CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials
Zscaler details CaptiveCrunch: Midnight Blizzard's Storm-2945 compromises hotel Wi-Fi captive portals to redirect guests and harvest Microsoft 365 credentials via device code phishing.
Zscaler ThreatLabz analyzed the CaptiveCrunch credential theft campaign first reported by Microsoft on July 31. Microsoft attributes the activity to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard (APT29, Cozy Bear, NOBELIUM, BlueBravo). The actor manipulates DNS and HTTP traffic on captive portal networks at hotels and conference centers, redirecting victims to attacker-controlled infrastructure for Microsoft 365 credential harvesting, device code phishing, and malware delivery. Evidence indicates shared captive portal services were compromised rather than each venue being breached individually.
- Storm-2945 (Midnight Blizzard/APT29) targets hospitality captive portals
- DNS and HTTP manipulation redirects guests to attacker infrastructure
- Microsoft 365 credential harvesting and device code phishing employed
- Shared captive portal services compromised, not individual venues
IntroductionOn July 31, Microsoft Threat Intelligence reported an ongoing credential theft campaign tracked as CaptiveCrunch. Microsoft attributes this activity to Storm-2945, a sub-cluster of Midnight Blizzard (also known as APT29, Cozy Bear, NOBELIUM, and BlueBravo), a threat group linked to Russia. The campaign manipulates DNS and HTTP traffic on captive portal networks at hospitality venues, redirecting victims to attacker-controlled infrastructure for Microsoft 365 credential harvesting, device code phishing, and malware delivery.Evidence suggests that Storm-2945 compromised shared captive portal services used by hotels, conference centers, and similar venues rather than breaching each…
This source does not provide full text. Read it at zscaler.com.