< Back to all clusters
[TECHNOLOGY] · 4 sources

Microsoft warns of CaptiveCrunch cyberattacks on hotel Wi-Fi

Microsoft has issued a warning regarding ‘CaptiveCrunch’, a cyberattack campaign targeting hotel, airport, and conference center Wi-Fi networks globally. The campaign, tracked since early May 2026, is attributed to Storm-2945, a sub-group of the Midnight Blizzard actor.

Attackers exploit captive portals—the sign-in pages used to access guest networks—to manipulate internet traffic. Once a user connects, they may be presented with fake security checks, Windows updates, or browser installers. These fraudulent pages can trick users into downloading malware such as ‘CornFlake’, which possesses broad surveillance capabilities including keystroke logging, screen capturing, and the ability to activate microphones and cameras.

Another tool identified, ‘ChocoShell’, specifically targets session cookies, Microsoft 365 sign-in tokens, and stored passwords to facilitate unauthorized access to cloud storage and workplace systems. Microsoft advises travelers to treat all shared public networks as untrusted.

Entities

Microsoft · Midnight Blizzard · ReliaQuest · Storm-2945