CaptiveCrunch: Midnight Blizzard (Storm-2945) Hospitality Captive-Portal AiTM Campaign

CaptiveCrunch (TL-2026-2765), also tracked as CaptiveCrunch, is a high-severity advanced persistent threat campaign, first published 2026-07-31. It is attributed to UNC2452 (Russia) with high confidence, affects Various hospitality operators Captive-portal gateways / guest Wi-Fi, maps to 24 MITRE ATT&CK techniques (T1020, T1053.005, T1056.001), and is covered by 9 detection rules and 26 indicators of compromise.

Key facts for TL-2026-2765

Threat ID
TL-2026-2765
Also known as
CaptiveCrunch
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-07-31
Last reviewed
2026-07-31
Attribution
UNC2452
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
hospitality, finance, professional-services, legal, health, energy, retail, government administration
Target regions
united states of america, india, saudi arabia, Europe, Worldwide
Detection rules
9
Indicators of compromise
26

Malware and tooling in CaptiveCrunch

Malware and tooling: ChocoShell, CornFlake, FruitStone, Storm, ChromeKatz, FakeUpdates

Microsoft Threat Intelligence attributes CaptiveCrunch to Storm-2945, a sub-cluster of Russia's SVR-linked Midnight Blizzard, active since early May 2026. The actor compromises captive-portal gateways at hotels and conference venues, forges DNS/HTTP responses to push corporate travelers to Microsoft Entra device-code phishing and ClickFix/fake-update lures, and delivers the CornFlake RAT and ChocoShell infostealer, run from the FruitStone operator panel.

How CaptiveCrunch works

CaptiveCrunch is a cyber-espionage campaign that Microsoft Threat Intelligence attributes to Storm-2945, a sub-cluster of Midnight Blizzard (APT29 / NOBELIUM), the threat actor tied to Russia's Foreign Intelligence Service (SVR). Microsoft reports the campaign has manipulated DNS/HTTP traffic since early May 2026 and published its findings on 2026-07-31, following a ReliaQuest report of 2026-07-23 that documented DNS poisoning on hospitality Wi-Fi and first compared it to FrostArmada (APT28) before Microsoft's attribution. Microsoft notes earlier device-code/OAuth phishing operations from February 2026 and technical overlap with the Storm-2372 device-code cluster.

Initial position: the actor controls captive-portal gateways at hotels, conference centers and other shared venues. On the networks ReliaQuest investigated, the gateway also served as the DNS resolver handed to clients, so administrative control let the actor forge DNS answers and redirect traffic without touching the victim device. ReliaQuest suspects exploitation of exposed management interfaces (SSH, SNMP, web administration) combined with weak credentials, and observed WPAD abuse. Microsoft states the initial compromise vector for the portals is still under investigation; commonalities in equipment and management systems suggest shared service access rather than isolated compromises. Victim venues reported by ReliaQuest span multiple US cities, India and Saudi Arabia (hotels, conference centers, airports, co-working spaces, universities, healthcare facilities), and targeted users came from financial services, professional services, legal, healthcare, energy and retail.

User-facing lures: connectivity-check (NCSI/captive-detection) requests are redirected to fake browser or OS updates and to ClickFix pages (fake Windows Driver Repair Utility, verification-failure prompts, instructions to run commands via Windows Terminal); Android variants instruct APK download. Since 2026-07-16 some landing pages redirect guests into Microsoft's legitimate device-code sign-in flow, so entering the actor-supplied code grants the actor's session MFA-satisfied access. AiTM infrastructure uses look-alike Microsoft 365/OWA domains. Infection is not silent: the victim must download or execute the payload.

Malware: CornFlake is a Go Windows RAT that installs to %APPDATA%\svchost32\svchost32.exe and registers a service (display name 'Cloud Sync Service'), plus Run-key and scheduled-task persistence with a watchdog. It uses ECDH P-256 key exchange with SHA-256-derived session keys over a custom JSON protocol, and supports keylogging, clipboard monitoring, screenshots, microphone and webcam capture, a ChromeKatz-derived browser credential stealer (Chrome App-Bound Encryption bypass, Firefox NSS decryption), extension-based file exfiltration (up to 1,000 files / 500MB per cycle), USB monitoring, an 18-category security posture sweep, a remote shell, and a localhost HTTP API (/upload, /reload, /status) with hot reconfiguration through sync.dat. ChocoShell is an in-memory PowerShell infostealer that disables AMSI via .NET reflection, exits on timing-based VM checks, tries three silent UAC bypasses (SilentCleanup windir hijack, wsreset.exe COM hijack, sdclt.exe folder hijack) with a visible RunAs fallback, and steals Chromium/Firefox cookies and passwords, Wi-Fi keys and M365 Token Broker .tbres tokens for session replay. It beacons to 213.145.86.112 over HTTPS using tracking-pixel-style URIs (/t/pixel.gif?m=<status>), fetches its payload from /cdn/chunks/polyfill-7e2b.min.js and exfiltrates GZip+Base64 JSON to /t/event. FruitStone is the operator SPA branded 'CloudSync Console': JWT multi-operator auth, SSE agent dashboard, remote shell and file browser, a four-step campaign/dropper builder with evasion options, proxy relays, beacon profiles with SNI spoofing (teams.microsoft.com) and staging servers. Microsoft assesses the actor uses AI to support a significant portion of operations (ChocoShell comments suggest AI-assisted code); Anthropic and OpenAI collaborated on the investigation.

