ChocoShell is an in-memory PowerShell infostealer used in the CaptiveCrunch espionage campaign attributed to Storm-2945, a sub-cluster of Midnight Blizzard (APT29), which has been linked by Western governments to Russia’s SVR. It is used primarily against Windows systems, especially in operations targeting travelers through compromised captive-portal environments at hotels, conference centers, and similar venues. In observed activity, victims were redirected from hostile captive portals to fake update or ClickFix-style pages that led to execution of ChocoShell entirely in memory, sometimes alongside or via the CornFlake implant.
Its core function is credential and session theft. ChocoShell harvests browser cookies and saved passwords, Microsoft 365 single sign-on material, Azure AD and Web Account Manager tokens, and stored Wi-Fi credentials. Reported tradecraft also includes theft of Token Broker cache artifacts to obtain access and refresh tokens that can support session replay and cloud access without requiring the victim to re-enter credentials. Browser-focused collection includes techniques to access protected Chromium data and plaintext cookies, including methods described as bypassing Chrome App-Bound Encryption.
ChocoShell incorporates multiple defense-evasion and privilege-abuse measures. It disables AMSI via .NET reflection, performs sandbox and virtual-machine detection, and uses silent UAC bypass techniques with fallback options. Reporting also describes SYSTEM token impersonation to access protected browser material. Data is exfiltrated over HTTPS to command-and-control endpoints disguised to resemble benign web traffic. Within the broader intrusion set, ChocoShell complements CornFlake by rapidly extracting high-value credentials and session artifacts that enable follow-on access to enterprise cloud environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Microsoft also found evidence that the group used AI tools to assist operations, including the development of the CornFlake and ChocoShell malware.
Microsoft also found evidence that the group used AI tools to assist operations, including the development of the CornFlake and ChocoShell malware.
CornFlake exposes a localhost HTTP API server to transform the malware into a modular platform, delivering additional payloads such as ChocoShell, a PowerShell-based infostealer. ChocoShell is delivered and executed entirely in-memory.
CornFlake exposes a localhost HTTP API server to transform the malware into a modular platform, delivering additional payloads such as ChocoShell, a PowerShell-based infostealer. ChocoShell is delivered and executed entirely in-memory.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The campaign abuses captive portal networks at hotels, conference centers, and similar venues to redirect victims to attacker-controlled infrastructure.
Using this technique, they were able to redirect users to fraudulent Microsoft 365 login pages, phishing portals containing device codes, or fake software update screens when connecting to hotel Wi-Fi. | Microsoft observed the scheme expanding to include Microsoft Entra device code phishing, in which the victims are tricked into completing a legitimate Microsoft authentication process that unknowingly allows the attackers' session to be authorized instead of their own.
Additional defense evasion and privilege abuse across the toolset include SYSTEM token impersonation
OAuth code phishing and doppelganger domains mimicking Microsoft services support the same objective.
Additional defense evasion and privilege abuse across the toolset include ... Volume Shadow Copy Service abuse
Additional defense evasion and privilege abuse across the toolset include SYSTEM token impersonation
ChocoShell ... escalates privileges using silent User Account Control (UAC) bypass techniques (such as SilentCleanup task hijack, wsreset.exe COM hijack, and sdclt.exe folder hijack)
ChocoShell runs entirely in memory, disabling the Antimalware Scan Interface (AMSI) before harvesting browser cookies, saved passwords, Microsoft 365 single sign-on tokens and Wi-Fi credentials.
ChocoShell harvests browser cookies and passwords using ChromeKatz-derived techniques, Chrome ABE bypass, Firefox NSS/SDR decryption, and Chrome DevTools Protocol remote debugging for cookie extraction.
It also harvests Microsoft 365 and Azure AD/WAM tokens from the Token Broker cache, as well as Wi-Fi credentials via netsh wlan .
ChocoShell harvests browser cookies and passwords using ChromeKatz-derived techniques, Chrome ABE bypass, Firefox NSS/SDR decryption
After compromising captive portal equipment or shared infrastructure, Storm-2945 manipulates DNS and HTTP traffic on the network. When a victim connects to Wi-Fi and encounters the captive portal login prompt, traffic is redirected through an Adversary-in-the-Middle (AitM) position to attacker-controlled infrastructure
After compromising captive portal equipment or shared infrastructure, Storm-2945 manipulates DNS and HTTP traffic on the network. When a victim connects to Wi-Fi and encounters the captive portal login prompt, traffic is redirected through an Adversary-in-the-Middle (AitM) position to attacker-controlled infrastructure
Collected data is compressed, encoded, and exfiltrated via HTTPS POST to C2 endpoints disguised as tracking pixels and JavaScript polyfill files.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware developed and used in support of the CaptiveCrunch campaign; the content indicates it was part of operations involving credential theft and malicious APK delivery, but gives no further functionality details.
An in-memory PowerShell stealer that disables AMSI, performs sandbox/VM detection, uses UAC bypass techniques, steals browser cookies and passwords, harvests Microsoft 365 and Azure AD/WAM tokens from the Token Broker cache, collects Wi-Fi credentials, and exfiltrates data over HTTPS POST to C2 endpoints disguised as tracking pixels and JavaScript polyfill files.
An in-memory PowerShell stealer that disables AMSI, performs sandbox/VM detection, uses UAC bypass techniques, steals browser cookies and passwords, harvests Microsoft 365 and Azure AD/WAM tokens, collects Wi-Fi credentials, and exfiltrates data over HTTPS to disguised C2 endpoints.
An in-memory PowerShell credential stealer that targets browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.