# Wi‑Fi DNS hijacks targeting Microsoft 365 – Aug 2026

> Live situation record from CLSTR: https://clstr.news/situations/wifi-dns-hijacks-targeting-microsoft-365
> Updated: 2026-08-20T21:17:00.000Z. Sources: 52. Developments: 7.

Since at least May 2026, the Russian SVR-backed Midnight Blizzard (APT29) sub-unit Storm-2945 has been conducting a “global scale” cyber-espionage operation dubbed “CaptiveCrunch”. The campaign targets Windows and Android users by compromising the legitimate administration systems of Wi-Fi captive-portal gateways in hotels, airports, and conference centers, often by exploiting weak passwords.

By gaining control of these gateways, attackers poison DNS and manipulate HTTP traffic to redirect users to counterfeit Microsoft 365 sign-in pages or “ClickFix” fake-update prompts (disguised as Windows or browser updates). These tactics are used to harvest credentials, cookies, and OAuth tokens, which can be used to bypass multi-factor authentication (MFA) via device-code flows. 

Victims are also led to install the Go-based RAT CornFlake and the ChocoShell PowerShell stealer. These tools enable keylogging, audio-video capture, and the theft of saved passwords and session tokens. The campaign has been observed across North America, Europe, South America, Asia, and India.

In addition to Microsoft’s advisories, the Norwegian Center for Information Security (NorsIS) has warned that these deceptive networks allow attackers to intercept sensitive information from travelers. Security experts recommend that travelers use personal mobile hotspots or full-tunnel VPNs, employ phishing-resistant MFA such as FIDO2/WebAuthn, and avoid interacting with unexpected pop-up updates while connected to public hospitality Wi-Fi.

## Claims

- The CaptiveCrunch campaign has been active since early May 2026. (corroborated by 17 sources)
- Storm‑2945, a sub‑cluster of Midnight Blizzard, is behind the CaptiveCrunch campaign. (corroborated by 17 sources)
- Attackers compromise hospitality Wi‑Fi captive portals and manipulate DNS and HTTP traffic to redirect users. (corroborated by 17 sources)
- Victims are redirected to counterfeit Microsoft 365 sign‑in pages that harvest credentials. (corroborated by 17 sources)
- Attackers use ClickFix‑style fake update prompts to deliver malware. (corroborated by 17 sources)
- The malware families CornFlake and ChocoShell are deployed on compromised devices. (corroborated by 17 sources)
- The malware can record keystrokes, capture audio/video, and steal session tokens to bypass MFA. (corroborated by 17 sources)
- Microsoft advises travelers to use personal mobile hotspots, VPNs, and avoid installing unexpected pop‑up updates on captive portals. (corroborated by 17 sources)
- The CaptiveCrunch campaign targets travelers by compromising hotel Wi‑Fi captive portals. (corroborated by 15 sources)
- The campaign is attributed to Storm‑2945, a sub‑cluster of the Russian state‑sponsored group Midnight Blizzard (APT29/Cozy Bear). (corroborated by 15 sources)
- Microsoft recommends using personal hotspots, VPNs, and phishing‑resistant MFA to mitigate the threat. (corroborated by 13 sources)

## Timeline

### 2026-08-20: Microsoft warns of Russian hacking campaign targeting hotel Wi-Fi

Microsoft warns of a Russian hacking campaign targeting hotel and conference center Wi-Fi networks to steal Microsoft 365 credentials and bypass two-factor authentication.

4 sources. https://clstr.news/cluster/microsoft-warns-of-russian-hacking-campaign-targeting-hotel-wi-fi

### 2026-08-09: Storm-2945 hackers target hotel Wi-Fi in global espionage campaign

Russian hackers from Storm-2945 are targeting hotel and airport Wi-Fi via the ‘CaptiveCrunch’ campaign, using DNS hijacking to steal credentials from Windows and Android users.

3 sources. https://clstr.news/cluster/storm-2945-hackers-target-hotel-wi-fi-in-global-espionage-campaign

### 2026-08-04: Midnight Blizzard exploits hotel Wi‑Fi captive portals to steal Microsoft 365 credentials

Midnight Blizzard’s Storm‑2945 group runs the CaptiveCrunch campaign, hijacking hotel Wi‑Fi captive portals since May 2026 to deliver CornFlake/ChocoShell malware via fake Microsoft 365 logins and ClickFix fake

21 sources. https://clstr.news/cluster/russian-hackers-compromise-hotel-wifi-networks-microsoft-warns

### 2026-08-01: Midnight Blizzard's CaptiveCrunch hijacks hotel Wi‑Fi to steal Microsoft 365 credentials

Midnight Blizzard’s Storm‑2945 sub‑cluster runs the CaptiveCrunch campaign, hijacking hotel Wi‑Fi to phish Microsoft 365 credentials and deploy CornFlake and ChocoShell malware; Microsoft advises VPNs, personal

16 sources. https://clstr.news/cluster/microsoft-warns-of-cozy-bear-hotel-wifi-attacks-on-business-travelers

### 2026-07-27: Microsoft authentication systems targeted in multi‑stage cyber attacks

Cyber attackers are abusing legitimate remote‑access tools, hijacking hotel Wi‑Fi DNS to steal Microsoft 365 credentials, and exploiting Microsoft’s own login flow in phishing campaigns that hit dozens of firms

6 sources. https://clstr.news/cluster/microsoft-authentication-systems-targeted-in-multistage-cyber-attacks

### 2026-07-26: APT28-linked Wi‑Fi hijacks steal Microsoft 365 credentials, MedusaHVNC RAT uncovered

APT28-linked Wi‑Fi hijacks steal Microsoft 365 credentials worldwide, while the new MedusaHVNC RAT uses hidden desktops to evade detection.

3 sources. https://clstr.news/cluster/apt28-linked-wifi-hijacks-steal-microsoft-365-credentials-medusahvnc-rat-uncovered

### 2026-07-25: Microsoft-365 Accounts Compromised by Hotel Wi‑Fi DNS Attacks and AI Cloud Security Gaps

Check Point reports 78% of firms faced AI‑related breaches in 2025, with a large enforcement gap. Meanwhile, hackers hijack hotel Wi‑Fi gateways to redirect Microsoft‑365 logins, bypassing MFA via a DNS and Dev

4 sources. https://clstr.news/cluster/microsoft-365-accounts-compromised-by-hotel-wifi-dns-attacks-and-ai-cloud-security-gaps

---
Cite as: Wi‑Fi DNS hijacks targeting Microsoft 365 – Aug 2026. CLSTR, https://clstr.news/situations/wifi-dns-hijacks-targeting-microsoft-365
