Storm-0558
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Profile updated
- 2026-07-07 11:48:38
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:cn country_code:au
Context
Storm-0558 is a China-based threat actor with espionage objectives. While there are some minimal overlaps with other Chinese groups such as Violet Typhoon (ZIRCONIUM, APT31), Microsoft maintain high confidence that Storm-0558 operates as its own distinct group
Reports & references
- bsi.bund.de — Aktive Apt Gruppen Node (report)
- Microsoft — Analysis Of Storm 0558 Techniques For Unauthorized Email Access (report)
- wiz.io — Storm 0558 Compromised Microsoft Key Enables Authentication Of Countless Micr (report)
- Microsoft — Results Of Major Technical Investigations For Storm 0558 Key Acquisition (report)
- Microsoft — Mitigation China Based Threat Actor (report)
- Microsoft — Microsoft Mitigates China Based Threat Actor Storm 0558 Targeting Of Customer Email (report)
- youtube.com — Watch (report)
- CISA — Csrb Review Of The Summer 2023 Meo Intrusion Final 508C (report)
Attributed from
- Storm-0558 Unauthorized Email Access Activity (campaign)