Storm-0558 is a China-based nation-state actor targeting government sectors in the US and Germany.
Analyst brief
Storm-0558 is a China-based nation-state actor with espionage objectives, primarily targeting government sectors in the United States and Germany. The group is tracked by Microsoft with high confidence as a distinct entity, despite minimal overlaps with Violet Typhoon (APT31). While specific TTPs are not provided in the presented data, defenders should focus on standard nation-state espionage tactics. Organizations in targeted sectors should monitor for anomalous access patterns, enforce multi-factor authentication, and remain aware of potential indicators overlapping with Chinese state-sponsored groups.
Storm-0558
nation-state
Storm-0558 is a China-based threat actor with espionage objectives. While there are some minimal overlaps with other Chinese groups such as Violet Typhoon (ZIRCONIUM, APT31), Microsoft maintain high confidence that Storm-0558 operates as its own distinct group
origin (suspected)
🇨🇳China· state-sponsoredattribution confidence: medium (50)