Chinese Threat Group Compromises US Government

Chinese Threat Group Compromises GovernmentsMicrosoft has uncovered yet another Chinese cyber-espionage campaign that compromised at least 25 organisations, including the US government.

The tech giant initiated an investigation into suspicious email activity after a customer's alert on June 16. It subsequently identified that the Chinese group, known as Storm-0558, had accessed customer email accounts from May 15.

The group is renowned for targeting government agencies in Western Europe and primarily focuses on espionage, data theft, and credential access, as stated in a Microsoft blog post.

The threat actors apparently gained entry to customer email accounts through Outlook Web Access in Exchange Online (OWA) and Outlook.com by forging authentication tokens.

"The actor used an acquired [Microsoft account] MSA key to forge tokens to access OWA and Outlook.com. MSA (consumer) keys and Azure AD (enterprise) keys are issued and managed from separate systems and should only be valid for their respective systems," Microsoft explained.

"The actor exploited a token validation issue to impersonate Azure AD users and gain access to enterprise mail. We have no indications that Azure AD keys or any other MSA keys were used by this actor. OWA and Outlook.com are the only services where we have observed the actor using tokens forged with the acquired MSA key."

Microsoft has addressed the issue by blocking the use of tokens signed with the acquired MSA key in OWA, replacing the key to prevent hackers from forging more tokens, and blocking the use of tokens issued with the key for all affected consumer customers.

While Microsoft did not disclose the agencies impacted by the campaign, the US Department of Commerce confirmed to the BBC that it was compromised.

John Hultquist, chief analyst at Mandiant, noted that Chinese cyber-espionage has become increasingly stealthy.

"Instead of tricking unsuspecting victims into opening malicious files or links, these actors are innovating and designing new methods that are already challenging us," he added.

"They've even transformed their infrastructure – the way they connect to targeted systems. There was a time when they would come through a simple proxy or even directly from China, but now they are connecting through elaborate, ephemeral proxy networks of compromised systems. The result is an adversary much harder to track and detect."

Zane Bond, Head of Product at Keeper Security, argued that Microsoft was able to swiftly resolve the incident thanks to its focus on cloud customers.

"From a technical perspective, this attack highlights an unexpected advantage of cloud providers that also provide security," he said. "Because this attack targeted the cloud, as opposed to individual customers, Microsoft was able to immediately patch and resolve this issue for all of its Azure customers globally."

Related Articles

What is StormWarning! ?

 StormWarning! is a Cybersecurity consultancy. Our experienced team of cybersecurity experts provide cybersecurity assessments, cybersecurity training and cybersecurity solutions to organisations that have a high risk public profile. StormWarning! is your organisation's best defense against the ever growing cascade of innovative security threats raining down on all organisations with a public digital footprint.

What is Cybersecurity?

Cybersecurity is the practice of protecting critical systems and sensitive information from digital attacks. Also known as information technology (IT) security, cybersecurity measures are designed to combat threats against networked systems and applications, whether those threats originate from inside or outside of an organization. StormWarning! is constantly researching the latest cybersecurity threats and building innovative measures to prevent them.

 

NIST Audit & Targeted Cyber-Risk Training

StormWarning! offers comprehensive Cybersecurity Consulting, with a focus on its Automated Online Auditing Solutions, primarily the NIST CSF Readiness Audit. This audit is prioritized as its results directly inform the organization's needs for targeted cybersecurity training. By identifying specific gaps in risk management knowledge, they deliver precise education via Short Courses—like Cybersecurity Risk Management or Understanding Cybersecurity GRC—to ensure staff and leadership close deficiencies and maintain compliance.

Their full suite of services also includes robust Risk Management planning, development of essential Policies, impactful Cybersecurity Awareness Campaigns, and a security monitoring/incident response platform, StormFront. Additionally, we offer a resource library of Cybersecurity Books authored by our esteemed associate Dr. Zoran Mitrovic.