Microsoft linked the CaptiveCrunch campaign to Storm-2945, a subgroup of the Russian state-backed Midnight Blizzard actor, after attackers compromised captive portal ecosystems used by hospitality organizations and other shared public venues. By manipulating DNS and HTTP traffic on public Wi-Fi gateway infrastructure, the group conducted adversary-in-the-middle (AiTM) attacks that intercepted login flows and stole Microsoft 365 credentials from traveling employees across multiple sectors.
The operation also pushed follow-on malware and phishing lures through the hijacked portals. Victims were shown fake browser update prompts delivering malware including CornFlake and ChocoShell, alongside ClickFix-style social engineering and malicious Android APK prompts; some recent landing pages also added device code phishing, a technique Microsoft said Midnight Blizzard has used since 2024. The campaign has reportedly been active since May and focused on hospitality-linked networks and other public access environments where users expect captive portal authentication.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Microsoft said CaptiveCrunch operators may redirect Android users on targeted captive portals to download malicious APK files. The warning expanded the campaign's known impact from credential theft to possible persistent compromise of Android devices, including credential harvesting and activity monitoring.
Microsoft said Storm-2945 began manipulating DNS and HTTP traffic from captive portal networks in May 2026. The campaign targeted hospitality-related and other shared-venue Wi-Fi environments to steal Microsoft 365 credentials using adversary-in-the-middle techniques.
Microsoft said phishing OAuth activity associated with the CaptiveCrunch campaign was observed as early as February 2026, predating the captive-portal traffic-manipulation phase. This indicates the operation was active in an earlier credential-theft stage before the May 2026 Wi-Fi manipulation activity.
Microsoft said the device code phishing activity seen in recent CaptiveCrunch landing pages is consistent with Midnight Blizzard operations previously reported since August 2024.
Microsoft discovered an unprotected web-based management panel called FruitStone used by the CaptiveCrunch operators to manage infected systems. The panel allowed browsing victim files, executing PowerShell commands, and capturing screenshots and keystrokes.
Microsoft attributed the public Wi-Fi gateway credential theft campaign dubbed CaptiveCrunch to Storm-2945, a subgroup of the Russian state-linked Midnight Blizzard threat actor. It also reported widespread compromise of captive-portal-serviced networks in several countries and described malware including CornFlake and ChocoShell.
Microsoft said that over the prior two weeks, some CaptiveCrunch landing pages redirected victims to Microsoft device code authentication flow experiences. The pages instructed victims to enter device codes to authenticate the threat actor's session.
ReliaQuest observed attackers modifying DNS configurations on compromised SOHO routers to redirect users to attacker-controlled infrastructure. SecurityWeek reported this was flagged roughly a week before Microsoft's attribution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
ghacks.net
Open sourcecysecurity.news
Open sourcescworld.com
Open sourcemalware.news
Open sourcesecurityweek.com
Open sourcecyberveille.ch
Open sourcethreats.wiz.io
Open sourcepushsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.