Connect with us

NEWS

Russian Spies Keep Returning to Hotel Wi-Fi for Microsoft 365 Thefts

CaptiveCrunch by Storm-2945 hijacks hotel captive portals to deliver CornFlake malware and steal Microsoft 365 tokens.

Published

on

Microsoft Threat Intelligence has tied a global campaign of hotel and conference Wi-Fi hijacks that steal Microsoft 365 accounts to Storm-2945, a sub-cluster of the Russian SVR-linked group Midnight Blizzard. The operation, named CaptiveCrunch, has manipulated captive-portal traffic since at least early May 2026 and delivers custom malware alongside phishing pages.

The pattern is older than the new names. Russian intelligence services have treated hospitality networks as soft targets for traveler espionage for nearly a decade, and the latest tooling only makes the old playbook more efficient.

What has changed is the packaging. Earlier hotel campaigns leaned on quiet credential harvest and lateral movement. CaptiveCrunch layers phishing pages, device-code abuse, and full remote-access malware on the same captive-portal foothold, so a single compromised guest network can yield both immediate tokens and long-lived implants.

How the Captive Portal Redirect Works

Attackers first gain administrative control of captive-portal equipment that hotels and conference venues use to serve guest Wi-Fi. Microsoft and earlier researchers could not pin the exact initial access method, yet common equipment and management systems across victims point to possible shared infrastructure rather than one-off breaches.

Once inside, the operators alter DNS and HTTP handling so every guest who joins the network can be redirected. The guest never has to click a malicious email link. Joining the network is enough to place them on a path the operators control.

Three main paths appear:

  • Phishing pages that impersonate Microsoft 365 login portals.
  • Device-code phishing pages that abuse legitimate Microsoft Entra ID flows, observed more heavily since mid-July.
  • Fake browser or operating-system update pages that use ClickFix-style prompts to push users into running malware.

Some ClickFix landings also include Android APK instructions. That mobile branch widens the net beyond Windows laptops without changing the core captive-portal premise.

ReliaQuest earlier mapped the DNS-poisoning stage to multiple U.S. cities plus India and Saudi Arabia and saw traffic from financial services, legal, health care, energy and retail travelers. The goal is corporate Microsoft 365 access, not random consumer accounts.

Because the redirect happens at the network edge, ordinary browser warnings about suspicious sites offer little help. The page the guest sees can look like a normal login or update prompt served from infrastructure the venue itself appears to own.

CornFlake, ChocoShell and the FruitStone Panel

Microsoft’s analysis centers on two Windows malware families that work as a pair. CornFlake is a full-featured Go-based remote-access trojan. On first run it shows a fake progress window while it copies itself into %AppData% and installs persistence.

Configurable fake windows include:

  • Windows Update screen
  • Windows Security virus scan
  • DirectX or Visual C++ redistributable installers
  • Disk optimization or network diagnostics tools
  • Browser update or document-viewer installer prompts

The implant registers as a service named “Cloud Sync Service,” adds registry run keys and scheduled tasks, and runs a watchdog that restores any removed persistence. Its capability set is broad:

Capability What it does
Keylogging Raw input capture including password fields
Clipboard monitoring Records changes plus active window title
Screenshot and AV capture Idle-triggered and on-demand images plus microphone and webcam
Browser credential theft Live cookies from memory and stored passwords, including Chrome ABE bypass
File exfiltration Extension-targeted monitoring with upload throttle
USB monitoring and posture sweep Removable media scans plus 18 categories of host intel
Remote shell cmd.exe or PowerShell command execution

ChocoShell is the in-memory PowerShell companion focused on high-value theft: browser cookies and passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials. It disables AMSI, uses sandbox checks, performs silent UAC bypasses, and can lock Defender signatures. Extensive developer comments in the script led Microsoft to assess that AI tools likely assisted development of both families.

The division of labor is deliberate. CornFlake stays resident, watches the host, and gives operators a durable shell. ChocoShell runs lighter and faster against the credentials and tokens that matter most for cloud access. Together they cover both the long game of host control and the short game of session theft.

Component Role in the pair Primary yield
CornFlake Persistent Go RAT with fake UI and watchdog Keylogs, screenshots, files, remote shell, host posture
ChocoShell In-memory PowerShell companion Browser secrets, M365 and Azure AD tokens, Wi-Fi credentials
FruitStone panel Unauthenticated operator console Live control, payload building, proxy management

Operators manage everything through FruitStone, an unauthenticated web panel branded as “CloudSync Console” from a fictional Acuity Systems. It shows live agent status, remote shell, file browser, screenshot and keylog collection, payload building, and proxy management. Microsoft thanked Anthropic and OpenAI for collaboration during the investigation.

