Five Years, 88,000 Backdoors, and a Pair of Handcuffs: Inside the Global Manhunt That Ended in an Arrest
Cybersecurity Classified by Officially
In 2021, a "limited and targeted" Microsoft Exchange attack turned out to be anything but. Huntress and a group of security vendors traced it to 88,000 compromised servers worldwide, tied to the Chinese state-sponsored group now known as Silk Typhoon.
Notifying tens of thousands of victims one phone call at a time didn't work. The FBI eventually used a Rule 41 search-and-seizure warrant, one of the first of its kind, to remotely remove the malicious web shells at scale.
In 2025, alleged HAFNIUM aka Silk Typhoon, co-conspirator Xu Zewei was arrested in Milan and extradited to Houston, Texas, to face charges.
The FBI isn't just chasing individual hackers anymore. Operation Riptide is going after the infrastructure that criminal ecosystems depend on: phishing platforms, residential proxy networks, and bulletproof hosting providers.
That's the story we dug into on Episode 3 of _declassified, where John Hammond, Principal Security Researcher, sat down with Huntress CEO Kyle Hanslovan and Brett Leatherman, Assistant Director of the FBI Cyber Division. The conversation covered a five-year manhunt, a global public-private partnership, and what it actually takes to put a state-sponsored hacker in handcuffs.
A "limited" attack that turned into 88,000 backdoors
Back in 2021, security researchers noticed something odd: a small, targeted wave of exploitation against on-premises Microsoft Exchange servers. Huntress documented what it was seeing in real time as the incident unfolded. The assumption was that this was a narrow, surgical operation, but it turned out to be something much larger.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.huntress.com/blog/declassified-cybercrime-episode-three
Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Huntress — imported from official source
- Official source
- https://www.huntress.com/blog/rss.xml RSS
- Imported
- September 20, 2026 19:55
- Versions
- 1 recorded
- Identity
https://www.huntress.com/blog/declassified-cybercrime-episode-three