Storm-2945 is an operational sub-cluster of Midnight Blizzard, the Russia-linked espionage threat actor also tracked as APT29, Cozy Bear, NOBELIUM, BlueBravo, and the Dukes. Midnight Blizzard has been publicly linked by Western governments to Russia’s Foreign Intelligence Service (SVR), and Storm-2945 is assessed to operate in support of that broader espionage mission. Storm-2945 is associated with the CaptiveCrunch campaign, active since at least early 2026, which targeted travelers through compromised captive-portal infrastructure used by hotels, conference centers, and other shared hospitality venues. The actor manipulated DNS and HTTP traffic on affected networks to place itself in an adversary-in-the-middle position and redirect victims to attacker-controlled phishing and malware-delivery pages. Observed lures included Microsoft 365 credential-harvesting pages, Microsoft Entra ID device-code phishing flows, OAuth-related phishing, and ClickFix-style fake browser or operating-system update prompts. The campaign appears designed primarily to compromise corporate travelers and gain access to enterprise cloud accounts and associated data. Storm-2945’s malware set includes CornFlake, a Go-based Windows remote access trojan used for persistent access, surveillance, credential theft, and file exfiltration, and ChocoShell, an in-memory PowerShell infostealer focused on browser secrets, Microsoft 365 and Azure AD or Web Account Manager tokens, and Wi-Fi credentials. Reported CornFlake capabilities include keylogging, screenshot capture, microphone and webcam surveillance, USB monitoring, remote shell access, and host reconnaissance, with persistence established through multiple redundant mechanisms. ChocoShell has been observed using AMSI tampering, sandbox and virtual-machine checks, silent UAC-bypass methods, and browser-data extraction techniques to evade defenses and steal high-value authentication material. Operators also used a web-based management panel known as FruitStone to manage implants, payloads, and stolen data. The campaign has also shown expansion beyond Windows to Android through malicious application delivery. Reporting further indicates Storm-2945 incorporated AI-assisted support into parts of its operations, including malware development. Overall, Storm-2945 is best characterized as a Russian state-aligned espionage operator specializing in credential theft, session and token theft, covert malware deployment, persistence, and post-compromise collection against travelers and the organizations to which they connect.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Compromised hotel login portals to deliver malware and steal traveler credentials in Operation CaptiveCrunch.
Conducting an ongoing credential theft campaign that abuses captive portal networks at hotels, conference centers, and similar venues to redirect victims to attacker-controlled infrastructure for Microsoft 365 credential harvesting, device-code phishing, and malware delivery.
Conducting the CaptiveCrunch credential theft campaign by manipulating DNS and HTTP traffic on captive portal networks at hospitality venues to redirect victims to attacker-controlled infrastructure for Microsoft 365 credential harvesting, device code phishing, and malware delivery, including CornFlake and ChocoShell.
Sub-cluster behind the CaptiveCrunch campaign targeting travelers through compromised hotel and conference captive portal infrastructure to steal Microsoft 365 credentials and deploy malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.