CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive Portal Wi-Fi — Threadlinqs Intelligence
As of 2026-08-04, CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive Portal Wi-Fi is a high-severity malware threat attributed to Storm-2945 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-1857 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Storm-2945 · Russia · ESPIONAGE
Microsoft Threat Intelligence disclosed the CaptiveCrunch campaign (July 31, 2026), attributed to Storm-2945, a sub-cluster of the Russia-linked Midnight Blizzard (APT29/SVR). The campaign compromises
Storm-2945, first observed conducting AI-augmented device code and OAuth phishing operations in February 2026, escalated to widespread traffic manipulation via compromised hospitality captive portal networks beginning in early May 2026. The actor compromises Wi-Fi gateway appliances — likely via exposed management interfaces (SSH, SNMP, web admin) with weak or reused credentials — and uses control over DNS resolution to forge responses, redirecting all guest traffic through actor-controlled infrastructure. Unlike APT28's FrostArmada campaign, which used keyword-based selective DNS filtering, CaptiveCrunch redirects all DNS requests indiscriminately. In roughly one-third of observed cases, the actor also abuses Web Proxy Auto-Discovery (WPAD) to push a malicious PAC file that proxies application traffic through attacker infrastructure, a technique not previously documented in FrostArmada-linked campaigns.
Upon connection to the compromised network, victims are redirected to doppelganger domains impersonating Microsoft online services (m365-owa.com, owa-ms365.com, ms365-live.com, ms365-device.com). These landing pages serve one of several payload delivery mechanisms: (1) ClickFix-style prompts instructing users to open a terminal and run an attacker-supplied command that downloads and executes signed binaries; (2) fake browser or OS update pages delivering CornFlake via a multi-stage dropper chain; or (3) since July 16, 2026, Microsoft Entra ID device code authentication pages that trick victims into entering attacker-generated device codes into legitimate Microsoft sign-in pages, authorizing the attacker's OAuth session and yielding MFA-satisfied tokens without requiring password interception.
CornFlake (compiled Go RAT, SHA256: 918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593, first observed July 3, 2026) masquerades as a benign Windows service named 'svchost32' with display name 'Cloud Sync Service' and description 'Synchronizes files with the cloud storage provider,' installed at %APPDATA%\svchost32\svchost32.exe with config in sync.dat. It uses ECDH P-256 ephemeral key exchange with SHA-256 derived session keys over TLS-wrapped TCP (magic bytes 0xAB hello / 0xAC ack), with per-session AES-256-GCM encryption and 18-41 second randomized heartbeat intervals (opcode 0xE7). CornFlake registers layered persistence: Windows service, Registry Run keys, scheduled tasks, and a watchdog routine that recreates any deleted persistence artifacts. During installation it displays a configurable fake progress window (winupdate, defender, directx, vcredist, sysopt, netfix, browser, pdfview). Capabilities include keylogging via Raw Input API, clipboard monitoring with SHA-256 dedup and active window title capture, screenshot capture, WASAPI microphone recording, Media Foundation webcam capture (JPEG), a ChromeKatz-derived credential theft module for Chromium (ABE bypass) and Firefox (NSS/SDR), file exfiltration (1000 files/500 MB per cycle categorized by extension), USB removable media monitoring, security posture sweep across 18 categories, and remote shell for arbitrary cmd.exe or PowerShell (-NoP) execution. It exposes a localhost HTTP API (/upload, /reload, /status).
ChocoShell (PowerShell infostealer, SHA256: be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c, first observed July 10, 2026) runs entirely in memory with no long-term persistence. Its C2 infrastructure centers on 213.145.86.112 with three URL paths: beacon via /t/pixel.gif?m=<status> (mimicking tracking pixels), tooling fetch from /cdn/chunks/polyfill-7e2b.min.js (mimicking JavaScript polyfill libraries), and exfiltration via POST to /t/event (JSON-structured, GZip-compressed, Base64-encoded over HTTPS). Defense evasion includes AMSI disablement via .NET reflection and timing-based VM/sandbox detection with silent exit. Privilege escalation uses three ordered UAC bypass techniques with fallback — SilentCleanup task hijack (%windir% env var),
Target sectors: financial-services, professional-services, legal, health, energy, retail
Target regions: united states of america, india, saudi arabia, Europe
Detections & IOCs
As of 2026-08-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583.001, T1584.002, T1557, T1566.003, T1204.002, T1059.001, T1059.003, T1543.003, T1547.001, T1053.005