Back to Intelligence

$10M Reward for HAFNIUM Operator Zhang Yu: Defending Microsoft Exchange Against Silk Typhoon Tradecraft — Detection and Hardening Guide

SA
Security Arsenal Team
October 8, 2026
9 min read

The U.S. State Department's Rewards for Justice program is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server mass-exploitation campaign tracked as HAFNIUM — the activity Microsoft now attributes to the state-backed actor it calls Silk Typhoon. The reward notice, first reported by NTD, is a reminder that this campaign was not a historical footnote: it was one of the most consequential zero-day mass-compromise events in enterprise history, and the Department of Justice is still actively pursuing the operators behind it.

Why should defenders care about a five-year-old campaign in 2026? Three reasons. First, the actor is still active — Silk Typhoon has continued to target edge devices, IT supply chains, and cloud tenants in the years since. Second, the remediation debt from 2021 never fully closed: incident responders still encounter Exchange servers that were patched but never properly swept for webshells and persistence, meaning dormant access from that era surfaces in IR engagements to this day. Third, the tradecraft HAFNIUM industrialized — ProxyLogon-style SSRF-to-webshell chains against internet-facing Microsoft infrastructure — is now standard playbook for multiple Chinese state-nexus actors. If you can detect HAFNIUM's behaviors, you can detect a whole class of threats.

Technical Analysis

The threat actor and the charges

Zhang Yu is charged in the United States for his role in the HAFNIUM intrusions. The Rewards for Justice notice offers payment for information on his identification or location — a standard U.S. government pressure mechanism against indicted foreign state hackers who remain beyond extradition reach. For defenders, the operational significance is attribution confirmation: the U.S. government has formally tied named individuals to a campaign that compromised an estimated tens of thousands of Exchange servers worldwide in early 2021.

Historical attack chain (context, not the headline)

The original campaign chained four Exchange Server vulnerabilities — commonly referenced as CVE-2021-26855 (a server-side request forgery in the Exchange frontend, CVSS 9.8), CVE-2021-26857 (insecure deserialization in the Unified Messaging service), CVE-2021-26858 and CVE-2021-27065 (post-authentication arbitrary file writes) — to achieve unauthenticated remote code execution and drop China Chopper-style webshells into web-accessible directories. We cite these strictly as historical context: the present-day defensive value is not the patch (which shipped in March 2021) but the residual compromise and the reusable TTPs.

Why this is still a live threat in 2026

  • Patching is not remediation. Applying the security update closed the vulnerability but did nothing to remove webshells, scheduled tasks, rogue admin accounts, or exfiltrated credentials. Any server that was internet-facing and unpatched between late February and mid-March 2021 should be treated as presumptively compromised until forensically cleared.
  • End-of-life Exchange is everywhere. Exchange 2010 long ago left support, and Exchange 2016/2019 environments that lag cumulative updates remain exposed to a steady stream of post-2021 Exchange CVEs exploited by the same actor clusters. An unpatched, internet-facing Exchange server in 2026 is not a hypothetical risk — it is a target on a scan list.
  • The TTPs generalized. Webshell deployment to C:\inetpub\wwwroot\aspnet_client\, w3wp.exe spawning cmd.exe, LSASS dumping for credential theft, and .aspx files with single-character or obfuscated filenames are now observed across multiple PRC-nexus campaigns against Exchange, SharePoint, and other edge applications.

Exploitation status

The original ProxyLogon vulnerabilities saw confirmed, massive in-the-wild exploitation before patches were available and are permanently listed in CISA's Known Exploited Vulnerabilities catalog. There is no new CVE associated with this news item — the story is the reward offer and the enduring threat actor. The defensive posture below is aimed at detecting residual HAFNIUM-era compromise and the continued reuse of this tradecraft.

Detection & Response

The highest-fidelity detections for this tradecraft are behavioral, not signature-based. Webshell filenames and content mutate; the IIS worker process spawning a shell does not.

