Home/Threat Actor/Storm-0558
Threat Actor

Storm-0558

storm_0558 · china · active since 2021-08

Storm-0558 is a China-affiliated cyber espionage cluster assessed by Microsoft Threat Intelligence and the US Cyber Safety Review Board (CSRB) with high confidence as a PRC state-affiliated actor.

disclosed by Microsoft in July 2023 following its compromise of approximately 25 organizations' Exchange Online email accounts including the US Department of State (~60,000 State Department emails) and Department of Commerce (Secretary Gina Raimondo's account)

cluster acquired a Microsoft consumer MSA private signing key through a multi-stage compromise of Microsoft's debugging environment (crash dump containing key material due to cryptographic scrubbing race condition, subsequent compromise of a Microsoft engineer's corporate account with debugging-environment access), developed token-forging capability, and exploited an additional Microsoft token- validation flaw to extend consumer-MSA-signed tokens to authenticate against enterprise Azure AD tenants, enabling cross-tenant email collection across approximately 25 victim organizations from a single upstream cloud-identity- infrastructure compromise.

the US CSRB Final Report (April 2024) assessed the intrusion as "preventable" with a "cascade of avoidable errors" in Microsoft's security posture.

targeting profile consistent with PRC foreign-policy and diplomatic-intelligence-collection priorities; operationally distinct from Volt Typhoon, Salt Typhoon, Silk Typhoon, Flax Typhoon, and the APT* China-aligned clusters all curated separately.

china confidence: high 10 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

Storm-0558 (Microsoft canonical designation, July 2023 first-disclosure) is a China-affiliated cyber espionage cluster assessed by Microsoft Threat Intelligence and the US Cyber Safety Review Board (CSRB) with high confidence to be a People's Republic of China state-affiliated actor conducting diplomatic-intelligence-collection espionage operations. The cluster's July 2023 disclosed intrusion against US Department of State Exchange Online email accounts (and approximately 25 total victim organizations including the Department of Commerce, foreign diplomatic missions, and policy-research organizations) stands as one of the most operationally significant cloud-identity-trust compromises in the public record. The cluster's operational tradecraft is signature in two operationally-distinctive ways that set it apart from the broader Chinese-aligned cyber-operations ecosystem: (1) AUTHENTICATION TOKEN FORGING AS PRIMARY OPERATIONAL CAPABILITY.

Rather than relying on credential phishing, vulnerability exploitation of victim infrastructure, or lateral movement from compromised endpoints, Storm-0558's Exchange Online access was achieved entirely through forged authentication tokens, signed by a compromised Microsoft consumer MSA private signing key that the cluster acquired through a multi-stage compromise of Microsoft's debugging environment. The token-forging operational architecture is operationally distinctive: forged tokens authenticate as valid users against Exchange Online and OWA without requiring victim-side compromise, leaving no traces on victim endpoints or in victim authentication logs that would be visible to victim-side detection tools. The signature operational capability operationally distinguishes Storm-0558 from endpoint-compromise-based Chinese espionage clusters and represents a higher-sophistication cloud-identity-attack tradecraft.

(2) CLOUD IDENTITY INFRASTRUCTURE AS PRIMARY TARGET. The cluster's operational focus on the cloud identity infrastructure itself, rather than victim endpoints, networks, or individual user accounts, represents an operationally higher-leverage attack pattern. By compromising the signing key at the cloud service provider level, Storm-0558 acquired authentication-token forging capability that operated above individual victim tenants, allowing the cluster to authenticate against approximately 25 victim organizations from a single compromise of upstream cloud infrastructure.

The supply-chain- attack-style operational model (compromising the trust infrastructure that protects many downstream customers, rather than compromising customers individually) is consistent with sophisticated state-aligned cyber-operations tradecraft. The root cause of the MSA signing key acquisition, as disclosed by Microsoft in September 2023, was a chain of operational and systems-engineering failures: a crash dump from a Microsoft consumer signing system in April 2021 contained MSA private key material due to a cryptographic scrubbing race condition, the crash dump was moved to the debugging environment, Microsoft's credential scanning failed to detect the key in the debugging environment, and Storm-0558 subsequently compromised a Microsoft engineer's corporate account with debugging environment access. Once possessing the MSA private key, the cluster discovered and exploited an additional Microsoft token validation flaw that allowed consumer-MSA-signed tokens to authenticate against enterprise Azure AD tenants, expanding the cluster's operational reach from "consumer email accounts only" to "enterprise email accounts across any Azure AD tenant," and enabling the State Department intrusion.

The US Cyber Safety Review Board (CSRB) Final Report on the intrusion (April 2, 2024) assessed the intrusion as "preventable" and identified a "cascade of avoidable errors" in Microsoft's security posture, corporate culture, and cloud identity infrastructure design. The CSRB Final Report made 25 recommendations and stands as the most authoritative public-record governance assessment of a major commercial cloud service provider security failure. The report assessed Storm-0558 with high confidence as PRC-affiliated and conducting espionage operations consistent with PRC intelligence collection priorities on US foreign policy, Indo-Pacific affairs, and related diplomatic intelligence collection requirements.

