Five Years, 88,000 Backdoors, and a Pair of Handcuffs: Inside the Global Manhunt That Ended in an Arrest

Key Takeaways

  • In 2021, a "limited and targeted" Microsoft Exchange attack turned out to be anything but. Huntress and a group of security vendors traced it to 88,000 compromised servers worldwide, tied to the Chinese state-sponsored group now known as Silk Typhoon.

  • Notifying tens of thousands of victims one phone call at a time didn't work. The FBI eventually used a Rule 41 search-and-seizure warrant, one of the first of its kind, to remotely remove the malicious web shells at scale.

  • In 2025, alleged HAFNIUM aka Silk Typhoon, co-conspirator Xu Zewei was arrested in Milan and extradited to Houston, Texas, to face charges.

  • The FBI isn't just chasing individual hackers anymore. Operation Riptide is going after the infrastructure that criminal ecosystems depend on: phishing platforms, residential proxy networks, and bulletproof hosting providers.

That's the story we dug into on Episode 3 of _declassified, where John Hammond, Principal Security Researcher, sat down with Huntress CEO Kyle Hanslovan and Brett Leatherman, Assistant Director of the FBI Cyber Division. The conversation covered a five-year manhunt, a global public-private partnership, and what it actually takes to put a state-sponsored hacker in handcuffs.

A "limited" attack that turned into 88,000 backdoors

Back in 2021, security researchers noticed something odd: a small, targeted wave of exploitation against on-premises Microsoft Exchange servers. Huntress documented what it was seeing in real time as the incident unfolded. The assumption was that this was a narrow, surgical operation, but it turned out to be something much larger. 

The threat actor, later attributed to the Chinese state-sponsored group HAFNIUM aka Silk Typhoon, made mistakes that exposed pieces of its own infrastructure. By working with a cloud hosting provider's privacy and legal teams, alongside law enforcement authorization, Huntress gained cloned access to the adversary's actual infrastructure, which is how the security community could confidently say that the incident had grown well past "limited and targeted." Our security researchers watched it happen in real time, tracking real-time logs across more than 80,000 victims.

The victim list read like a cross-section of everyday infrastructure: water utilities, county governments, title and mortgage companies, MSSPs, and police departments around the world. Huntress and a handful of other security researchers, including teams from CrowdStrike, split up the list and started calling organizations directly to warn them.

When phone calls and voicemails stop being enough

Manual victim notification is slow, and slow doesn't scale to 88,000 backdoors. After five weeks of cold-calling organizations that had never heard of Huntress and getting hung up on more than once, it was clear that private industry had hit a ceiling.

That's where a Unified Coordination Group, convened through the National Security Council, stepped in. The Department of Justice authorized one of the first uses of a Rule 41 search-and-seizure warrant of this kind, letting the FBI Houston Division remotely remove the malicious web shells from vulnerable servers at scale, with no individual outreach required. The FBI's approach is to move from least intrusive to most intrusive, but once it became clear that targeting was accelerating faster than victims could be reached, waiting stopped being an option.

Removing the web shells didn't just protect the original victims. It cut off access for copycat actors who had started scanning for and exploiting the same exposed servers once the vulnerability became public knowledge.

From HAFNIUM to handcuffs

Xu Zewei, one of the alleged co-conspirators behind the HAFNIUM attacks and also linked to targeting COVID-19 vaccine research on behalf of the Chinese Communist Party, was arrested in Milan in early July 2025 on a provisional warrant, coordinated between the FBI and Italy's Polizia Postale. He's since been extradited to Houston to face charges.

These cases can take years to close, and that timeline is exactly the point. According to Leatherman:

"It doesn't matter how long. If you are a cyber hacker, you should expect that you may have a warrant for your arrest. The FBI has a long memory."

The FBI has completed at least a dozen extraditions of cyber actors in just the first half of 2026 alone, working through 22 cyber-assistant legal attaches stationed in embassies worldwide.

Beyond one arrest: Going after the whole ecosystem

Individual arrests get headlines, but the FBI Cyber Division is increasingly focused on dismantling the infrastructure that entire criminal ecosystems rely on. Operation Riptide, an accelerated 60-day FBI campaign launched in June under Executive Order 14390 and the White House Cyber Strategy for America, is built around that idea. A few examples from this year:

  • Outsider, a Chinese phishing-as-a-service platform running since 2023, tied to over 8,000 phishing domains, an estimated 3.87 million stolen credit cards, and roughly $1.9 billion in global losses. The FBI worked with Google and LumenTechnologies to take down its domains.

  • NetNut, a residential proxy platform that let foreign actors route traffic through US residential IP space to disguise fraud and targeting was dismantled by the FBI, Lumen Technologies, and Google's Threat Intelligence Group.

  • MediaLand, a Russian bulletproof hosting provider tied to more than $62 million in losses and used by numerous ransomware operations was called out publicly when a 2024 indictment was unsealed in the Northern District of Ohio. 

The scale of this work shows up in the numbers. In 2025, the FBI's cyber teams made 197 arrests, secured 158 convictions, and unsealed 345 indictments, on top of 261 disruptions and 26 extraditions. Through mid-June of 2026 alone, there have been 87 arrests, 137 indictments, 145 disruptions, and 11 dismantlements. Every one of those numbers has real victims behind it, and every one is a case where the ecosystem got smaller.

AI is compressing the timeline on both sides

A lot of security teams are quietly wrestling with the same question right now: is AI about to make this an unwinnable fight? The FBI doesn't see it that way. Intrusions still trace back to human or systemic failures, whether AI is involved or not. What's changed is speed. AI lets attackers identify and enumerate vulnerabilities far faster than before, and that compressed timeline is already showing up in exploitation trends.

Edge devices have been targeted at scale over the past year and a half, and that's expected to accelerate further over the next year or two as attackers lean on AI to find weak points before defenders can patch them. The fix is pointing AI at the areas with the highest blast radius first: privileged end users and exposed edge devices, then working outward from there.

What this means for you

Whether they signed up for it or not, everyone with an internet-connected device, including small businesses and home users, is already part of this fight. Attackers want trusted, everyday IP space to pivot from, and a home router in Ohio can be just as valuable to them as enterprise infrastructure.

The stakes go beyond any single breach. The FBI's Operation Winter Shield outlines the top 10 ways attackers actually get into environments today. Picking the top three that apply to your environment and focusing there first is a realistic place to start. And if you're already compromised or targeted, contacting your local FBI field office early can make a real difference. The sooner they're looped in, the more likely they can help recover stolen data or, in some cases, provide a decryptor before a ransom ever gets paid.

Want the full story, including the screenshots from inside the adversary's own infrastructure and the Q&A with the live audience? Catch the full replay of Know Your Adversary: Counter Operations that Wreck Global Cybercrime.