CaptiveCrunch: Storm-2945 (Midnight Blizzard / APT29) compromises hotel WiFi gateways globally for credential theft and malware delivery — Threadlinqs Intelligence
As of 2026-08-03, CaptiveCrunch: Storm-2945 (Midnight Blizzard / APT29) compromises hotel WiFi gateways globally for credential theft and malware delivery is a critical-severity threat intel threat attributed to Midnight Blizzard (APT29 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-1838 · Severity: CRITICAL · Status: ACTIVE · Category: THREAT_INTEL
Attribution: Midnight Blizzard (APT29 · Russia · ESPIONAGE
Russia-linked threat actor Storm-2945, a sub-cluster of Midnight Blizzard (APT29 / Cozy Bear, SVR), has been conducting a global traffic-manipulation campaign since May 2026 targeting hotel,
CaptiveCrunch is an ongoing global cyber espionage campaign attributed to Storm-2945, an operational sub-cluster of the Russia-based threat actor Midnight Blizzard (APT29 / Cozy Bear), which is attributed by US and UK governments to the Foreign Intelligence Service of the Russian Federation (SVR). First tracked by Microsoft since February 2026 and observed in its captive-portal form since early May 2026, the campaign represents a significant evolution in adversary-in-the-middle (AitM) attacks at scale, combining physical-network compromise with sophisticated OAuth credential theft and custom malware delivery.
Attack Methodology: The threat actor gains administrative access to internet-facing captive portal gateway appliances at hotels, conference centers, and shared venues. The initial compromise vector remains under investigation, but Microsoft found notable commonalities in equipment and management systems across affected networks, suggesting potential access to shared services within the captive portal ecosystem rather than isolated compromises. ReliaQuest assesses with low-to-medium confidence that initial access likely exploited exposed management interfaces (including internet-facing SSH, SNMP, and web administration consoles) in combination with weak or reused administrative credentials. Once in control, the attackers modify DNS and HTTP traffic so that all DNS requests from guests connected to the network resolve to actor-controlled IP addresses. This approach bypasses common DNS protections because hard-coded resolvers like 8.8.8.8 still send unencrypted requests the gateway can forge, and opportunistic-mode encrypted DNS permits plaintext fallback. In approximately one-third of observed cases, the attackers also abused Web Proxy Auto-Discovery (WPAD) by controlling DHCP option 252 or DNS lookups for 'wpad', enabling deployment of malicious proxy auto-configuration (PAC) files that route application traffic through attacker proxies.
From this AitM position, the attackers redirect users through actor-controlled phishing infrastructure using ClickFix (fake verification/update pages) that present fake browser update prompts, Windows Driver Repair utilities, Google-branded verification checks, and other social engineering lures. Users are directed either to malware downloads or to device code authentication flows.
Malware Arsenal: CornFlake is a full-featured Windows remote access trojan written in Go, serving as the primary persistent implant. It uses ECDH P-256 ephemeral key exchange for C2 encryption with session keys derived via SHA-256 over a custom JSON protocol. On execution, it operates in dropper mode displaying a fake progress window, copies itself to %APPDATA%\svchost32\svchost32.exe, and establishes redundant persistence via Windows service creation (svchost32 / 'Cloud Sync Service'), Registry Run keys, and scheduled tasks with a continuous watchdog. Capabilities include raw-input keylogging, clipboard monitoring with SHA-256 deduplication, idle-triggered and on-demand screenshots, WASAPI-based microphone capture, Media Foundation-based webcam capture, ChromeKatz-derived browser credential theft (supporting Chrome ABE bypass for v127+ and Firefox NSS/SDR decryption), real-time filesystem exfiltration (throttled at 1,000 files or 500 MB per cycle), USB removable media scanning, security posture enumeration across 18 categories, and remote shell via cmd.exe or PowerShell. It also exposes a localhost HTTP API server with /upload, /reload, and /status endpoints allowing companion payloads to task file exfiltration or trigger config reloads. ChocoShell is a PowerShell-based infostealer executed entirely in-memory, targeting high-volume theft of browser session cookies, saved passwords, Microsoft 365 SSO tokens, and Wi-Fi credentials. It communicates with a hardcoded C2 at 213.145.86.112 via HTTPS beacons disguised as tracking pixels (/t/pixel.gif?m=<status>) and fetches tooling from paths like /cdn/chunks/polyfi
Target sectors: government administration, diplomatic, ngos, it services, finance, legal, health, energy, retail, professional services, defense, education
Target regions: North America, Europe, india, saudi arabia, Middle East, Multiple countries worldwide
Detections & IOCs
As of 2026-08-07, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, CRITICAL, threat intelligence, cybersecurity, T1190, T1133, T1078, T1566, T1195, T1199, T1204, T1059, T1053, T1543