< Back to all clusters
[TECHNOLOGY] · Romania, Brazil, Germany, Italy, Japan · 16 sources

started · updated

Midnight Blizzard's CaptiveCrunch hijacks hotel Wi‑Fi to steal Microsoft 365 credentials

Microsoft has identified a state‑sponsored cyber‑espionage operation, dubbed CaptiveCrunch, that compromises hotel and other hospitality Wi‑Fi captive‑portal gateways. The campaign, active since at least May 2026, is attributed to Storm‑2945, a sub‑cluster of the Russian group Midnight Blizzard (APT29/Cozy Bear) linked to the SVR. Attackers hijack DNS and HTTP traffic on the gateway, redirecting travelers to convincing Microsoft‑themed phishing pages that harvest OAuth tokens and can bypass MFA via the device‑code flow. The operation also delivers the CornFlake remote‑access trojan and the ChocoShell PowerShell stealer, which enable keylogging, webcam/audio capture and credential theft. Microsoft warns that the threat targets business travelers worldwide and recommends using personal hotspots, full‑tunnel VPNs, phishing‑resistant MFA (e.g., FIDO2/WebAuthn) and avoiding public Wi‑Fi updates or installers.

The campaign has been observed across multiple regions, with compromised networks reported in Europe, North America, South America and Asia. Fake update prompts (Windows, browser, driver tools) are used to trick users into executing the malware. Microsoft’s mitigation guidance emphasizes treating hotel Wi‑Fi as untrusted and employing corporate security controls to block device‑code authentication where possible.

Entities

CaptiveCrunch · CornFlake · Cozy Bear · Microsoft · Microsoft Corporation · Midnight Blizzard · Storm-2945 · Storm‑2945

Claims

What the coverage asserts, and how many sources carry each claim.

Sources