< Back to situation

[REVISION HISTORY]

Wi‑Fi DNS hijacks targeting Microsoft 365 – Aug 2026

Updated 11 times since CLSTR started tracking revisions of this situation.

What changed

2026-08-10 09:51 UTC → 2026-08-22 07:49 UTC · added removed

Since late June at least May 2026, threat actors have the Russian SVR-backed Midnight Blizzard (APT29) sub-unit Storm-2945 has been conducting a “global scale” cyber-espionage operation dubbed “CaptiveCrunch”. The campaign targets Windows and Android users by compromising public Wi‑Fi the legitimate administration systems of Wi-Fi captive-portal gateways in hotels, airports, conference centers and other hospitality venues. conference centers, often by exploiting weak passwords. By gaining administrative control of captive‑portal appliances, they these gateways, attackers poison DNS and alter manipulate HTTP responses, redirecting traffic to redirect users to counterfeit Microsoft 365 sign‑in sign-in pages and fake update or “ClickFix” fake-update prompts (named “ClickFix”). (disguised as Windows or browser updates). These tactics are used to harvest credentials, cookies, and OAuth tokens, which can be used to bypass multi-factor authentication (MFA) via device-code flows. Victims are also led to install the Go‑based Go-based RAT CornFlake and the secondary tool ChocoShell, which log keystrokes, capture audio‑video, steal ChocoShell PowerShell stealer. These tools enable keylogging, audio-video capture, and the theft of saved passwords, cookies passwords and session tokens, and can bypass MFA via device‑code flows. tokens. The campaign, first linked to APT28’s FrostArmada activity, now involves the Russian SVR‑backed Midnight Blizzard (APT29) sub‑unit Storm‑2945, identified by Microsoft as the CaptiveCrunch operation. Recent reports indicate the group is conducting a “global scale” campaign targeting both Windows and Android users. Rather than creating rogue networks, attackers infiltrate legitimate administration systems, often by exploiting weak passwords, to manipulate DNS settings. Over 200 phishing emails impersonating Microsoft Teams tasks have has been sent to roughly 120 organizations observed across finance, legal, healthcare, energy, retail and professional services, using compromised gateways in the United States, India North America, Europe, South America, Asia, and Saudi Arabia. A parallel development disclosed on 26 July revealed a new remote‑access trojan, MedusaHVNC, offered as malware‑as‑a‑service. While not directly tied to the Wi‑Fi hijacks, its emergence highlights the expanding toolbox available India. In addition to the same espionage groups. Microsoft’s advisories reiterate advisories, the recommendation Norwegian Center for travelers Information Security (NorsIS) has warned that these deceptive networks allow attackers to avoid public hospitality Wi‑Fi, intercept sensitive information from travelers. Security experts recommend that travelers use personal mobile hotspots or full-tunnel VPNs, employ phishing-resistant MFA such as FIDO2/WebAuthn, and ignore avoid interacting with unexpected pop‑up update prompts pop-up updates while connected to captive portals. public hospitality Wi-Fi.

Versions

  1. 2026-08-22 07:49 UTC Wi‑Fi DNS hijacks targeting Microsoft 365 – Aug 2026
  2. 2026-08-10 09:51 UTC Wi‑Fi DNS hijacks targeting Microsoft 365 – Aug 2026
  3. 2026-08-06 07:27 UTC Wi‑Fi DNS hijacks targeting Microsoft 365 – Aug 2026
  4. 2026-08-05 19:47 UTC Wi‑Fi DNS hijacks targeting Microsoft 365 – August 2026
  5. 2026-08-04 23:27 UTC Wi‑Fi DNS hijacks targeting Microsoft 365
  6. 2026-08-04 23:17 UTC Wi‑Fi DNS hijacks targeting Microsoft 365 (2026 updates)
  7. 2026-08-04 12:46 UTC Wi‑Fi DNS hijacks targeting Microsoft 365 (2026 updates)
  8. 2026-08-03 20:25 UTC Wi‑Fi DNS hijacks targeting Microsoft 365 (2026 updates)
  9. 2026-08-03 14:13 UTC Wi‑Fi DNS hijacks targeting Microsoft 365 (2026 updates)
  10. 2026-08-02 13:05 UTC Wi‑Fi DNS hijacks targeting Microsoft 365
  11. 2026-07-29 14:20 UTC Wi‑Fi DNS hijacks targeting Microsoft 365
  12. 2026-07-27 19:18 UTC Wi‑Fi DNS hijacks targeting Microsoft 365

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.