CaptiveCrunch Malware Campaign Hijacks Hotel Wi-Fi Worldwide
ID: 237095ae-c71c-5bd6-82f8-305ade948d98
STIX ID: report--237095ae-c71c-5bd6-82f8-305ade948d98
Feed Name: securityonline.info
Microsoft and ReliaQuest report that a Russia-linked group tracked as Storm-2945 has been manipulating captive-portal Wi‑Fi at hotels and conference venues since May 2026 to push fake updates (CaptiveCrunch), delivering a Go-based RAT and an in-memory PowerShell credential stealer to harvest corporate credentials and Microsoft 365 tokens; the activity is assessed as part of a broader espionage campaign attributed to Midnight Blizzard with guidance provided for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
