< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

7 clusters · 52 sources · 27 days · First seen · Last updated

Wi‑Fi DNS hijacks targeting Microsoft 365 – Aug 2026

Overview

Since at least May 2026, the Russian SVR-backed Midnight Blizzard (APT29) sub-unit Storm-2945 has been conducting a “global scale” cyber-espionage operation dubbed “CaptiveCrunch”. The campaign targets Windows and Android users by compromising the legitimate administration systems of Wi-Fi captive-portal gateways in hotels, airports, and conference centers, often by exploiting weak passwords.

By gaining control of these gateways, attackers poison DNS and manipulate HTTP traffic to redirect users to counterfeit Microsoft 365 sign-in pages or “ClickFix” fake-update prompts (disguised as Windows or browser updates). These tactics are used to harvest credentials, cookies, and OAuth tokens, which can be used to bypass multi-factor authentication (MFA) via device-code flows.

Victims are also led to install the Go-based RAT CornFlake and the ChocoShell PowerShell stealer. These tools enable keylogging, audio-video capture, and the theft of saved passwords and session tokens. The campaign has been observed across North America, Europe, South America, Asia, and India.

In addition to Microsoft’s advisories, the Norwegian Center for Information Security (NorsIS) has warned that these deceptive networks allow attackers to intercept sensitive information from travelers. Security experts recommend that travelers use personal mobile hotspots or full-tunnel VPNs, employ phishing-resistant MFA such as FIDO2/WebAuthn, and avoid interacting with unexpected pop-up updates while connected to public hospitality Wi-Fi.

Entities

Microsoft · ReliaQuest · Midnight Blizzard · Storm‑2945 · CornFlake

Claims

What the coverage asserts, and how many sources carry each claim.

Timeline

  1. 22 days ago

    [TECHNOLOGY] 4 sources
    Microsoft warns of Russian hacking campaign targeting hotel Wi-Fi

    Microsoft warns of a Russian hacking campaign targeting hotel and conference center Wi-Fi networks to steal Microsoft 365 credentials and bypass two-factor authentication.

  2. about 1 month ago

    [TECHNOLOGY] 3 sources
    Storm-2945 hackers target hotel Wi-Fi in global espionage campaign

    Russian hackers from Storm-2945 are targeting hotel and airport Wi-Fi via the ‘CaptiveCrunch’ campaign, using DNS hijacking to steal credentials from Windows and Android users.

  3. about 1 month ago

    [TECHNOLOGY] 21 sources
    Midnight Blizzard exploits hotel Wi‑Fi captive portals to steal Microsoft 365 credentials

    Midnight Blizzard’s Storm‑2945 group runs the CaptiveCrunch campaign, hijacking hotel Wi‑Fi captive portals since May 2026 to deliver CornFlake/ChocoShell malware via fake Microsoft 365 logins and ClickFix fake

  4. about 1 month ago

    [TECHNOLOGY] 16 sources
    Midnight Blizzard's CaptiveCrunch hijacks hotel Wi‑Fi to steal Microsoft 365 credentials

    Midnight Blizzard’s Storm‑2945 sub‑cluster runs the CaptiveCrunch campaign, hijacking hotel Wi‑Fi to phish Microsoft 365 credentials and deploy CornFlake and ChocoShell malware; Microsoft advises VPNs, personal

  5. about 2 months ago

    [TECHNOLOGY] 6 sources
    Microsoft authentication systems targeted in multi‑stage cyber attacks

    Cyber attackers are abusing legitimate remote‑access tools, hijacking hotel Wi‑Fi DNS to steal Microsoft 365 credentials, and exploiting Microsoft’s own login flow in phishing campaigns that hit dozens of firms

  6. about 2 months ago

    [TECHNOLOGY] 3 sources
    APT28-linked Wi‑Fi hijacks steal Microsoft 365 credentials, MedusaHVNC RAT uncovered

    APT28-linked Wi‑Fi hijacks steal Microsoft 365 credentials worldwide, while the new MedusaHVNC RAT uses hidden desktops to evade detection.

  7. about 2 months ago

    [TECHNOLOGY] 4 sources
    Microsoft-365 Accounts Compromised by Hotel Wi‑Fi DNS Attacks and AI Cloud Security Gaps

    Check Point reports 78% of firms faced AI‑related breaches in 2025, with a large enforcement gap. Meanwhile, hackers hijack hotel Wi‑Fi gateways to redirect Microsoft‑365 logins, bypassing MFA via a DNS and Dev

Sources

agora-web.jp · b2b-cyber-security.de · bergischeuhren.de · blog.clavis.com.br · blogspan.net · borncity.com · c3pb.de · capital.fr · chip.cz · connect.ro · countryrebel.com · cumbernauld-media.com · cyberinsider.com · cybersecuritynews.com · dagens.no · descopera.ro · flagthis.com · focus.de · gamesite.sk · gulfnews.com · hothardware.com · ilsoftware.it · iltalehti.fi · infoguerra.com.br · it-boltwise.de · ithome.com · itnerd.blog · itvoice.in · kosmo.at · lifehacker.com.au · m.macitynet.it · m.winfuture.de · michael-bickel.de · musikknyheter.no · ntd.com · nytimespost.com · planet.fr · que.com · sea.mashable.com · securityaffairs.co · securityaffairs.com · solidsoftwaretools.com · tecnologia.libero.it · teknoblog.com · thehackernews.com · trend.dk · upday.com · vegandisneyfood.com

This summary has been updated 11 times: see revision history