logo

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

ID: a58e3839-1b78-5a5d-a1bb-0e5121c10400

STIX ID: report--a58e3839-1b78-5a5d-a1bb-0e5121c10400

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-08-01

Date Updated: 2026-08-02

Author: Pierluigi Paganini

...
...

**Executive summary:** Microsoft Threat Intelligence attributes the CaptiveCrunch campaign to Storm-2945 (an SVR-linked APT) that since May 2026 has been manipulating DNS/HTTP on captive-portal hotel and venue Wi‑Fi to redirect guests to fake update/installer pages that deploy CornFlake (a full-featured Go RAT) and ChocoShell (an in-memory PowerShell infostealer) to harvest Microsoft 365/Azure AD tokens, browser credentials, and other sensitive data; operators use the FruitStone web C2 and device-code phishing to obtain MFA-satisfied sessions, and defenders are advised to treat venue Wi‑Fi as hostile, avoid executing portal-provided binaries, and block device-code flow via Conditional Access where possible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.