Midnight Blizzard CaptiveCrunch hospitality Wi-Fi phishing campaign
Campaign
Summary
Hide ▲
Show ▼
Microsoft linked CaptiveCrunch to Midnight Blizzard / APT29, a global operation that abuses hospitality Wi‑Fi to steal Microsoft 365 accounts and deliver malware. The attackers manipulate DNS/HTTP traffic on captive portal equipment to redirect hotel and conference-center users to phishing pages and device-code phishing flows. Microsoft says the campaign has been active since early May, with related phishing activity running since February and observed since July. The operation also uses CornFlake and ChocoShell for persistence, credential theft, surveillance, and exfiltration.
Related Happenings
CaptiveCrunch Storm-2945 hotel Wi-Fi redirection campaign
Campaign
H score40
First: 01.08.2026 09:29
Last: 01.08.2026 09:29
Sources 1
How related:
Microsoft named the campaign CaptiveCrunch and believes it has been active since at least early May, although the threat actor has been running device and OAuth code phishing operations since February.
About this happening:
Microsoft linked the CaptiveCrunch campaign to Midnight Blizzard / APT29 / Storm-2945, saying it has been active since early May and targets hospitality Wi‑Fi ne...
CaptiveCrunch Storm-2945 hotel Wi-Fi redirection campaign
CampaignHow related: Microsoft named the campaign CaptiveCrunch and believes it has been active since at least early May, although the threat actor has been running device and OAuth code phishing operations since February.
About this happening: Microsoft linked the CaptiveCrunch campaign to Midnight Blizzard / APT29 / Storm-2945, saying it has been active since early May and targets hospitality Wi‑Fi ne...
Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign
Campaign
H score34
First: 24.07.2026 20:50
Last: 24.07.2026 20:50
Sources 1
About this happening:
Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can...
Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign
CampaignAbout this happening: Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can...
DNS poisoning campaign targeting captive Wi‑Fi routers to harvest corporate credentials
Campaign
H score34
First: 24.07.2026 15:00
Last: 24.07.2026 15:00
Sources 1
About this happening:
An ongoing DNS poisoning campaign is redirecting traffic from hotel and conference venue Wi‑Fi routers to harvest corporate login credentials, putting traveling employ...
DNS poisoning campaign targeting captive Wi‑Fi routers to harvest corporate credentials
CampaignAbout this happening: An ongoing DNS poisoning campaign is redirecting traffic from hotel and conference venue Wi‑Fi routers to harvest corporate login credentials, putting traveling employ...
ReliaQuest DNS poisoning mitigation guidance
Advisory/Mitigation
H score26
First: 24.07.2026 15:00
Last: 24.07.2026 15:00
Sources 1
About this happening:
ReliaQuest issued mitigation advice for DNS poisoning that can redirect legitimate traffic and expose endpoints to credential-harvesting. The guidance targets operator...
ReliaQuest DNS poisoning mitigation guidance
Advisory/MitigationAbout this happening: ReliaQuest issued mitigation advice for DNS poisoning that can redirect legitimate traffic and expose endpoints to credential-harvesting. The guidance targets operator...
Kratos ecosystem shift changes threat-actor operations
Threat Actor Meta
H score39
First: 22.07.2026 02:07
Last: 22.07.2026 02:07
Sources 1
About this happening:
The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...
Kratos ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...
Timeline
-
04.08.2026 03:17 2 articles · 1h ago
Microsoft links CaptiveCrunch to Midnight Blizzard and APT29
Initial DisclosureMicrosoft links the CaptiveCrunch campaign against hospitality Wi-Fi networks to Midnight Blizzard, also known as APT29, and says the operation has been active since at least early May after related device and OAuth code phishing began in February and was observed since July. The campaign manipulates DNS and HTTP traffic on captive portal equipment to redirect hotel and conference center users to Microsoft 365 login phishing pages and Microsoft Entra ID device-code phishing flows, while custom malware families CornFlake and ChocoShell support persistence, credential theft, surveillance, and data exfiltration; Microsoft also found an unprotected FruitStone management panel used to control infected systems and capture files, screenshots, and keystrokes.
Show sources
- Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts — www.bleepingcomputer.com — 04.08.2026 03:17
- Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts — www.bleepingcomputer.com — 04.08.2026 03:17