FruitStone is a web-based command-and-control and operations panel used by Storm-2945, a sub-cluster of the Russia-linked espionage actor Midnight Blizzard (APT29), in the CaptiveCrunch campaign. It is presented to operators as a fictitious enterprise cloud management product branded as CloudSync Console and serves as the central management interface for compromised systems and associated malware operations.
The panel is used to administer infected endpoints, particularly systems running the CornFlake implant, and to coordinate broader campaign infrastructure. Reported functions include viewing and managing compromised hosts, deploying payloads, browsing victim files, executing PowerShell commands, reviewing stolen data, and collecting surveillance output such as screenshots and keystrokes. Multiple accounts describe FruitStone as the interface through which operators managed agents and monitored exfiltrated information. Some reporting also indicates integrated payload-building capability and support for multi-operator use.
FruitStone is associated with attacks against travelers and enterprise users connecting through compromised captive-portal Wi-Fi environments at hotels, conference centers, and similar venues. In that activity, Storm-2945 manipulated captive-portal traffic to redirect victims to phishing pages and fake update lures that delivered Windows malware including CornFlake and ChocoShell. Within that intrusion set, FruitStone functioned as the operator-facing control layer rather than the endpoint implant itself.
High-confidence reporting consistently characterizes FruitStone as a web-based C2 panel used for post-compromise management, tasking, and review of stolen data in support of credential theft and espionage operations targeting Microsoft 365 and related enterprise access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Operators manage compromised systems, deploy payloads, and review stolen data through FruitStone, an unauthenticated web-based C2 panel branded as CloudSync Console.
Operators manage compromised systems, deploy payloads, and review stolen data through FruitStone, an unauthenticated web-based C2 panel branded as CloudSync Console.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
CornFlake is a Go-based remote access trojan with a broad capability set: remote shell access, keylogging, clipboard monitoring, screenshot capturing, microphone and webcam surveillance...
ChocoShell is a PowerShell credential stealer that targets cookie files... The malware has been identified as targeting access and refresh tokens for Microsoft 365 and Azure Active Directory, thereby allowing attackers to potentially hijack enterprise sessions without requiring users to enter their credentials again.
Microsoft also discovered an unprotected web-based management panel, FruitStone, which the threat actor used to manage infected systems, browse victim files, execute PowerShell commands, and capture screenshots and keystrokes.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A web-based command-and-control panel used by operators to manage compromised systems, deploy payloads, and review stolen data associated with the CaptiveCrunch campaign.
A web-based command-and-control panel used by operators to manage compromised systems, deploy payloads, and review stolen data associated with the campaign.
A web-based management panel used by the threat actor to manage infected systems, browse victim files, execute PowerShell commands, and capture screenshots and keystrokes.
A malicious control panel/backdoor component used to oversee the operation, disguised as 'Cloud Sync Console' from a fictional vendor to appear benign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.