Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals to Deliver Malware and Steal Credentials
Midnight Blizzard’s CaptiveCrunch campaign abuses hotel Wi-Fi portals to deliver malware and steal cloud credentials.
Microsoft attributes the CaptiveCrunch campaign to Storm-2945, an operational sub-cluster of Midnight Blizzard, after first seeing network manipulation in May 2026 and renewed activity from September 29. Attackers alter DNS and HTTP on hotel and other guest Wi-Fi captive portals, using fake update or sign-in pages and ClickFix prompts to deliver Go remote-access trojans, a Rust CornFlake variant, and Android APK instructions. CornFlake persists as a fake Cloud Sync Service, while the in-memory PowerShell infostealer ChocoShell collects browser cookies, saved passwords, Microsoft 365 tokens, and Wi-Fi credentials. Lookalike domains and device-code phishing can approve an attacker’s cloud session, putting corporate travelers’ accounts at risk.
- Microsoft links CaptiveCrunch to Storm-2945, a Midnight Blizzard sub-cluster.
- Attackers manipulate DNS and HTTP on hotel and guest Wi-Fi portals.
- ClickFix prompts deliver Go remote-access trojans, CornFlake, and Android APKs.
- ChocoShell steals browser cookies, passwords, and Microsoft 365 tokens.
- Device-code phishing and lookalike domains can authorize attacker cloud sessions.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | cdn-gstat.com | rs of compromise (IoCs):- Type Indicator Description Domain cdn-gstat[.]com CaptiveCrunch redirect Domain sslcdnhost[.]com CaptiveCru |
| domain | m365-owa.com | 5-live[.]com CaptiveCrunch device-code-flow redirect Domain m365-owa[.]com CaptiveCrunch adversary-in-the-middle infrastructure Doma |
| domain | ms365-device.com | Domain network-privacy[.]com CaptiveCrunch redirect Domain ms365-device[.]com CaptiveCrunch device-code-flow redirect Domain ms365-live |
| domain | ms365-live.com | device[.]com CaptiveCrunch device-code-flow redirect Domain ms365-live[.]com CaptiveCrunch device-code-flow redirect Domain m365-owa[. |
| domain | network-privacy.com | irect Domain sslcdnhost[.]com CaptiveCrunch redirect Domain network-privacy[.]com CaptiveCrunch redirect Domain ms365-device[.]com CaptiveC |
| domain | owa-ms365.com | CaptiveCrunch adversary-in-the-middle infrastructure Domain owa-ms365[.]com CaptiveCrunch adversary-in-the-middle infrastructure IP a |
Full article886 words · extracted from cybersecuritynews.com · click to collapse
Travelers connecting to hotel Wi-Fi may now face more than an unreliable internet signal. A campaign linked to Midnight Blizzard has turned captive portals, the sign-in pages shown before online access, into a route for malware, credential theft, and possible access to corporate accounts.
The operation, known as CaptiveCrunch, has affected hospitality-related networks and other venues using captive-portal equipment in several countries.
It targets people during routine connectivity checks, replacing expected web pages with convincing update prompts or account sign-in requests.
Microsoft analysts identified the activity as the work of Storm-2945, an operational sub-cluster of Midnight Blizzard. Microsoft first observed network manipulation in May 2026.
In an October 5 update, researchers reported renewed activity beginning September 29, including a Rust variant of CornFlake consistent with continued AI-assisted malware development.
Microsoft said in a report shared with Cyber Security News (CSN) that the risk extends beyond a single infected laptop. Stolen passwords and cloud session tokens can expose business services, while device-code phishing can persuade victims to approve an attacker’s authentication session.
Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals
CaptiveCrunch begins when attackers manipulate DNS and HTTP traffic on affected guest networks, redirecting users through infrastructure they control.
The operation targets travelers worldwide, while evidence suggests compromises may involve shared captive-portal services rather than isolated venues.
The altered page can pose as a browser or operating-system update and exploit ClickFix techniques, which tell people to perform a supposed repair or verification step.
This turns familiar warnings into a delivery channel, much like recent fake update attacks, where user interaction installs the malicious payload.
Microsoft observed Windows remote-access trojans written in Go that can collect files and keystrokes, steal credentials and tokens, record audio or video, and open a remote command shell.
