Microsoft Threat Intelligence and Zscaler reported that Storm-2945, a sub-cluster of Midnight Blizzard / APT29 linked to Russia, has been compromising shared captive-portal infrastructure at hotels, conference centers, and similar venues to intercept traveler traffic and steal Microsoft 365 credentials. The operation, dubbed CaptiveCrunch, manipulates DNS and HTTP flows to redirect victims from legitimate Wi-Fi login pages to attacker-controlled phishing and malware-delivery sites, including lures for Microsoft Entra ID device code phishing and ClickFix-style fake updates. Activity has been observed in multiple U.S. cities as well as India and Saudi Arabia, indicating a broad campaign aimed at travelers across sectors.
Researchers said the campaign deploys multiple payloads after credential theft, including CornFlake, a Go-based Windows RAT used for persistence and surveillance, and ChocoShell, an in-memory PowerShell stealer designed to collect browser secrets, Microsoft 365 and Azure AD/WAM tokens, and Wi-Fi credentials. The operation has also expanded to Android through malicious APKs, and Microsoft assessed that AI-assisted tooling supported parts of the intrusion set, including development of CornFlake and ChocoShell. The reporting indicates the attackers are using trusted hospitality network infrastructure as an initial access vector to harvest identities and extend compromise onto victim devices.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft Threat Intelligence reported the ongoing CaptiveCrunch campaign, which steals credentials by abusing captive portal infrastructure at hotels, conference centers, and similar venues. The campaign was attributed to Storm-2945, a sub-cluster of Midnight Blizzard/APT29.
Subsequent reporting described how Storm-2945 redirected victims on compromised captive portal networks to Microsoft 365 phishing, Entra ID device code phishing, ClickFix-style fake update pages, and Android APK delivery. The reporting also identified the CornFlake Windows RAT and ChocoShell PowerShell stealer as malware used in the campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
schneier.com
Open sourcecommunity.gurucul.com
Open sourcemalware.news
Open sourcezscaler.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.