logo

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

ID: 9de146bc-d548-58de-ba53-0235fc8dcf61

STIX ID: report--9de146bc-d548-58de-ba53-0235fc8dcf61

Feed Name: Microsoft Security

Threat Score
92/100

Date Published: 2026-07-31

Date Updated: 2026-08-01

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence describes CaptiveCrunch, an ongoing targeted campaign by Storm-2945 (a sub-cluster of the Midnight Blizzard APT) that manipulates DNS/HTTP on captive-portal networks in hospitality and shared venues to perform device-code phishing, AitM redirections, and deliver malicious payloads. The report details two primary tools — CornFlake (a Go-based RAT providing persistent remote access and extensive data collection) and ChocoShell (an in-memory PowerShell infostealer focused on browser cookies, SSO tokens, and Wi‑Fi credentials) — plus the FruitStone operator C2, comprehensive IOCs, detection queries, and mitigation recommendations for organizations and travelers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.