CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3661

As cited

Copy frozen at (site build).

threat intel

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Microsoft Threat Intelligence identified Storm-2945, a sub-cluster of Midnight Blizzard, conducting the CaptiveCrunch campaign since May 2026, targeting travelers through compromised captive portals in hospitality networks worldwide. The attackers manipulate DNS and HTTP traffic to redirect users through phishing infrastructure, deliver malware disguised as system updates, and steal credentials using device code authentication flows and adversary-in-the-middle techniques. The operation leverages AI-augmented methods and deploys fully-featured Windows remote access trojans with surveillance and credential theft capabilities, with potential targeting of Android devices as well.

Why it matters: Travelers and hospitality organizations face immediate risk of credential theft, system compromise, and surveillance when connecting to affected networks; security teams should prioritize detection of captive portal traffic manipulation and implement the provided Microsoft Defender guidance and indicators of compromise to protect users, especially while traveling.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Microsoft Threat Intelligence attributed the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Midnight Blizzard, which since May 2026 has manipulated DNS and HTTP traffic in hospitality sector captive portals worldwide to redirect travelers through phishing infrastructure and deliver malware. The operation uses artificial intelligence, doppelganger domains mimicking Microsoft services, device code authentication abuse, and ClickFix social engineering to steal credentials and deploy Windows remote access trojans with surveillance and keystroke logging capabilities, with potential targeting of Android devices as well.

Why it matters: Travelers and hospitality networks face credential theft and system compromise through captive portal manipulation; security teams managing enterprise device policies and Entra ID authentication should monitor for Storm-2945 indicators and implement detection rules immediately, especially for device code flow abuse.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Microsoft Threat Intelligence attributed the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Midnight Blizzard, which since May 2026 has manipulated DNS and HTTP traffic in hospitality sector captive portals worldwide to redirect travelers through phishing infrastructure and deliver malware. The operation uses artificial intelligence, doppelganger domains mimicking Microsoft services, device code authentication abuse, and ClickFix social engineering to steal credentials and deploy Windows remote access trojans with surveillance and keystroke logging capabilities, with potential targeting of Android devices as well.

Why it matters: Travelers and hospitality networks face credential theft and system compromise through captive portal manipulation; security teams managing enterprise device policies and Entra ID authentication should monitor for Storm-2945 indicators and implement detection rules immediately, especially for device code flow abuse.

VendorsMicrosoftGoogle
Actorsmidnight blizzardforest blizzard
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary