Microsoft says Russia’s SVR used hacked public Wi-Fi captive portals to deliver CornFlake malware and steal Microsoft 365 access

Microsoft says Russian intelligence hackers compromised public Wi-Fi login systems at hotels, conference centers, and similar venues to infect users and steal account access. The campaign, which Microsoft calls CaptiveCrunch and attributes to Storm-2945, a subgroup of Midnight Blizzard (SVR), manipulates DNS and HTTP traffic to place attackers in the middle, serves ClickFix-style fake update prompts, deploys the CornFlake Windows remote-access trojan and the in-memory ChocoShell infostealer, and also uses Microsoft device-code phishing to capture browser cookies, saved passwords, single sign-on tokens, and cloud access.
Why it matters: People connecting to public Wi‑Fi at hotels and conferences could be tricked into infecting their own devices or handing over cloud access without realizing it. Organizations should warn travelers, harden Microsoft 365 against device-code phishing, monitor for unusual token use, and treat public Wi‑Fi as untrusted.

Sources

Russian snoops add OAuth abuse to targeted phishing campaigns
2026.08.21 82% relevant
This article adds Google’s broader view of the same Russian espionage activity around UNC7005, including that the group targets academia, diplomatic, nonprofit, aerospace, defense, and government users, abuses OAuth and device-code login flows, and overlaps with the public-Wi-Fi/captive-portal tradecraft previously reported by Microsoft and ReliaQuest.
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Bill Toulas 2026.08.04 99% relevant
This article appears to be direct coverage of that same Microsoft disclosure, describing the same CaptiveCrunch operation using captive portals, CornFlake malware, and Microsoft 365 credential theft tied to Midnight Blizzard.
Russian spies turn public Wi-Fi into malware delivery systems
2026.08.03 100% relevant
This article establishes a distinct espionage campaign centered on compromised captive-portal Wi-Fi networks, newly named CaptiveCrunch, with specific malware families, actor attribution, and attack flow.
← Back to all stories