← Back to Daily Briefing

The "CaptiveCrunch" campaign, attributed to the Russian state-sponsored actor Storm-2945 (a Midnight Blizzard sub-cluster), targets global travelers by compromising hospitality WiFi gateways. The attack utilizes DNS hijacking and poisoning to redirect users from legitimate captive portals to malicious, Microsoft-themed phishing sites. This redirection facilitates two primary objectives: the theft of Microsoft 365 credentials through OAuth token interception and the deployment of the CornFlake Remote Access Trojan (RAT). CornFlake enables persistent endpoint surveillance, including keystroke logging and audio/visual interception. This sophisticated operation, active since May 2026, represents a high-severity threat to enterprise users traveling internationally.

  • Incident Overview: The CaptiveCrunch Campaign

    • Targeting global travelers through the compromise of hotel WiFi gateways and hospitality sign-in portals.
    • Operational timeline shows the campaign has been active since at least May 2026.
    • High-severity threat profile characterized by state-sponsored intelligence gathering and widespread credential theft.
  • Attack Mechanics: DNS Hijacking and Redirection

    • Employs DNS poisoning and hijacking to intercept legitimate network traffic at the gateway level.
    • Redirects unsuspecting users to highly convincing, Microsoft-themed phishing landing pages.
    • Utilizes "ClickFix" pages and fraudulent browser update prompts to trick users into executing malicious payloads.
  • Threat Actor Profile: Midnight Blizzard/Storm-2945

    • Attributed to Storm-2945, a specialized operational sub-cluster of the Midnight Blizzard threat group.
    • Identified as a sophisticated Russian state-sponsored entity focused on high-value intelligence.
    • Leverages opportunistic infrastructure (hospitality networks) to reach enterprise-level targets.
  • Payload Analysis: Credential Theft and CornFlake RAT

    • Facilitates OAuth token theft to compromise Microsoft 365 accounts and bypass traditional MFA.
    • Deploys the CornFlake Remote Access Trojan (RAT) for deep-level endpoint surveillance.
    • CornFlake provides capabilities for webcam image capture, microphone audio interception, and keystroke logging.
  • Defensive Actions and Mitigations

    • Transition to phishing-resistant MFA (such as FIDO2/WebAuthn) to mitigate the risk of OAuth token theft.
    • Implement robust DNS security monitoring to detect unauthorized hijacking or poisoning attempts.
    • Deploy advanced Endpoint Detection and Response (EDR) to identify the specific surveillance behaviors of the CornFlake RAT.

Related posts

  1. Risky Business Newsletters — Risky Bulletin: Russia is behind the recent hotel WiFi hacks
  2. Ic3
  3. Microsoft Security Blog — CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
  4. feeds.feedburner.com — Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
  5. Technewsworld
  6. Riskybiznews
  7. Hackread
  8. SecurityWeek — Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials

LINK COPIED TO CLIPBOARD