Microsoft Blames Nation-State Threat Actor for Confluence Zero-Day Attacks


A note from Redmond linked the ongoing attacks to an APT group tracked as Storm-0062 and warned that malicious activity dates back to September 14, a full three weeks before Atlassian’s public disclosure of the issue.

“Microsoft has observed nation-state threat actor Storm-0062 exploiting CVE-2023-22515 in the wild since September 14, 2023. CVE-2023-22515 was disclosed on October 4, 2023. Storm-0062 is tracked by others as DarkShadow or Oro0lxy,” the company said.

According to SecurityWeek sources, the Storm-0062 hacking team has been observed conducting cyberespionage operations for China’s Ministry of State Security, a state intelligence agency.