Particle.news
Download on the App Store

Russian-Linked Hackers Hijack Hotel Wi‑Fi to Steal Microsoft 365 Logins and Deliver Malware

Microsoft says the operation compromises captive-portal systems to serve fake sign‑in or update pages that harvest tokens or install CornFlake and ChocoShell.

Overview

  • Microsoft has named the campaign CaptiveCrunch and attributed it to Storm-2945, a subcluster of the Russian group Midnight Blizzard, after tracing related phishing to February and captive-portal manipulation to early May.
  • Operators alter DNS and HTTP on compromised captive-portal equipment to redirect guests to convincing phishing pages, device-code (OAuth) prompts, or fake update dialogs that pressure users to download files.
  • Microsoft identified two payloads: CornFlake, a Go-based remote access trojan that logs keystrokes, captures audio/video, steals browser credentials and Microsoft 365 tokens, and exfiltrates files, and ChocoShell, an in-memory PowerShell stealer that targets cookies, saved passwords and Azure AD tokens.
  • Investigators have not confirmed the exact initial access vector and say commonalities across affected sites point to access to shared captive-portal management services or misconfigured admin interfaces rather than only isolated venue breaches.
  • Microsoft and security vendors urge treating hotel and conference Wi‑Fi as untrusted, using private cellular or a VPN, enabling phishing-resistant MFA or passkeys, disabling unneeded device-code flows and WPAD, enforcing encrypted DNS in strict mode, and having SOCs hunt for the published indicators.