Microsoft Threat Intelligence has identified the CaptiveCrunch campaign, where the Russian-linked group Storm-2945 compromises hotel and conference Wi-Fi networks to deploy malware and steal corporate user credentials.
Key Points
- Storm-2945, a sub-cluster of the Russian SVR-linked Midnight Blizzard, has been active since May 2026.
- Attackers manipulate DNS and HTTP traffic on captive portal networks to redirect guests to malicious landing pages.
- The campaign deploys CornFlake, a sophisticated Windows remote access trojan, and ChocoShell, an in-memory PowerShell infostealer.
- Malicious pages impersonate legitimate software updates or verification prompts to trick users into executing payloads.
- Attackers are utilizing device code phishing to bypass multi-factor authentication and hijack active Microsoft 365 and Azure sessions.