CaptiveCrunch: Midnight Blizzard (Storm-2945) Hospitality Captive-Portal AiTM Campaign
CaptiveCrunch (TL-2026-2765), also tracked as CaptiveCrunch, is a high-severity advanced persistent threat campaign, first published 2026-07-31. It is attributed to UNC2452 (Russia) with high confidence, affects Various hospitality operators Captive-portal gateways / guest Wi-Fi, maps to 24 MITRE ATT&CK techniques (T1020, T1053.005, T1056.001), and is covered by 9 detection rules and 26 indicators of compromise.
Key facts for TL-2026-2765
- Threat ID
- TL-2026-2765
- Also known as
- CaptiveCrunch
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-07-31
- Last reviewed
- 2026-07-31
- Attribution
- UNC2452
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- hospitality, finance, professional-services, legal, health, energy, retail, government administration
- Target regions
- united states of america, india, saudi arabia, Europe, Worldwide
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in CaptiveCrunch
Malware and tooling: ChocoShell, CornFlake, FruitStone, Storm, ChromeKatz, FakeUpdates
Microsoft Threat Intelligence attributes CaptiveCrunch to Storm-2945, a sub-cluster of Russia's SVR-linked Midnight Blizzard, active since early May 2026. The actor compromises captive-portal gateways at hotels and conference venues, forges DNS/HTTP responses to push corporate travelers to Microsoft Entra device-code phishing and ClickFix/fake-update lures, and delivers the CornFlake RAT and ChocoShell infostealer, run from the FruitStone operator panel.
How CaptiveCrunch works
CaptiveCrunch is a cyber-espionage campaign that Microsoft Threat Intelligence attributes to Storm-2945, a sub-cluster of Midnight Blizzard (APT29 / NOBELIUM), the threat actor tied to Russia's Foreign Intelligence Service (SVR). Microsoft reports the campaign has manipulated DNS/HTTP traffic since early May 2026 and published its findings on 2026-07-31, following a ReliaQuest report of 2026-07-23 that documented DNS poisoning on hospitality Wi-Fi and first compared it to FrostArmada (APT28) before Microsoft's attribution. Microsoft notes earlier device-code/OAuth phishing operations from February 2026 and technical overlap with the Storm-2372 device-code cluster.
Initial position: the actor controls captive-portal gateways at hotels, conference centers and other shared venues. On the networks ReliaQuest investigated, the gateway also served as the DNS resolver handed to clients, so administrative control let the actor forge DNS answers and redirect traffic without touching the victim device. ReliaQuest suspects exploitation of exposed management interfaces (SSH, SNMP, web administration) combined with weak credentials, and observed WPAD abuse. Microsoft states the initial compromise vector for the portals is still under investigation; commonalities in equipment and management systems suggest shared service access rather than isolated compromises. Victim venues reported by ReliaQuest span multiple US cities, India and Saudi Arabia (hotels, conference centers, airports, co-working spaces, universities, healthcare facilities), and targeted users came from financial services, professional services, legal, healthcare, energy and retail.
User-facing lures: connectivity-check (NCSI/captive-detection) requests are redirected to fake browser or OS updates and to ClickFix pages (fake Windows Driver Repair Utility, verification-failure prompts, instructions to run commands via Windows Terminal); Android variants instruct APK download. Since 2026-07-16 some landing pages redirect guests into Microsoft's legitimate device-code sign-in flow, so entering the actor-supplied code grants the actor's session MFA-satisfied access. AiTM infrastructure uses look-alike Microsoft 365/OWA domains. Infection is not silent: the victim must download or execute the payload.
Malware: CornFlake is a Go Windows RAT that installs to %APPDATA%\svchost32\svchost32.exe and registers a service (display name 'Cloud Sync Service'), plus Run-key and scheduled-task persistence with a watchdog. It uses ECDH P-256 key exchange with SHA-256-derived session keys over a custom JSON protocol, and supports keylogging, clipboard monitoring, screenshots, microphone and webcam capture, a ChromeKatz-derived browser credential stealer (Chrome App-Bound Encryption bypass, Firefox NSS decryption), extension-based file exfiltration (up to 1,000 files / 500MB per cycle), USB monitoring, an 18-category security posture sweep, a remote shell, and a localhost HTTP API (/upload, /reload, /status) with hot reconfiguration through sync.dat. ChocoShell is an in-memory PowerShell infostealer that disables AMSI via .NET reflection, exits on timing-based VM checks, tries three silent UAC bypasses (SilentCleanup windir hijack, wsreset.exe COM hijack, sdclt.exe folder hijack) with a visible RunAs fallback, and steals Chromium/Firefox cookies and passwords, Wi-Fi keys and M365 Token Broker .tbres tokens for session replay. It beacons to 213.145.86.112 over HTTPS using tracking-pixel-style URIs (/t/pixel.gif?m=<status>), fetches its payload from /cdn/chunks/polyfill-7e2b.min.js and exfiltrates GZip+Base64 JSON to /t/event. FruitStone is the operator SPA branded 'CloudSync Console': JWT multi-operator auth, SSE agent dashboard, remote shell and file browser, a four-step campaign/dropper builder with evasion options, proxy relays, beacon profiles with SNI spoofing (teams.microsoft.com) and staging servers. Microsoft assesses the actor uses AI to support a significant portion of operations (ChocoShell comments suggest AI-assisted code); Anthropic and OpenAI collaborated on the investigation.
