Storm-0558 — APT Profile
Storm-0558 compromised Microsoft cloud email infrastructure in 2023, accessing accounts of 25+ organizations including US State and Commerce Departments. Used stolen Microsoft signing key to forge Azure AD tokens. Led to Congressional hearings and CSRB report.Also tracked as
Antique Typhoon
Tools & malware
- China Chopper Webshell
- Cigril Malware
- SoftEther Proxy software
- Token Forge Tooling Credential Access
Vendor research
- Microsoft mitigates China-based threat actor Storm-0558 targeting of customer email Microsoft
- Compromised Microsoft Key: More Impactful Than We Thought Wiz
- Analysis of Storm-0558 Techniques for Unauthorized Email Access Microsoft
- Results of Major Technical Investigations for Storm-0558 Key Acquisition Microsoft MSRC
- Storm-0558 Update: Takeaways from Microsoft Recent Report Wiz
- Cyber Safety Review Board: Review of the Summer 2023 Microsoft Exchange Incident CSRB / DHS