Storm-2945 is a Russian cyber-espionage cluster tracked as an operational sub-cluster of Midnight Blizzard, the threat actor attributed to Russia’s Foreign Intelligence Service (SVR). Midnight Blizzard is also known as APT29, Cozy Bear, NOBELIUM, and BlueBravo; these names identify the broader actor rather than interchangeable aliases for Storm-2945. Storm-2945 targets corporate travelers and enterprise accounts through phishing and malware delivery, with affected hospitality networks identified in the United States, India, and Saudi Arabia. The cluster conducts the CaptiveCrunch campaign, whose captive-portal traffic manipulation was observed beginning in early May 2026, following device-code and OAuth phishing activity observed since February 2026. It manipulates DNS and HTTP traffic on compromised hotel, conference-center, and other shared guest networks, redirecting automated connectivity checks to malicious authentication pages or fake software updates. Attack paths combine adversary-in-the-middle phishing, Microsoft Entra ID device-code phishing, and ClickFix social engineering. Device-code phishing induces victims to complete legitimate Microsoft authentication flows that authorize attacker-controlled sessions, enabling access to Microsoft 365 data. Storm-2945’s principal tools include CornFlake, a Go-based Windows remote-access trojan, and ChocoShell, an in-memory PowerShell information stealer. CornFlake provides redundant persistence through services, startup entries, scheduled tasks, and a watchdog, alongside encrypted command-and-control, remote shell access, keylogging, clipboard monitoring, screen capture, microphone and webcam surveillance, credential theft, and file exfiltration. ChocoShell steals browser passwords and cookies, Microsoft 365 and other enterprise authentication tokens, and stored Wi-Fi credentials. It employs anti-malware scanning interface tampering, analysis-environment checks, privilege-escalation techniques, and browser-debugging abuse to obtain protected credentials and session material. Operators use the FruitStone web-based command-and-control panel to manage implants, build payloads, task collection, and review stolen data. The cluster also distributes Android-targeted installation lures and uses AI assistance in its operations and malware development.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
30 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Identified as the operational sub-cluster responsible for CaptiveCrunch. The campaign compromises captive-portal connectivity flows on hospitality-related and other guest networks to deliver CornFlake and ChocoShell and conduct account phishing. Network manipulation was first observed in May 2026; renewed activity beginning September 29 included a Rust variant of CornFlake.
Identified by Microsoft as the Midnight Blizzard operational sub-cluster responsible for CaptiveCrunch. The operation compromises the captive-portal experience on hospitality-related and other guest networks to infect travelers' devices, steal credentials and session tokens, and obtain access to corporate accounts.
Compromised hotel login portals to deliver malware and steal traveler credentials in Operation CaptiveCrunch.
Conducting an ongoing credential theft campaign that abuses captive portal networks at hotels, conference centers, and similar venues to redirect victims to attacker-controlled infrastructure for Microsoft 365 credential harvesting, device-code phishing, and malware delivery.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.