Storm-2945 hackers target hotel Wi-Fi in global espionage campaign
The Russian hacking group Storm-2945, a subunit of Midnight Blizzard linked to the SVR, is conducting a global cyber espionage campaign named ‘CaptiveCrunch’. The operation targets Windows and Android users by compromising the Wi-Fi networks of hotels, conference centers, and airports.
Instead of creating fake networks, the attackers infiltrate the legitimate administration systems of Wi-Fi portals, often exploiting weak passwords. Once in control, they manipulate DNS settings to redirect users to highly realistic fraudulent login pages, such as fake Microsoft 365 sites, to steal credentials and authentication tokens.
The campaign also distributes malware, including the CornFlake remote access Trojan and the ChocoShell data stealer. These tools allow attackers to monitor computers, steal files, and siphon cookies. Microsoft has characterized the attack as a ‘global scale’ threat affecting professional travelers and leisure users alike.
Entities
Microsoft · Midnight Blizzard · ReliaQuest · SVR · Storm-2945