Adversary Intelligence — 2026-08-07

Russian SVR-Linked Hackers Intercepted Hotel WiFi Worldwide to Steal Officials and Executives Data

BLUFStorm-2945's exploitation of shared venue Wi-Fi infrastructure creates a collection threat that individual hotels cannot remediate, leaving traveling officials exposed until Microsoft identifies the initial access vector.

Microsoft Threat Intelligence reported on July 31 that a Russia-linked group it tracks as Storm-2945, a sub-cluster of Midnight Blizzard and associated with the SVR, has been intercepting DNS and HTTP traffic on hotel, conference-center, and shared-venue Wi-Fi networks worldwide since early May, with device-code and OAuth phishing activity dating to February 12. The operation, which Microsoft named CaptiveCrunch, redirects victims to fake Microsoft 365 login pages or delivers malware through spoofed browser and operating-system update prompts and ClickFix "verification" scripts 12. Microsoft identified two malware families used in the campaign: CornFlake, a Go-based remote-access trojan with keylogging, webcam and microphone surveillance, and credential-theft capabilities, and ChocoShell, a PowerShell infostealer targeting browser cookies, Microsoft 365 tokens, and Wi-Fi passwords, both controlled through an unprotected web panel called FruitStone that researchers could access directly 2. Microsoft assessed the malware was likely developed with AI assistance based on code comments found in the samples 2. BleepingComputer noted the campaign was earlier disclosed by cybersecurity firm ReliaQuest and that Microsoft has also found evidence the group is attempting to deliver malicious Android APK files 2.

Analysis
Microsoft's formal unmasking of Storm-2945 hands defenders a name and toolset, but the shared captive-portal infrastructure behind CaptiveCrunch cannot be patched hotel by hotel, and the initial access vector remains unidentified, leaving traveling officials and executives exposed at any venue on the same portal systems. The group's push toward Android APK delivery extends collection onto devices treated as personal and less scrutinized. Sourcing rests on a single Microsoft technical disclosure, with BleepingComputer and other outlets summarizing rather than independently verifying; the AI-assisted malware and commodity-style FruitStone control panel may instead reflect SVR-linked operators borrowing criminal-market tooling rather than fielding a purpose-built intelligence platform.
3 sources
  1. Hackers linked to Russia Foreign Intelligence Service intercepted hotel Wi-Fi worldwide to steal officials and executives data - The Insider
  2. Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts - BleepingComputer
  3. CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft - Microsoft Security Blog

View in full brief →

UNCLASSIFIED // OPEN SOURCE