VYPR
researchPublished Aug 3, 2026· 1 source

Midnight Blizzard Hijacks Hotel Wi-Fi to Deploy Espionage Malware

Russian state-sponsored actor Midnight Blizzard is exploiting hotel captive portals to redirect travelers to fake update pages, aiming to steal credentials and deploy espionage malware.

A sophisticated espionage campaign attributed to Russia's state-sponsored actor Midnight Blizzard, also known as APT29 or Cozy Bear, has been observed hijacking public Wi-Fi captive portals in hotels and conference centers. The campaign, dubbed CaptiveCrunch by Microsoft Threat Intelligence, aims to trick travelers into downloading malware by presenting them with fake browser and operating system updates.

The threat actor has been active since early May, compromising the infrastructure of these public Wi-Fi networks. While the exact method of compromise is still under investigation, Microsoft noted commonalities in the equipment and management systems across affected networks, suggesting potential access to shared services within the captive portal ecosystem rather than isolated venue breaches.

Instead of waiting for users to visit malicious websites, the attackers proactively intercept the automated connectivity checks that devices perform upon joining a new network. These checks trigger the display of fake update pages, designed to appear legitimate and prompt users to download software. Some of these pages also served an Android Package (APK) file, indicating potential targeting of Android devices.

Starting mid-July, the campaign evolved to include device code authentication flows. Users were directed to enter an attacker-supplied code on a genuine Microsoft sign-in page, a technique that leverages the trust associated with legitimate authentication processes to bypass user suspicion. This method, while not entirely new, is made more convincing when embedded within a compromised captive portal.

The primary malware payload used in this campaign is CornFlake, a Go-based remote access trojan (RAT). Once installed, it masquerades as a Windows service named 'Cloud Sync Service' and provides attackers with capabilities such as keylogging, screen and microphone surveillance, credential theft from browsers, and a remote shell. A notable feature is its watchdog routine, which actively works to restore any persistence mechanisms that security defenders might remove.

Complementing CornFlake is ChocoShell, a PowerShell infostealer designed to operate entirely in memory. It disables the Antimalware Scan Interface (AMSI) to evade detection before exfiltrating sensitive data, including browser cookies, saved passwords, Microsoft 365 single sign-on tokens, and Wi-Fi credentials. The developer comments within ChocoShell suggest the use of AI-assisted code generation, with specific mentions of Microsoft detection signatures and evasion techniques.

Attackers manage the campaign through FruitStone, a web panel branded as a fictitious enterprise cloud product, aligning with the cover story used to trick victims. Microsoft recommends that users treat public Wi-Fi networks in hotels, conference centers, and airports with extreme caution, advising them to prefer cellular or eSIM connectivity and to never install software offered through captive portals. Blocking device code flows where not required and adopting passkeys are also suggested mitigations.

Synthesized by Vypr AI