Storm-0062
Aliases: Oro0lxy, DarkShadow, Storm-0062
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:05:31
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services
Context
The cyberattack campaign that Microsoft uncovered was launched by a China-linked hacking group called Storm-0062. According to the company, the group is launching cyberattacks by exploiting a vulnerability in the Data Center and Server editions of Confluence. Those are versions of the application that companies run on-premises.
Reports & references
- Microsoft — 3970796 (report)
- sentinelone.com — The Good The Bad And The Ugly In Cybersecurity Week 41 5 (report)
- twitter.com — 1711871732644970856 (report)
- raw.githubusercontent.com — Microsoftmapping (report)