Travelers connecting to hotel Wi-Fi may now face more than an unreliable internet signal. A campaign linked to Midnight Blizzard has turned captive portals, the sign-in pages shown before online access, into a route for malware, credential theft, and possible access to corporate accounts.
The operation, known as CaptiveCrunch, has affected hospitality-related networks and other venues using captive-portal equipment in several countries.
It targets people during routine connectivity checks, replacing expected web pages with convincing update prompts or account sign-in requests.
Microsoft analysts identified the activity as the work of Storm-2945, an operational sub-cluster of Midnight Blizzard. Microsoft first observed network manipulation in May 2026.
In an October 5 update, researchers reported renewed activity beginning September 29, including a Rust variant of CornFlake consistent with continued AI-assisted malware development.
Microsoft said in a report shared with Cyber Security News (CSN) that the risk extends beyond a single infected laptop. Stolen passwords and cloud session tokens can expose business services, while device-code phishing can persuade victims to approve an attacker’s authentication session.
CaptiveCrunch begins when attackers manipulate DNS and HTTP traffic on affected guest networks, redirecting users through infrastructure they control.
The operation targets travelers worldwide, while evidence suggests compromises may involve shared captive-portal services rather than isolated venues.
The altered page can pose as a browser or operating-system update and exploit ClickFix techniques, which tell people to perform a supposed repair or verification step.
This turns familiar warnings into a delivery channel, much like recent fake update attacks, where user interaction installs the malicious payload.
Microsoft observed Windows remote-access trojans written in Go that can collect files and keystrokes, steal credentials and tokens, record audio or video, and open a remote command shell.
Researchers also saw Android instructions on ClickFix pages encouraging users to download and install an APK file. A principal implant, CornFlake, displays a false progress window while copying itself to an application-data folder and creating several ways to restart after reboot.
It masquerades as a Windows service called Cloud Sync Service, helping it blend in while maintaining access. The campaign also redirects some victims to lookalike online-service domains for adversary-in-the-middle phishing.
A user may be asked to enter a device code on a real sign-in page, but the code authorizes the attacker’s session, an evolution of earlier Teams credential theft operations associated with Midnight Blizzard.
ChocoShell, an in-memory PowerShell infostealer, focuses on browser cookies, saved passwords, Microsoft 365 single sign-on tokens, and stored Wi-Fi credentials.
It can retrieve browser encryption keys and use browser debugging features to obtain readable cookies, giving attackers a route to authenticated cloud sessions without relying only on a password.
That makes the campaign especially serious for corporate travelers. As infostealer fueled cloud breaches have shown, usable session data can be replayed against cloud services, VPNs, and SaaS applications, creating a fast path from device infection to account compromise.
The malware attempts to evade inspection by disabling Windows anti-malware scanning controls, checking for analysis environments, and using disguised HTTPS paths.
It can elevate privileges, compress stolen data, and send it to its command-and-control server before removing temporary traces. Travelers should treat hotel, conference, airport, and other guest wireless networks as untrusted.
Prefer a mobile hotspot or other private connection when practical, avoid downloads offered by a captive portal, and confirm updates only through normal operating-system or browser update channels.
Organizations should prevent managed devices from joining unapproved Wi-Fi networks where feasible and use travel routers or hotspots that establish encrypted connections to trusted infrastructure.
Staff should never reuse corporate credentials on a guest-network registration page or follow a prompt to paste commands into PowerShell or other system command tools.
Identity defenses matter as much as endpoint controls. Use passkeys and phishing-resistant multifactor authentication, restrict device-code authentication to required cases, and use sign-in risk policies to challenge or block suspicious access.
Security teams should investigate the listed infrastructure, unexpected downloads after connectivity tests, and CornFlake artifacts.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | cdn-gstat[.]com | CaptiveCrunch redirect |
| Domain | sslcdnhost[.]com | CaptiveCrunch redirect |
| Domain | network-privacy[.]com | CaptiveCrunch redirect |
| Domain | ms365-device[.]com | CaptiveCrunch device-code-flow redirect |
| Domain | ms365-live[.]com | CaptiveCrunch device-code-flow redirect |
| Domain | m365-owa[.]com | CaptiveCrunch adversary-in-the-middle infrastructure |
| Domain | owa-ms365[.]com | CaptiveCrunch adversary-in-the-middle infrastructure |
| IP address | 154.29.75[.]245 | CaptiveCrunch infrastructure |
| IP address | 149.3.170[.]186 | CaptiveCrunch device-code-flow infrastructure |
| IP address | 31.57.243[.]154 | CaptiveCrunch adversary-in-the-middle infrastructure |
| IP address | 38.146.28[.]75 | CaptiveCrunch adversary-in-the-middle infrastructure |
| IP address | 38.146.28[.]132 | CaptiveCrunch DNS resolver |
| IP address | 104.194.159[.]150 | CaptiveCrunch adversary-in-the-middle infrastructure |
| IP address | 107.189.26[.]194 | ChocoShell C2 and CaptiveCrunch DNS resolver |
| IP address | 213.145.86[.]112 | ChocoShell command-and-control server |
| URL path | 213.145.86[.]112/t/pixel.gif?m= | ChocoShell beacon pattern |
| URL path | 213.145.86[.]112/cdn/chunks/polyfill-7e2b.min.js | ChocoShell secondary module retrieval |
| URL path | 213.145.86[.]112/t/event | ChocoShell data-exfiltration endpoint |
| File path | %APPDATA%\svchost32\svchost32.exe | CornFlake RAT executable location |
| SHA-256 | 918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593 | CornFlake |
| SHA-256 | be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c | ChocoShell |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Meta and Microsoft are reducing employee use of Anthropic’s Claude AI while pushing their own…
ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote…
The FBI removed an Accenture contractor on October 5, 2026, after a missed security patch…
Google has detailed six Advanced Protection enhancements for Android 17, targeting sophisticated attacks, scams and…
Atlassian has disclosed a critical arbitrary file access vulnerability affecting eight products, including Jira, Confluence,…
The AI-code flood made one truth undeniable: static analysis only matters if developers fix what…