VYPR
researchPublished Jul 31, 2026· 1 source

CaptiveCrunch Campaign Leverages Hospitality Networks for Malware Delivery and Credential Theft

Microsoft reports on CaptiveCrunch, a campaign by Midnight Blizzard sub-cluster Storm-2945, manipulating hospitality Wi-Fi to deliver malware and steal credentials globally.

Microsoft Threat Intelligence has identified a sophisticated global campaign dubbed CaptiveCrunch, orchestrated by Storm-2945, a sub-cluster of the notorious Midnight Blizzard threat actor group. Since early May 2026, Storm-2945 has been actively manipulating traffic from hospitality sector captive portals worldwide. This campaign aims to deliver malware, including Golang-based remote access trojans (RATs), and conduct phishing attacks that exploit Microsoft Entra ID's device code authentication flow, ultimately leading to credential theft and system compromise.

The CaptiveCrunch campaign exhibits a notable evolution in tactics, with Storm-2945 leveraging AI to enhance its operations. The threat actor manipulates DNS and HTTP traffic from captive portal networks, redirecting unsuspecting users through actor-controlled infrastructure. This allows for man-in-the-middle (AitM) phishing attacks, often disguised as legitimate browser or operating system updates, prompting users to download and execute malicious payloads. The delivered malware includes fully-featured Windows RATs capable of system enumeration, file and keystroke collection, credential and session token theft, audio/video surveillance, and establishing a remote shell.

Beyond Windows, Microsoft has observed indications that Storm-2945 may also be targeting Android devices. The "ClickFix" landing pages, used to trick users into downloading malware, also include instructions for Android users to install malicious APK files. This broad targeting underscores the campaign's expansive reach and the diverse threat landscape faced by travelers.

Attribution to Midnight Blizzard, a group linked to Russia's SVR, is based on significant technical and operational overlaps with known Midnight Blizzard sub-clusters. Midnight Blizzard is known for its persistent espionage operations targeting governments, NGOs, and IT service providers, with a focus on intelligence gathering to support Russian foreign policy. Their methods often involve compromising valid accounts and employing advanced techniques to evade detection and expand access.

The campaign's infrastructure is designed to be deceptive, employing "doppelganger" domains that mimic legitimate Microsoft online services. This tactic, combined with the abuse of Microsoft Entra ID's device code authentication flow, allows attackers to register malicious devices to an organization's tenant, facilitating further access and data exfiltration. The use of AI in these operations suggests an increasing sophistication and adaptability in threat actor methodologies.

Microsoft's investigation into the initial compromise vector for the captive portal networks is ongoing. However, commonalities in equipment and management systems across affected venues suggest that the compromises might extend beyond isolated incidents, potentially indicating access to shared services within the captive portal ecosystem. This highlights a systemic vulnerability within shared network infrastructure commonly used by travelers.

To combat this threat, Microsoft is providing detailed detection and hunting guidance, along with Microsoft Defender detections. Organizations are urged to implement security best practices, particularly for users who travel frequently. This includes enabling multi-factor authentication, monitoring for suspicious device registrations in Entra ID, and educating users about phishing and malware delivery tactics.

The CaptiveCrunch campaign represents a significant threat to travelers and organizations worldwide, leveraging compromised network infrastructure and advanced techniques to achieve its espionage and credential theft objectives. The involvement of AI and the persistent nature of Midnight Blizzard underscore the evolving challenges in cybersecurity defense.

Synthesized by Vypr AI