CaptiveCrunch Campaign Exposes Corporate Travelers to Credential Stealing Malware
Microsoft's Threat Intelligence has uncovered an ongoing operation, dubbed CaptiveCrunch, where attackers are redirecting travelers connected to hospitality and shared Wi-Fi networks in several countries. The campaign is attributed to Storm-2945, an operational sub-cluster of Midnight Blizzard, a group linked to the Foreign Intelligence Service of the Russian Federation.
The attacks can expose users to device code phishing or malware capable of stealing credentials, files, and Microsoft 365 authentication tokens. Since early May 2026, Microsoft has observed Storm-2945 manipulating DNS and HTTP traffic from networks served by captive portals. ReliaQuest has identified activity at hotels, conference centers, and other shared venues, assessing that corporate travelers' accounts are the intended targets.
The attackers use AI to support their operations, including device code and OAuth code phishing campaigns that can result in Microsoft Entra device registration and subsequent collection of Microsoft 365 data. The CaptiveCrunch campaign has also been found to target Android users, with some landing pages directing them to download and install an APK file.