The cluster's targeting profile is consistent with PRC state- intelligence-collection priorities: US Department of State and Department of Commerce email accounts (foreign policy and trade policy intelligence), foreign diplomatic missions (diplomatic communications intelligence), think tanks and policy research organizations (foreign policy analysis collection), defense and aerospace organizations (defense industrial intelligence), and higher-education institutions with policy-relevant research programs. The geographic targeting is overwhelmingly Western (US primary, Europe and Indo-Pacific allies secondary), consistent with PRC foreign intelligence collection priorities. Storm-0558 is analytically distinct from the broader Chinese-aligned cluster ecosystem curated in this corpus, Volt Typhoon (volt_typhoon.yaml, US critical infrastructure preposition operations), Salt Typhoon (salt_typhoon.yaml, US telecommunications carrier intrusions 2024), Silk Typhoon (silk_typhoon.yaml, Exchange Server zero-day operator), Flax Typhoon (flax_typhoon.yaml, Taiwan-targeting), APT1 (apt1_commentcrew.yaml), APT3 (apt3_gothic_panda.yaml), APT10 (apt10_stonepanda.yaml), APT17 (apt17_aurora_panda.yaml), APT31 (apt31_zirconium.yaml), APT40 (apt40_leviathan.yaml), and APT41 (apt41_wickedpanda.yaml).

The cluster's cloud- identity-focused operational profile is operationally unique within the Chinese-aligned ecosystem and fills the cloud-identity-compromise cell in this curated corpus.

Aliases

10
storm_0558storm-0558storm 0558msft-exchange-token-forging-clustermsa-signing-key-forging-actorowa-token-forging-clusterexchange-online-token-theft-clustercsrb-2024-microsoft-cloud-intrusion-actorstorm0558china exchange online intrusion cluster 2023

Notable Campaigns

4
2024US Cyber Safety Review Board (CSRB) Final Report on Microsoft Cloud Intrusion (April 2, 2024)
2023US Government Exchange Online Email Intrusion, Discovery and Disclosure (June-July 2023)
2023Cross-Tenant Token Validation Flaw, Operational Significance and Scope Expansion
2021-2023Microsoft MSA Signing Key Compromise, Root Cause Analysis (Microsoft Disclosure, September 2023)

Attribution & Reporting

Attributed by
Microsoft Threat Intelligence (MSTIC)Microsoft Security Response Center (MSRC)US Cyber Safety Review Board (CSRB)CISA (US Cybersecurity and Infrastructure Security Agency)FBI (Federal Bureau of Investigation)Mandiant (Google Threat Intelligence)CrowdStrikeSentinelOneWiz ResearchRecorded FutureUS Department of Homeland Security
Key reporting
reportMicrosoft Security Response Center: Storm-0558 Targeting of Customer Email (July 11, 2023), canonical first-disclosure
reportMicrosoft Threat Intelligence: Storm-0558 Key Acquisition Root Cause Analysis (September 6, 2023), canonical root-cause disclosure
reportUS Cyber Safety Review Board: Review of the Summer 2023 Microsoft Exchange Online Intrusion (April 2, 2024), canonical governance review
reportMandiant / Google Threat Intelligence: Storm-0558 China Microsoft Cloud Operational Analysis
reportWiz Research: Storm-0558 Technical Analysis, MSA Key Compromise Implications
reportCISA Cybersecurity Advisory: Enhanced Microsoft 365 Audit Logging Requirements (post-Storm-0558 policy response)
reportSenator Ron Wyden Public Statement: Microsoft Security Practices and Storm-0558 Intrusion (multiple 2023-2024 statements)
reportMalpedia Actor Profile: Storm-0558

Operational

State sponsor

China-linked cyber espionage cluster assessed by Microsoft Threat Intelligence with high confidence to be a Chinese state-affiliated actor focused on espionage objectives. The cluster was first publicly disclosed by Microsoft in July 2023 following discovery of a sophisticated intrusion in which Storm-0558 operators forged authentication tokens to access Microsoft Exchange Online and Outlook Web Access (OWA) email accounts at approximately 25 organizations including United States government departments. Microsoft's attribution is based on the cluster's targeting profile (US government departments, including the Department of State and the Department of Commerce.

foreign diplomatic missions.

think tanks.

defense and aerospace organizations; higher-education institutions), operational tradecraft consistent with professional state-aligned espionage operations (highly-targeted tokenized access rather than mass-credential phishing, focused collection of diplomatic-and-policy-relevant email traffic, careful operational security to evade detection), and infrastructure analysis correlating with broader Chinese-aligned cyber- operations tradecraft. The cluster has not been formally attributed by any government cybersecurity authority to a specific Chinese government agency, military unit (PLA SSF), or intelligence service (MSS). The US Cyber Safety Review Board (CSRB) Final Report on the Microsoft Cloud Intrusion (April 2024) assessed the cluster with high confidence as a People's Republic of China affiliated actor conducting espionage operations. The cluster is operationally distinct from Volt Typhoon (volt_typhoon.yaml), Salt Typhoon (salt_typhoon.yaml), Silk Typhoon (silk_typhoon.yaml), Flax Typhoon (flax_typhoon.yaml), and earlier China-aligned clusters APT1 (apt1_commentcrew.yaml), APT3 (apt3_gothic_panda.yaml), APT10 (apt10_stonepanda.yaml), APT17 (apt17_aurora_panda.yaml), APT31 (apt31_zirconium.yaml), APT40 (apt40_leviathan.yaml), APT41 (apt41_wickedpanda.yaml), all curated separately in this corpus, though all operate within the broader Chinese state-aligned cyber-operations ecosystem.

Motivations
cyber_espionage, diplomatic_intelligence_collection, government_email_targeting, foreign_policy_intelligence, chinese_state_intelligence_priorities, persistent_email_access_collection
Sectors
Regions

Detection Blind Spots

47 techniques
Across this actor’s 47 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)37/47 · 78%
Analytics (MITRE CAR)12/47 · 25%
Runtime / container (Falco)6/47 · 12%
File / malware (YARA)1/47 · 2%
Network (Suricata/Snort)12/47 · 25%
Vuln scan (Nuclei)0/47 · 0%

Atomic Test Plan

22 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MSA SIGNING KEY TOKEN FORGER
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin