Storm-2945 is a Russia-linked threat actor assessed to be an operational sub-cluster of Midnight Blizzard, the espionage group widely attributed to the Russian Foreign Intelligence Service (SVR). Since at least early 2026, the actor has conducted the CaptiveCrunch campaign, targeting hospitality and other captive-portal-served networks worldwide in order to compromise travelers, particularly corporate users, and gain access to enterprise identities and cloud resources. The group is notable for manipulating DNS and HTTP traffic on affected captive-portal environments to redirect victims through adversary-in-the-middle phishing infrastructure and counterfeit Microsoft-themed authentication experiences. A key tradecraft element is abuse of Microsoft Entra ID device code authentication and related OAuth phishing to capture authenticated sessions and enable subsequent access to Microsoft 365 and other enterprise environments. The actor has also used social engineering, including ClickFix-style lures, and has reportedly incorporated AI support into a significant portion of its operations. Storm-2945 delivers malware disguised as browser or operating system updates. Two principal malware components have been associated with the cluster. CornFlake is a Go-based Windows remote access trojan used as a primary persistent implant. It supports redundant persistence mechanisms, encrypted command-and-control, remote shell access, keylogging, clipboard and screenshot capture, microphone and webcam surveillance, browser credential theft, USB monitoring, security posture collection, and file exfiltration. ChocoShell is an in-memory PowerShell infostealer focused on harvesting browser cookies and saved passwords, Microsoft 365 and Azure-related tokens, Web Account Manager material, and Wi-Fi credentials. ChocoShell also employs defense-evasion and privilege-escalation techniques including AMSI bypass, sandbox evasion, and silent UAC bypass methods. Operators use a web-based command-and-control management panel known as FruitStone to administer compromised endpoints, manage payloads, browse files, run remote shell tasks, push configuration changes, and collect stolen data. Reporting has also noted indications of Android targeting through instructions to install mobile application packages from malicious landing pages. Victimology centers on hospitality venues and other shared-network environments, with the apparent objective of compromising corporate travelers and collecting intelligence from downstream enterprise accounts and cloud tenants. The campaign’s tactics, victimology, and identity-focused collection align with Midnight Blizzard’s broader long-running espionage mission.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
47 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.