Adversary Intelligence — 2026-08-03

Russian SVR-Linked Hackers Compromise Hotel Wi-Fi Networks Worldwide for Credential Theft and Espionage

BLUFStorm-2945's use of shared captive-portal infrastructure and device code phishing creates a collection threat against traveling personnel that per-hotel remediation and standard MFA cannot close.

Microsoft reported that Storm-2945, a sub-cluster of the Russia-linked Midnight Blizzard group tied to the SVR, has since early May been manipulating DNS and HTTP traffic on hotel and conference-center Wi-Fi captive portals worldwide in a campaign it tracks as CaptiveCrunch, redirecting guests toward credential theft and malware 12. Compromised networks have been identified across multiple US cities, India, and Saudi Arabia, according to ReliaQuest, which first disclosed the activity on July 23 3. The campaign delivers CornFlake, a Golang remote access trojan capable of keylogging, webcam and microphone capture, and browser credential theft, and ChocoShell, an in-memory PowerShell infostealer that harvests Microsoft 365 tokens and Wi-Fi credentials, both via fake browser or OS update pages using ClickFix techniques 12. Microsoft attributes the activity to Storm-2945 rather than APT28, the attribution ReliaQuest's earlier reporting had suggested based on tactical similarities 34, and says some landing pages have since July 16 added device code phishing against Microsoft Entra ID 4.

Analysis
Storm-2945's use of shared captive-portal infrastructure across hotels and conference venues means remediation cannot proceed property by property; any site sharing the same portal management system stays exposed until the initial access vector is identified. Attributing the campaign to Storm-2945 rather than APT28 recasts it as SVR-directed foreign intelligence collection against traveling officials and executives, a different threat than the GRU-style disruptive access initially suggested. The tactical overlap with Forest Blizzard's router-hijacking operations and shared equipment signatures across venues plausibly point to a common access broker or compromised managed-service vendor rather than direct intrusion into each property. The July 16 addition of device code phishing against Entra ID lets operators hijack an already-MFA-satisfied session without a password, closing only if device code flow is separately restricted beyond standard MFA policy. Sourcing rests on a single primary account, with other outlets republishing without independent corroboration of scope or malware samples.
4 sources
  1. CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft - Microsoft Security Blog
  2. Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware - The Hacker News
  3. Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says - The Record
  4. Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens - Security Affairs

View in full brief →

UNCLASSIFIED // OPEN SOURCE