CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Microsoft reports that the Midnight Blizzard sub-cluster Storm-2945 has conducted a global malware campaign since May 2026, targeting travelers via compromised hospitality Wi-Fi networks to steal credentials and deliver malware.
Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, manipulating DNS and HTTP traffic on hospitality sector networks using captive portals to redirect users to actor-controlled infrastructure. The campaign, named CaptiveCrunch, involves widespread but targeted attacks that deliver malware and steal credentials, including through adversary-in-the-middle phishing operations mimicking Microsoft services. The threat actor has leveraged AI to support portions of these operations, according to Microsoft’s assessment.
Microsoft identified multiple malware variants delivered during these attacks, including fully-featured Windows remote access trojans written in Golang, such as CornFlake, which provides system enumeration, file collection, keystroke logging, and remote shell access. The malware establishes persistence through redundant mechanisms, including a Windows service mimicking legitimate processes, and communicates via encrypted channels using ephemeral keys to evade detection. Android devices may also be targeted, with similar techniques observed in phishing landings.
Storm-2945 has compromised Wi-Fi networks at hospitality venues, conference centers, and other shared locations in several countries, primarily to target corporate travelers. The threat actor’s operations align with Midnight Blizzard’s known espionage objectives, which focus on long-term intelligence collection in support of Russian foreign policy interests, often targeting governments, NGOs, and IT service providers in the US and Europe.
Microsoft has provided detailed mitigation, detection, and hunting guidance to help organizations defend against Storm-2945 and related activity. The company also shared technical analysis of the campaign’s malware, tradecraft, and infrastructure, including the Powershell-based infostealer ChocoShell, which extracts browser session cookies, saved passwords, and Microsoft 365 SSO tokens from compromised systems.