CaptiveCrunch Campaign Leverages Hospitality Networks for Malware Delivery and Credential Theft
Microsoft reports on CaptiveCrunch, a campaign by Midnight Blizzard sub-cluster Storm-2945, manipulating hospitality Wi-Fi to deliver malware and steal credentials globally.

Microsoft Threat Intelligence has identified a sophisticated global campaign dubbed CaptiveCrunch, orchestrated by Storm-2945, a sub-cluster of the notorious Midnight Blizzard threat actor group. Since early May 2026, Storm-2945 has been actively manipulating traffic from hospitality sector captive portals worldwide. This campaign aims to deliver malware, including Golang-based remote access trojans (RATs), and conduct phishing attacks that exploit Microsoft Entra ID's device code authentication flow, ultimately leading to credential theft and system compromise.
The CaptiveCrunch campaign exhibits a notable evolution in tactics, with Storm-2945 leveraging AI to enhance its operations. The threat actor manipulates DNS and HTTP traffic from captive portal networks, redirecting unsuspecting users through actor-controlled infrastructure. This allows for man-in-the-middle (AitM) phishing attacks, often disguised as legitimate browser or operating system updates, prompting users to download and execute malicious payloads. The delivered malware includes fully-featured Windows RATs capable of system enumeration, file and keystroke collection, credential and session token theft, audio/video surveillance, and establishing a remote shell.
Beyond Windows, Microsoft has observed indications that Storm-2945 may also be targeting Android devices. The "ClickFix" landing pages, used to trick users into downloading malware, also include instructions for Android users to install malicious APK files. This broad targeting underscores the campaign's expansive reach and the diverse threat landscape faced by travelers.
Attribution to Midnight Blizzard, a group linked to Russia's SVR, is based on significant technical and operational overlaps with known Midnight Blizzard sub-clusters. Midnight Blizzard is known for its persistent espionage operations targeting governments, NGOs, and IT service providers, with a focus on intelligence gathering to support Russian foreign policy. Their methods often involve compromising valid accounts and employing advanced techniques to evade detection and expand access.
The campaign's infrastructure is designed to be deceptive, employing "doppelganger" domains that mimic legitimate Microsoft online services. This tactic, combined with the abuse of Microsoft Entra ID's device code authentication flow, allows attackers to register malicious devices to an organization's tenant, facilitating further access and data exfiltration. The use of AI in these operations suggests an increasing sophistication and adaptability in threat actor methodologies.
Microsoft's investigation into the initial compromise vector for the captive portal networks is ongoing. However, commonalities in equipment and management systems across affected venues suggest that the compromises might extend beyond isolated incidents, potentially indicating access to shared services within the captive portal ecosystem. This highlights a systemic vulnerability within shared network infrastructure commonly used by travelers.
To combat this threat, Microsoft is providing detailed detection and hunting guidance, along with Microsoft Defender detections. Organizations are urged to implement security best practices, particularly for users who travel frequently. This includes enabling multi-factor authentication, monitoring for suspicious device registrations in Entra ID, and educating users about phishing and malware delivery tactics.
The CaptiveCrunch campaign represents a significant threat to travelers and organizations worldwide, leveraging compromised network infrastructure and advanced techniques to achieve its espionage and credential theft objectives. The involvement of AI and the persistent nature of Midnight Blizzard underscore the evolving challenges in cybersecurity defense.
This new report details how the CaptiveCrunch campaign, attributed to Storm-2945 and linked to Midnight Blizzard (APT29), specifically hijacks hotel Wi-Fi networks to distribute the CornFlake RAT. The malware is delivered via fake browser updates, and the attackers can then capture webcam images, microphone audio, and keystrokes from victims. Researchers also identified ChocoShell, an in-memory PowerShell stealer, as part of the toolkit, capable of stealing Microsoft 365 and Azure Active Directory tokens.
Microsoft has identified that Storm-2945, a subgroup of Midnight Blizzard, is behind the CaptiveCrunch campaign. This actor, believed to be sponsored by the Russian Foreign Intelligence Service (SVR), has been actively manipulating DNS and HTTP traffic from captive portal networks since May. The campaign has also been observed serving Golang-based Windows remote access trojans (RATs) disguised as browser updates, and targeting Android users with similar malware delivery tactics.
This new reporting from The Register provides further details on the CaptiveCrunch campaign, specifically highlighting the SVR's Storm-2945 unit's involvement and the use of the CornFlake RAT and ChocoShell infostealer. It also elaborates on the 'ClickFix-style' methods used to trick users into installing malware disguised as updates and details the device code phishing technique used to compromise Microsoft 365 accounts.
This new reporting from Help Net Security, citing Microsoft Threat Intelligence, provides further details on the CaptiveCrunch campaign. It highlights the specific malware strains, CornFlake (a Windows RAT) and ChocoShell (a PowerShell credential stealer), used by the Midnight Blizzard sub-cluster Storm-2945. The article also details the campaign's multi-stage attack flow, including DNS/HTTP traffic manipulation, phishing pages, and the use of a C2 panel named FruitStone, while noting potential targeting of Android devices.