Midnight Blizzard Hijacks Hotel Wi-Fi to Steal Traveler Credentials
Microsoft has issued a warning about a Russia-linked threat group called Midnight Blizzard, which is compromising hospitality networks worldwide to target travelers with credential-stealing malware and phishing pages.
The campaign, dubbed CaptiveCrunch, involves the Storm-2945 subgroup of Midnight Blizzard and has been active since early May. The attackers are conducting 'widespread but targeted traffic manipulation attacks' against networks that use captive portals, including Wi-Fi services at hotels and conference centers.
Victims may encounter fake Microsoft sign-in pages or prompts claiming that a browser, Windows component, or device driver requires an update. Some phishing pages use adversary-in-the-middle techniques to capture credentials and session tokens, while others abuse the Microsoft Entra ID device code authentication flow.
The group is also deploying a Windows remote access trojan called CornFlake, which can log keystrokes, collect files, steal browser credentials and session tokens, monitor removable drives, and capture audio and video. A companion PowerShell implant called ChocoShell runs in memory and focuses on stealing browser cookies, saved passwords, Microsoft 365 single sign-on tokens, and Wi-Fi credentials.