Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Midnight Blizzard Abuses Hotel Wi-Fi to Deliver Malware, Steal Credentials
October 6, 2026
Meta and Microsoft Restrict Employee Access to Anthropic Claude AI
October 6, 2026
FBI Removes Accenture Contractor After Unpatched PeopleSoft Flaw Exposes Thousands of Employees
October 6, 2026
Home/Threats/Midnight Blizzard Abuses Hotel Wi-Fi to Deliver Malware, Steal Credentials
Threats

Midnight Blizzard Abuses Hotel Wi-Fi to Deliver Malware, Steal Credentials

Key Takeaways The state-backed hacking group Midnight Blizzard (Storm-2945) is actively exploiting hotel Wi-Fi captive portals to distribute malware and steal credentials. The campaign, dubbed...

Sarah simpson
Sarah simpson
October 6, 2026 5 Min Read
2 0

Key Takeaways

  • The state-backed hacking group Midnight Blizzard (Storm-2945) is actively exploiting hotel Wi-Fi captive portals to distribute malware and steal credentials.
  • The campaign, dubbed “CaptiveCrunch,” manipulates DNS and HTTP traffic to redirect users to malicious pages disguised as system updates or sign-in prompts.
  • Victims risk infection with remote-access trojans like CornFlake and the ChocoShell infostealer, leading to data exfiltration and potential corporate account compromise.
  • The attacks leverage AI-assisted malware development, including a new Rust variant of CornFlake, indicating sophisticated and evolving threats.
  • Mitigation requires treating public Wi-Fi as untrusted, using secure connections, and implementing strong identity defenses like phishing-resistant MFA and sign-in risk policies.

Travelers relying on hotel Wi-Fi networks are now confronting a sophisticated threat far beyond typical connectivity issues. A campaign linked to the notorious state-sponsored threat actor Midnight Blizzard has transformed seemingly innocuous captive portals—the web pages users encounter before gaining internet access—into a potent vector for malware delivery, credential theft, and potential infiltration of corporate accounts.

Table Of Content

  • Key Takeaways
  • Midnight Blizzard Exploits Hotel Wi-Fi Captive Portals
  • Malware, Credential Theft, and Defense
  • What You Should Do

This operation, identified as “CaptiveCrunch,” has impacted hospitality networks and other venues utilizing captive-portal technology across multiple countries. Attackers are targeting individuals during routine internet connectivity checks, substituting legitimate web pages with highly convincing prompts for system updates or requests for account sign-in credentials.

Microsoft’s security analysts have attributed this activity to Storm-2945, a specific operational subgroup within Midnight Blizzard. Microsoft initially detected this network manipulation in May 2026. In an update released on October 5, researchers noted a resurgence of activity beginning September 29, which included a Rust-based variant of the CornFlake malware, indicative of ongoing AI-assisted malware development efforts. This information was detailed in a report from Microsoft.

Microsoft said in a report that the repercussions of this campaign extend far beyond a single compromised device. Stolen credentials and cloud session tokens can expose critical business services, while sophisticated device-code phishing techniques can trick victims into approving an attacker’s authentication session, granting unauthorized access to sensitive accounts.

Midnight Blizzard Exploits Hotel Wi-Fi Captive Portals

The CaptiveCrunch attack sequence initiates with the manipulation of DNS and HTTP traffic on compromised guest networks. This redirection reroutes unsuspecting users through infrastructure controlled by the attackers. While the operation targets travelers globally, evidence suggests that the compromises may stem from vulnerabilities in shared captive-portal services rather than isolated, individual venues.

Upon redirection, users encounter a meticulously crafted fake page, often disguised as a legitimate browser or operating system update. These pages leverage “ClickFix” techniques, instructing users to perform a seemingly benign repair or verification step. This tactic effectively transforms familiar system warnings into a delivery mechanism for malicious payloads, echoing recent trends in fake update attacks where user interaction inadvertently installs malware.

Microsoft researchers have observed the deployment of Windows remote-access trojans (RATs), primarily written in Go. These RATs are capable of extensive malicious activities, including file collection, keystroke logging, credential and token theft, audio and video recording, and the establishment of remote command shells. Additionally, ClickFix pages targeting Android users have been seen prompting them to download and install malicious APK files. A primary implant, dubbed CornFlake, displays a deceptive progress window while stealthily copying itself to an application-data folder and establishing multiple persistence mechanisms to ensure re-execution after system reboots.

