Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
7 clusters · 52 sources · 27 days · First seen · Last updated
Wi‑Fi DNS hijacks targeting Microsoft 365 – Aug 2026
Overview
Since at least May 2026, the Russian SVR-backed Midnight Blizzard (APT29) sub-unit Storm-2945 has been conducting a “global scale” cyber-espionage operation dubbed “CaptiveCrunch”. The campaign targets Windows and Android users by compromising the legitimate administration systems of Wi-Fi captive-portal gateways in hotels, airports, and conference centers, often by exploiting weak passwords.
By gaining control of these gateways, attackers poison DNS and manipulate HTTP traffic to redirect users to counterfeit Microsoft 365 sign-in pages or “ClickFix” fake-update prompts (disguised as Windows or browser updates). These tactics are used to harvest credentials, cookies, and OAuth tokens, which can be used to bypass multi-factor authentication (MFA) via device-code flows.
Victims are also led to install the Go-based RAT CornFlake and the ChocoShell PowerShell stealer. These tools enable keylogging, audio-video capture, and the theft of saved passwords and session tokens. The campaign has been observed across North America, Europe, South America, Asia, and India.
In addition to Microsoft’s advisories, the Norwegian Center for Information Security (NorsIS) has warned that these deceptive networks allow attackers to intercept sensitive information from travelers. Security experts recommend that travelers use personal mobile hotspots or full-tunnel VPNs, employ phishing-resistant MFA such as FIDO2/WebAuthn, and avoid interacting with unexpected pop-up updates while connected to public hospitality Wi-Fi.
Entities
Microsoft · ReliaQuest · Midnight Blizzard · Storm‑2945 · CornFlake
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 17 SOURCES] The CaptiveCrunch campaign has been active since early May 2026.
- [● 17 SOURCES] Storm‑2945, a sub‑cluster of Midnight Blizzard, is behind the CaptiveCrunch campaign.
- [● 17 SOURCES] Attackers compromise hospitality Wi‑Fi captive portals and manipulate DNS and HTTP traffic to redirect users.
- [● 17 SOURCES] Victims are redirected to counterfeit Microsoft 365 sign‑in pages that harvest credentials.
- [● 17 SOURCES] Attackers use ClickFix‑style fake update prompts to deliver malware.
- [● 17 SOURCES] The malware families CornFlake and ChocoShell are deployed on compromised devices.
- [● 17 SOURCES] The malware can record keystrokes, capture audio/video, and steal session tokens to bypass MFA.
- [● 17 SOURCES] Microsoft advises travelers to use personal mobile hotspots, VPNs, and avoid installing unexpected pop‑up updates on captive portals.
- [● 15 SOURCES] The CaptiveCrunch campaign targets travelers by compromising hotel Wi‑Fi captive portals.
- [● 15 SOURCES] The campaign is attributed to Storm‑2945, a sub‑cluster of the Russian state‑sponsored group Midnight Blizzard (APT29/Cozy Bear).
- [● 13 SOURCES] Microsoft recommends using personal hotspots, VPNs, and phishing‑resistant MFA to mitigate the threat.
Timeline
-
22 days ago
[TECHNOLOGY] 4 sourcesMicrosoft warns of Russian hacking campaign targeting hotel Wi-FiMicrosoft warns of a Russian hacking campaign targeting hotel and conference center Wi-Fi networks to steal Microsoft 365 credentials and bypass two-factor authentication.
-
about 1 month ago
[TECHNOLOGY] 3 sourcesStorm-2945 hackers target hotel Wi-Fi in global espionage campaignRussian hackers from Storm-2945 are targeting hotel and airport Wi-Fi via the ‘CaptiveCrunch’ campaign, using DNS hijacking to steal credentials from Windows and Android users.
-
about 1 month ago
[TECHNOLOGY] 21 sourcesMidnight Blizzard exploits hotel Wi‑Fi captive portals to steal Microsoft 365 credentialsMidnight Blizzard’s Storm‑2945 group runs the CaptiveCrunch campaign, hijacking hotel Wi‑Fi captive portals since May 2026 to deliver CornFlake/ChocoShell malware via fake Microsoft 365 logins and ClickFix fake
-
about 1 month ago
[TECHNOLOGY] 16 sourcesMidnight Blizzard's CaptiveCrunch hijacks hotel Wi‑Fi to steal Microsoft 365 credentialsMidnight Blizzard’s Storm‑2945 sub‑cluster runs the CaptiveCrunch campaign, hijacking hotel Wi‑Fi to phish Microsoft 365 credentials and deploy CornFlake and ChocoShell malware; Microsoft advises VPNs, personal
-
about 2 months ago
[TECHNOLOGY] 6 sourcesMicrosoft authentication systems targeted in multi‑stage cyber attacksCyber attackers are abusing legitimate remote‑access tools, hijacking hotel Wi‑Fi DNS to steal Microsoft 365 credentials, and exploiting Microsoft’s own login flow in phishing campaigns that hit dozens of firms
-
about 2 months ago
[TECHNOLOGY] 3 sourcesAPT28-linked Wi‑Fi hijacks steal Microsoft 365 credentials, MedusaHVNC RAT uncoveredAPT28-linked Wi‑Fi hijacks steal Microsoft 365 credentials worldwide, while the new MedusaHVNC RAT uses hidden desktops to evade detection.
-
about 2 months ago
[TECHNOLOGY] 4 sourcesMicrosoft-365 Accounts Compromised by Hotel Wi‑Fi DNS Attacks and AI Cloud Security GapsCheck Point reports 78% of firms faced AI‑related breaches in 2025, with a large enforcement gap. Meanwhile, hackers hijack hotel Wi‑Fi gateways to redirect Microsoft‑365 logins, bypassing MFA via a DNS and Dev
Sources
agora-web.jp · b2b-cyber-security.de · bergischeuhren.de · blog.clavis.com.br · blogspan.net · borncity.com · c3pb.de · capital.fr · chip.cz · connect.ro · countryrebel.com · cumbernauld-media.com · cyberinsider.com · cybersecuritynews.com · dagens.no · descopera.ro · flagthis.com · focus.de · gamesite.sk · gulfnews.com · hothardware.com · ilsoftware.it · iltalehti.fi · infoguerra.com.br · it-boltwise.de · ithome.com · itnerd.blog · itvoice.in · kosmo.at · lifehacker.com.au · m.macitynet.it · m.winfuture.de · michael-bickel.de · musikknyheter.no · ntd.com · nytimespost.com · planet.fr · que.com · sea.mashable.com · securityaffairs.co · securityaffairs.com · solidsoftwaretools.com · tecnologia.libero.it · teknoblog.com · thehackernews.com · trend.dk · upday.com · vegandisneyfood.com
This summary has been updated 11 times: see revision history