Organizations should assume that public and hospitality network infrastructure might not be trustworthy and should adopt controls that limit exposure to traffic manipulation, credential theft, and device code phishing.

That closing line from the Microsoft Threat Intelligence CaptiveCrunch findings frames the practical response.

A Decade of Hotel Wi-Fi as Espionage Real Estate

CaptiveCrunch is not an isolated invention. Russian actors have returned to the same physical venues for years.

  1. 2016-2017, FireEye documented APT28 (Fancy Bear / Forest Blizzard, linked to GRU) compromising European hotel networks, planting GameFish and XTunnel malware, and later using the leaked NSA EternalBlue exploit to move laterally and harvest guest credentials silently over Wi-Fi.
  2. August 2025 onward, Forest Blizzard and sub-group Storm-2754 compromised large numbers of SOHO routers, altered DNS settings, and enabled adversary-in-the-middle collection in the campaign Microsoft later detailed as Forest Blizzard SOHO DNS hijacking campaign.
  3. February 2026, Storm-2945 began AI-augmented device-code and OAuth phishing against Entra ID, later folding the same techniques into captive-portal redirects.
  4. Early May 2026, CaptiveCrunch traffic manipulation on hospitality captive portals begins; Microsoft attributes it to Storm-2945 of Midnight Blizzard (SVR) rather than Forest Blizzard despite TTP overlap.
  5. 23 July 2026, ReliaQuest publishes its hospitality DNS-poisoning findings, mapping venues and industries before Microsoft’s fuller malware disclosure on 31 July.

The services change (GRU then SVR) and the tooling grows more polished, yet the venue choice stays constant: places where corporate and government travelers drop their guard for a few hours of free internet.

The timeline also shows technique reuse across clusters. Device-code phishing that Storm-2945 ran against Entra ID in February reappears inside CaptiveCrunch redirects by mid-year. DNS tampering that Forest Blizzard applied to SOHO routers finds a hospitality echo in captive-portal handling. Overlap in methods does not erase the attribution split Microsoft draws, but it does explain why defenders keep seeing familiar moves in new wrappers.

Shared Equipment Raises the Blast Radius

Microsoft notes “notable commonalities in the equipment and management systems” across affected networks. That observation matters more than any single hotel name. If operators can reach a shared captive-portal management service or a common vendor platform, one compromise can seed many properties without individual physical access.

ReliaQuest assessed initial access with low-to-medium confidence as exposed management interfaces (SSH, SNMP, web consoles) plus weak or reused credentials. Neither firm has published a full list of affected brands or a hard count of venues. The absence of that list leaves every hospitality operator and every frequent traveler in the same uncertain position.

Shared management is what turns a local breach into a campaign. A single weak console credential, reused across properties, can place redirect logic in front of travelers who never visit the first compromised site. That is why the equipment commonality note carries more weight than any one city on the ReliaQuest map.

Until vendors and operators harden those management planes, travelers cannot know whether the portal in front of them is clean. The practical result is a default posture of distrust for any guest network that forces a captive page before granting access.

Corporate Travelers Carry the Cost

Victimology is consistent across both the ReliaQuest and Microsoft reporting: traveling employees from finance, professional services, legal, health care, energy and retail. The prize is long-lived access to Microsoft 365 mail, files and Teams, plus the ability to replay SSO tokens.

On X and security forums the immediate reaction mixed dark humor with practical advice. One widely shared post called CornFlake “this complete breakfast\ldots brought to you by the Kremlin.” Others simply repeated the oldest rule: treat hotel Wi-Fi as hostile and tether instead. The timing near DEF CON also produced jokes about burner devices, but the underlying point is serious. Once session tokens leave the device, MFA that only guards the initial password is already bypassed.

  • Primary target: corporate Microsoft 365 and Entra ID accounts of travelers
  • Secondary collection: browser cookies, saved passwords, Wi-Fi credentials, screenshots, keystrokes, microphone and webcam
  • Persistence goal: long-term intelligence collection consistent with Midnight Blizzard’s SVR remit

Those secondary items feed the primary goal. A stolen Wi-Fi credential or browser cookie can open a later path back into the same account ecosystem. Screenshots and keystrokes fill gaps when tokens expire. The collection mix matches an intelligence service that expects to stay on a target, not a smash-and-grab fraud crew.

