Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Midnight Blizzard Targets Travelers via Captive Portals

August 3, 2026

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

August 3, 2026

Chinese Threat Actors Weaponize New Vulnerabilities in Under a Day

August 3, 2026
Facebook X (Twitter) Instagram
Monday, August 3
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Midnight Blizzard Targets Travelers via Captive Portals
News

Midnight Blizzard Targets Travelers via Captive Portals

Team-CWDBy Team-CWDAugust 3, 2026No Comments5 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Captive portals on hotel and conference Wi-Fi networks have been hijacked to route guests through attacker infrastructure, serving fake browser and operating system updates that install Russian espionage malware.

According to research published by Microsoft Threat Intelligence on July 31, the campaign, which it named CaptiveCrunch, has run since early May and is attributed to Storm-2945, a sub-cluster of Midnight Blizzard.

The US and UK government have previously attributed Midnight Blizzard (also known as APT29, the Dukes, or Cozy Bear) to Russia’s Foreign Intelligence Service, the SVR.

Microsoft is still investigating how the portals were compromised but noted commonalities in the equipment and management systems across affected networks, which it said could reflect access to shared services within the captive portal ecosystem rather than isolated venue compromises.

Read more on Russian device code phishing: Russian Hackers Target Microsoft 365 Accounts with Device Code Attacks

Fake Updates Triggered by Connectivity Checks

Rather than waiting for a user to visit a website, the threat actor answered the automated connectivity checks that browsers and operating systems issue on joining a new network. Those checks returned pages offering browser or system updates.

The landings used ClickFix techniques, presenting fake verification failures with paste-and-run instructions. Microsoft said some also served an APK, indicating possible Android targeting.

From July 16, some pages redirected users into device code authentication flows, instructing them to enter an attacker-supplied code on a genuine Microsoft sign-in page.

Microsoft said the technique was not new but embedding it in a captive portal made the request more likely to seem legitimate.

ReliaQuest, which reported part of the activity on July 23, found it at hotels, conference centers and other shared venues, targeting corporate travelers’ accounts.

Three Tools, One Cover Story

The primary implant is CornFlake, a Go remote access trojan (RAT) that displays a fake progress window while installing itself, then registers as a Windows service with the display name Cloud Sync Service.

It carries keylogging, screenshots, microphone and webcam surveillance, browser credential theft and a remote shell, plus a watchdog routine that restores any persistence mechanism defenders remove.

A PowerShell infostealer called ChocoShell runs entirely in memory, disabling the Antimalware Scan Interface (AMSI) before harvesting browser cookies, saved passwords, Microsoft 365 single sign-on tokens and Wi-Fi credentials.

Its developer comments named specific Microsoft detection signatures and explained each evasion choice, which Microsoft said suggested AI-assisted code generation. The company said the actor used AI across a significant portion of the operation and thanked Anthropic and OpenAI for their support during the investigation.

Operators run the campaign from FruitStone, a web panel branded as a fictitious enterprise cloud product, matching the implant’s cover story.

Microsoft’s recommendations include treating hotel, conference and airport wireless as untrustworthy, preferring cellular or eSIM connectivity and never installing software offered through a captive portal. It also advised blocking device code flow where it is not required and deploying passkeys.

Captive portals on hotel and conference Wi-Fi networks have been hijacked to route guests through attacker infrastructure, serving fake browser and operating system updates that install Russian espionage malware.

According to research published by Microsoft Threat Intelligence on July 31, the campaign, which it named CaptiveCrunch, has run since early May and is attributed to Storm-2945, a sub-cluster of Midnight Blizzard.

The US and UK government have previously attributed Midnight Blizzard (also known as APT29, the Dukes, or Cozy Bear) to Russia’s Foreign Intelligence Service, the SVR.

Microsoft is still investigating how the portals were compromised but noted commonalities in the equipment and management systems across affected networks, which it said could reflect access to shared services within the captive portal ecosystem rather than isolated venue compromises.

Read more on Russian device code phishing: Russian Hackers Target Microsoft 365 Accounts with Device Code Attacks

Fake Updates Triggered by Connectivity Checks

Rather than waiting for a user to visit a website, the threat actor answered the automated connectivity checks that browsers and operating systems issue on joining a new network. Those checks returned pages offering browser or system updates.

The landings used ClickFix techniques, presenting fake verification failures with paste-and-run instructions. Microsoft said some also served an APK, indicating possible Android targeting.

From July 16, some pages redirected users into device code authentication flows, instructing them to enter an attacker-supplied code on a genuine Microsoft sign-in page.

Microsoft said the technique was not new but embedding it in a captive portal made the request more likely to seem legitimate.

ReliaQuest, which reported part of the activity on July 23, found it at hotels, conference centers and other shared venues, targeting corporate travelers’ accounts.

Three Tools, One Cover Story

The primary implant is CornFlake, a Go remote access trojan (RAT) that displays a fake progress window while installing itself, then registers as a Windows service with the display name Cloud Sync Service.

It carries keylogging, screenshots, microphone and webcam surveillance, browser credential theft and a remote shell, plus a watchdog routine that restores any persistence mechanism defenders remove.

A PowerShell infostealer called ChocoShell runs entirely in memory, disabling the Antimalware Scan Interface (AMSI) before harvesting browser cookies, saved passwords, Microsoft 365 single sign-on tokens and Wi-Fi credentials.

Its developer comments named specific Microsoft detection signatures and explained each evasion choice, which Microsoft said suggested AI-assisted code generation. The company said the actor used AI across a significant portion of the operation and thanked Anthropic and OpenAI for their support during the investigation.

Operators run the campaign from FruitStone, a web panel branded as a fictitious enterprise cloud product, matching the implant’s cover story.

Microsoft’s recommendations include treating hotel, conference and airport wireless as untrustworthy, preferring cellular or eSIM connectivity and never installing software offered through a captive portal. It also advised blocking device code flow where it is not required and deploying passkeys.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
Team-CWD
  • Website

Related Posts

News

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

August 3, 2026
News

HollowFrame Loader Uses Fake Python DLL to Evade Defender

August 3, 2026
News

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

August 3, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Drowning in spam or scam emails lately? Here’s why

January 27, 2026

Chronology of a Skype attack

February 5, 2026

Why LinkedIn is a hunting ground for threat actors – and how to protect yourself

January 16, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.