CaptiveCrunch: Midnight Blizzard Hospitality Network AiTM Campaign (Campaign)
ID: db642761-8606-5220-b8dd-ecea65958d06
STIX ID: report--db642761-8606-5220-b8dd-ecea65958d06
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2026-07-31
Date Updated: 2026-08-03
Author: [email protected] (Wiz Threat Research)
Microsoft Threat Intelligence identified "CaptiveCrunch," an ongoing nation-state cyberespionage campaign by Storm-2945/Midnight Blizzard that compromises hospitality captive-portal infrastructure to perform adversary-in-the-middle attacks against travelers, redirecting DNS/HTTP traffic to malicious infrastructure to deliver malware or phishing (including Microsoft Entra device code prompts) to hijack Microsoft 365 sessions; operators deploy CornFlake RAT and ChocoShell PowerShell infostealer to persist, steal credentials and tokens, exfiltrate sensitive data (browser credentials, SSO/Azure AD tokens, Wi‑Fi credentials, documents, media, keystrokes) and leverage AI for development and operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
