Russian Hackers Exploit Hotel Wi-Fi Networks to Breach Microsoft 365 Accounts
A sophisticated global campaign has been linked to a Russian threat actor, targeting hospitality Wi-Fi networks and compromising Microsoft 365 accounts. The attackers use custom malware to intercept user connections, steal credentials, and gain persistent access to sensitive data.
The campaign, dubbed CaptiveCrunch by Microsoft, involves manipulating DNS settings on hotel and conference center Wi-Fi networks. By altering these settings, the attackers can redirect victims to phishing pages that impersonate Microsoft 365 login portals or device code phishing pages that abuse Microsoft Entra ID authentication flows. This allows them to steal sensitive information, including Microsoft 365 session tokens and browser credentials.
The threat actor, tracked as Storm-2945 – a sub-cluster of Midnight Blizzard, has been active since at least early May, although the campaign’s exact initial compromise remains unknown. The attackers also use fake browser and operating system update pages that deliver malware to Windows via ClickFix prompts for user verification. In some cases, they attempt to target Android devices with an APK file.
Microsoft analyzed two new Windows malware families: CornFlake and ChocoShell. CornFlake is a Go-based remote access trojan (RAT) that offers a range of capabilities, including remote shell access, keylogging, clipboard monitoring, and browser credential theft. It disguises itself as “Cloud Sync Service” to appear legitimate and uses multiple persistence mechanisms on the host.
ChocoShell, an in-memory PowerShell credential stealer, targets browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials. The code suggests that AI tools were used to develop these malware pieces. An unprotected web-based management panel named FruitStone was also discovered, allowing the threat actor to handle infected systems, browse victim files, and capture screenshots.
The attack highlights the importance of treating hotel and conference Wi-Fi as untrusted networks. Microsoft recommends using private cellular or managed connections whenever possible and avoiding software updates or tools offered through captive portals. Adopting phishing-resistant authentication with MFA and passkeys is also crucial to preventing such attacks. Security teams should regularly test their defenses to ensure that threats are not slipping through undetected.
In the face of increasingly sophisticated cyber threats, it’s essential for individuals and organizations to stay vigilant. By understanding the tactics used by attackers like Storm-2945 and implementing robust security measures, we can reduce our exposure to these types of attacks.
Source: Bleeping Computer — 2026-08-04