started · updated
Midnight Blizzard's CaptiveCrunch hijacks hotel Wi‑Fi to steal Microsoft 365 credentials
Microsoft has identified a state‑sponsored cyber‑espionage operation, dubbed CaptiveCrunch, that compromises hotel and other hospitality Wi‑Fi captive‑portal gateways. The campaign, active since at least May 2026, is attributed to Storm‑2945, a sub‑cluster of the Russian group Midnight Blizzard (APT29/Cozy Bear) linked to the SVR. Attackers hijack DNS and HTTP traffic on the gateway, redirecting travelers to convincing Microsoft‑themed phishing pages that harvest OAuth tokens and can bypass MFA via the device‑code flow. The operation also delivers the CornFlake remote‑access trojan and the ChocoShell PowerShell stealer, which enable keylogging, webcam/audio capture and credential theft. Microsoft warns that the threat targets business travelers worldwide and recommends using personal hotspots, full‑tunnel VPNs, phishing‑resistant MFA (e.g., FIDO2/WebAuthn) and avoiding public Wi‑Fi updates or installers.
The campaign has been observed across multiple regions, with compromised networks reported in Europe, North America, South America and Asia. Fake update prompts (Windows, browser, driver tools) are used to trick users into executing the malware. Microsoft’s mitigation guidance emphasizes treating hotel Wi‑Fi as untrusted and employing corporate security controls to block device‑code authentication where possible.
Entities
CaptiveCrunch · CornFlake · Cozy Bear · Microsoft · Microsoft Corporation · Midnight Blizzard · Storm-2945 · Storm‑2945
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 7 SOURCES] A second tool used in the campaign is ChocoShell, employed to steal Microsoft authentication tokens. www.it-boltwise.de · www.kosmo.at · flagthis.com · cyberinsider.com · nytimespost.com · +2 more
- [● 7 SOURCES] Attackers use DNS hijacking and HTTP manipulation to redirect users to fake Microsoft 365 login pages. flagthis.com · cyberinsider.com · www.it-boltwise.de · nytimespost.com · securityaffairs.com · +2 more
- [● 15 SOURCES] The CaptiveCrunch campaign targets travelers by compromising hotel Wi‑Fi captive portals. flagthis.com · cyberinsider.com · www.it-boltwise.de · www.macitynet.it · nytimespost.com · +10 more
- [● 13 SOURCES] Microsoft recommends using personal hotspots, VPNs, and phishing‑resistant MFA to mitigate the threat. flagthis.com · www.it-boltwise.de · www.kosmo.at · www.connect.ro · cyberinsider.com · +8 more
- [● 8 SOURCES] The malware delivered includes the CornFlake remote‑access trojan. flagthis.com · cyberinsider.com · www.it-boltwise.de · www.kosmo.at · securityaffairs.com · +3 more
- [● 15 SOURCES] The campaign is attributed to Storm‑2945, a sub‑cluster of the Russian state‑sponsored group Midnight Blizzard (APT29/Cozy Bear). cyberinsider.com · www.it-boltwise.de · www.kosmo.at · securityaffairs.com · flagthis.com · +10 more
- [● 7 SOURCES] The CaptiveCrunch campaign has been active since at least May 2026. cyberinsider.com · www.it-boltwise.de · securityaffairs.com · flagthis.com · nytimespost.com · +2 more
- [● 7 SOURCES] The attacks can bypass MFA by stealing OAuth tokens or exploiting the device‑code authentication flow. cyberinsider.com · www.it-boltwise.de · www.kosmo.at · flagthis.com · nytimespost.com · +2 more