CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver CornFlake RAT and Steal Microsoft 365 Tokens — Threadlinqs Intelligence
As of 2026-08-03, CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver CornFlake RAT and Steal Microsoft 365 Tokens is a high-severity apt threat attributed to Storm-2945 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 31 indicators of compromise.
Threat ID: TL-2026-1808 · Severity: HIGH · Status: ACTIVE · Category: APT
Updated: 2026-08-03 · 3 updates · revalidated 3× · latest source
Attribution: Storm-2945 · Russia · ESPIONAGE
Storm-2945, an operational sub-cluster of Russian SVR-linked Midnight Blizzard (APT29/Cozy Bear), has since early May 2026 compromised hospitality captive-portal gateways to forge DNS responses and
CaptiveCrunch is a network-level initial-access campaign in which Storm-2945 operators obtain administrative control of hotel, conference-center, and shared-venue captive-portal gateways/appliances -- ReliaQuest assesses with low-to-medium confidence via exposed internet-facing SSH, SNMP, and web administration consoles combined with weak or reused administrator credentials. Because these gateways also serve as the DHCP-assigned DNS resolver for connected devices, the actor forges DNS answers for the victim's automatic connectivity-check domains and Microsoft authentication domains, redirecting traffic to attacker infrastructure even when the endpoint is configured to use a public resolver such as 8.8.8.8 (the request still leaves the device in plaintext and is forged in transit). In roughly one-third of observed incidents the actor additionally abuses Web Proxy Auto-Discovery (WPAD, via DHCP option 252 or DNS 'wpad' lookups) to route all Windows application traffic through an attacker-controlled proxy.
Victims are shown configurable ClickFix-style fake progress/verification pages (Windows Update, Windows Security/Defender scan, Google verification, DirectX installer, Visual C++ redistributable, disk optimizer, network diagnostics, browser update, PDF viewer) that socially engineer the user into pasting and executing a command that installs CornFlake, a full-featured Go-based RAT that copies itself to %APPDATA%\svchost32\svchost32.exe and registers as the Windows service 'svchost32' (display name 'Cloud Sync Service', description 'Synchronizes files with the cloud storage provider'), reinforced with an HKCU Run-key entry and a scheduled task, each restored by a watchdog routine if removed. CornFlake negotiates its C2 channel via ECDH P-256 ephemeral key exchange with SHA-256 session-key derivation and a custom JSON protocol, is hot-reconfigurable via a local sync.dat file, and exposes a localhost API (/upload, /reload, /status). Its collection modules include Raw-Input-API keylogging (including password fields), SHA-256-deduplicated clipboard capture with active-window-title context, idle-triggered and on-demand screenshots, WASAPI microphone capture, Media Foundation webcam capture, a ChromeKatz-derived module that defeats Chrome App-Bound Encryption plus Firefox NSS/SDR cookie and password decryption, extension-filtered file exfiltration (throttled to 1,000 files/500MB per cycle), removable-media scanning, an 18-category system/security-posture survey, and an interactive cmd.exe/PowerShell remote shell.
Where the operators want cloud-token access specifically, they deploy ChocoShell, an in-memory PowerShell infostealer executed via [ScriptBlock]::Create() that beacons over HTTPS to a hardcoded C2 (213.145.86.112) using a tracking-pixel-styled path (/t/pixel.gif?m=<status>), fetches follow-on payloads disguised as a JS polyfill (/cdn/chunks/polyfill-7e2b.min.js), and exfiltrates GZip-compressed, Base64-wrapped JSON to /t/event. ChocoShell tampers with AMSI via .NET reflection, performs a timing-based sandbox/VM check with a silent exit, and chains three silent UAC-bypass techniques with a visible-prompt fallback: a SilentCleanup scheduled-task hijack via HKCU\Environment\windir (with a 2-second registry cleanup to dodge cloud detection), a wsreset.exe auto-elevation COM hijack via HKCU\Software\Classes, and an sdclt.exe folder-hijack via HKCU\Software\Classes\Folder\shell\open\command using the /KickOffElev flag. Once elevated it disables Windows Defender signatures, extracts the Chromium 'Local State' master key (handling both legacy DPAPI and Chrome v127+ App-Bound Encryption via SYSTEM-level token impersonation from winlogon.exe/wininit.exe/services.exe, or by launching Chrome with --remote-debugging-port and calling the Chrome DevTools Protocol's Network.getAllCookies to bypass ABE entirely), copies unencrypted cookies.sqlite from Firefox-family browsers, harvests Wi-Fi credentials via 'netsh wlan show profile key=clear
Weaknesses (CWE)
CWE-290, CWE-306
Target sectors: hospitality, financial-services, professional-services, legal, health, energy, retail
Target regions: united states of america, india, saudi arabia, Global
Update History
- 2026-08-03 — CaptiveCrunch: Midnight Blizzard (Storm-2945) Compromises Hospitality Wi-Fi Captive Portals to Deliver CornFlake/ChocoShell Malware and Steal Traveler Credentials: What changed No change to severity (HIGH), exploitability (ACTIVE), status (ACTIVE), or attribution confidence (HIGH) -- the newer report's own CRITICAL severity/impact labeling is not backed by new evidence beyond what the existing, more h
- 2026-08-03 — CaptiveCrunch: Midnight Blizzard Subgroup Storm-2945 Hijacks Hotel Wi-Fi Captive Portals to Deliver CornFlake RAT and ChocoShell Infostealer: What changed No whitelisted field escalations — severity, exploitability, status, and attribution confidence are unchanged. The newer report adds an Android APK delivery vector alongside the existing Windows ClickFix chain and confirms 38.1
- 2026-08-03 — CaptiveCrunch: Russian Midnight Blizzard Subgroup Storm-2945 Hijacks Hotel Wi-Fi Captive Portals to Deliver Malware and Steal Microsoft 365 Credentials: What changed No change in severity (HIGH), exploitability (ACTIVE), status (ACTIVE), or attribution_confidence (HIGH) -- the newer report corroborates rather than escalates the existing assessment. New indicators (2) 2 new behavioral IOCs:
Detections & IOCs
As of 2026-08-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 31 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1566.002, T1566.004, T1195.003, T1584.006, T1583.001, T1059.001, T1059.003, T1204.001, T1204.002, T1543.003