Storm-0558, also known as Antique Typhoon, is a China-affiliated cyberespionage threat actor assessed to operate in support of the People’s Republic of China. The group is associated with long-running Chinese state-linked intrusion activity and has been linked by multiple assessments to operations focused on intelligence collection, particularly against diplomatic, government, economic, and legislative targets. Storm-0558 is best known for the 2023 compromise of Microsoft-hosted email environments, in which it used a stolen Microsoft consumer signing key to forge authentication tokens and gain unauthorized access to Exchange Online and Outlook.com mailboxes. That campaign affected more than 500 individuals across 22 organizations, including senior U.S. government officials, and resulted in the theft of a large volume of unclassified diplomatic email. The operation demonstrated a strong focus on cloud identity abuse, token forgery, and stealthy mailbox access rather than disruptive or destructive effects. Reported targeting includes U.S. and European government entities, especially diplomatic and foreign-policy organizations, as well as individuals connected to Taiwan and Uyghur geopolitical interests. Public reporting also characterizes the actor as targeting diplomatic, economic, and legislative bodies in the United States and Europe. The group’s tradecraft in the 2023 campaign centered on credential- and identity-adjacent abuse rather than conventional malware deployment, including theft or acquisition of sensitive signing material, forged authentication tokens, unauthorized access to cloud email, and collection of victim communications for espionage purposes. Storm-0558 is widely assessed as a nation-state espionage actor rather than a financially motivated or ransomware operator. No high-confidence reporting in the supplied material supports ransomware, extortion, or destructive activity by this actor. Known aliases include Antique Typhoon and Storm-0558.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a cybersecurity incident/example illustrating private-sector exposure to national security risk.
Conducted an intrusion into Microsoft Outlook systems (July 2023) to steal email data from 25 organizations; cited in the context of nation-state compromise of Microsoft services.
Compromised Microsoft Outlook systems and stole email data from multiple organizations (espionage/data theft).
Referenced as the actor behind a major breach of Microsoft cloud email accounts by using a stolen Microsoft Account (MSA) consumer signing key to forge authentication and access customer email for more than 20 organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.