Midnight Blizzard’s CaptiveCrunch Campaign Targets Hospitality Wi-Fi Networks
Microsoft has attributed a global cyber campaign, dubbed CaptiveCrunch, to the Russian threat actor Midnight Blizzard (also known as APT29 or Storm-2945). The operation, active since at least early May 2024 with precursor phishing activity dating back to February targets hospitality Wi-Fi networks, including hotels and conference centers, to steal Microsoft 365 credentials and deploy malware.
Attack Methodology
The attackers exploit captive portal equipment by manipulating DNS and HTTP traffic, redirecting users to malicious pages. Victims are tricked into:
- Phishing portals mimicking Microsoft 365 logins.
- Device code phishing abusing Microsoft Entra ID authentication (observed since July 2024).
- Fake update prompts (e.g., browser or OS updates) delivering malware via ClickFix verification, including Android APKs in some cases.
Malware Payloads
Microsoft identified two new malware families:
-
CornFlake – A Go-based remote access trojan (RAT) with capabilities including:
- Remote shell access, keylogging, and clipboard monitoring.
- Screenshot, microphone, and webcam surveillance.
- Theft of browser credentials, cookies, and Microsoft 365 session tokens.
- File exfiltration, USB monitoring, and system reconnaissance.
- Persistence via fake progress windows (e.g., Windows updates, Defender scans) and multiple registry/Task Scheduler entries.
-
ChocoShell – An in-memory PowerShell credential stealer targeting:
- Browser cookies and saved passwords.
- Microsoft 365 and Azure AD tokens.
- Wi-Fi credentials.
Both malware families show AI-generated code signatures, suggesting tool-assisted development. Attackers also used FruitStone, an unprotected web-based management panel, to control infected systems, execute commands, and exfiltrate data.
Initial Compromise & Impact
While the exact entry point remains unclear, Microsoft observed breaches in shared infrastructure rather than isolated devices. The campaign highlights risks of untrusted Wi-Fi networks, particularly in high-traffic hospitality settings, where attackers can intercept credentials and deploy surveillance tools.
Microsoft Threat Intelligence cybersecurity rating report: https://www.rankiteo.com/company/microsoft-threat-intelligence
"id": "MIC1785803042",
"linkid": "microsoft-threat-intelligence",
"type": "Cyber Attack",
"date": "5/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Users of compromised Wi-Fi '
'networks',
'industry': 'Hospitality',
'location': 'Global',
'type': 'Hospitality Industry (Hotels, Conference '
'Centers)'}],
'attack_vector': ['Phishing',
'Device Code Phishing',
'Fake Update Prompts',
'DNS/HTTP Traffic Manipulation'],
'data_breach': {'data_exfiltration': 'Yes (via CornFlake and ChocoShell '
'malware)',
'personally_identifiable_information': 'Yes (browser '
'credentials, session '
'tokens, Wi-Fi '
'credentials)',
'sensitivity_of_data': 'High (PII, corporate credentials, '
'surveillance data)',
'type_of_data_compromised': ['Credentials',
'Session Tokens',
'Browser Data',
'Wi-Fi Credentials']},
'date_detected': '2024-05-01',
'date_publicly_disclosed': '2024-08-01',
'description': 'Microsoft has attributed a global cyber campaign, dubbed '
'*CaptiveCrunch*, to the Russian threat actor Midnight '
'Blizzard (also known as APT29 or Storm-2945). The operation '
'targets hospitality Wi-Fi networks, including hotels and '
'conference centers, to steal Microsoft 365 credentials and '
'deploy malware. The attack exploits captive portal equipment '
'by manipulating DNS and HTTP traffic, redirecting users to '
'malicious pages.',
'impact': {'brand_reputation_impact': 'Risk of reputational damage for '
'hospitality entities due to '
'compromised Wi-Fi networks',
'data_compromised': ['Microsoft 365 credentials',
'Browser credentials',
'Cookies',
'Wi-Fi credentials',
'Microsoft 365/Azure AD tokens',
'Personally Identifiable Information (PII)'],
'identity_theft_risk': 'High (due to stolen credentials and '
'session tokens)',
'operational_impact': 'Potential unauthorized access to corporate '
'systems, surveillance of affected users',
'systems_affected': ['Hospitality Wi-Fi networks',
'Captive portal equipment',
'User devices connecting to compromised '
'networks']},
'initial_access_broker': {'backdoors_established': 'Yes (via CornFlake and '
'ChocoShell malware)',
'entry_point': 'Compromised hospitality Wi-Fi '
'networks',
'high_value_targets': 'Microsoft 365 credentials, '
'corporate users',
'reconnaissance_period': 'February 2024 (precursor '
'phishing activity)'},
'investigation_status': 'Ongoing',
'lessons_learned': 'Risks of untrusted Wi-Fi networks in hospitality '
'settings, importance of securing captive portal '
'equipment, and the evolving tactics of APT29 using '
'AI-generated malware.',
'motivation': 'Cyber Espionage, Credential Theft, Surveillance',
'post_incident_analysis': {'corrective_actions': ['Secure captive portal '
'infrastructure',
'Implement MFA for all '
'authentication flows',
'Monitor for anomalous '
'authentication attempts',
'Deploy AI-assisted threat '
'detection'],
'root_causes': ['Exploitation of captive portal '
'equipment',
'Abuse of Microsoft Entra ID '
'authentication',
'Phishing and social engineering '
'tactics']},
'recommendations': ['Enhance monitoring of captive portal equipment',
'Implement multi-factor authentication (MFA) for '
'Microsoft 365 and Azure AD',
'Educate users on risks of public Wi-Fi and phishing '
'tactics',
'Deploy endpoint detection and response (EDR) solutions',
'Regularly audit and update authentication mechanisms'],
'references': [{'date_accessed': '2024-08-01',
'source': 'Microsoft Threat Intelligence'}],
'response': {'third_party_assistance': 'Microsoft Threat Intelligence'},
'threat_actor': 'Midnight Blizzard (APT29, Storm-2945)',
'title': 'Midnight Blizzard’s CaptiveCrunch Campaign Targets Hospitality '
'Wi-Fi Networks',
'type': 'Cyber Espionage, Credential Theft, Malware Deployment',
'vulnerability_exploited': 'Captive portal equipment misconfiguration, '
'Microsoft Entra ID authentication abuse'}