Microsoft warns Russian hackers exploiting hotel Wi‑Fi in CaptiveCrunch campaign
Microsoft has identified a cyber‑espionage operation called CaptiveCrunch that targets public Wi‑Fi networks at hotels, airports and conference venues. The attackers compromise captive‑portal infrastructure, manipulate DNS and HTTP traffic and redirect users to fake login pages that mimic Microsoft 365, enabling credential theft and bypass of multi‑factor authentication through device‑code prompts.
The campaign is attributed to a Russian SVR‑linked group known as Midnight Blizzard (also APT29, Nobelium) and its sub‑unit Storm‑2945. It deploys surveillance‑oriented malware, including the CornFlake and ChocoShell strains, which can record keystrokes, capture audio‑visual data and provide remote access to infected devices. Microsoft says the compromise of hospitality Wi‑Fi networks has been widespread since May 2026, though the initial method of gaining control over captive portals remains unclear. Users are advised to avoid public Wi‑Fi where possible, for example by using a personal mobile hotspot.
Entities: CaptiveCrunch campaign · ChocoShell malware · CornFlake malware · Microsoft Corporation · Midnight Blizzard (APT29/Nobelium) · Russian Foreign Intelligence Service (SVR) · Storm-2945 (Midnight Blizzard group)
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [● 4 SOURCES] The campaign is attributed to the Russian SVR‑linked hacking group Midnight Blizzard, also known as APT29, Nobelium, and its sub‑unit Storm‑2945. (Microsoft)
- [○ 1 SOURCE] Attackers may have compromised a central service provider that hosts multiple captive portals, though this is not confirmed. (Microsoft)
- [○ 1 SOURCE] The malware strains CornFlake and ChocoShell are used to provide remote access, keylogging, and audio‑visual surveillance. (Microsoft)
- [○ 1 SOURCE] The campaign can bypass multi‑factor authentication by using device‑code authentication prompts. (Microsoft)
- [● 3 SOURCES] Microsoft observed a widespread compromise of hospitality Wi‑Fi networks starting in May 2026. (Microsoft)
- [● 4 SOURCES] The CaptiveCrunch campaign uses public Wi‑Fi captive portals to phish Microsoft 365 credentials. (Microsoft)
- [● 4 SOURCES] Attackers manipulate DNS and HTTP traffic to redirect users to fake login pages resembling Microsoft services. (Microsoft)
- [○ 1 SOURCE] Users are advised to use a personal mobile hotspot instead of public Wi‑Fi to avoid infection. (Microsoft)