Researchers also saw Android instructions on ClickFix pages encouraging users to download and install an APK file. A principal implant, CornFlake, displays a false progress window while copying itself to an application-data folder and creating several ways to restart after reboot.
.webp)
It masquerades as a Windows service called Cloud Sync Service, helping it blend in while maintaining access. The campaign also redirects some victims to lookalike online-service domains for adversary-in-the-middle phishing.
A user may be asked to enter a device code on a real sign-in page, but the code authorizes the attacker’s session, an evolution of earlier Teams credential theft operations associated with Midnight Blizzard.
Malware, Credential Theft, and Defense
ChocoShell, an in-memory PowerShell infostealer, focuses on browser cookies, saved passwords, Microsoft 365 single sign-on tokens, and stored Wi-Fi credentials.
It can retrieve browser encryption keys and use browser debugging features to obtain readable cookies, giving attackers a route to authenticated cloud sessions without relying only on a password.
That makes the campaign especially serious for corporate travelers. As infostealer fueled cloud breaches have shown, usable session data can be replayed against cloud services, VPNs, and SaaS applications, creating a fast path from device infection to account compromise.
The malware attempts to evade inspection by disabling Windows anti-malware scanning controls, checking for analysis environments, and using disguised HTTPS paths.
.webp)
It can elevate privileges, compress stolen data, and send it to its command-and-control server before removing temporary traces. Travelers should treat hotel, conference, airport, and other guest wireless networks as untrusted.
Prefer a mobile hotspot or other private connection when practical, avoid downloads offered by a captive portal, and confirm updates only through normal operating-system or browser update channels.
Organizations should prevent managed devices from joining unapproved Wi-Fi networks where feasible and use travel routers or hotspots that establish encrypted connections to trusted infrastructure.
Staff should never reuse corporate credentials on a guest-network registration page or follow a prompt to paste commands into PowerShell or other system command tools.
Identity defenses matter as much as endpoint controls. Use passkeys and phishing-resistant multifactor authentication, restrict device-code authentication to required cases, and use sign-in risk policies to challenge or block suspicious access.
Security teams should investigate the listed infrastructure, unexpected downloads after connectivity tests, and CornFlake artifacts.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | cdn-gstat[.]com | CaptiveCrunch redirect |
| Domain | sslcdnhost[.]com | CaptiveCrunch redirect |
| Domain | network-privacy[.]com | CaptiveCrunch redirect |
| Domain | ms365-device[.]com | CaptiveCrunch device-code-flow redirect |
| Domain | ms365-live[.]com | CaptiveCrunch device-code-flow redirect |
| Domain | m365-owa[.]com | CaptiveCrunch adversary-in-the-middle infrastructure |
| Domain | owa-ms365[.]com | CaptiveCrunch adversary-in-the-middle infrastructure |
| IP address | 154.29.75[.]245 | CaptiveCrunch infrastructure |
| IP address | 149.3.170[.]186 | CaptiveCrunch device-code-flow infrastructure |
| IP address | 31.57.243[.]154 | CaptiveCrunch adversary-in-the-middle infrastructure |
| IP address | 38.146.28[.]75 | CaptiveCrunch adversary-in-the-middle infrastructure |
| IP address | 38.146.28[.]132 | CaptiveCrunch DNS resolver |
| IP address | 104.194.159[.]150 | CaptiveCrunch adversary-in-the-middle infrastructure |
| IP address | 107.189.26[.]194 | ChocoShell C2 and CaptiveCrunch DNS resolver |
| IP address | 213.145.86[.]112 | ChocoShell command-and-control server |
| URL path | 213.145.86[.]112/t/pixel.gif?m= | ChocoShell beacon pattern |
| URL path | 213.145.86[.]112/cdn/chunks/polyfill-7e2b.min.js | ChocoShell secondary module retrieval |
| URL path | 213.145.86[.]112/t/event | ChocoShell data-exfiltration endpoint |
| File path | %APPDATA%\svchost32\svchost32.exe | CornFlake RAT executable location |
| SHA-256 | 918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593 | CornFlake |
| SHA-256 | be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c | ChocoShell |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.