Storm-0558
Actor Type | Nation State |
---|---|
Attributed to Nation | China |
Affiliated Intrusion Sets | APT31 , Violet Typhoon |
Storm-0558 is an intrusion set tracked by researchers at Microsoft and attributed as a China based threat actor. In May 2023, the group was able to forge Microsoft authentication tokens which it used to access user email from multiple customer organizations, including government agencies.
Microsoft have identified limited overlap with other groups (including APT31 / Violet Typhoon) and have observed the group previously targeting US and European government bodies and individuals connected to Taiwan and Uyghur geopolitical interests.
According to a report by the US Cyber Safety Review Board, the group has been active since approximately the year 2000. Google's Threat Analysis Group have also linked an entity tied to Storm-0558 to the 2009 compromise of Google known as 'Operation Aurora' as well as the 2011 RSA SecurID breach.
Cyber Threat Graph Context
Explore how this Intrusion Set relates to the wider threat graph
Storm-0558 Threat Reports
Review of the Summer 2023 Microsoft Exchange Online Intrusion
This report by the US Cyber Safety Review Board presents the findings of an investigation into compromise of Microsoft Exchange Online mailboxes ...