FruitStone is a web-based command-and-control management panel associated with the Storm-2945 intrusion set and the CaptiveCrunch campaign, which has been linked to the Russia-aligned Midnight Blizzard/APT29 ecosystem. It is branded as a fictitious enterprise cloud administration product, commonly presented as CloudSync Console, and serves as the centralized operator interface for managing compromised endpoints and campaign infrastructure.
The panel is used to administer infected systems, deploy and configure payloads, review collected data, and coordinate multi-stage operations. Reported operator functions include browsing victim files, executing PowerShell commands, capturing screenshots, collecting keystrokes, and managing implants such as CornFlake. FruitStone has also been described as supporting payload building and broader infrastructure administration for the campaign.
FruitStone is part of an espionage-oriented operation targeting travelers and organizations through compromised captive-portal and hospitality Wi-Fi ecosystems, with downstream targeting affecting sectors such as government, diplomacy, academia, defense, aerospace, nonprofits, and think tanks. Its role is not initial compromise itself, but centralized post-compromise control, tasking, and review of stolen information from infected Windows hosts. The panel has been described as exposed on the internet and, in some reporting, lacking effective authentication on administrative functions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Operators manage compromised systems, deploy payloads, and review stolen data through FruitStone, an unauthenticated web-based C2 panel branded as CloudSync Console.
Operators manage compromised systems, deploy payloads, and review stolen data through FruitStone, an unauthenticated web-based C2 panel branded as CloudSync Console.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
CornFlake is a Go-based remote access trojan with a broad capability set: remote shell access, keylogging, clipboard monitoring, screenshot capturing, microphone and webcam surveillance...
ChocoShell is a PowerShell credential stealer that targets cookie files... The malware has been identified as targeting access and refresh tokens for Microsoft 365 and Azure Active Directory, thereby allowing attackers to potentially hijack enterprise sessions without requiring users to enter their credentials again.
Microsoft also discovered an unprotected web-based management panel, FruitStone, which the threat actor used to manage infected systems, browse victim files, execute PowerShell commands, and capture screenshots and keystrokes.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A centralized web-based command-and-control panel used to manage compromised endpoints, deploy payloads, and review stolen data.
A web-based command-and-control panel used by operators to manage compromised systems, deploy payloads, and review stolen data associated with the CaptiveCrunch campaign.
A web-based command-and-control panel used by operators to manage compromised systems, deploy payloads, and review stolen data associated with the campaign.
A web-based management panel used by the threat actor to manage infected systems, browse victim files, execute PowerShell commands, and capture screenshots and keystrokes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.