YAML
---
title: IIS Worker Process Spawning Command Shell or PowerShell
id: 8f2c1a4b-3e5d-4f6a-9b7c-2d1e0a9f8c7b
status: experimental
description: Detects the Exchange IIS worker process (w3wp.exe) spawning cmd.exe, powershell.exe, or other script interpreters — a hallmark of China Chopper-style webshell execution observed in HAFNIUM/Silk Typhoon intrusions.
references:
  - https://attack.mitre.org/techniques/T1505/003/
  - https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/01/15
tags:
  - attack.persistence
  - attack.t1505.003
  - attack.execution
  - attack.t1059
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith: '\w3wp.exe'
  selection_child:
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\cscript.exe'
      - '\wscript.exe'
      - '\rundll32.exe'
      - '\regsvr32.exe'
      - '\net.exe'
      - '\net1.exe'
      - '\whoami.exe'
  filter_owa_layouts:
    CommandLine|contains:
      - 'OABGen'
  condition: selection_parent and selection_child and not filter_owa_layouts
falsepositives:
  - Rare legitimate Exchange administrative tooling; validate against change windows
level: critical
---
title: Webshell Dropped to IIS or Exchange Web Directory
id: 4b7d9e2f-1a3c-4d5e-8f6b-0c9d2e1a3b4c
status: experimental
description: Detects creation of ASPX script files in Exchange/IIS web-accessible directories by non-standard processes — consistent with HAFNIUM arbitrary-file-write webshell deployment to aspnet_client and Exchange virtual directories.
references:
  - https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/01/15
tags:
  - attack.persistence
  - attack.t1505.003
logsource:
  category: file_event
  product: windows
detection:
  selection_path:
    TargetFilename|contains:
      - '\inetpub\wwwroot\aspnet_client\'
      - '\FrontEnd\HttpProxy\'
      - '\ClientAccess\'
      - '\wwwroot\'
  selection_ext:
    TargetFilename|endswith:
      - '.aspx'
      - '.asp'
      - '.ashx'
      - '.asmx'
  filter_installers:
    Image|endswith:
      - '\setup.exe'
      - '\msiexec.exe'
      - '\TiWorker.exe'
      - '\wuauclt.exe'
  condition: selection_path and selection_ext and not filter_installers
falsepositives:
  - Legitimate Exchange cumulative update installation; correlate with patch windows
level: high
---
title: LSASS Memory Dump via comsvcs.dll MiniDump
id: 6c1e8a3d-9b2f-4e7d-a5c6-3f8b0d2e4a6c
status: experimental
description: Detects credential dumping of LSASS memory using the built-in comsvcs.dll MiniDump export — a technique used by HAFNIUM/Silk Typhoon operators for post-compromise credential theft without dropping procdump.
references:
  - https://attack.mitre.org/techniques/T1003/001/
author: Security Arsenal
date: 2026/01/15
tags:
  - attack.credential_access
  - attack.t1003.001
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|endswith: '\rundll32.exe'
    CommandLine|contains:
      - 'comsvcs.dll'
      - 'MiniDump'
  condition: selection
falsepositives:
  - Very rare; some EDR/forensics tooling uses this technique — allowlist by signer and parent
level: critical
KQL — Microsoft Sentinel / Defender
// Hunt: IIS worker process spawning shells or recon binaries (Exchange webshell behavior)
// Tables: Microsoft Defender for Endpoint process telemetry
let shell_binaries = dynamic(["cmd.exe", "powershell.exe", "pwsh.exe", "whoami.exe", "net.exe", "net1.exe", "ipconfig.exe", "nltest.exe", "quser.exe", "rundll32.exe"]);
DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where InitiatingProcessFileName =~ "w3wp.exe"
| where FileName in~ (shell_binaries)
| extend InitiatingCmd = InitiatingProcessCommandLine
| project TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingCmd, AccountName, SHA256
| order by TimeGenerated desc
;
// Companion hunt: .aspx/.ashx file creation under IIS or Exchange web roots
DeviceFileEvents
| where TimeGenerated > ago(30d)
| where FolderPath has_any ("\\inetpub\\wwwroot\\", "\\aspnet_client\\", "\\FrontEnd\\HttpProxy\\", "\\ClientAccess\\")
| where FileName endswith ".aspx" or FileName endswith ".ashx" or FileName endswith ".asmx"
| where InitiatingProcessFileName !in~ ("TiWorker.exe", "msiexec.exe", "setup.exe", "w3wp.exe", "svchost.exe")
| project TimeGenerated, DeviceName, FileName, FolderPath, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256
| order by TimeGenerated desc
VQL — Velociraptor
-- Velociraptor hunt: enumerate recently created/modified script files in Exchange/IIS web roots
-- Deploy as a multi-client hunt across all Exchange servers. Review hits for small file size,
-- single-line content, or timestamps correlating with exposure windows.
LET webroots = glob(globs=['C:/inetpub/wwwroot/**/*.aspx',
  'C:/inetpub/wwwroot/aspnet_client/**/*.aspx',
  'C:/inetpub/wwwroot/**/*.ashx',
  'C:/Program Files/Microsoft/Exchange Server/V15/FrontEnd/HttpProxy/**/*.aspx'])
SELECT FullPath, Size, Mtime, Btime,
  read_file(filename=FullPath, length=300) AS FileHeader
FROM foreach(row=webroots)
WHERE Mtime > now() - 86400 * 90
  OR Size < 4096
ORDER BY Mtime DESC
PowerShell
# Exchange hygiene & residual-compromise verification script (run elevated on each Exchange server)
# 1) Report installed Exchange version and CU build — compare against the Microsoft
#    Exchange Server build number reference to confirm you are on a supported CU + latest SU
$exSetup = Get-Command ExSetup.exe -ErrorAction SilentlyContinue
if (Test-Path "$env:ExchangeInstallPath\bin\Microsoft.Exchange.Clients.Owa2.Server.dll") {
    $ver = (Get-Item "$env:ExchangeInstallPath\bin\Microsoft.Exchange.Clients.Owa2.Server.dll").VersionInfo
    Write-Output "Exchange build: $($ver.ProductVersion)"
}

