleged Hafnium hacker Xu Zewei

Illustration representing international cyber-espionage extradition case involving alleged Hafnium hacker Xu Zewei

Italy Moves to Hand Over Alleged Hafnium Member to US Authorities

The Italian government has approved the extradition of Xu Zewei, a Chinese national accused by the United States of participating in one of the most consequential state-sponsored cyber-espionage campaigns in recent history one that targeted enterprise infrastructure and sensitive research institutions across the globe.

The decision, confirmed by a source with direct knowledge of the matter, follows an Italian court ruling earlier this month that cleared the legal path for extradition. Xu was arrested in Milan in July 2025 at the request of US authorities.

What Xu Zewei Is Accused Of

The US Department of Justice (DOJ) alleges that Xu was an active participant in two major cyber operations:

COVID-19 Research Theft (2020): Xu is alleged to have been part of a coordinated team that targeted US-based universities, immunologists, and virologists conducting COVID-19 vaccine, treatment, and testing research with the goal of stealing proprietary findings on behalf of the Chinese government.

The Hafnium Exchange Server Campaign (2021): More significantly for enterprise security teams, Xu is also linked to Hafnium the Chinese state-sponsored advanced persistent threat (APT) group, now also tracked by Microsoft under the name Silk Typhoon. Hafnium became notorious in early 2021 after exploiting four critical zero-day vulnerabilities in Microsoft Exchange Server, granting attackers the ability to bypass authentication, execute arbitrary code, and exfiltrate entire email inboxes all without detection.

The group's targets spanned defense contractors, law firms, policy think tanks, NGOs, higher education institutions, and infectious disease researchers sectors that remain highly active in the GCC and broader MENA enterprise landscape.

Why This Case Matters for Enterprise Security Leaders

The Hafnium campaign was one of the most damaging cyber-espionage operations ever recorded. According to Microsoft and independent security researchers, the operation compromised tens of thousands of Exchange servers globally, affecting both private enterprises and government agencies. At least ten additional APT groups subsequently piled in to exploit the same vulnerabilities once they were publicly disclosed.

For CISOs and IT security teams particularly those still running on-premises Microsoft Exchange infrastructure this case is a reminder that the threat from state-backed actors has not diminished. In fact, Microsoft's own threat intelligence confirmed that Hafnium/Silk Typhoon continued its operations well past the initial disclosure, with a SharePoint vulnerability exploitation campaign reported as recently as July 2025.

Enterprise organizations across the MENA region running legacy or hybrid Exchange environments should treat this case as an active reminder to audit their exposure to known Hafnium-linked indicators of compromise (IoCs).

China Pushes Back

Beijing's Foreign Ministry rejected the US charges as political fabrication, urging Italy to "respect facts and law" and avoid becoming what it called an accomplice to Washington. Xu's legal team maintains he is a victim of mistaken identity a claim that Italian courts have now assessed and declined to uphold at the extradition review stage.

China's response follows a well-established pattern: denial and diplomatic pressure whenever state-linked threat actors face legal accountability in Western jurisdictions.

What Security Teams Should Do Now

If your organization uses or has historically used on-premises Microsoft Exchange, the following steps remain critical:

  • Audit for web shells: Hafnium routinely deployed ASPX web shells on compromised Exchange servers to maintain persistent access even after patches were applied.
  • Review IOCs: Microsoft has published a detailed list of Hafnium indicators of compromise that security teams can cross-reference against log data.
  • Migrate where possible: Microsoft has long recommended migration to Exchange Online as a means of reducing on-premises attack surface.
  • Monitor for lateral movement: Hafnium operations typically moved from email servers deeper into enterprise networks to conduct further reconnaissance and data exfiltration.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

Nation-State Cyber ThreatsEnterprise Threat IntelligenceAPT Groups & TacticsCyber Law & AccountabilityMicrosoft Security