Overview of the CaptiveCrunch attack flow | Image: Microsoft
At a glance
| Actor or group | Storm-2945, assessed as an operational sub-cluster of Midnight Blizzard |
| Activity type | Traffic manipulation on captive portals, malware delivery, and credential theft |
| Targets or victims | Corporate travelers at hotels, conference centers, and shared venues worldwide |
| Scale | Widespread compromise of Wi-Fi networks at hospitality organizations in several countries; exact victim count not disclosed |
| Jurisdiction or status | Midnight Blizzard is attributed by the US and UK governments to Russia’s Foreign Intelligence Service (SVR); no criminal charges announced for this campaign |
| Source | Microsoft Threat Intelligence, with corroborating research from ReliaQuest |
TL;DR: Microsoft says a group it tracks as Storm-2945 has hijacked hotel and conference-venue Wi-Fi networks since early May 2026. The CaptiveCrunch malware campaign redirects captive portal traffic to push fake software updates and steal credentials. Microsoft assesses Storm-2945 as a sub-cluster of Midnight Blizzard, the Russia-linked group also known as APT29.
What happened
Microsoft Threat Intelligence reports that Storm-2945 has manipulated DNS and HTTP traffic on captive portal networks since early May 2026. Captive portals are the login pages guests see when joining hotel or conference Wi-Fi. According to Microsoft, “we have observed notable commonalities in the equipment and management systems used across multiple affected networks.”
That overlap suggests the CaptiveCrunch malware campaign might exploit shared infrastructure rather than hitting each venue one at a time. Once a device joins a compromised network, the attackers intercept its automatic connectivity check and serve a fake browser or operating system update instead.
Victims who click through are prompted using ClickFix-style instructions that walk them through manually downloading and running the payload. Microsoft also found evidence the group targets Android devices, since the same landing pages include instructions to install an APK file.
The earlier stages of this activity date back further than the Wi-Fi hijacking itself. Since February 2026, Storm-2945 had already run separate device code and OAuth code phishing campaigns aimed at Microsoft 365 accounts, well before the captive portal activity began.
Who is behind it
Microsoft attributes the CaptiveCrunch malware campaign to Storm-2945 with direct confidence, based on its own telemetry. The link between Storm-2945 and Midnight Blizzard is stated as an assessment, not a certainty, resting on overlapping tactics with a previously tracked sub-cluster called Storm-2372.
Midnight Blizzard itself carries a firmer, government-level attribution. US and UK authorities have named the group as linked to Russia’s SVR foreign intelligence service. Officials have not filed criminal charges tied specifically to CaptiveCrunch, and no individuals have been named as suspects.
The malware toolkit
Microsoft’s report details three custom tools used in the campaign. A Go-based remote access trojan gives the operators keylogging, screenshot, and webcam capabilities on infected Windows machines. A PowerShell-based script then steals browser cookies, saved passwords, and Microsoft 365 sign-in tokens. A separate web panel lets operators manage compromised machines and build new payloads.
The remote access trojan disguises itself with fake progress windows resembling ordinary system updates, so victims see what looks like a routine install rather than an infection. The credential-stealing script runs entirely in memory, leaving little trace on disk for defenders to recover afterward.
Part of the operation, per ReliaQuest’s July 23 findings that Microsoft cites, uses lookalike domains impersonating Microsoft services. These domains support follow-on phishing that abuses a legitimate Microsoft sign-in feature called device code authentication.
Impact and scale
Microsoft describes the compromise as widespread across several countries, without publishing an exact victim count or financial loss figure. ReliaQuest’s independent research links the activity to hotels, conference centers, and other shared venues, with corporate travelers as the apparent target.
The CaptiveCrunch malware campaign appears aimed at corporate accounts rather than individual consumers, consistent with Midnight Blizzard’s historical focus on espionage against governments, NGOs, and IT service providers.
How to stay protected
Treat any hotel or conference Wi-Fi as untrusted, and avoid installing software prompted by a captive portal login page. Legitimate operating system and browser updates never arrive through a Wi-Fi sign-in screen.
Use a VPN when connecting to public or hospitality networks, and enable multi-factor authentication that resists phishing where possible. For the full technical breakdown, including detection rules, see Microsoft’s CaptiveCrunch security blog post. Organizations should also train traveling employees to recognize device code phishing prompts before entering any code into a sign-in page.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.