Storm-0558 is a China-based, People’s Republic of China-affiliated cyberespionage threat actor tracked by Microsoft. Microsoft later mapped this actor to Antique Typhoon. The group is associated with the 2023 intrusion into Microsoft-hosted email environments, including Exchange Online and Outlook.com/Outlook Web Access. According to the provided content, Storm-0558 obtained or used a Microsoft consumer signing key to forge authentication tokens and access email accounts at approximately 25 organizations; other reporting in the content states 22 organizations and 503 individuals were affected worldwide. Victims included U.S. and European government entities, and reporting cited theft of about 60,000 U.S. State Department emails. The activity is described as likely conducted for espionage purposes. The content states the campaign began in May 2023 and that the actor accessed Microsoft customer email accounts through forged tokens accepted by Microsoft cloud mail services. The actor is described as well-resourced, surgical in targeting a small number of mailboxes, and linked in the content to long-running PRC cyber activity, with CSRB commentary noting the threat actor had been tracked for over two decades and linking it to Operation Aurora in 2009 and the 2011 RSA SecurID compromises.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a cybersecurity incident/example illustrating private-sector exposure to national security risk.
Conducted an intrusion into Microsoft Outlook systems (July 2023) to steal email data from 25 organizations; cited in the context of nation-state compromise of Microsoft services.
Compromised Microsoft Outlook systems and stole email data from multiple organizations (espionage/data theft).
Referenced as the actor behind a major breach of Microsoft cloud email accounts by using a stolen Microsoft Account (MSA) consumer signing key to forge authentication and access customer email for more than 20 organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.