Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-0062

Also known as: Oro0lxy, DarkShadow

Description

The cyberattack campaign that Microsoft uncovered was launched by a China-linked hacking group called Storm-0062. According to the company, the group is launching cyberattacks by exploiting a vulnerability in the Data Center and Server editions of Confluence. Those are versions of the application that companies run on-premises.

AI Analysis

· 1 week ago

Executive Summary

Storm-0062, also known as Oro0lxy or DarkShadow, is a cyber threat actor linked to China, targeting vulnerabilities in on-premises Confluence Server and Data Center versions. While initial reports indicate exploit-based attacks, their broader strategic goals and other TTPs remain unclear at present.

Goals & Targeting

The actor appears to focus on exploiting known vulnerabilities in widely used server software such as Confluence, targeting organizations that operate these systems in their data centers. Given its suspected Chinese origin, Storm-0062 may align with state-sponsored cyber espionage or theft activities typically seen in nation-state actors. Target selection is likely driven by operational opportunities rather than sector-specific preferences, but campaigns may evolve to focus on critical infrastructure industries.

Enhanced Description

Storm-0062 gained attention after being identified by Microsoft as a China-linked hacking group exploiting a vulnerability in the on-premises versions of Atlassian Confluence Server and Data Center. The actor is known to leverage server software vulnerabilities for cyberattacks, with their primary campaign involving exploit-based intrusions targeting critical infrastructure and enterprise organizations. Despite this activity, limited information exists regarding Storm-0062's broader objectives, long-term goals, or association with specific sectors outside of the initial findings.

Key Capabilities

  • Exploitation of server software vulnerabilities
  • Potential phishing and initial access mechanisms

MITRE ATT&CK Tactics

Reconnaissance
Initial Access
Execution
Defense Evasion

ATT&CK Techniques

T1064.003 - Exploit Public-Server Vulnerability
T1003 -Credential Dumping
T1021 - Internal Lateral Movement
T1098.001 - Valid Accounts

Software / Tooling

Custom exploit toolkits for server vulnerabilities
Potential phishing email campaigns

Campaigns & Victims

Storm-0062 has been observed in limited campaigns, primarily through Microsoft's identification of their activity against Confluence vulnerabilities. The group's operational tempo suggests a focus on high-value targets, possibly within critical infrastructure or government sectors, but specific victims and long-term campaign patterns remain undefined.

IOC Patterns

  • Exploitation attempts targeting Confluence Server vulnerabilities
  • Network traffic indicating scans for vulnerable Confluence instances

Recommended Actions

  • Patch all known Confluence Server and Data Center versions immediately to mitigate zero-day exploit risk.
  • Monitor network traffic for signs of exploitation attempts consistent with the known TTPs of this actor.
  • Conduct periodic phishing simulations to test employee susceptibility to email-based attacks.

Suggested Tags

APT
Nation-State
China-linked
Vulnerability_Exploitation

Confidence Assessment

High confidence in the Chinese linkage of Storm-0062 based on Microsoft's findings, but limited data availability makes precise details about this actor scarce. Additional information regarding specific campaigns beyond the Confluence vulnerability exploitation is lacking, leaving gaps in understanding their strategic objectives and full capability set.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Nation-State
China-linked
Vulnerability_Exploitation

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.