Microsoft has warned that the Russian advanced persistent threat actor Storm-2945, a sub-cluster of Midnight Blizzard or APT29, is exploiting hotel Wi-Fi networks to breach Microsoft 365 accounts and install custom malware. Midnight Blizzard is linked to Russia’s Foreign Intelligence Service (SVR) and typically targets individuals in government, academia, defense, and non-governmental organizations.
Cybersecurity firm ReliaQuest had detailed a similar campaign linked to APT28, Fancy Bear, or Forest Blizzard, linked to Russia’s GRU Military Intelligence Unit. It involved changing the DNS settings on vulnerable gateway devices to compromise Microsoft 365 accounts. Microsoft believes that the APTs share similar tactics but operate independently.
CaptiveCrunch hacking campaign targets enterprise travelers at public venues
Dubbed CaptiveCrunch by Microsoft, the hacking campaign has been active since May 2026. It targets hotels, hospitality establishments, conference centers, and other popular venues that attract corporate travelers across the United States, India, and Saudi Arabia. ReliaQuest also identified airports, universities, event venues, co-working spaces, and health care facilities as popular targets.
Microsoft assesses that Storm-2945 leveraged AI to support the campaign, including malware coding, based on extensive code comments, and OAuth code phishing. Microsoft also collaborated with AI juggernauts Anthropic and OpenAI during the investigation.
“The broader concern is that business travel has become an extension of the enterprise attack surface,” said Michael Centrella, Head of Public Policy at SecurityScorecard. “Executives, government officials, and employees routinely access sensitive corporate resources from hotels, often assuming the network is legitimate. Campaigns like this show that attackers are investing in persistent access through third-party infrastructure, allowing them to collect intelligence long before an organization detects unusual activity within its own environment.”
Russian hackers exploit hotel Wi-Fi networks to breach Microsoft 365 accounts
According to Microsoft, Russian hackers intercept user connections to hotel Wi-Fi networks by manipulating DNS and HTTP traffic from breached devices. They leveraged adversary-in-the-middle (AitM) tactics to redirect victims to phishing pages that impersonate Microsoft 365 login portals or Microsoft Entra ID authentication flows. If the victim approves the login request and supplies the device code, Microsoft allows authentication without requiring MFA.
Called captive portals, victims must access those pages before connecting to hotel Wi-Fi networks and accessing the internet.
They also used ClickFix to redirect victims to fake operating system and browser update pages and install malware through fake update download prompts or harvest credentials through fake user verification login pages. The campaign also expanded to target Android devices through malicious APK downloads since the mobile operating system allows sideloading apps from unverified third-party sources.
CaptiveCrunch hacking campaign leverages CornFlake and ChocoShell malware
Microsoft says the CaptiveCrunch campaign leverages two malware families to compromise Hotel Wi-Fi Networks: CornFlake and ChocoShell, to obtain persistent access, harvest credentials, exfiltrate data, and perform audio and video surveillance.
CornFlake is a Go-based remote access Trojan (RAT) capable of keylogging, monitoring the clipboard, capturing screenshots, monitoring the microphone and webcam, and stealing browser credentials, cookies, and Microsoft 365 sessions. It can also copy files, monitor removable media, grant remote shell access, and perform system reconnaissance.
When executed, it displays a fake progress bar to distract the user while copying malicious binaries to the %APPDATA%\svchost32\svchost32.exe to maintain persistence. Additionally, the threat actors can customize the window to mimic other actions such as a Microsoft Defender virus scan, Windows update (winupdate), disk optimization (sysopt), network diagnostics, browser update, or document viewer (pdfview) installation. Other actions include installing Microsoft Visual C++ 2015-2022 Redistributable (vcredist) or DirectX End-User Runtime Web (directx).
The malware also disguises itself as the “Cloud Sync Service” to mimic the legitimate Windows service svchost32 (svchost.exe). It also uses Windows service registration, named tasks, registry keys, and a watchdog routine to restore persistence mechanisms removed by Windows Defender. It relies on runtime configuration file sync.dat to reconfigure C2 servers, watch directories, and manage Transport Layer Security (TLS) settings.
ChocoShell is an in-memory, PowerShell-based infostealer targeting browser cookies and saved passwords, Microsoft 365 Single Sign-On (SSO) tokens, and Wi-Fi credentials.
Unlike CornFlake, ChocoShell does not establish persistence but extracts the most valuable credentials during runtime to compromise the victim’s cloud environments. The malware communicates with a hardcoded C2 server, disables the Antimalware Scan Interface (AMSI) to block Microsoft behavior-based detection, and escalates privileges for most impactful operations.
Microsoft believes the threat actor leveraged AI in coding ChocoShell due to “descriptive commentary” and a clear explanation of every decision.
FruitStone unsecured web management portal to manage compromised devices
Microsoft also identified an unsecured web management portal, FruitStone, that the attackers use to manage infected devices. The management portal enables the attacker to perform various malicious actions, including browsing files on infected devices, executing PowerShell commands, capturing screenshots, and logging keystrokes. Additionally, the unsecured web management portal exposes victims to additional cyber risks from opportunistic threat actors.
Meanwhile, Microsoft has recommended treating hotel Wi-Fi networks as untrusted and using cellular networks while using corporate devices in public venues.
“Organizations should assume that public and hospitality network infrastructure might not be trustworthy,” stated the tech giant.
Redmond also recommended enabling phishing-resistant multi-factor authentication (MFA), avoiding corporate credentials while logging onto hotel Wi-Fi networks, and turning off Microsoft Entra device code authentication unless necessary.
ReliaQuest also recommended routing all traffic via an always-on, full-tunnel VPN to protect traffic before it reaches hotel networks to limit exposure.
“Organizations should treat travel-related connectivity as an elevated-risk scenario by enforcing phishing-resistant multi-factor authentication, requiring encrypted VPN connections on untrusted networks, continuously monitoring for anomalous login activity, and limiting privileged access while employees are traveling,” added Centrella. “As espionage-focused operations continue to evolve, organizations must extend security visibility beyond their own networks to account for the external environments where business is conducted.”

