Microsoft warned of a cyber campaign it named CaptiveCrunch, which exploits Wi-Fi networks that use login portals in hotels, conference centers, and other hospitality venues to manipulate user traffic and then direct users to attacker-controlled infrastructure to distribute malware and steal credentials.
According to a Microsoft Threat Intelligence assessment, the campaign is linked to Storm-2945, an operational subgroup of the Russian threat actor Midnight Blizzard. Microsoft has observed the activity since early May 2026, across several countries, while ReliaQuest indicated that some operations also targeted shared venues such as conference centers, with a potential focus on travelers’ corporate accounts.
Network manipulation and phishing through Microsoft services
Storm-2945 uses sites and servers under its control to redirect DNS and HTTP traffic originating from networks served by captive portals. Users may see fake messages claiming to be updates for the browser or operating system, or a network diagnostic tool, in an attempt to persuade them to download and run a file.
Microsoft also observed domains resembling Microsoft services being used in adversary-in-the-middle phishing operations that exploit the device code authentication flow in Microsoft Entra ID. In this scenario, the attacker convinces the user to enter a code generated by the attacker into a legitimate Microsoft sign-in page, causing the attacker’s session to be authenticated instead of the user’s session. On July 16, Microsoft began observing this technique being used within some CaptiveCrunch pages.
Microsoft said Storm-2945 uses artificial intelligence to support a large portion of its operations. It also linked the group to Midnight Blizzard based on technical and operational similarities, including previous phishing campaigns using device codes and OAuth, email extraction through Microsoft Graph, and social engineering techniques.
Malware with broad capabilities
The observed tools include CornFlake, a Go-written remote access trojan targeting Windows. The program can collect system information, files, keystrokes, credentials, and session tokens, in addition to monitoring removable media and providing a remote control shell, with audio and video surveillance capabilities.
ChocoShell is a PowerShell-based information stealer that runs entirely in memory. It focuses on browser session cookies, saved passwords, Microsoft 365 single sign-on tokens, and Wi-Fi credentials. Microsoft also observed a control panel named FruitStone used to manage infected devices, build payloads, and review stolen data.
Guidance for travelers and organizations
Microsoft recommends treating hotel, conference, airport, and guest networks as untrusted, and favoring mobile hotspots or eSIM connections and private connections whenever possible. It also urges users not to install updates, certificates, or security tools that appear through captive portals or unexpected pop-up windows, and to verify updates through trusted operating system mechanisms.
At the organizational level, the guidance includes not reusing corporate credentials on guest-network sign-in pages, using passkeys, multifactor authentication, and conditional access policies, and blocking the device code flow wherever possible. Microsoft also provides detection and investigation guidance through Microsoft Defender and Microsoft Sentinel, including searching for file creation after Wi-Fi connectivity tests, connections to infrastructure associated with Storm-2945, and the presence of a CornFlake file or a Windows service named Cloud Sync Service.