Microsoft said the China-aligned espionage group Storm-0558 stole a Microsoft consumer signing key and used it to forge authentication tokens that granted unauthorized access to Exchange Online and Outlook.com mailboxes. The company said the activity began in May and affected email accounts at 25 organizations as well as related consumer accounts, prompting mitigation and a broader investigation into how the actor obtained and abused the key to access cloud-hosted email.
Subsequent analysis indicated the impact may have extended beyond email. Researchers reported the compromised key could potentially authenticate access to additional Microsoft services, including Azure Active Directory, SharePoint, Teams, and OneDrive, as well as some customer-managed applications relying on Microsoft authentication. SecurityScorecard later identified 10 IP addresses in NetFlow data that may have served as attacker proxies linked to the campaign, and said the traffic suggested possible targeting of Microsoft and a Western European government ministry, although the full victim scope remained unconfirmed.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
On July 14, 2023, Microsoft published a technical analysis of Storm-0558's techniques for unauthorized email access. The company described the actor's use of SoftEther VPN, dedicated servers, TOR or SOCKS5 proxies, and released indicators of compromise including IP addresses and usage timeframes.
On July 11, 2023, Microsoft disclosed that a threat actor had obtained a Microsoft private encryption key and used forged tokens to access customer Exchange Online and Outlook.com accounts. Microsoft attributed the campaign to Storm-0558 and said it affected email accounts at 25 organizations plus related consumer accounts.
Microsoft said the observed Storm-0558 activity began on May 15, 2023. The campaign used a stolen Microsoft private encryption key to forge tokens and access Exchange Online and Outlook.com accounts.
SecurityScorecard analyzed partner traffic data, public reporting, and NetFlow and identified ten IP addresses that may have been used as proxies to communicate with dedicated servers tied to the Storm-0558 campaign. It also observed traffic that could suggest targeting of Microsoft and a Western European government ministry, while noting the evidence was not conclusive.
Subsequent reporting found that the compromised Microsoft key may have enabled access beyond Exchange Online and Outlook.com, including Azure Active Directory, SharePoint, Teams, OneDrive, and customer-managed applications using Microsoft authentication. This suggested the compromise may have affected more organizations than the 25 Microsoft originally estimated.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
securityscorecard.com
Open sourcewiz.io
Open sourcemicrosoft.com
Open sourceblogs.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.