# 2) Sweep IIS web roots for suspicious script files: recently modified or unusually small .aspx/.ashx
$roots = @("C:\inetpub\wwwroot", "$env:ExchangeInstallPath\FrontEnd\HttpProxy")
foreach ($root in $roots) {
    if (Test-Path $root) {
        Get-ChildItem -Path $root -Recurse -Include *.aspx,*.ashx,*.asmx,*.asp -ErrorAction SilentlyContinue |
            Where-Object { $_.Length -lt 4096 -or $_.LastWriteTime -gt (Get-Date).AddDays(-180) } |
            Select-Object FullName, Length, LastWriteTime, CreationTime |
            Format-Table -AutoSize
    }
}

# 3) Enumerate local admins and Exchange privileged groups for unauthorized accounts
Get-LocalGroupMember -Group "Administrators" -ErrorAction SilentlyContinue | Select-Object Name, ObjectClass
Get-ADGroupMember -Identity "Organization Admins" -ErrorAction SilentlyContinue | Select-Object Name, SamAccountName

# 4) Check for rogue scheduled tasks running as SYSTEM with script/shell actions
Get-ScheduledTask | Where-Object {
    $_.Principal.UserId -match 'SYSTEM' -and
    ($_.Actions.Execute -match 'powershell|cmd|wscript|cscript|rundll32')
} | Select-Object TaskName, TaskPath, @{n='Action';e={$_.Actions.Execute}}, @{n='Args';e={$_.Actions.Arguments}}

# 5) Verify Hybrid/OWA auth: list any unexpected virtual directory auth or external URLs changed from baseline
Get-OwaVirtualDirectory -Server $env:COMPUTERNAME | Select-Object Server, InternalUrl, ExternalUrl, BasicAuthentication, FormsAuthentication
Get-EcpVirtualDirectory -Server $env:COMPUTERNAME | Select-Object Server, ExternalUrl, AdminEnabled

Remediation

  1. Confirm patch posture against the current servicing baseline, not 2021's. Every supported Exchange 2016/2019 server must be on a supported Cumulative Update with the latest monthly Security Update applied. Validate build numbers against Microsoft's official Exchange Server update history page (https://learn.microsoft.com/en-us/exchange/new-features/build-numbers-and-release-dates). Anything end-of-life must be decommissioned or isolated from the internet immediately.
  2. Treat historically exposed servers as presumptively compromised. If a server was internet-facing and unpatched during the February–March 2021 exploitation window and was never forensically swept, hunt it now using the detections above, review IIS logs (default C:\inetpub\logs\LogFiles) for POSTs to unexpected .aspx paths, and validate every local/domain credential that touched the box — HAFNIUM dumped LSASS and harvested Exchange Offline Address Books at scale.
  3. Reset credentials that were ever on a suspect host. Domain admin, Exchange service, and hybrid-identity sync account passwords must be rotated if the server was exposed. Kerberos krbtgt should be double-reset if domain-level compromise is suspected.
  4. Reduce the attack surface Silk Typhoon hunts. If OWA/ECP does not need to be internet-facing, put it behind VPN or a modern reverse proxy with conditional access. Enable AMSI integration for Exchange, ensure Windows Defender (or equivalent) AV exclusions on Exchange directories follow Microsoft's guidance exactly — overly broad exclusions are a webshell blind spot — and deploy the Emergency Mitigation Service / Exchange Health Checker script on a schedule.
  5. Apply CISA's standing guidance. The ProxyLogon CVEs are permanent CISA KEV entries, and CISA's joint advisories on PRC state-sponsored actors (https://www.cisa.gov/news-events/cybersecurity-advisories) prescribe exactly this posture: patch edge systems within mandated BOD 22-01 timelines, hunt for webshells, and assume credential theft on any compromised host.
  6. If you find a live webshell or unexplained IIS child processes — stop and call IR. Do not simply delete the file. Capture memory, preserve IIS logs and USN journal data, and scope laterally before remediation. A webshell is evidence of a breach, and HAFNIUM-era actors are documented to have exfiltrated mailboxes and pivoted to cloud tenants.

The $10 million reward is a law-enforcement lever, but the enduring lesson is operational: nation-state initial access against Exchange was cheap, fast, and industrialized — and the actors behind it are still working. Verify, don't assume, that your Exchange estate was ever truly cleaned.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.