Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals to Deliver Malware and Steal Credentials
Midnight Blizzard’s CaptiveCrunch campaign abuses hotel Wi-Fi portals to deliver malware and steal cloud credentials.
Microsoft attributes the CaptiveCrunch campaign to Storm-2945, an operational sub-cluster of Midnight Blizzard, after first seeing network manipulation in May 2026 and renewed activity from September 29. Attackers alter DNS and HTTP on hotel and other guest Wi-Fi captive portals, using fake update or sign-in pages and ClickFix prompts to deliver Go remote-access trojans, a Rust CornFlake variant, and Android APK instructions. CornFlake persists as a fake Cloud Sync Service, while the in-memory PowerShell infostealer ChocoShell collects browser cookies, saved passwords, Microsoft 365 tokens, and Wi-Fi credentials. Lookalike domains and device-code phishing can approve an attacker’s cloud session, putting corporate travelers’ accounts at risk.