Storm-0558, also known as Antique Typhoon, is a People’s Republic of China-affiliated cyberespionage actor. In 2023, it conducted a campaign against Microsoft-hosted email services, using forged authentication tokens signed with a compromised Microsoft consumer signing key to access Exchange Online and Outlook.com mailboxes. The operation affected more than 500 individuals across 22 organizations, including senior U.S. government officials, and resulted in the exfiltration of approximately 60,000 unclassified U.S. Department of State emails. Microsoft assessed that the actor primarily targets diplomatic, economic, and legislative organizations in the United States and Europe, as well as individuals and entities associated with Taiwanese and Uyghur geopolitical interests. Additional targets have included media organizations, think tanks, and telecommunications equipment and service providers. Storm-0558 used SoftEther VPN infrastructure, dedicated servers, and TOR or SOCKS proxying to interact with victim environments. It abused authentication-token validation weaknesses to impersonate consumer and enterprise users and access targeted mailboxes. Although Microsoft initially assessed that the signing key may have been acquired from a crash dump accessible through a compromised corporate account, the U.S. Cyber Safety Review Board found that the mechanism by which the actor obtained the key remained unproven.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a cybersecurity incident/example illustrating private-sector exposure to national security risk.
Referenced as another Microsoft-identified group comparable to Flax Typhoon due to shared use of SoftEther VPN software for communication with victim devices.
Espionage activity involving theft of a Microsoft private encryption key to forge tokens and access customer email and potentially other Microsoft cloud applications; the group has focused on email account access and targeted government, media, think tanks, telecommunications, and parties linked to Taiwanese and Uyghur causes.
Conducted an intrusion into Microsoft Outlook systems (July 2023) to steal email data from 25 organizations; cited in the context of nation-state compromise of Microsoft services.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.