Particle.news
Download on the App Store

Microsoft Links CaptiveCrunch to Hijacked Hotel and Conference Wi‑Fi

Security teams warn attackers altered captive‑portal gateways to show fake updates and device‑code prompts that can grant MFA‑satisfied access or install persistent surveillance malware.

Overview

  • Microsoft disclosed on Saturday that a campaign it calls CaptiveCrunch, which it attributes to Storm‑2945, has been manipulating DNS and HTTP on guest Wi‑Fi at hotels, conference centers and other venues since early May.
  • The hijacked captive portals redirected users to fake browser or update pages that either prompt victims to run installers or route them into Microsoft’s legitimate device‑code sign‑in flow so attackers receive valid tokens.
  • Microsoft named CornFlake as a Windows remote‑access trojan used in the campaign and described ChocoShell as an in‑memory PowerShell tool that steals Microsoft 365, Azure AD and WAM tokens for session replay.
  • ReliaQuest’s earlier research corroborated the redirection tradecraft and reported that exposed gateway management interfaces and weak admin credentials are plausible access points, though investigators have not confirmed the exact initial vector.
  • Researchers and Microsoft urge travelers to treat guest networks as untrusted, use private hotspots or full‑tunnel VPNs, avoid captive‑portal updates, and have organizations block unneeded device‑code flows and tighten Conditional Access policies.