Storm-0558 forges authentication tokens to access Exchange Online mailboxes
Microsoft reported that the China-based threat actor it tracks as Storm-0558 used a stolen Microsoft account (MSA) signing key to forge authentication tokens and gain access to Outlook Web Access and Exchange Online mailboxes of targeted organizations, including government entities. Microsoft described mitigations taken to block the actor’s access and remediate the signing key issue. The U.S. Cyber Safety Review Board (CSRB) later issued a report on the incident, including recommendations related to cloud identity, logging, and key management.
First reported July 11, 2023Espionagehigh overall confidence
T1550.001: Microsoft described forged authentication tokens being used to access mailboxes, consistent with using alternate authentication material in the form of application access tokens.
Mitigations
Now
Strengthen signing key management and rotate compromised keys rapidlyReduces risk of token forgery and limits the window of misuse if a key is compromised.
Soon
Increase logging visibility and retention for cloud email access (including detailed token/audit logs)Improves detection and investigation of suspicious mailbox access patterns.
Later
Apply conditional access and session controls for sensitive tenants and privileged operationsAdds barriers for anomalous access even when tokens or credentials are abused.
Detection ideas
Detect anomalous mailbox access patterns in cloud audit logs
Alert on rare client/app IDs, unusual source IPs/ASNs, and access to many mailboxes or sensitive folders by the same principal in a short time.
Data sources: Microsoft 365 audit logs, Exchange Online mailbox audit logs, SIEM