Defender relevance: corporate travelers on untrusted Wi-Fi are the exposure. Priority controls are always-on full-tunnel VPN with corporate DNS, blocking device-code flow via Conditional Access, phishing-resistant MFA, refusing updates or tools offered through captive portals, and hunting for the published IOCs and the svchost32 service artifacts. No CVE is cited by the sources.
MITRE ATT&CK techniques used in TL-2026-2765
Exfiltration
Persistence
T1053.005 Scheduled Task; T1543.003 Windows Service; T1547.001 Registry Run Keys / Startup Folder
Credential Access
T1056.001 Keylogging; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers; T1557 Adversary-in-the-Middle
Execution
T1059.001 PowerShell; T1204.004 Malicious Copy and Paste
Command and Control
T1071.001 Web Protocols; T1573.002 Asymmetric Cryptography
Collection
T1113 Screen Capture; T1123 Audio Capture; T1125 Video Capture
Defense Evasion
Privilege Escalation
T1546.015 Component Object Model Hijacking; T1548.002 Bypass User Account Control
Lateral Movement
T1550.001 Application Access Token
Initial Access
Resource Development
T1583.001 Domains; T1584.008 Network Devices
defense-impairment
Affected products and versions in CaptiveCrunch
- Various hospitality operators — Captive-portal gateways / guest Wi-Fi (hotels, conference centers, airports, co-working spaces, universities, healthcare facilities)
Vulnerable versions: Unspecified; initial compromise vector under investigation - Microsoft — Microsoft Entra ID / Microsoft 365 (device code authentication flow, Token Broker cache)
Vulnerable versions: Tenants permitting device code flow - Microsoft — Windows endpoints used by corporate travelers (CornFlake and ChocoShell targets)
Vulnerable versions: Windows clients whose users execute the fake update or ClickFix payload
Remediation for CaptiveCrunch
Immediate actions
- Block and hunt the published Storm-2945 domains and IPs (ms365-device.com, ms365-live.com, m365-owa.com, owa-ms365.com; 31.57.243.154, 38.146.28.75, 38.146.28.132, 104.194.159.150, 107.189.26.194, 213.145.86.112)
- Hunt for %APPDATA%\svchost32\svchost32.exe and a svchost32 service named 'Cloud Sync Service'
- Review Entra sign-in logs for device code flow authentications and revoke sessions and tokens for affected users
- Reset credentials and revoke M365 tokens for users who connected to hotel or conference Wi-Fi and ran a fake update or ClickFix command
Workarounds
- Block the OAuth device code flow with Conditional Access where it is not required
- Disable WPAD via Group Policy where unnecessary
- Do not download updates, certificates or utilities offered through captive portals
- Do not reuse corporate credentials on hotel or conference registration pages
Longer-term hardening
- Require always-on full-tunnel VPN so DNS resolves through corporate resolvers
- Enforce phishing-resistant MFA (passkeys) and sign-in risk policies
- Prevent managed devices from joining non-provisioned networks (policy-csp-wifi allowmanualwificonfiguration)
- Issue enterprise-managed travel routers or use mobile hotspots and eSIM cellular instead of public Wi-Fi
- Train users to recognize ClickFix prompts and never paste commands into cmd, PowerShell or Windows Terminal from a web page
Timeline of CaptiveCrunch
- 107.189.26.194, later identified as ChocoShell C2 / DNS resolver infrastructure, is first seen by Microsoft. Microsoft also notes earlier Storm-2945 device-code/OAuth phishing operations in February 2026.
- AiTM infrastructure IP 104.194.159.150 first seen.
- Per Microsoft, Storm-2945 begins the CaptiveCrunch campaign in early May 2026, manipulating DNS/HTTP traffic on compromised hospitality captive portals (date approximate).
- Device-code redirect domain ms365-live.com first seen.
- ChocoShell C2 213.145.86.112 and AiTM IP 38.146.28.75 first seen.
- CornFlake sample (SHA256 918fa52a...1c593) first seen; ChocoShell sample (SHA256 be998574...d42c) follows on 2026-07-10.
- Some CaptiveCrunch landing pages begin redirecting guests into Microsoft's legitimate device-code sign-in flow; AiTM domain owa-ms365.com and IP 31.57.243.154 first seen the same day.
- ReliaQuest publishes its Threat Spotlight on DNS poisoning of hospitality Wi-Fi (activity since June 2026; venues in multiple US cities, India, Saudi Arabia); ms365-device.com first seen the same day.
- Microsoft Threat Intelligence publishes CaptiveCrunch attribution to Storm-2945 (Midnight Blizzard), names CornFlake, ChocoShell and the FruitStone C2 panel, and releases IOCs and hunting queries. Anthropic and OpenAI collaborated on the investigation.
Sources cited for CaptiveCrunch
- CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft (Microsoft Security Blog)
- CaptiveCrunch: Midnight Blizzard Hospitality Network AiTM Campaign (Wiz Threats)
- DNS Poisoning Tactics Expand to Hospitality Wi-Fi (ReliaQuest Threat Spotlight)
- Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking (SecurityWeek)
- Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware (The Hacker News)
- Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware (Help Net Security)
- Midnight Blizzard Targets Travelers via Captive Portals (Infosecurity Magazine)
- Russian spies turn public Wi-Fi into malware delivery systems (The Register)
More in apt
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)
- Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti UniFi OS Flaws to Steal Government Data
- NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and DCSync to Compromise Russian Active Directory
- North Korean WaterPlum (Contagious Interview) Campaign Infects 30,000 Devices, Steals $10.71M in Crypto via Fake Job Interviews and npm/PyPI/Go/Rust Supply-Chain Packages
Detection coverage for TL-2026-2765
As of 2026-07-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2765 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.