Midnight Blizzard Subgroup Exploits Hotel Wi-Fi Networks in CaptiveCrunch Espionage Campaign
Microsoft Threat Intelligence identified CaptiveCrunch, an espionage campaign attributed to Storm-2945, a
Attribution to Storm-2945 recasts CaptiveCrunch as SVR-directed foreign intelligence collection against traveling corporate and government personnel rather than opportunistic cybercrime, though the tooling, phishing, and victim-selection overlaps Microsoft cites could instead reflect a shared contractor or leaked toolset used across multiple Russian-aligned units. Shared captive-portal infrastructure spanning multiple hospitality providers means remediation cannot proceed hotel by hotel; venues served by the same portal management system stay exposed until the initial access vector is patched. Detailed source-code comments in the ChocoShell infostealer point to AI-assisted development, suggesting accelerating malware production within Midnight Blizzard's toolset. Reporting rests on a single primary Microsoft disclosure extending, not independently discovering, campaign activity ReliaQuest first flagged July 23. Because organizations cannot verify captive-portal integrity client-side, mitigation falls to network-layer controls: phishing-resistant authentication, OAuth restriction, and avoiding hospitality Wi-Fi for sensitive access.
3 sources
- Russian Hackers Exploit Hotel Wi-Fi in New CaptiveCrunch Espionage Campaign -
The Cyber Express - Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware -
Help Net Security - CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft -
Microsoft Security Blog