Find notable cyber news and cases, enriched with sources, timelines, and signals.

CaptiveCrunch Storm-2945 hotel Wi-Fi redirection campaign

Campaign
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

CaptiveCrunch is an active hotel Wi-Fi redirection campaign that is using fake browser updates and related lures to push payloads and redirect victims across several countries. The operation is attributed to Storm-2945 and linked to Midnight Blizzard / APT29 / Cozy Bear, giving it a clear operator thread. Its delivery chain can steer travelers into malware installation or MFA-satisfied access through Microsoft device code authentication. The persistence and breadth of the activity make it a continuing access risk for hospitality networks and their guests.

Related Happenings

Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign

Campaign
H score34 First: 24.07.2026 20:50 Last: 24.07.2026 20:50 Sources 1

About this happening: Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can...

ReliaQuest DNS poisoning mitigation guidance

Advisory/Mitigation
H score26 First: 24.07.2026 15:00 Last: 24.07.2026 15:00 Sources 1

About this happening: ReliaQuest issued mitigation advice for DNS poisoning that can redirect legitimate traffic and expose endpoints to credential-harvesting. The guidance targets operator...

DNS poisoning campaign targeting captive Wi‑Fi routers to harvest corporate credentials

Campaign
H score34 First: 24.07.2026 15:00 Last: 24.07.2026 15:00 Sources 1

About this happening: An ongoing DNS poisoning campaign is redirecting traffic from hotel and conference venue Wi‑Fi routers to harvest corporate login credentials, putting traveling employ...

SeasonalInvite eCard phishing campaign targeting Windows and macOS users

Campaign
H score30 First: 15.07.2026 18:00 Last: 15.07.2026 18:00 Sources 1

About this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...

TonRAT Node.js implant with TON blockchain C2

Malware Activity
H score24 First: 26.06.2026 12:27 Last: 26.06.2026 12:27 Sources 1

About this happening: TonRAT is using a Node.js implant to hide command-and-control lookups behind the TON blockchain API, increasing the chance that blocking and detection will fail. The a...

Timeline

  1. 01.08.2026 09:29 2 articles · 2h ago

    CaptiveCrunch Storm-2945 hotel Wi-Fi redirection campaign

    Initial Disclosure

    Since early May, the campaign has used hijacked hotel Wi-Fi and compromised captive portals to forge DNS answers and push fake browser updates. From July 16 onward, some landing pages also redirected guests into the device code authentication flow.

    Show sources