Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
ID: a58e3839-1b78-5a5d-a1bb-0e5121c10400
STIX ID: report--a58e3839-1b78-5a5d-a1bb-0e5121c10400
Feed Name: Security Affairs
**Executive summary:** Microsoft Threat Intelligence attributes the CaptiveCrunch campaign to Storm-2945 (an SVR-linked APT) that since May 2026 has been manipulating DNS/HTTP on captive-portal hotel and venue Wi‑Fi to redirect guests to fake update/installer pages that deploy CornFlake (a full-featured Go RAT) and ChocoShell (an in-memory PowerShell infostealer) to harvest Microsoft 365/Azure AD tokens, browser credentials, and other sensitive data; operators use the FruitStone web C2 and device-code phishing to obtain MFA-satisfied sessions, and defenders are advised to treat venue Wi‑Fi as hostile, avoid executing portal-provided binaries, and block device-code flow via Conditional Access where possible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
