As cited
Copy frozen at (site build).
threat intel
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Microsoft Threat Intelligence identified Storm-2945, a sub-cluster of Midnight Blizzard, conducting the CaptiveCrunch campaign since May 2026, targeting travelers through compromised captive portals in hospitality networks worldwide. The attackers manipulate DNS and HTTP traffic to redirect users through phishing infrastructure, deliver malware disguised as system updates, and steal credentials using device code authentication flows and adversary-in-the-middle techniques. The operation leverages AI-augmented methods and deploys fully-featured Windows remote access trojans with surveillance and credential theft capabilities, with potential targeting of Android devices as well.
Why it matters: Travelers and hospitality organizations face immediate risk of credential theft, system compromise, and surveillance when connecting to affected networks; security teams should prioritize detection of captive portal traffic manipulation and implement the provided Microsoft Defender guidance and indicators of compromise to protect users, especially while traveling.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Microsoft Threat Intelligence attributed the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Midnight Blizzard, which since May 2026 has manipulated DNS and HTTP traffic in hospitality sector captive portals worldwide to redirect travelers through phishing infrastructure and deliver malware. The operation uses artificial intelligence, doppelganger domains mimicking Microsoft services, device code authentication abuse, and ClickFix social engineering to steal credentials and deploy Windows remote access trojans with surveillance and keystroke logging capabilities, with potential targeting of Android devices as well.
Why it matters: Travelers and hospitality networks face credential theft and system compromise through captive portal manipulation; security teams managing enterprise device policies and Entra ID authentication should monitor for Storm-2945 indicators and implement detection rules immediately, especially for device code flow abuse.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Microsoft Threat Intelligence attributed the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Midnight Blizzard, which since May 2026 has manipulated DNS and HTTP traffic in hospitality sector captive portals worldwide to redirect travelers through phishing infrastructure and deliver malware. The operation uses artificial intelligence, doppelganger domains mimicking Microsoft services, device code authentication abuse, and ClickFix social engineering to steal credentials and deploy Windows remote access trojans with surveillance and keystroke logging capabilities, with potential targeting of Android devices as well.
Why it matters: Travelers and hospitality networks face credential theft and system compromise through captive portal manipulation; security teams managing enterprise device policies and Entra ID authentication should monitor for Storm-2945 indicators and implement detection rules immediately, especially for device code flow abuse.
- Source published
- First seen by Cybersecurity Tracker