CaptiveCrunch Storm-2945 hotel Wi-Fi redirection campaign
Campaign
Summary
Hide ▲
Show ▼
CaptiveCrunch is an active hotel Wi-Fi redirection campaign that is using fake browser updates and related lures to push payloads and redirect victims across several countries. The operation is attributed to Storm-2945 and linked to Midnight Blizzard / APT29 / Cozy Bear, giving it a clear operator thread. Its delivery chain can steer travelers into malware installation or MFA-satisfied access through Microsoft device code authentication. The persistence and breadth of the activity make it a continuing access risk for hospitality networks and their guests.
Related Happenings
Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign
Campaign
H score34
First: 24.07.2026 20:50
Last: 24.07.2026 20:50
Sources 1
About this happening:
Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can...
Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign
CampaignAbout this happening: Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can...
ReliaQuest DNS poisoning mitigation guidance
Advisory/Mitigation
H score26
First: 24.07.2026 15:00
Last: 24.07.2026 15:00
Sources 1
About this happening:
ReliaQuest issued mitigation advice for DNS poisoning that can redirect legitimate traffic and expose endpoints to credential-harvesting. The guidance targets operator...
ReliaQuest DNS poisoning mitigation guidance
Advisory/MitigationAbout this happening: ReliaQuest issued mitigation advice for DNS poisoning that can redirect legitimate traffic and expose endpoints to credential-harvesting. The guidance targets operator...
DNS poisoning campaign targeting captive Wi‑Fi routers to harvest corporate credentials
Campaign
H score34
First: 24.07.2026 15:00
Last: 24.07.2026 15:00
Sources 1
About this happening:
An ongoing DNS poisoning campaign is redirecting traffic from hotel and conference venue Wi‑Fi routers to harvest corporate login credentials, putting traveling employ...
DNS poisoning campaign targeting captive Wi‑Fi routers to harvest corporate credentials
CampaignAbout this happening: An ongoing DNS poisoning campaign is redirecting traffic from hotel and conference venue Wi‑Fi routers to harvest corporate login credentials, putting traveling employ...
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
Campaign
H score30
First: 15.07.2026 18:00
Last: 15.07.2026 18:00
Sources 1
About this happening:
The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
CampaignAbout this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
TonRAT Node.js implant with TON blockchain C2
Malware Activity
H score24
First: 26.06.2026 12:27
Last: 26.06.2026 12:27
Sources 1
About this happening:
TonRAT is using a Node.js implant to hide command-and-control lookups behind the TON blockchain API, increasing the chance that blocking and detection will fail. The a...
TonRAT Node.js implant with TON blockchain C2
Malware ActivityAbout this happening: TonRAT is using a Node.js implant to hide command-and-control lookups behind the TON blockchain API, increasing the chance that blocking and detection will fail. The a...
Timeline
-
01.08.2026 09:29 2 articles · 2h ago
CaptiveCrunch Storm-2945 hotel Wi-Fi redirection campaign
Initial DisclosureSince early May, the campaign has used hijacked hotel Wi-Fi and compromised captive portals to forge DNS answers and push fake browser updates. From July 16 onward, some landing pages also redirected guests into the device code authentication flow.
Show sources
- Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware — thehackernews.com — 01.08.2026 09:29
- Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware — thehackernews.com — 01.08.2026 09:29