OFICIAL Microsoft Source Gadgets · Aug 03, 2026

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

In brief · 4 sentences
Based on Microsoft Source · Aug 03, 2026

Microsoft reports a new espionage campaign by Midnight Blizzard’s Storm-2945 targeting travelers via manipulated Wi-Fi networks, delivering malware and stealing credentials through fake updates and phishing.

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Microsoft Source — Microsoft
Key points
·
Main topic: captiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft.
·
Category affected: gadgets and hardware.
·
Figures mentioned: 2945, 2026, 23.
·
The information comes from an official source.
·
The next step is to watch availability, pricing and real-world impact.

The useful question is what changes for users, developers or buyers, and whether the announcement stays industry context or becomes something people can actually use.

Since early May 2026, Microsoft Threat Intelligence has tracked Storm-2945, a subgroup of the Russia-linked Midnight Blizzard, conducting attacks on hospitality sector networks using captive portals worldwide. The campaign, dubbed CaptiveCrunch, involves DNS and HTTP traffic manipulation to redirect users to actor-controlled infrastructure, enabling adversary-in-the-middle phishing and malware delivery, including Windows and Android variants. Microsoft assesses the goal is to compromise corporate travelers’ accounts, leveraging AI to support operations and mimic Microsoft services via doppelganger domains.

Storm-2945 has deployed malware such as CornFlake, a persistent Windows RAT written in Go, which establishes redundant persistence mechanisms and communicates via encrypted channels using ephemeral keys. The malware includes a modular platform with an HTTP API for tasking companion payloads like ChocoShell, an in-memory infostealer designed to extract browser session cookies, passwords, Microsoft 365 SSO tokens, and Wi-Fi credentials from compromised systems.

ChocoShell employs multiple evasion techniques, including disabling AMSI, evading behavioral detection, and using sandbox checks to avoid analysis. It communicates with its C2 server via HTTPS with URI paths mimicking legitimate traffic, such as /t/pixel.gif?m=, and exfiltrates data as GZip-compressed, Base64-wrapped JSON to /t/event. The script requires administrative privileges for its most impactful capabilities, including SYSTEM token impersonation and Defender signature locking.

Microsoft attributes Storm-2945 to Midnight Blizzard based on technical and operational overlaps, including prior device code and OAuth phishing operations. Midnight Blizzard, attributed to Russia’s SVR by the US and UK governments, focuses on long-term espionage to support Russian foreign policy interests, often compromising valid accounts or abusing OAuth applications to move laterally within cloud environments.

Original source → Deals on Clipraptor.com →
Extracted signals · detected in the story
CaptiveCrunchMidnight BlizzardStorm-2945RussianMaySinceMicrosoft Threat IntelligenceDespiteTTPForest Blizzard DNS29452026233652372