惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

美团技术团队
Microsoft Azure Blog
Microsoft Azure Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
B
Blog
Y
Y Combinator Blog
博客园_首页
有赞技术团队
有赞技术团队
博客园 - Franky
腾讯CDC
G
Google Developers Blog
Recent Announcements
Recent Announcements
博客园 - 【当耐特】
D
Docker
The GitHub Blog
The GitHub Blog
MyScale Blog
MyScale Blog
H
Help Net Security
Apple Machine Learning Research
Apple Machine Learning Research
A
About on SuperTechFans
D
DataBreaches.Net
T
The Blog of Author Tim Ferriss
V
V2EX
U
Unit 42
aimingoo的专栏
aimingoo的专栏
WordPress大学
WordPress大学

The Register - Security

India's cyber agency sets clock at 12 hours to tackle exploited bugs as AI turns up the heat Are we human? MyPillow must decide whether to be firm or soft as ransomware crims demand pay Experts pour cold borscht on Farage's Russian hack claim AI eyes scanning for bugs create a worrisome Linux security trend A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Techie claims Trump Mobile website was leaking thousands of people's data Dems slam Trump for making cybersecurity hold out the tin cup while splurging on ballroom and Jan. 6 'slush fund' Attackers spill plaintext passwords of 46k Myspace93 users after 2021 breach Microsoft open-sources agentic AI safety tools Are we human? America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames America's top cyber-defense agency left a GitHub repo open with passwords, keys, tokens – and incredibly obvious filenames Shai-Hulud copycat worm infects yet another npm package MPs want social media treated more like unsafe toys than harmless apps Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data To gain root access, intruder just had to ask AWS patched Quick auth bypass, says customers weren't using control Disgruntled researcher releases two more Microsoft zero-days Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files US bank reports itself after slinging customer data at 'unauthorized AI app' Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator Best Western Hotels confirms web app data breach Arctic Wolf cuts 250 jobs in AI push 1 in 8 workers say selling company logins is justifiable Iran cyberspies LARPing as ransomware crims in espionage ops UK age-gating plans risk breaking the internet, privacy groups warn India orders infosec red alert in case Mythos sparks crime 'CopyFail' attackers start cashing in on Linux flaw
FBI: China's hacker-for-hire ecosystem 'out of control'
2026-05-01 · via The Register - Security

REG AD

Security

One alleged cyber contractor was extradited to the US over the weekend

China's "hacker-for-hire ecosystem has gotten out of control," according to Brett Leatherman, assistant director of the FBI's cyber division.

This ecosystem includes private technology companies operating at the behest of the PRC's intelligence agencies while allowing Beijing to maintain plausible deniability. 

"Motivated by profit, this network of private companies and contractors in China cast a wide net to identify vulnerable computers, exploit those computers, and then identify information that it could sell directly or indirectly to the PRC government," Leatherman told reporters on Thursday.

REG AD

Or, if the Chinese government won't buy it, the hackers-for-hire "turn from cyber mercenaries into cyber dealers," selling access to the compromised systems and stolen data to third parties on the dark web.

REG AD

"This leads to a less secure environment that is ripe for further lawlessness," Leatherman said. 

Xu Zewei's extradition and the criminal charges against him, however, should send a message to China's contractor ecosystem, he added: "The protection you assume from operating inside China does not extend the moment you cross a border."

Xu, a Chinese national, was extradited from Italy to the United States over the weekend and charged with nine hacking-related crimes. Italian cops arrested Xu last July.

According to American prosecutors, China's Ministry of State Security (MSS) and Shanghai State Security Bureau allegedly directed Xu to hack thousands of computers and steal sensitive information in a way that hid the Chinese government's involvement.

This happened between February 2020 and June 2021, and some of the digital intrusions were part of the 2021 campaign in which Hafnium (now better known as Silk Typhoon) exploited zero-day bugs in Microsoft Exchange and compromised hundreds of thousands of servers worldwide, including 12,700 organizations in the US alone.

Other intrusions targeted American universities and researchers working on COVID-19 vaccines, treatments, and testing during the height of the pandemic, prosecutors allege. 

The indictment claims that at the time, Xu worked as a general manager at a company named Shanghai Powerock Network, which the feds previously linked to Hafnium/Silk Typhoon.

"Among other things, Xu worked on taskings from the SSSB, supervised hacking activity of other Powerock personnel in support of such taskings, coordinated hacking activities with fellow hacker Zhang Yu, and reported the results of the hacking activities to the SSSB," according to the indictment [PDF].

REG AD

The indictment also charges Zhang, a director at Shanghai Firetech Information Science and Technology Company who allegedly operated at the direction of the SSSB, along with two unnamed SSSB officers who directed the hacking operations.

Court records show Xu is charged with conspiracy to cause damage to and obtain information by unauthorized access to protected computers, to commit wire fraud, and to commit aggravated identity theft, which carries a maximum penalty of five years in prison; conspiracy to commit wire fraud and two counts of wire fraud, each carrying a maximum penalty of 20 years; two counts of obtaining information by unauthorized access to protected computers, each carrying a maximum penalty of five years; two counts of intentional damage to a protected computer, each carrying a maximum penalty of 10 years; and one count of aggravated identity theft, which carries a mandatory consecutive two-year sentence.

Zhang remains at large, according to the DoJ. ®