Midnight Blizzard Abuses Hotel Wi-Fi to Deliver Malware, Steal Credentials
Key Takeaways The state-backed hacking group Midnight Blizzard (Storm-2945) is actively exploiting hotel Wi-Fi captive portals to distribute malware and steal credentials. The campaign, dubbed...
Key Takeaways
- The state-backed hacking group Midnight Blizzard (Storm-2945) is actively exploiting hotel Wi-Fi captive portals to distribute malware and steal credentials.
- The campaign, dubbed “CaptiveCrunch,” manipulates DNS and HTTP traffic to redirect users to malicious pages disguised as system updates or sign-in prompts.
- Victims risk infection with remote-access trojans like CornFlake and the ChocoShell infostealer, leading to data exfiltration and potential corporate account compromise.
- The attacks leverage AI-assisted malware development, including a new Rust variant of CornFlake, indicating sophisticated and evolving threats.
- Mitigation requires treating public Wi-Fi as untrusted, using secure connections, and implementing strong identity defenses like phishing-resistant MFA and sign-in risk policies.
Travelers relying on hotel Wi-Fi networks are now confronting a sophisticated threat far beyond typical connectivity issues. A campaign linked to the notorious state-sponsored threat actor Midnight Blizzard has transformed seemingly innocuous captive portals—the web pages users encounter before gaining internet access—into a potent vector for malware delivery, credential theft, and potential infiltration of corporate accounts.
Table Of Content
This operation, identified as “CaptiveCrunch,” has impacted hospitality networks and other venues utilizing captive-portal technology across multiple countries. Attackers are targeting individuals during routine internet connectivity checks, substituting legitimate web pages with highly convincing prompts for system updates or requests for account sign-in credentials.
Microsoft’s security analysts have attributed this activity to Storm-2945, a specific operational subgroup within Midnight Blizzard. Microsoft initially detected this network manipulation in May 2026. In an update released on October 5, researchers noted a resurgence of activity beginning September 29, which included a Rust-based variant of the CornFlake malware, indicative of ongoing AI-assisted malware development efforts. This information was detailed in a report from Microsoft.
Microsoft said in a report that the repercussions of this campaign extend far beyond a single compromised device. Stolen credentials and cloud session tokens can expose critical business services, while sophisticated device-code phishing techniques can trick victims into approving an attacker’s authentication session, granting unauthorized access to sensitive accounts.
Midnight Blizzard Exploits Hotel Wi-Fi Captive Portals
The CaptiveCrunch attack sequence initiates with the manipulation of DNS and HTTP traffic on compromised guest networks. This redirection reroutes unsuspecting users through infrastructure controlled by the attackers. While the operation targets travelers globally, evidence suggests that the compromises may stem from vulnerabilities in shared captive-portal services rather than isolated, individual venues.
Upon redirection, users encounter a meticulously crafted fake page, often disguised as a legitimate browser or operating system update. These pages leverage “ClickFix” techniques, instructing users to perform a seemingly benign repair or verification step. This tactic effectively transforms familiar system warnings into a delivery mechanism for malicious payloads, echoing recent trends in fake update attacks where user interaction inadvertently installs malware.
Microsoft researchers have observed the deployment of Windows remote-access trojans (RATs), primarily written in Go. These RATs are capable of extensive malicious activities, including file collection, keystroke logging, credential and token theft, audio and video recording, and the establishment of remote command shells. Additionally, ClickFix pages targeting Android users have been seen prompting them to download and install malicious APK files. A primary implant, dubbed CornFlake, displays a deceptive progress window while stealthily copying itself to an application-data folder and establishing multiple persistence mechanisms to ensure re-execution after system reboots.
The CornFlake malware further enhances its stealth by masquerading as a legitimate Windows service named “Cloud Sync Service,” allowing it to blend into normal system operations and maintain persistent access. In some instances, the campaign redirects victims to carefully crafted lookalike domains of legitimate online services, facilitating adversary-in-the-middle (AiTM) phishing attacks. Users might be prompted to enter a device code on a seemingly authentic sign-in page, but this code is then used to authorize the attacker’s session, representing an evolution of earlier Teams credential theft operations linked to Midnight Blizzard.
