Overview
- Microsoft on July 31 publicly attributed the campaign called CaptiveCrunch to Storm‑2945, a subgroup of Midnight Blizzard that is assessed to be linked to Russia’s SVR, and released detailed indicators and tooling signatures for defenders to hunt.
- Researchers say the attackers manipulated DNS and HTTP responses on captive‑portal gateways at hotels, conference centers and other shared venues to force users onto attacker‑controlled pages that mimic update or verification flows.
- From about July 16 some landing pages redirected victims into real Microsoft device‑code sign‑in flows that asked users to enter attacker‑provided codes, a technique that can issue valid tokens without stealing passwords.
- Microsoft identified CornFlake, a Go remote‑access trojan, and ChocoShell, an in‑memory PowerShell infostealer, managed through a FruitStone web panel; the malware can steal tokens, credentials, files and record audio or video.
- ReliaQuest first flagged altered SOHO router DNS on July 23, and investigators are probing access to shared captive‑portal services or misconfigured appliances as the likely initial vector while urging travelers to use cellular or VPN, block device‑code flows when not needed, disable WPAD, and deploy passkeys.