Attackers have been compromising captive portal and hotel Wi-Fi gateway appliances, then changing DNS settings to redirect connected guests to attacker-controlled infrastructure that impersonates Microsoft 365 sign-in pages. ReliaQuest said the activity has hit hotels, conference centers, and similar shared venues in multiple U.S. cities as well as India and Saudi Arabia, affecting travelers from sectors including finance, legal, healthcare, energy, and retail. The campaign uses lookalike domains such as m365-owa.com, owa-ms365.com, ms365-device.com, and ms365-live.com to harvest credentials or lure users into Microsoft device code authentication flows.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
In the observed campaign, attackers used Microsoft-themed domains and in some cases abused Microsoft device code authentication flow to obtain OAuth tokens and MFA-satisfied access to Microsoft 365. In about one-third of investigated cases, they also attempted to exploit WPAD to force Windows devices to fetch malicious proxy auto-configuration files and route traffic through attacker-controlled proxies.
ReliaQuest reported that attackers have been compromising captive portal and hotel Wi-Fi gateway appliances at hotels and conference centers, altering DNS settings to redirect users to attacker-controlled Microsoft 365 phishing infrastructure. The activity has been active since at least June and has been observed in multiple U.S. cities as well as India and Saudi Arabia, affecting travelers across several sectors.
Since July 16, 2026, some CaptiveCrunch landing pages began abusing Microsoft's legitimate device code authentication flow, prompting victims to enter a code on the real sign-in page and authenticate the attackers' session, including MFA completion. Microsoft said this expanded the campaign beyond fake update delivery and credential theft to token-focused account compromise.
Microsoft Threat Intelligence reported that since early May 2026, Storm-2945—assessed as a sub-cluster of Russia-linked Midnight Blizzard—has run the CaptiveCrunch campaign by manipulating captive-portal network traffic to phish travelers and deliver malware. Microsoft also disclosed the CornFlake Windows RAT and ChocoShell PowerShell infostealer as malware used in the operation.
Microsoft reported that attackers controlling hospitality captive portals redirected connectivity checks to fake browser or operating system update pages that tricked victims into downloading and executing the CornFlake RAT. Microsoft said it had observed this traffic-manipulation and malware-delivery activity across hospitality networks in several countries since early May 2026.
Lumen Black Lotus Labs published research on a DNS hijacking campaign dubbed FrostArmada and linked it to Forest Blizzard. The report represents an earlier public disclosure of activity related to the captive-portal and DNS-manipulation tradecraft later covered in the existing timeline.
Microsoft disclosed that the CornFlake RAT and CocoShell/ChocoShell PowerShell infostealer used in the CaptiveCrunch campaign communicated with a previously unseen command-and-control panel called FruitStone. This added new technical detail about the campaign's malware infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
18 references tracked. Mallory keeps watching after this page renders.
blog.knowbe4.com
Open sourceinfosecurity-magazine.com
Open sourcenews.risky.biz
Open sourcesecurityaffairs.com
Open sourcereliaquest.com
Open sourcelumen.com
Open sourcevolexity.com
Open sourcencsc.gov.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.