Malware, Credential Theft, and Defense
Another key component of this campaign is ChocoShell, an in-memory PowerShell infostealer. ChocoShell is designed to target browser cookies, saved passwords, Microsoft 365 single sign-on (SSO) tokens, and stored Wi-Fi credentials. It possesses the capability to retrieve browser encryption keys and exploit browser debugging features to obtain readable cookies. This functionality provides attackers with a direct route to authenticated cloud sessions, circumventing the need for traditional password-based authentication.
This makes the CaptiveCrunch campaign particularly hazardous for corporate travelers. As demonstrated by numerous infostealer-fueled cloud breaches, reusable session data can be replayed against cloud services, virtual private networks (VPNs), and Software-as-a-Service (SaaS) applications. This creates a rapid pathway from initial device infection to a full-scale account compromise.
The deployed malware employs various evasion techniques to avoid detection, including disabling Windows anti-malware scanning controls, checking for analysis environments, and utilizing disguised HTTPS paths. The malware can also elevate privileges, compress stolen data, and exfiltrate it to its command-and-control (C2) server before meticulously removing temporary traces from the compromised system.
What You Should Do
- Treat Public Wi-Fi as Untrusted: Always assume hotel, conference, airport, and other guest wireless networks are insecure.
- Prioritize Secure Connections: Whenever possible, use a mobile hotspot or a personal encrypted connection instead of public Wi-Fi.
- Avoid Unsolicited Downloads: Never download software or updates prompted by a captive portal. Always obtain updates directly through official operating system or browser update channels.
- Implement Network Restrictions: Organizations should configure managed devices to prevent joining unapproved Wi-Fi networks. Provide employees with travel routers or secure hotspots that establish encrypted connections to trusted corporate infrastructure.
- Exercise Credential Caution: Never reuse corporate credentials on guest network registration pages. Do not follow prompts to paste commands into PowerShell or other system command tools.
- Strengthen Identity Defenses: Utilize passkeys and implement phishing-resistant multifactor authentication (MFA). Restrict device-code authentication to only absolutely necessary scenarios and enforce sign-in risk policies to challenge or block suspicious access attempts.
- Investigate IoCs: Security teams should actively investigate the provided Indicators of Compromise (IoCs), unexpected downloads following connectivity tests, and any artifacts related to the CornFlake malware.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | cdn-gstat[.]com |
CaptiveCrunch redirect |
| Domain | sslcdnhost[.]com |
CaptiveCrunch redirect |
| Domain | network-privacy[.]com |
CaptiveCrunch redirect |
| Domain | ms365-device[.]com |
CaptiveCrunch device-code-flow redirect |
| Domain | ms365-live[.]com |
CaptiveCrunch device-code-flow redirect |
| Domain | m365-owa[.]com |
CaptiveCrunch adversary-in-the-middle infrastructure |
| Domain | owa-ms365[.]com |
CaptiveCrunch adversary-in-the-middle infrastructure |
| IP address | 154.29.75[.]245 |
CaptiveCrunch infrastructure |
| IP address | 149.3.170[.]186 |
CaptiveCrunch device-code-flow infrastructure |
| IP address | 31.57.243[.]154 |
CaptiveCrunch adversary-in-the-middle infrastructure |
| IP address | 38.146.28[.]75 |
CaptiveCrunch adversary-in-the-middle infrastructure |
| IP address | 38.146.28[.]132 |
CaptiveCrunch DNS resolver |
| IP address | 104.194.159[.]150 |
CaptiveCrunch adversary-in-the-middle infrastructure |
| IP address | 107.189.26[.]194 |
ChocoShell C2 and CaptiveCrunch DNS resolver |
| IP address | 213.145.86[.]112 |
ChocoShell command-and-control server |
| URL path | 213.145.86[.]112/t/pixel.gif?m= |
ChocoShell beacon pattern |
| URL path | 213.145.86[.]112/cdn/chunks/polyfill-7e2b.min.js |
ChocoShell secondary module retrieval |
| URL path | 213.145.86[.]112/t/event |
ChocoShell data-exfiltration endpoint |
| File path | %APPDATA%svchost32svchost32.exe |
CornFlake RAT executable location |
| SHA-256 | 918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593 |
CornFlake |
| SHA
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources. |



No Comment! Be the first one.