Microsoft says Russian intelligence hackers compromised public Wi-Fi login systems at hotels, conference centers, and similar venues to infect users and steal account access. The campaign, which Microsoft calls CaptiveCrunch and attributes to Storm-2945, a subgroup of Midnight Blizzard (SVR), manipulates DNS and HTTP traffic to place attackers in the middle, serves ClickFix-style fake update prompts, deploys the CornFlake Windows remote-access trojan and the in-memory ChocoShell infostealer, and also uses Microsoft device-code phishing to capture browser cookies, saved passwords, single sign-on tokens, and cloud access.
Why it matters: People connecting to public Wi‑Fi at hotels and conferences could be tricked into infecting their own devices or handing over cloud access without realizing it. Organizations should warn travelers, harden Microsoft 365 against device-code phishing, monitor for unusual token use, and treat public Wi‑Fi as untrusted.
2026.08.21
82% relevant
This article adds Google’s broader view of the same Russian espionage activity around UNC7005, including that the group targets academia, diplomatic, nonprofit, aerospace, defense, and government users, abuses OAuth and device-code login flows, and overlaps with the public-Wi-Fi/captive-portal tradecraft previously reported by Microsoft and ReliaQuest.
Bill Toulas
2026.08.04
99% relevant
This article appears to be direct coverage of that same Microsoft disclosure, describing the same CaptiveCrunch operation using captive portals, CornFlake malware, and Microsoft 365 credential theft tied to Midnight Blizzard.
2026.08.03
100% relevant
This article establishes a distinct espionage campaign centered on compromised captive-portal Wi-Fi networks, newly named CaptiveCrunch, with specific malware families, actor attribution, and attack flow.
← Back to all stories