The CornFlake malware further enhances its stealth by masquerading as a legitimate Windows service named “Cloud Sync Service,” allowing it to blend into normal system operations and maintain persistent access. In some instances, the campaign redirects victims to carefully crafted lookalike domains of legitimate online services, facilitating adversary-in-the-middle (AiTM) phishing attacks. Users might be prompted to enter a device code on a seemingly authentic sign-in page, but this code is then used to authorize the attacker’s session, representing an evolution of earlier Teams credential theft operations linked to Midnight Blizzard.

Malware, Credential Theft, and Defense

Another key component of this campaign is ChocoShell, an in-memory PowerShell infostealer. ChocoShell is designed to target browser cookies, saved passwords, Microsoft 365 single sign-on (SSO) tokens, and stored Wi-Fi credentials. It possesses the capability to retrieve browser encryption keys and exploit browser debugging features to obtain readable cookies. This functionality provides attackers with a direct route to authenticated cloud sessions, circumventing the need for traditional password-based authentication.

This makes the CaptiveCrunch campaign particularly hazardous for corporate travelers. As demonstrated by numerous infostealer-fueled cloud breaches, reusable session data can be replayed against cloud services, virtual private networks (VPNs), and Software-as-a-Service (SaaS) applications. This creates a rapid pathway from initial device infection to a full-scale account compromise.

The deployed malware employs various evasion techniques to avoid detection, including disabling Windows anti-malware scanning controls, checking for analysis environments, and utilizing disguised HTTPS paths. The malware can also elevate privileges, compress stolen data, and exfiltrate it to its command-and-control (C2) server before meticulously removing temporary traces from the compromised system.

What You Should Do

  • Treat Public Wi-Fi as Untrusted: Always assume hotel, conference, airport, and other guest wireless networks are insecure.
  • Prioritize Secure Connections: Whenever possible, use a mobile hotspot or a personal encrypted connection instead of public Wi-Fi.
  • Avoid Unsolicited Downloads: Never download software or updates prompted by a captive portal. Always obtain updates directly through official operating system or browser update channels.
  • Implement Network Restrictions: Organizations should configure managed devices to prevent joining unapproved Wi-Fi networks. Provide employees with travel routers or secure hotspots that establish encrypted connections to trusted corporate infrastructure.
  • Exercise Credential Caution: Never reuse corporate credentials on guest network registration pages. Do not follow prompts to paste commands into PowerShell or other system command tools.
  • Strengthen Identity Defenses: Utilize passkeys and implement phishing-resistant multifactor authentication (MFA). Restrict device-code authentication to only absolutely necessary scenarios and enforce sign-in risk policies to challenge or block suspicious access attempts.
  • Investigate IoCs: Security teams should actively investigate the provided Indicators of Compromise (IoCs), unexpected downloads following connectivity tests, and any artifacts related to the CornFlake malware.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain cdn-gstat[.]com CaptiveCrunch redirect
Domain sslcdnhost[.]com CaptiveCrunch redirect
Domain network-privacy[.]com CaptiveCrunch redirect
Domain ms365-device[.]com CaptiveCrunch device-code-flow redirect
Domain ms365-live[.]com CaptiveCrunch device-code-flow redirect
Domain m365-owa[.]com CaptiveCrunch adversary-in-the-middle infrastructure
Domain owa-ms365[.]com CaptiveCrunch adversary-in-the-middle infrastructure
IP address 154.29.75[.]245 CaptiveCrunch infrastructure
IP address 149.3.170[.]186 CaptiveCrunch device-code-flow infrastructure
IP address 31.57.243[.]154 CaptiveCrunch adversary-in-the-middle infrastructure
IP address 38.146.28[.]75 CaptiveCrunch adversary-in-the-middle infrastructure
IP address 38.146.28[.]132 CaptiveCrunch DNS resolver
IP address 104.194.159[.]150 CaptiveCrunch adversary-in-the-middle infrastructure
IP address 107.189.26[.]194 ChocoShell C2 and CaptiveCrunch DNS resolver
IP address 213.145.86[.]112 ChocoShell command-and-control server
URL path 213.145.86[.]112/t/pixel.gif?m= ChocoShell beacon pattern
URL path 213.145.86[.]112/cdn/chunks/polyfill-7e2b.min.js ChocoShell secondary module retrieval
URL path 213.145.86[.]112/t/event ChocoShell data-exfiltration endpoint
File path %APPDATA%svchost32svchost32.exe CornFlake RAT executable location
SHA-256 918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593 CornFlake
SHA

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitMalwarephishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Meta and Microsoft Restrict Employee Access to Anthropic Claude AI

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Atlassian Patches Critical Flaws in Jira, Confluence, Bitbucket, 5 More Products
October 6, 2026
Top SAST Tools 2024: The Best Static Analysis Security Testers
October 6, 2026
Top 10 Just-in-Time (JIT) Access Tools for 2026
October 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us