FILTERING BY: CLEAR FILTER

Midnight Blizzard and the 'CaptiveCrunch' Campaign Targeting Microsoft 365 via Hotel WiFi

The "CaptiveCrunch" campaign, attributed to the Russian state-sponsored actor Storm-2945 (a Midnight Blizzard sub-cluster), targets global travelers by compromising hospitality WiFi gateways. The attack utilizes DNS hijacking and poisoning to redirect users from legitimate captive portals to malicious, Microsoft-themed phishing sites. This redirection facilitates two primary objectives: the theft of Microsoft 365 credentials through OAuth token interception and the deployment of the CornFlake Remote Access Trojan (RAT). CornFlake enables persistent endpoint surveillance, including keystroke logging and audio/visual interception. This sophisticated operation, active since May 2026, represents a high-severity threat to enterprise users traveling internationally.

The CINEMAGOAL Evolution: From Piracy App to Credential Harvesting Engine

Italian law enforcement, including the Polizia Postale and Guardia di Finanza, has successfully disrupted the CINEMAGOAL ecosystem, a sophisticated mobile operation that evolved from a simple piracy application into a high-scale credential-harvesting platform. By leveraging malicious mobile binaries (APK/IPA) to perform session hijacking and Man-in-the-Middle (MitM) attacks, the app exfiltrated authentication tokens and session codes from legitimate users of major streaming services like Netflix, Disney+, and Spotify. This shift from content redistribution to active identity theft poses a significant threat to the streaming economy, necessitating enhanced scrutiny of mobile application behavior and session management protocols to prevent large-scale account takeovers.


LINK COPIED TO CLIPBOARD