Cybersecurity

Microsoft warns of CaptiveCrunch campaign targeting travelers through hotel networks and stealing credentials

Microsoft detected a campaign conducted by Storm-2945, a subgroup of Midnight Blizzard, to manipulate traffic through hotel networks and captive portals in order to distribute malware and steal passwords, cookies, and Microsoft 365 session tokens. The campaign also uses phishing pages that exploit the Microsoft Entra ID device code authentication flow.

2026-07-31
3 min read
7 views
فريق تحرير certi.news
Microsoft warns of CaptiveCrunch campaign targeting travelers through hotel networks and stealing credentials

Microsoft warned of a cyber campaign it named CaptiveCrunch, which exploits Wi-Fi networks that use login portals in hotels, conference centers, and other hospitality venues to manipulate user traffic and then direct users to attacker-controlled infrastructure to distribute malware and steal credentials.

According to a Microsoft Threat Intelligence assessment, the campaign is linked to Storm-2945, an operational subgroup of the Russian threat actor Midnight Blizzard. Microsoft has observed the activity since early May 2026, across several countries, while ReliaQuest indicated that some operations also targeted shared venues such as conference centers, with a potential focus on travelers’ corporate accounts.

Network manipulation and phishing through Microsoft services

Storm-2945 uses sites and servers under its control to redirect DNS and HTTP traffic originating from networks served by captive portals. Users may see fake messages claiming to be updates for the browser or operating system, or a network diagnostic tool, in an attempt to persuade them to download and run a file.

Microsoft also observed domains resembling Microsoft services being used in adversary-in-the-middle phishing operations that exploit the device code authentication flow in Microsoft Entra ID. In this scenario, the attacker convinces the user to enter a code generated by the attacker into a legitimate Microsoft sign-in page, causing the attacker’s session to be authenticated instead of the user’s session. On July 16, Microsoft began observing this technique being used within some CaptiveCrunch pages.

Microsoft said Storm-2945 uses artificial intelligence to support a large portion of its operations. It also linked the group to Midnight Blizzard based on technical and operational similarities, including previous phishing campaigns using device codes and OAuth, email extraction through Microsoft Graph, and social engineering techniques.

Malware with broad capabilities

The observed tools include CornFlake, a Go-written remote access trojan targeting Windows. The program can collect system information, files, keystrokes, credentials, and session tokens, in addition to monitoring removable media and providing a remote control shell, with audio and video surveillance capabilities.

ChocoShell is a PowerShell-based information stealer that runs entirely in memory. It focuses on browser session cookies, saved passwords, Microsoft 365 single sign-on tokens, and Wi-Fi credentials. Microsoft also observed a control panel named FruitStone used to manage infected devices, build payloads, and review stolen data.

Guidance for travelers and organizations

Microsoft recommends treating hotel, conference, airport, and guest networks as untrusted, and favoring mobile hotspots or eSIM connections and private connections whenever possible. It also urges users not to install updates, certificates, or security tools that appear through captive portals or unexpected pop-up windows, and to verify updates through trusted operating system mechanisms.

At the organizational level, the guidance includes not reusing corporate credentials on guest-network sign-in pages, using passkeys, multifactor authentication, and conditional access policies, and blocking the device code flow wherever possible. Microsoft also provides detection and investigation guidance through Microsoft Defender and Microsoft Sentinel, including searching for file creation after Wi-Fi connectivity tests, connections to infrastructure associated with Storm-2945, and the presence of a CornFlake file or a Windows service named Cloud Sync Service.

News source
Microsoft Security Blog
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news