CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
ID: 9de146bc-d548-58de-ba53-0235fc8dcf61
STIX ID: report--9de146bc-d548-58de-ba53-0235fc8dcf61
Feed Name: Microsoft Security
Microsoft Threat Intelligence describes CaptiveCrunch, an ongoing targeted campaign by Storm-2945 (a sub-cluster of the Midnight Blizzard APT) that manipulates DNS/HTTP on captive-portal networks in hospitality and shared venues to perform device-code phishing, AitM redirections, and deliver malicious payloads. The report details two primary tools — CornFlake (a Go-based RAT providing persistent remote access and extensive data collection) and ChocoShell (an in-memory PowerShell infostealer focused on browser cookies, SSO tokens, and Wi‑Fi credentials) — plus the FruitStone operator C2, comprehensive IOCs, detection queries, and mitigation recommendations for organizations and travelers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
