OFICIAL Microsoft Source

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

What happened
Based on Microsoft Source · Aug 03, 2026

Microsoft reports that the Midnight Blizzard sub-cluster Storm-2945 has conducted a global malware campaign since May 2026, targeting travelers via compromised hospitality Wi-Fi networks to steal credentials and deliver malware.

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Microsoft Source — Microsoft
Key points
·
Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide.
·
Despite some tactic, technique, and procedure (TTP) similarities to the Forest Blizzard DNS hijacking operation that we publicly disclosed in April 2026, we attribute this campaign, which we call CaptiveCrunch, to Storm-2945.
·
Threat Intelligence has also identified active traffic manipulation attacks leading to the delivery of malware on impacted systems.
·
Microsoft has observed Storm-2945 leveraging AI to support a significant portion of these operations.
Key numbers
·
Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, manipulating DNS and HTTP traffic on hospitality sector networks using captive portals to redirect users to actor-controlled...
·
Storm-2945 has compromised Wi-Fi networks at hospitality venues, conference centers, and other shared locations in several countries, primarily to target corporate travelers.
·
Microsoft has provided detailed mitigation, detection, and hunting guidance to help organizations defend against Storm-2945 and related activity.

Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, manipulating DNS and HTTP traffic on hospitality sector networks using captive portals to redirect users to actor-controlled infrastructure. The campaign, named CaptiveCrunch, involves widespread but targeted attacks that deliver malware and steal credentials, including through adversary-in-the-middle phishing operations mimicking Microsoft services. The threat actor has leveraged AI to support portions of these operations, according to Microsoft’s assessment.

Microsoft identified multiple malware variants delivered during these attacks, including fully-featured Windows remote access trojans written in Golang, such as CornFlake, which provides system enumeration, file collection, keystroke logging, and remote shell access. The malware establishes persistence through redundant mechanisms, including a Windows service mimicking legitimate processes, and communicates via encrypted channels using ephemeral keys to evade detection. Android devices may also be targeted, with similar techniques observed in phishing landings.

Storm-2945 has compromised Wi-Fi networks at hospitality venues, conference centers, and other shared locations in several countries, primarily to target corporate travelers. The threat actor’s operations align with Midnight Blizzard’s known espionage objectives, which focus on long-term intelligence collection in support of Russian foreign policy interests, often targeting governments, NGOs, and IT service providers in the US and Europe.

Microsoft has provided detailed mitigation, detection, and hunting guidance to help organizations defend against Storm-2945 and related activity. The company also shared technical analysis of the campaign’s malware, tradecraft, and infrastructure, including the Powershell-based infostealer ChocoShell, which extracts browser session cookies, saved passwords, and Microsoft 365 SSO tokens from compromised systems.

Original source → Deals on Clipraptor.com →