The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server intrusion campaign attributed to the hacking group HAFNIUM.

The reward offer was reported this week by The Hacker News, which was in turn reporting on a State Department notice originally covered by NTD. The notice sets out the terms of the bounty: payment is contingent on information that helps authorities locate or identify the suspect.

The charges behind the bounty

Zhang Yu is among the individuals charged by U.S. authorities over the HAFNIUM operation, a wave of attacks that came to light in March 2021 when Microsoft disclosed a set of Exchange Server vulnerabilities — collectively known in the security community as ProxyLogon — that were being actively exploited to compromise on-premises mail servers worldwide.

The attacks gave intruders persistent access to affected organisations' email systems and contact lists, and in some cases the ability to plant web shells that survived long after the initial compromise. Microsoft attributed the operations to a state-sponsored group it tracked as HAFNIUM, described at the time as operating from China. U.S. authorities subsequently moved to charge individuals they alleged were linked to the attacks.

The practical difficulty, however, is enforcement. Suspects located in jurisdictions without extradition arrangements with the United States are, in practice, unlikely to ever face a U.S. courtroom. That is precisely what makes a public reward notice a meaningful instrument rather than a formality: it shifts the objective from prosecution to identification, banking on travel, third-country exposure, or insider cooperation to produce a lead that an indictment alone cannot secure. It is the same logic that has underpinned previous State Department reward offers in cyber cases — the target is mobility, not extradition.

Why the 2021 campaign still matters

Five and a half years on, the HAFNIUM case retains relevance for defenders well beyond the geopolitics, for one stubborn reason: the vulnerable estate was never fully retired.

The attacks exploited on-premises Exchange Server — software that runs inside an organisation's own data centre or private cloud, not Microsoft's hosted service. Organisations that migrated fully to cloud-hosted mail have largely removed themselves from the risk. Those still running legacy on-premises installations, whether by regulatory requirement, integration dependency, or simple inertia, remain exposed to the same class of vulnerability whenever a new Exchange flaw is disclosed. The subsequent ProxyShell exploitation wave in 2021 demonstrated that these systems attract multiple, overlapping threat groups, not just one campaign.

Any organisation still operating on-premises Exchange should treat the HAFNIUM reward notice as a reminder to verify a small but non-negotiable baseline: that all January 2021 Emergency Patch (ProxyLogon) fixes and later cumulative updates are applied; that the February 2021 indicators of compromise published by Microsoft and CISA have been swept for; that web shells and unexplained IIS worker processes are actively hunted for rather than assumed absent; and that internet-facing Exchange administrative interfaces are behind VPN or equivalent access controls.

The wider signal

Reward notices in cyber cases remain a relatively rare instrument, which is why they attract attention when deployed. For the security community, the more durable lesson from HAFNIUM is less about the bounty than about the initial failure mode: a widely deployed piece of on-premises infrastructure, with administrative panels exposed to the internet, running unpatched software. That pattern — not any single hacking group — is what continues to generate incidents.

The State Department's notice does not indicate any change to the underlying U.S. charges against Zhang Yu. It is, at this stage, an open call for leads.

Source: The Hacker News, reporting on a State Department notice originally covered by NTD.


美國國務院正懸賞最多1,000萬美元,徵集能協助確認張宇身份或下落的線索。張宇為中國公民,已就2021年被歸咎於黑客組織HAFNIUM的Microsoft Exchange Server入侵行動,在美國遭正式起訴。

該懸賞公告於本星期由 The Hacker News 報道,而其消息則源自國務院公告,最初由 NTD 作出報導。公告列明了賞金條款:必須是有助當局定位或確認嫌疑人身份的資料,方可獲得付款。

懸賞背後的控罪

張宇是美國當局就HAFNIUM行動作出起訴的對象之一。該行動是一場大規模攻擊浪潮,於2021年3月Microsoft披露一組Exchange Server漏洞後曝光,這些漏洞在安全界統稱為 ProxyLogon,當時正遭積極利用,以入侵全球各地機構自設數據中心(on-premises)運作的郵件伺服器。

攻擊令入侵者得以長期存取受影響機構的電郵系統及通訊錄,在部分情況下更可在系統植入即使在最初入侵後仍長久存活的 web shell。Microsoft將相關行動歸咎於一個由它追蹤並名為 HAFNIUM 的國家支持組織,當時指其在中國境內運作。美國其後採取法律行動,起訴據稱與這些攻擊有關的個人。

然而,實務上的難處在於執法。被控者若身處與美國沒有引渡安排的司法管轄區,實際上幾乎不可能在美國法庭受審。正因如此,公開懸賞公告才不只是形式,而是實質有效的工具:它將目標從起訴轉移至身份確認,寄望透過旅行、第三國曝光或內部人士合作,取得單靠起訴書無法取得的線索。這與美國國務院過去在網絡安全案件中採用懸賞措施的邏輯如出一轍——目標是涉案者的流動性,而非引渡。

2021年行動至今仍然重要

事隔五年半,HAFNIUM事件對防禦者的相關性遠超地緣政治層面,原因只有一個:脆弱的系統資產從未被完全取代。

是次攻擊利用的是自設環境(on-premises)的 Exchange Server——即在機構自己的數據中心或私有雲內運作的軟件,而非Microsoft的託管服務。已全面遷移至雲端託管電郵的機構,基本上已脫離此風險。那些因法規要求、系統整合依賴或單純惰性而繼續運行舊有自設安裝的機構,每逢有新的 Exchange 漏洞被披露,便會再度暴露於同類漏洞風險之下。2021年隨後出現的 ProxyShell 利用浪潮,已證明這些系統吸引的不只是單一攻擊行動,而是多個互相重疊的威脅組織。

任何仍在運行自設 Exchange 的機構,都應將 HAFNIUM 懸賞公告視為一個提醒,去核實一套雖小但不可妥協的基準:確認已套用2021年1月緊急修補程式(ProxyLogon)及其後所有累積更新;已就Microsoft及 CISA 於2021年2月公布的入侵指標(indicators of compromise)進行排查;web shell 及無合理解釋的 IIS worker process 應主動搜查,而非假設並不存在;以及對外連接的 Exchange 管理介面應設於 VPN 或同等存取控制之後。

更廣泛的訊號

網絡安全案件的懸賞公告至今仍屬相對罕見的工具,因此一經採用便會引起注意。對安全社群而言,HAFNIUM帶出的更持久教訓,與其說是關於賞金,不如說是關於最初的失敗模式:一套部署廣泛的自設基礎設施,管理介面直接暴露於互聯網,並運行未經修補的軟件。持續造成事故的是這個模式,而不是任何個別黑客組織。

美國國務院的公告並無顯示美國對張宇的原有控罪有任何改變。在現階段,這只是一次公開的線索徵集。

資料來源:The Hacker News,報道美國國務院公告,該公告最初由 NTD 報道。

新聞來源 / Original News Source