CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Permanent story citation

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 3661

As cited

Citation snapshot as of .

threat intel

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Microsoft Threat Intelligence identified Storm-2945, a sub-cluster of Midnight Blizzard, conducting the CaptiveCrunch campaign since May 2026, targeting travelers through compromised captive portals in hospitality networks worldwide. The attackers manipulate DNS and HTTP traffic to redirect users through phishing infrastructure, deliver malware disguised as system updates, and steal credentials using device code authentication flows and adversary-in-the-middle techniques. The operation leverages AI-augmented methods and deploys fully-featured Windows remote access trojans with surveillance and credential theft capabilities, with potential targeting of Android devices as well.

Why it matters: Travelers and hospitality organizations face immediate risk of credential theft, system compromise, and surveillance when connecting to affected networks; security teams should prioritize detection of captive portal traffic manipulation and implement the provided Microsoft Defender guidance and indicators of compromise to protect users, especially while traveling.

Source published
First seen by Cybersecurity Tracker

Source attribution