CaptiveCrunch Storm-2945 hotel Wi-Fi redirection campaign
Campaign
Summary
Hide ▲
Show ▼
Microsoft linked the CaptiveCrunch campaign to Midnight Blizzard / APT29 / Storm-2945, saying it has been active since early May and targets hospitality Wi‑Fi networks through captive portal equipment. The activity manipulates DNS and HTTP traffic to redirect users from hotel and conference center Wi‑Fi to Microsoft 365 phishing pages, device code phishing pages, and some ClickFix lures. Microsoft also identified CornFlake and ChocoShell for persistent access, credential theft, surveillance, and data exfiltration. The campaign has also shown signs of targeting Android devices and uses an exposed FruitStone management panel.
Related Happenings
Midnight Blizzard CaptiveCrunch hospitality Wi-Fi phishing campaign
Campaign
H score37
First: 04.08.2026 03:17
Last: 04.08.2026 03:17
Sources 1
How related:
Microsoft named the campaign CaptiveCrunch and believes it has been active since at least early May, although the threat actor has been running device and OAuth code phishing operations since February.
About this happening:
Microsoft linked CaptiveCrunch to Midnight Blizzard / APT29, a global operation that abuses hospitality Wi‑Fi to steal Microsoft 365 accounts and deliver malware....
Midnight Blizzard CaptiveCrunch hospitality Wi-Fi phishing campaign
CampaignHow related: Microsoft named the campaign CaptiveCrunch and believes it has been active since at least early May, although the threat actor has been running device and OAuth code phishing operations since February.
About this happening: Microsoft linked CaptiveCrunch to Midnight Blizzard / APT29, a global operation that abuses hospitality Wi‑Fi to steal Microsoft 365 accounts and deliver malware....
Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign
Campaign
H score34
First: 24.07.2026 20:50
Last: 24.07.2026 20:50
Sources 1
About this happening:
Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can...
Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign
CampaignAbout this happening: Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can...
ReliaQuest DNS poisoning mitigation guidance
Advisory/Mitigation
H score26
First: 24.07.2026 15:00
Last: 24.07.2026 15:00
Sources 1
About this happening:
ReliaQuest issued mitigation advice for DNS poisoning that can redirect legitimate traffic and expose endpoints to credential-harvesting. The guidance targets operator...
ReliaQuest DNS poisoning mitigation guidance
Advisory/MitigationAbout this happening: ReliaQuest issued mitigation advice for DNS poisoning that can redirect legitimate traffic and expose endpoints to credential-harvesting. The guidance targets operator...
DNS poisoning campaign targeting captive Wi‑Fi routers to harvest corporate credentials
Campaign
H score34
First: 24.07.2026 15:00
Last: 24.07.2026 15:00
Sources 1
About this happening:
An ongoing DNS poisoning campaign is redirecting traffic from hotel and conference venue Wi‑Fi routers to harvest corporate login credentials, putting traveling employ...
DNS poisoning campaign targeting captive Wi‑Fi routers to harvest corporate credentials
CampaignAbout this happening: An ongoing DNS poisoning campaign is redirecting traffic from hotel and conference venue Wi‑Fi routers to harvest corporate login credentials, putting traveling employ...
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
Campaign
H score30
First: 15.07.2026 18:00
Last: 15.07.2026 18:00
Sources 1
About this happening:
The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
CampaignAbout this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
Timeline
-
01.08.2026 09:29 5 articles · 6d ago
CaptiveCrunch Storm-2945 hotel Wi-Fi redirection campaign
Initial DisclosureSince early May, the campaign has used hijacked hotel Wi-Fi and compromised captive portals to forge DNS answers and push fake browser updates. From July 16 onward, some landing pages also redirected guests into the device code authentication flow.
Show sources
- Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware — thehackernews.com — 01.08.2026 09:29
- Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware — thehackernews.com — 01.08.2026 09:29
- Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking — www.securityweek.com — 03.08.2026 12:17
- Midnight Blizzard Targets Travelers via Captive Portals — www.infosecurity-magazine.com — 03.08.2026 17:30
- Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts — www.bleepingcomputer.com — 04.08.2026 03:17