Also known as: Oro0lxy, DarkShadow
The cyberattack campaign that Microsoft uncovered was launched by a China-linked hacking group called Storm-0062. According to the company, the group is launching cyberattacks by exploiting a vulnerability in the Data Center and Server editions of Confluence. Those are versions of the application that companies run on-premises.
Executive Summary
Storm-0062, also known as Oro0lxy or DarkShadow, is a cyber threat actor linked to China, targeting vulnerabilities in on-premises Confluence Server and Data Center versions. While initial reports indicate exploit-based attacks, their broader strategic goals and other TTPs remain unclear at present.
Goals & Targeting
The actor appears to focus on exploiting known vulnerabilities in widely used server software such as Confluence, targeting organizations that operate these systems in their data centers. Given its suspected Chinese origin, Storm-0062 may align with state-sponsored cyber espionage or theft activities typically seen in nation-state actors. Target selection is likely driven by operational opportunities rather than sector-specific preferences, but campaigns may evolve to focus on critical infrastructure industries.
Enhanced Description
Storm-0062 gained attention after being identified by Microsoft as a China-linked hacking group exploiting a vulnerability in the on-premises versions of Atlassian Confluence Server and Data Center. The actor is known to leverage server software vulnerabilities for cyberattacks, with their primary campaign involving exploit-based intrusions targeting critical infrastructure and enterprise organizations. Despite this activity, limited information exists regarding Storm-0062's broader objectives, long-term goals, or association with specific sectors outside of the initial findings.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm-0062 has been observed in limited campaigns, primarily through Microsoft's identification of their activity against Confluence vulnerabilities. The group's operational tempo suggests a focus on high-value targets, possibly within critical infrastructure or government sectors, but specific victims and long-term campaign patterns remain undefined.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the Chinese linkage of Storm-0062 based on Microsoft's findings, but limited data availability makes precise details about this actor scarce. Additional information regarding specific campaigns beyond the Confluence vulnerability exploitation is lacking, leaving gaps in understanding their strategic objectives and full capability set.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics