Microsoft Links Hotel Wi-Fi Hijacking Campaign to Russian-Linked Storm-2945
The 'CaptiveCrunch' operation leverages compromised hospitality networks to deploy surveillance malware via fake software updates.
State-sponsored attackers have hijacked hotel Wi-Fi captive portals to trick travelers into installing surveillance malware. Microsoft has attributed the operation, tracked as CaptiveCrunch, to Storm-2945, a sub-cluster of the Russian SVR-linked group Midnight Blizzard (also known as APT29).
According to Microsoft, the campaign began appearing across hospitality networks in several countries in early May 2026. The attackers compromised captive portal gateways to perform DNS poisoning, which redirects the automatic connectivity checks devices perform when joining a network. This manipulation sends users to fake browser or operating system update pages, which then deliver two primary payloads: 'CornFlake' and 'ChocoShell'.
CornFlake is a remote access trojan (RAT) written in Go. Once installed, it provides attackers with extensive surveillance capabilities, including the ability to capture webcam images, record microphone audio, log keystrokes, and take screenshots triggered by user idleness. The malware is also designed to extract browser credentials and cookies from the infected system.
Complementing the RAT is ChocoShell, an in-memory PowerShell-based infostealer. ChocoShell specifically targets Microsoft 365 single sign-on (SSO) tokens and browser sessions, allowing attackers to hijack authenticated identities without needing the user's primary password.
This operation marks a shift in targeting strategy by compromising the infrastructure of the hospitality industry rather than attempting to breach individual devices directly. By exploiting the inherent trust users place in hotel Wi-Fi, the attackers can target high-value travelers—such as government officials or corporate executives—who are frequently in transit and using public networks.
The use of Go-based implants and in-memory execution demonstrates a high level of technical sophistication aimed at evading traditional security software. By targeting SSO tokens, the group can bypass many standard authentication hurdles to gain persistent access to sensitive cloud environments.
Security researchers continue to monitor the evolution of the CaptiveCrunch infrastructure. While the primary attribution points to Midnight Blizzard, the seamless nature of the DNS redirection suggests that other hospitality networks may remain compromised. Organizations are advised to treat hotel Wi-Fi as untrusted and utilize encrypted tunnels or cellular data for sensitive communications.