Storm-0558 — APT Profile
A stolen Microsoft account consumer signing key let Storm-0558 forge Azure AD enterprise and MSA consumer authentication tokens and read Exchange Online mail at approximately 25 organizations in 2023. Microsoft dated the activity to May 15, 2023 and opened its investigation on June 16, when a customer reported anomalous Exchange Online data access; the mailboxes reached included those of Commerce Secretary Gina Raimondo and US Ambassador to China R. Nicholas Burns. A consumer key worked against enterprise mail because developers had assumed the authentication libraries performed issuer and scope validation and never added it. Microsoft's September 2023 root cause blog attributed the theft to a 2021 crash dump, then appended a note on March 12, 2024 saying it had not found a crash dump containing the impacted key material, leaving the acquisition path undetermined. The DHS Cyber Safety Review Board's March 2024 review concluded the intrusion was preventable and that Microsoft's security culture was inadequate. Microsoft has since retired the temporary Storm designation for this cluster and tracks it as Antique Typhoon, a China-based espionage actor interested in token theft and replay against Microsoft accounts since at least August 2021.Also tracked as
Antique Typhoon
Tools & malware
- China Chopper Webshell
- Cigril Malware
- SoftEther Proxy software
- Token Forge Tooling Credential Access
Vendor research
- Microsoft mitigates China-based threat actor Storm-0558 targeting of customer email Microsoft
- Compromised Microsoft Key: More Impactful Than We Thought Wiz
- Analysis of Storm-0558 Techniques for Unauthorized Email Access Microsoft
- Results of Major Technical Investigations for Storm-0558 Key Acquisition Microsoft MSRC
- Storm-0558 Update: Takeaways from Microsoft Recent Report Wiz
- Cyber Safety Review Board: Review of the Summer 2023 Microsoft Exchange Incident CSRB / DHS