Midnight Blizzard Resumes Hotel Captive-Portal Credential Theft
Microsoft says Storm-2945 resumed CaptiveCrunch hotel portal attacks on September 29, 2026, delivering malware and stealing traveler credentials.
Microsoft attributes the CaptiveCrunch campaign to Storm-2945, a Midnight Blizzard subcluster that one report also links to Russia's SVR. Network manipulation was first observed in May 2026, with activity resuming on September 29, 2026. Attackers alter DNS and HTTP on hospitality and other guest Wi-Fi captive portals—including, according to one source, providers serving seven of the ten largest U.S. hotel chains—to send travelers to fake updates, sign-in pages, and ClickFix lures. Payloads described across the reports include a Rust CornFlake variant that one source says persists as a fake Cloud Sync Service, an in-memory PowerShell infostealer called ChocoShell, Go remote-access trojans, and Android APK instructions. ChocoShell is reported to steal browser credentials or cookies and saved passwords, Microsoft 365 tokens, and Wi-Fi passwords, while device-code phishing and lookalike domains can authorize attacker cloud sessions; one report specifically names Microsoft Entra. One source also says about 70 IP addresses tied to three North American providers were previously identified and that Microsoft published recent domains and IPs for hunting.
- Microsoft attributes CaptiveCrunch to Storm-2945, a Midnight Blizzard subcluster; one report also links it to Russia's SVR.
- Network manipulation was first observed in May 2026, with activity resuming on September 29, 2026.
- Attackers alter DNS and HTTP on hotel and other guest Wi-Fi captive portals; one report says affected hospitality providers serve seven of the ten largest U.S. hotel chains.
- Lures include fake update and sign-in pages and ClickFix prompts.
- Reported payloads include a Rust CornFlake variant (said by one source to persist as a fake Cloud Sync Service), in-memory PowerShell ChocoShell, Go remote-access trojans, and Android APK instructions.
- ChocoShell is reported to steal browser credentials or cookies and saved passwords, Microsoft 365 tokens, and Wi-Fi passwords.
- Device-code phishing and lookalike domains can authorize an attacker's cloud session; one report specifically names Microsoft Entra.
- One report says about 70 IP addresses tied to three North American providers were previously identified and that Microsoft published recent domains and IPs for hunting.
Coverage timelineoldest first · each row is one article
- · 2d agoMidnight Blizzard Uses Captive Portals to Deliver CornFlake RAT and Steal Traveler Credentials
GBHackers· 78
Midnight Blizzard's Storm-2945 resumed hotel captive-portal attacks that deliver CornFlake and steal traveler credentials.
- · 2d agoMidnight Blizzard Abuses Hotel Wi-Fi Captive Portals to Deliver Malware and Steal Credentials
Cyber Security News· 80
Midnight Blizzard’s CaptiveCrunch campaign abuses hotel Wi-Fi portals to deliver malware and steal cloud credentials.