logo

CaptiveCrunch Malware Campaign Hijacks Hotel Wi-Fi Worldwide

ID: 237095ae-c71c-5bd6-82f8-305ade948d98

STIX ID: report--237095ae-c71c-5bd6-82f8-305ade948d98

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-08-06

Date Updated: 2026-08-06

Author: Do Son

...
...

Microsoft and ReliaQuest report that a Russia-linked group tracked as Storm-2945 has been manipulating captive-portal Wi‑Fi at hotels and conference venues since May 2026 to push fake updates (CaptiveCrunch), delivering a Go-based RAT and an in-memory PowerShell credential stealer to harvest corporate credentials and Microsoft 365 tokens; the activity is assessed as part of a broader espionage campaign attributed to Midnight Blizzard with guidance provided for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.