Industry spread matters as much as geography. Finance, legal, health care, energy and retail travelers often carry cross-organization access. One compromised mailbox can expose counterparties who never set foot in the compromised hotel.

How Stolen Tokens Outrun Password MFA

CaptiveCrunch’s design shows why password-only multi-factor checks fall short once a guest network is hostile. Device-code phishing pages abuse legitimate Microsoft Entra ID flows. ChocoShell reaches for Microsoft 365 and Azure AD tokens directly. Browser credential theft pulls live cookies from memory.

In each path the operator is chasing proof of an already authenticated session, not the password that started it. When that proof leaves the device, a second factor that only protected the login form has nothing left to protect.

That is the mechanism behind the advice to block device code flow where possible and to pair phishing-resistant MFA with conditional access that evaluates device and location signals. The controls aim at the token and the context, not only at the password prompt the captive portal can fake.

CornFlake’s broader host access then keeps the door open if short-lived tokens need refreshing. Remote shell, keylogging and cookie theft from memory give operators ways to renew access without sending the user through another visible login.

Why Free Lobby Wi-Fi Stays Attractive

Nearly a decade of reporting still points at the same physical spaces. Hotels and conferences concentrate exactly the people Russian services want to read: corporate and government travelers who need mail, files and Teams while they are away from the office network.

Those venues also share structural weaknesses the campaigns keep exploiting. Captive portals must intercept traffic to authenticate guests. Management interfaces sit on equipment that is easy to leave exposed. Guests expect a login or welcome page and are primed to type credentials or approve prompts.

CaptiveCrunch does not invent that trap. It modernizes the bait with ClickFix-style update pages, Entra ID device-code flows and a polished RAT pair under a fake CloudSync brand. The efficiency gain is real, but the real estate is the same lobby network travelers have been warned about since the 2016-2017 hotel compromises.

Practical Defenses That Still Work

The technical mitigations are straightforward even if the infrastructure problem is not. Microsoft and ReliaQuest converge on the same short list.

  • Prefer private cellular, eSIM or managed travel hotspots over hotel or conference Wi-Fi whenever data plans allow.
  • Never install “updates,” certificates or diagnostics offered through a captive portal; verify any real update through the operating system’s own channels.
  • Enforce always-on full-tunnel VPN on corporate devices so DNS never hits the local gateway. ReliaQuest called this the single control that stops the attack at source.
  • Adopt phishing-resistant MFA and passkeys through Microsoft Authenticator; pair them with conditional access that evaluates device and location signals.
  • Block device code flow where possible in Entra Conditional Access; allow it only for specific, justified scenarios.
  • Do not enter corporate credentials on guest-network registration pages.
  • Treat any unexpected Windows Update, Defender scan or “verification” dialog on an untrusted network as hostile until proven otherwise.

The ReliaQuest July hospitality DNS report also notes that opportunistic encrypted DNS still fails open to plaintext; only strict DoH/DoT modes close the forgery window.

Layering matters. A full-tunnel VPN stops the DNS lie at the source. Passkeys and conditional access shrink the value of any page that still appears. Blocking device code flow closes a path Storm-2945 has already used outside and inside captive portals. None of these controls requires the hotel to fix its gear first.

Hotel Wi-Fi has been a known intelligence collection surface since at least 2017. CaptiveCrunch simply proves the surface is still open, the operators are still Russian services, and the payload has grown from quiet credential harvest to full remote-access and token theft. Travelers who already treat every captive portal as untrusted are already doing the most effective thing the reports recommend.

As the founder of Thunder Tiger Europe Media, Dr. Elias Thornwood brings over 25 years of experience in international journalism, having reported from conflict zones in the Middle East, Asia, and Africa for outlets like BBC World and Reuters. With a PhD in International Relations from Oxford University, his expertise lies in geopolitical analysis and global diplomacy. Elias has authored two bestselling books on European foreign policy and received the Pulitzer Prize for International Reporting in 2015, establishing his authoritativeness in the field. Committed to trustworthiness, he enforces rigorous fact-checking protocols at Thunder Tiger, ensuring unbiased, evidence-based coverage of worldwide news to empower informed global audiences.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending