Storm-0558

Actor Type Nation State
Attributed to Nation China
Affiliated Intrusion Sets APT31 , Violet Typhoon

Storm-0558 is an intrusion set tracked by researchers at Microsoft and attributed as a China based threat actor. In May 2023, the group was able to forge Microsoft authentication tokens which it used to access user email from multiple customer organizations, including government agencies.

Microsoft have identified limited overlap with other groups (including APT31 / Violet Typhoon) and have observed the group previously targeting US and European government bodies and individuals connected to Taiwan and Uyghur geopolitical interests.

According to a report by the US Cyber Safety Review Board, the group has been active since approximately the year 2000. Google's Threat Analysis Group have also linked an entity tied to Storm-0558 to the 2009 compromise of Google known as 'Operation Aurora' as well as the 2011 RSA SecurID breach.

Cyber Threat Graph Context

Explore how this Intrusion Set relates to the wider threat graph

Storm-0558 Threat Reports

Report

Review of the Summer 2023 Microsoft Exchange Online Intrusion

This report by the US Cyber Safety Review Board presents the findings of an investigation into compromise of Microsoft Exchange Online mailboxes ...

References