Overview
- Microsoft has named the campaign CaptiveCrunch and attributes it to a Russian‑linked cluster called Storm‑2945 that targets guest Wi‑Fi at hotels, airports and conference venues.
- Attackers manipulate captive‑portal gateways and DNS/HTTP responses to redirect users to realistic phishing pages that capture Microsoft credentials, device codes and OAuth tokens.
- Researchers say the campaign can also prompt fake software updates to deliver malware families reported as CornFlake and ChocoShell, which can log keystrokes, capture files and enable remote surveillance.
- Microsoft and security vendors advise treating guest networks as untrusted, using private hotspots or enterprise travel routers, running an always‑on full‑tunnel VPN with a killswitch, and enabling phishing‑resistant authentication or passkeys.
- Investigators are still probing how captive‑portal systems were first compromised and say common equipment and management links may point to shared services being abused, a finding that raises risks for corporate travelers and long‑term espionage.