Storm-0558 — APT Profile

A stolen Microsoft account consumer signing key let Storm-0558 forge Azure AD enterprise and MSA consumer authentication tokens and read Exchange Online mail at approximately 25 organizations in 2023. Microsoft dated the activity to May 15, 2023 and opened its investigation on June 16, when a customer reported anomalous Exchange Online data access; the mailboxes reached included those of Commerce Secretary Gina Raimondo and US Ambassador to China R. Nicholas Burns. A consumer key worked against enterprise mail because developers had assumed the authentication libraries performed issuer and scope validation and never added it. Microsoft's September 2023 root cause blog attributed the theft to a 2021 crash dump, then appended a note on March 12, 2024 saying it had not found a crash dump containing the impacted key material, leaving the acquisition path undetermined. The DHS Cyber Safety Review Board's March 2024 review concluded the intrusion was preventable and that Microsoft's security culture was inadequate. Microsoft has since retired the temporary Storm designation for this cluster and tracks it as Antique Typhoon, a China-based espionage actor interested in token theft and replay against Microsoft accounts since at least August 2021.

Also tracked as

Antique Typhoon

Tools & malware

Vendor research

Read the full analysis on IntelFusions