Storm-0558

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Profile updated
2026-07-07 11:48:38

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:cn country_code:au

Context

Storm-0558 is a China-based threat actor with espionage objectives. While there are some minimal overlaps with other Chinese groups such as Violet Typhoon (ZIRCONIUM, APT31), Microsoft maintain high confidence that Storm-0558 operates as its own distinct group

Reports & references

  • bsi.bund.de — Aktive Apt Gruppen Node (report)
  • Microsoft — Analysis Of Storm 0558 Techniques For Unauthorized Email Access (report)
  • wiz.io — Storm 0558 Compromised Microsoft Key Enables Authentication Of Countless Micr (report)
  • Microsoft — Results Of Major Technical Investigations For Storm 0558 Key Acquisition (report)
  • Microsoft — Mitigation China Based Threat Actor (report)
  • Microsoft — Microsoft Mitigates China Based Threat Actor Storm 0558 Targeting Of Customer Email (report)
  • youtube.com — Watch (report)
  • CISA — Csrb Review Of The Summer 2023 Meo Intrusion Final 508C (report)

Attributed from

  • Storm-0558 Unauthorized Email Access Activity (campaign)

External references