Microsoft Links Hotel Wi-Fi Attacks to Russian Hackers
Microsoft has linked a global campaign of Wi-Fi attacks targeting hospitality networks to the Russian threat actor Midnight Blizzard (APT29). The campaign, named CaptiveCrunch, manipulates DNS settings on hotel and conference equipment to steal Microsoft 365 accounts.
The company believes this activity is connected to Storm-2945, a sub-cluster of Midnight Blizzard, and has identified two malware families used for persistent access: CornFlake and ChocoShell. These families allow the attackers to steal credentials, surveil devices, and exfiltrate data.
Microsoft analyzed the attack's modus operandi, which involves intercepting user connections through captive portals. This allows them to redirect victims in three ways:
The first method leads to phishing pages impersonating Microsoft 365 login portals. The second uses device code phishing pages that exploit Microsoft Entra ID authentication flows.
The third, newly disclosed, involves fake browser and operating system update pages that deliver malware to Windows through ClickFix prompts requesting user verification.