
Microsoft has attributed an ongoing campaign targeting travelers on hotel and other hospitality Wi-Fi networks to a subgroup of the Russian state-sponsored hacking group Midnight Blizzard, warning that the attacks go beyond credential theft to also deploy malware on victims' devices.
The findings expand on research released by ReliaQuest last month documenting attackers compromising captive portal infrastructure at hotels and conference centers to redirect travelers to fake Microsoft 365 login pages. While ReliaQuest stopped short of attributing the activity to a known threat actor, Microsoft says it has identified the campaign as the work of Storm-2945, an operational sub-cluster of Midnight Blizzard (also tracked as APT29 or Cozy Bear), the Russian Foreign Intelligence Service (SVR)-linked espionage group.
Midnight Blizzard is one of Russia's most prolific cyber-espionage groups, with a long history of targeting governments, diplomatic organizations, NGOs, and technology providers to steal sensitive information. Microsoft says Storm-2945 shares technical and operational characteristics with other Midnight Blizzard operations, including earlier device code phishing campaigns and Microsoft 365 account compromises.
According to Microsoft, the campaign, dubbed CaptiveCrunch, has been active since at least May 2026, with AI-assisted operations observed as early as February. The attackers manipulate DNS and HTTP traffic on compromised captive portal networks, allowing them to intercept and redirect victims using hotel and other guest Wi-Fi networks. Microsoft said its investigation suggests the compromises may extend beyond individual venues and could involve shared infrastructure used by multiple captive portal providers.
As ReliaQuest previously reported, some victims are redirected to Microsoft-themed phishing domains that perform adversary-in-the-middle (AiTM) attacks against Microsoft 365 users or abuse Microsoft's device code authentication flow to obtain valid access tokens. Microsoft confirmed this activity but also found that the attackers increasingly use their privileged network position to distribute malware disguised as browser updates, Windows updates, driver repair tools, or network troubleshooting utilities.

Microsoft
The primary malware identified by Microsoft is CornFlake, a Go-based remote access trojan that installs persistent access and provides operators with capabilities including keylogging, browser credential theft, clipboard monitoring, screenshot capture, webcam and microphone surveillance, file exfiltration, USB monitoring, and remote command execution. The malware also establishes multiple persistence mechanisms and communicates with command-and-control servers over encrypted channels.
Microsoft also identified a PowerShell-based infostealer called ChocoShell, which is designed to steal browser passwords, cookies, Microsoft 365 single sign-on tokens, Azure AD authentication tokens, and saved Wi-Fi credentials. The script employs multiple defense-evasion techniques, attempts to bypass User Account Control, disables AMSI protections, and abuses Chrome's remote debugging interface to extract decrypted browser cookies directly from running browser sessions.

Microsoft
The researchers also uncovered FruitStone, a web-based command-and-control panel that allows operators to manage infected systems, deploy new malware, review stolen credentials and screenshots, and build customized CornFlake payloads for future attacks.

Microsoft
Microsoft advises organizations to treat hotel, conference, airport, and other guest Wi-Fi networks as untrusted. The company recommends using mobile hotspots or enterprise-managed VPNs whenever possible, avoiding software downloads or update prompts presented through captive portals, enabling phishing-resistant authentication such as passkeys and multifactor authentication, and restricting Microsoft's device code authentication flow where feasible.







Leave a Reply