Adversary Intelligence — 2026-08-06

Midnight Blizzard Subgroup Exploits Hotel Wi-Fi Networks in CaptiveCrunch Espionage Campaign

BLUFShared captive-portal infrastructure across hospitality providers gives SVR a scalable collection platform against business travelers that individual organizations cannot detect or remediate from the client side.

Microsoft Threat Intelligence identified CaptiveCrunch, an espionage campaign attributed to Storm-2945, a Midnight Blizzard subgroup linked to Russia's Foreign Intelligence Service, active since early May and targeting business travelers through hotel and conference-center Wi-Fi captive portals, with victims concentrated in financial services, professional services, legal, healthcare, energy, and retail sectors 1. Microsoft reported that the group manipulates DNS and HTTP traffic on public networks to redirect victims to fake Microsoft sign-in pages or malware downloads, and may have compromised shared captive-portal infrastructure used across multiple hospitality providers 1. The campaign deploys two strains, the Go-based CornFlake remote access trojan and the memory-resident ChocoShell infostealer, managed through a web-based platform called FruitStone 1. Help Net Security reported the findings build on earlier, independent research published July 23 by security firm ReliaQuest, which identified compromised captive-portal gateways across multiple US cities, India, and Saudi Arabia 2. Microsoft assessed with high confidence that Storm-2945 operates as part of Midnight Blizzard based on overlaps in tooling, phishing technique, and victim selection 1.

Analysis
Attribution to Storm-2945 recasts CaptiveCrunch as SVR-directed foreign intelligence collection against traveling corporate and government personnel rather than opportunistic cybercrime, though the tooling, phishing, and victim-selection overlaps Microsoft cites could instead reflect a shared contractor or leaked toolset used across multiple Russian-aligned units. Shared captive-portal infrastructure spanning multiple hospitality providers means remediation cannot proceed hotel by hotel; venues served by the same portal management system stay exposed until the initial access vector is patched. Detailed source-code comments in the ChocoShell infostealer point to AI-assisted development, suggesting accelerating malware production within Midnight Blizzard's toolset. Reporting rests on a single primary Microsoft disclosure extending, not independently discovering, campaign activity ReliaQuest first flagged July 23. Because organizations cannot verify captive-portal integrity client-side, mitigation falls to network-layer controls: phishing-resistant authentication, OAuth restriction, and avoiding hospitality Wi-Fi for sensitive access.
3 sources
  1. Russian Hackers Exploit Hotel Wi-Fi in New CaptiveCrunch Espionage Campaign - The Cyber Express
  2. Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware - Help Net Security
  3. CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft - Microsoft Security Blog

View in full brief →

UNCLASSIFIED // OPEN SOURCE