Midnight Blizzard Hackers Exploit Hotel Wi-Fi for Credential Theft
Russian hackers from the Midnight Blizzard group have been targeting public Wi-Fi networks at hotels and conference centers, stealing Microsoft 365 credentials and deploying malware. The campaign, dubbed CaptiveCrunch by Microsoft, has been ongoing since February 2026.
The attackers manipulate DNS and HTTP traffic on compromised captive portal networks to redirect victims down three paths: two for credential theft through phishing pages impersonating Microsoft 365 sign-in portals or device code phishing pages abusing Microsoft Entra ID authentication flows. The third displays fake browser or operating system update pages using the ClickFix social engineering method to persuade victims to download and run malware.
The CaptiveCrunch infrastructure is managed by a web-based C2 panel called FruitStone, which gives operators a dashboard for managing compromised endpoints, building and deploying new payloads, and reviewing collected data. Microsoft recommends treating hotel and conference Wi-Fi as untrusted and using private cellular or managed connections where practical.