Microsoft Threat Intelligence identified CaptiveCrunch, an ongoing cyberespionage campaign conducted by Storm-2945, a subgroup of the Russian state-sponsored actor Midnight Blizzard. The campaign compromises hospitality-sector captive portal infrastructure to perform adversary-in-the-middle attacks against travelers. By manipulating DNS and HTTP traffic, the attackers redirect victims to malicious infrastructure that delivers malware or phishing pages, including Microsoft Entra device code authentication prompts designed to hijack legitimate Microsoft 365 sessions.
Following successful compromise, the threat actors deploy the CornFlake remote access trojan and ChocoShell PowerShell infostealer to establish persistence, collect credentials and authentication tokens, perform surveillance, and exfiltrate sensitive data. The malware is capable of stealing browser credentials, Microsoft 365 SSO and Azure AD tokens, Wi-Fi credentials, documents, screenshots, audio, video, and keystrokes while providing operators with full remote command execution. Microsoft also observed the operators leveraging AI to support significant portions of the campaign, including malware development and operational activities.