CaptiveCrunch: Russian SVR-Aligned Storm-2945 Hijacks Hotel Wi-Fi Captive Portals to Deploy CornFlake RAT and ChocoShell Info-Stealer Against Corporate Travelers — Threadlinqs Intelligence
As of 2026-08-04, CaptiveCrunch: Russian SVR-Aligned Storm-2945 Hijacks Hotel Wi-Fi Captive Portals to Deploy CornFlake RAT and ChocoShell Info-Stealer Against Corporate Travelers is a critical-severity apt threat attributed to UNC2452 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-1853 · Severity: CRITICAL · Status: ACTIVE · Category: APT
Attribution: UNC2452 · Russia · ESPIONAGE
Microsoft Threat Intelligence reports that Storm-2945, an operational sub-cluster of the Russia SVR-aligned Midnight Blizzard (APT29/Cozy Bear), has been compromising hotel and conference center Wi-Fi
CaptiveCrunch is an active, AI-augmented espionage campaign conducted by Storm-2945, an operational sub-cluster of Midnight Blizzard (APT29/NOBELIUM), the threat actor attributed by the US and UK governments to the Russian Federation's Foreign Intelligence Service (SVR). Since at least early May 2026, the operators have been compromising captive portal Wi-Fi infrastructure at hotels, conference centers, and other shared venues worldwide and manipulating DNS and HTTP traffic to redirect connecting corporate travelers through actor-controlled infrastructure. The objective is sustained espionage: access to the Microsoft 365 accounts and devices of corporate travelers in sectors including government, defense, energy, media, financial services, legal, healthcare, and retail.
Microsoft Threat Intelligence identified notable commonalities in the equipment and management systems across affected networks, suggesting the adversary obtained access to shared services within portions of the captive portal ecosystem rather than breaching venues individually. ReliaQuest, which independently disclosed the activity on July 23, 2026, assessed with low-to-medium confidence that initial access to the captive portal appliances exploited exposed management interfaces (SSH, SNMP, web admin consoles) combined with weak or reused credentials, and documented DNS response forgery on the gateway that acts as the DHCP-assigned resolver for every connected client. Because requests to hard-coded resolvers leave the device as unencrypted traffic the gateway can read and forge, standard protections fail unless strict-mode encrypted DNS (DoH/DoT) or a full-tunnel VPN is enforced.
Once positioned, the actors present victims with three principal redirect outcomes: (1) fake Microsoft 365 authentication pages that harvest credentials; (2) ClickFix-style lures, such as fake browser/OS update screens, a Windows Driver Repair Utility page, and a Google verification failure page, that instruct users to copy and paste attacker-supplied commands into Windows Terminal, PowerShell, or the Run dialog; and (3) since July 16, 2026, redirects into Microsoft's legitimate device-code authentication flow, in which the victim enters an actor-supplied device code on a legitimate Microsoft sign-in page, authenticating an attacker-initiated session and yielding MFA-satisfied OAuth tokens. Some landing pages also direct Android users to download and install a malicious APK. In roughly one-third of observed Windows devices (and some Macs), the attackers additionally attempted Web Proxy Auto-Discovery (WPAD) abuse to route application traffic through an attacker-controlled proxy.
The ClickFix chain delivers two custom malware families. CornFlake is a full-featured Windows RAT written in Go that installs to %APPDATA%\svchost32\svchost32.exe, registers a Windows service named svchost32 displayed as 'Cloud Sync Service' with description 'Synchronizes files with the cloud storage provider', and maintains redundant persistence via service registration, registry Run keys, and scheduled tasks, plus a watchdog routine that continuously restores any removed persistence mechanism. On first execution it operates in dropper mode behind a configurable fake progress window (Windows update, Defender scan, DirectX/vcredist installer, disk optimization, network diagnostics, browser update, or document viewer installer). It provides keylogging, clipboard monitoring with active-window title capture, idle-triggered and on-demand screenshots, WASAPI microphone capture, Media Foundation webcam capture, ChromeKatz-derived browser credential and cookie theft (including Chrome App-Bound Encryption bypass and Firefox NSS/SDR decryption), real-time file exfiltration by category, USB removable-media monitoring, an 18-category security-posture sweep, and a remote shell via cmd.exe or PowerShell. C2 traffic is protected by per-session AES-256-GCM encryption derived from ephemeral P-256 ECDH key exchange with a S
Target sectors: government administration, defense, energy, news - media, financial-services, legal, health, retail, hospitality
Target regions: united states of america, india, saudi arabia, Europe, Global
Detections & IOCs
As of 2026-08-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, T1566.002, T1078, T1204.002, T1059.001, T1059.003, T1543.003, T1547.001, T1053.005, T1548.002, T1685