Defender relevance: corporate travelers on untrusted Wi-Fi are the exposure. Priority controls are always-on full-tunnel VPN with corporate DNS, blocking device-code flow via Conditional Access, phishing-resistant MFA, refusing updates or tools offered through captive portals, and hunting for the published IOCs and the svchost32 service artifacts. No CVE is cited by the sources.

MITRE ATT&CK techniques used in TL-2026-2765

Exfiltration

T1020 Automated Exfiltration

Persistence

T1053.005 Scheduled Task; T1543.003 Windows Service; T1547.001 Registry Run Keys / Startup Folder

Credential Access

T1056.001 Keylogging; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers; T1557 Adversary-in-the-Middle

Execution

T1059.001 PowerShell; T1204.004 Malicious Copy and Paste

Command and Control

T1071.001 Web Protocols; T1573.002 Asymmetric Cryptography

Collection

T1113 Screen Capture; T1123 Audio Capture; T1125 Video Capture

Defense Evasion

T1497.003 Time Based Checks

Privilege Escalation

T1546.015 Component Object Model Hijacking; T1548.002 Bypass User Account Control

Lateral Movement

T1550.001 Application Access Token

Initial Access

T1566.002 Spearphishing Link

Resource Development

T1583.001 Domains; T1584.008 Network Devices

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in CaptiveCrunch

  • Various hospitality operators — Captive-portal gateways / guest Wi-Fi (hotels, conference centers, airports, co-working spaces, universities, healthcare facilities)
    Vulnerable versions: Unspecified; initial compromise vector under investigation
  • Microsoft — Microsoft Entra ID / Microsoft 365 (device code authentication flow, Token Broker cache)
    Vulnerable versions: Tenants permitting device code flow
  • Microsoft — Windows endpoints used by corporate travelers (CornFlake and ChocoShell targets)
    Vulnerable versions: Windows clients whose users execute the fake update or ClickFix payload

Remediation for CaptiveCrunch

Immediate actions

  • Block and hunt the published Storm-2945 domains and IPs (ms365-device.com, ms365-live.com, m365-owa.com, owa-ms365.com; 31.57.243.154, 38.146.28.75, 38.146.28.132, 104.194.159.150, 107.189.26.194, 213.145.86.112)
  • Hunt for %APPDATA%\svchost32\svchost32.exe and a svchost32 service named 'Cloud Sync Service'
  • Review Entra sign-in logs for device code flow authentications and revoke sessions and tokens for affected users
  • Reset credentials and revoke M365 tokens for users who connected to hotel or conference Wi-Fi and ran a fake update or ClickFix command

Workarounds

  • Block the OAuth device code flow with Conditional Access where it is not required
  • Disable WPAD via Group Policy where unnecessary
  • Do not download updates, certificates or utilities offered through captive portals
  • Do not reuse corporate credentials on hotel or conference registration pages

Longer-term hardening

  • Require always-on full-tunnel VPN so DNS resolves through corporate resolvers
  • Enforce phishing-resistant MFA (passkeys) and sign-in risk policies
  • Prevent managed devices from joining non-provisioned networks (policy-csp-wifi allowmanualwificonfiguration)
  • Issue enterprise-managed travel routers or use mobile hotspots and eSIM cellular instead of public Wi-Fi
  • Train users to recognize ClickFix prompts and never paste commands into cmd, PowerShell or Windows Terminal from a web page

Timeline of CaptiveCrunch

  • 107.189.26.194, later identified as ChocoShell C2 / DNS resolver infrastructure, is first seen by Microsoft. Microsoft also notes earlier Storm-2945 device-code/OAuth phishing operations in February 2026.
  • AiTM infrastructure IP 104.194.159.150 first seen.
  • Per Microsoft, Storm-2945 begins the CaptiveCrunch campaign in early May 2026, manipulating DNS/HTTP traffic on compromised hospitality captive portals (date approximate).
  • Device-code redirect domain ms365-live.com first seen.
  • ChocoShell C2 213.145.86.112 and AiTM IP 38.146.28.75 first seen.
  • CornFlake sample (SHA256 918fa52a...1c593) first seen; ChocoShell sample (SHA256 be998574...d42c) follows on 2026-07-10.
  • Some CaptiveCrunch landing pages begin redirecting guests into Microsoft's legitimate device-code sign-in flow; AiTM domain owa-ms365.com and IP 31.57.243.154 first seen the same day.
  • ReliaQuest publishes its Threat Spotlight on DNS poisoning of hospitality Wi-Fi (activity since June 2026; venues in multiple US cities, India, Saudi Arabia); ms365-device.com first seen the same day.
  • Microsoft Threat Intelligence publishes CaptiveCrunch attribution to Storm-2945 (Midnight Blizzard), names CornFlake, ChocoShell and the FruitStone C2 panel, and releases IOCs and hunting queries. Anthropic and OpenAI collaborated on the investigation.

Sources cited for CaptiveCrunch

More in apt

Detection coverage for TL-2026-2765

As of 2026-07-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2765 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats