Russian Hackers Exploit Hotel Wi-Fi in New CaptiveCrunch Espionage Campaign
ID: effa84f0-a727-5666-9e3a-d9feafa2447d
STIX ID: report--effa84f0-a727-5666-9e3a-d9feafa2447d
Feed Name: The Cyber Express
Microsoft Threat Intelligence attributes an active campaign called “CaptiveCrunch” to Storm-2945 (Midnight Blizzard/SVR). The operation, active since May 2026, intercepts hospitality captive-portal and Wi‑Fi traffic to serve fake Microsoft sign-in pages and malicious updates, stealing Entra ID credentials and deploying CornFlake (a Go-based RAT) and ChocoShell (a memory-resident infostealer) managed via a FruitStone web C2; Microsoft advises treating public Wi‑Fi as untrusted, enforcing phishing-resistant MFA, restricting OAuth, monitoring device registrations, and using trusted VPNs or hotspots.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
