Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-0558

Description

Storm-0558 is a China-based threat actor with espionage objectives. While there are some minimal overlaps with other Chinese groups such as Violet Typhoon (ZIRCONIUM, APT31), Microsoft maintain high confidence that Storm-0558 operates as its own distinct group

Goals & Targeting

Targeted Sectors

Government

AI Analysis

· 1 week ago

Executive Summary

Storm-0558 is a nation-state threat actor based in China with suspected ties to state-sponsored espionage activities. The group targets government sectors and has been observed using sophisticated tactics that suggest high operational maturity. While it shares some overlaps with other Chinese APTs like Violet Typhoon, it operates as a distinct entity, targeting sensitive information for strategic intelligence purposes.

Goals & Targeting

Storm-0558's strategic objectives are likely aligned with the broader interests of China's state-sponsored cyber espionage efforts. The group targets government entities due to their potential access to classified information and influence over national policies. Their targeting profile indicates a focus on sectors that provide strategic advantage, such as defense, foreign policy, and intelligence gathering.

Enhanced Description

Storm-0558 is identified as a Chinese-based threat actor with primary objectives centered on espionage. The group has demonstrated the ability to infiltrate government networks, likely seeking to gather sensitive political or military information. Although there are minimal overlaps with other Chinese APTs like Violet Typhoon (ZIRCONIUM), Storm-0558 is considered a distinct entity by Microsoft. The actor's operations are characterized by precision and stealthiness, targeting high-value assets within government sectors. This suggests a capability for long-term, persistent campaigns aimed at maintaining access to sensitive networks.

Key Capabilities

  • Advanced persistent threat (APT) capabilities
  • Custom malware development
  • Spear-phishing campaigns
  • Network infiltration and lateral movement
  • Persistent access to target networks

MITRE ATT&CK Tactics

Espionage
Discovery
Defense Evasion
Exfiltration

ATT&CK Techniques

T1566.003 - Espionage Script Injection
T1095 -redential Dumping: OS Credential Hash Collection
T1027 - Account Access Removal
T1055 - Process Injection

Software / Tooling

Custom malware (likely used for initial access)
Cobalt Strike (for C2 and lateral movement)
Mimikatz (credential dumping)
Windows tools (e.g., Ps_EXEC, VBA scripts)

Campaigns & Victims

Storm-0558's campaigns are characterized by their stealthiness and targeted approach. The group likely conducts prolonged campaigns to gather sensitive information over time. Their operational tempo suggests a focus on maintaining persistence within networks rather than rapid exfiltration. Campaigns may involve initial access through spear-phishing, followed by internal movement using known tools like Cobalt Strike.

IOC Patterns

  • Spear-phishing emails with malicious attachments or links
  • DNS queries for C2 communication
  • Malicious scripts dropped on the endpoint (e.g., Powershell or VBA)
  • Scheduled tasks for persistence

Recommended Actions

  • Implement multi-factor authentication (MFA) for sensitive accounts
  • Monitor and block known IOC patterns in network traffic
  • Conduct regular employee training on phishing awareness
  • Deploy endpoint detection and response (EDR) solutions
  • Segment critical networks from general access
  • Use threat intelligence feeds to identify and block malicious domains

Suggested Tags

Nation-state
APT
Espionage
Government Sector

Confidence Assessment

High confidence that Storm-0558 exists as a distinct nation-state actor. The description aligns with known Chinese APT behavior, though specific TTPs and exact toolset details are lacking due to limited公开 reporting.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Nation-state
Espionage
Government Sector

Details

Type
Nation-State
Country of Origin
C
Confidence
50%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.