Microsoft has uncovered yet another Chinese cyber-espionage campaign that compromised at least 25 organisations, including the US government.
The tech giant initiated an investigation into suspicious email activity after a customer's alert on June 16. It subsequently identified that the Chinese group, known as Storm-0558, had accessed customer email accounts from May 15.
The group is renowned for targeting government agencies in Western Europe and primarily focuses on espionage, data theft, and credential access, as stated in a Microsoft blog post.
The threat actors apparently gained entry to customer email accounts through Outlook Web Access in Exchange Online (OWA) and Outlook.com by forging authentication tokens.
"The actor used an acquired [Microsoft account] MSA key to forge tokens to access OWA and Outlook.com. MSA (consumer) keys and Azure AD (enterprise) keys are issued and managed from separate systems and should only be valid for their respective systems," Microsoft explained.
"The actor exploited a token validation issue to impersonate Azure AD users and gain access to enterprise mail. We have no indications that Azure AD keys or any other MSA keys were used by this actor. OWA and Outlook.com are the only services where we have observed the actor using tokens forged with the acquired MSA key."
Microsoft has addressed the issue by blocking the use of tokens signed with the acquired MSA key in OWA, replacing the key to prevent hackers from forging more tokens, and blocking the use of tokens issued with the key for all affected consumer customers.
While Microsoft did not disclose the agencies impacted by the campaign, the US Department of Commerce confirmed to the BBC that it was compromised.
John Hultquist, chief analyst at Mandiant, noted that Chinese cyber-espionage has become increasingly stealthy.
"Instead of tricking unsuspecting victims into opening malicious files or links, these actors are innovating and designing new methods that are already challenging us," he added.
"They've even transformed their infrastructure – the way they connect to targeted systems. There was a time when they would come through a simple proxy or even directly from China, but now they are connecting through elaborate, ephemeral proxy networks of compromised systems. The result is an adversary much harder to track and detect."
Zane Bond, Head of Product at Keeper Security, argued that Microsoft was able to swiftly resolve the incident thanks to its focus on cloud customers.
"From a technical perspective, this attack highlights an unexpected advantage of cloud providers that also provide security," he said. "Because this attack targeted the cloud, as opposed to individual customers, Microsoft was able to immediately patch and resolve this issue for all of its Azure customers globally."