Microsoft Exchange HAFNIUM hacker bounty hits $10M

The U.S. State Department is offering a reward of up to $10 million for information leading to the identification or location of alleged Chinese state-backed hacker Zhang Yu, who is charged in the United States over his role in the 2021 HAFNIUM campaign targeting Microsoft Exchange Server installations worldwide[1][2][5][6][11][14].

The bounty is being offered through the State Department’s Rewards for Justice program, which describes Zhang as a Chinese national and director at Shanghai Firetech Information Science and Technology Co. Ltd., allegedly operating under the direction of the Ministry of State Security’s Shanghai State Security Bureau[1][5][8][14]. Zhang is accused of participating in a series of intrusions between 2020 and 2021 that hit U.S. critical infrastructure, including COVID-19 research organizations and on-premises Microsoft Exchange servers, as part of broader state-sponsored cyber operations[1][4][5][14].

According to U.S. authorities, Zhang and co-defendants took part in the indiscriminate HAFNIUM intrusion campaign that leveraged vulnerabilities in Microsoft Exchange Server to compromise thousands of systems used to send, receive, and store email messages in organizations around the world[1][5][11][14]. Beginning in late 2020, the group allegedly exploited these flaws to gain access to Exchange servers, steal data, and establish persistent footholds in victims’ environments, with U.S. prosecutors characterizing the operation as a massive, state-directed hack affecting both government and private-sector networks[6][11][14].

Microsoft publicly detailed the HAFNIUM activity in March 2021, warning that the group was chaining multiple zero-day vulnerabilities in on-premises Exchange to achieve remote code execution and data exfiltration[3][9][13]. The four core flaws disclosed at the time—CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065—span a server-side request forgery bug that allows an attacker to authenticate as the Exchange server, an insecure deserialization issue in the Unified Messaging service, and post-authentication arbitrary file write vulnerabilities that can be combined to run code as SYSTEM on vulnerable servers[3][9][10][12][15]. Public guidance from national cyber agencies notes that CVE-2021-26855 carries a CVSS v3 score of 9.1 and affects Exchange Server 2010, 2013, 2016, and 2019, underscoring the critical nature of the exposure for organizations still running on-premises email infrastructure[10][13][15].

Microsoft and government agencies released security updates for the affected Exchange versions on March 2, 2021, advising administrators to patch immediately and check for signs of compromise, including suspicious web shells and anomalous server-side activity[3][10][13][15]. Subsequent reports from security vendors and incident responders linked the HAFNIUM campaign to widespread exploitation in the wild, with threat hunters publishing detection analytics and indicators of compromise to help defenders identify post-exploitation behavior on Exchange servers[3][9][10][13][15].

For organizations that still maintain on-premises Microsoft Exchange infrastructure, the renewed focus on Zhang Yu is a reminder to verify that all 2021 Exchange security updates and later cumulative patches have been applied and to review historical logs for activity associated with the HAFNIUM exploitation patterns[3][9][10][13][15]. Security teams are encouraged to combine vendor-provided detection guidance with analytics from threat research platforms to hunt for SSRF abuse, UM service deserialization anomalies, and unexpected file writes on Exchange servers, while also monitoring U.S. government advisories for any new technical details that may emerge as the investigation into Zhang and his alleged co-conspirators continues[3][9][11][13][14].

References

  1. Zhang Yu (SSSB)
  2. US Seeks Alleged Chinese Hafnium Hacker With $10 Million …
  3. HAFNIUM targeting Exchange Servers with 0-day exploits
  4. U.S. Offers $10 Million for Chinese Hacker Accused of …
  5. US Offers $10 Million Reward for Chinese Hacker Accused of State-Backed Cyberattacks
  6. U.S. Offers Up to $10 Million for Tips on Zhang Yu, …
  7. Malicious Cyber Activities
  8. Analytics Story: HAFNIUM Group
  9. CVEs – Vulnerable Exchange Server
  10. U.S. Offers $10 Million Reward for Alleged HAFNIUM …
  11. Threat description search results – Microsoft Security Intelligence
  12. Multiple Vulnerabilities in Microsoft Exchange Server Could …
  13. Justice Department Announces Arrest of Prolific Chinese …
  14. Microsoft Exchange server

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply