Overview
- Microsoft has named the campaign CaptiveCrunch and attributed it to Storm-2945, a subcluster of the Russian group Midnight Blizzard, after tracing related phishing to February and captive-portal manipulation to early May.
- Operators alter DNS and HTTP on compromised captive-portal equipment to redirect guests to convincing phishing pages, device-code (OAuth) prompts, or fake update dialogs that pressure users to download files.
- Microsoft identified two payloads: CornFlake, a Go-based remote access trojan that logs keystrokes, captures audio/video, steals browser credentials and Microsoft 365 tokens, and exfiltrates files, and ChocoShell, an in-memory PowerShell stealer that targets cookies, saved passwords and Azure AD tokens.
- Investigators have not confirmed the exact initial access vector and say commonalities across affected sites point to access to shared captive-portal management services or misconfigured admin interfaces rather than only isolated venue breaches.
- Microsoft and security vendors urge treating hotel and conference Wi‑Fi as untrusted, using private cellular or a VPN, enabling phishing-resistant MFA or passkeys, disabling unneeded device-code flows and WPAD, enforcing encrypted DNS in strict mode, and having SOCs hunt for the published indicators.