August 11, 2026
August 11, 2026
In brief
Microsoft Threat Intelligence has identified a campaign called CaptiveCrunch, attributed to Storm-2945, an operational subgroup of the Russian SVR-linked Midnight Blizzard/APT29. Since early May 2026, the attackers have manipulated DNS and HTTP traffic on captive-portal networks at hotels, conference centers and other shared venues in several countries. Travelers are redirected to deceptive pages imitating Windows updates, Google verification checks, browser updates or software installers, where they are persuaded to execute CornFlake, a persistent Windows remote-access trojan. CornFlake can record keystrokes, capture screens, audio and webcam feeds, steal browser credentials and files, monitor USB devices and execute commands through an encrypted command-and-control channel. Microsoft also found indications that Android users may be targeted with malicious APK downloads.
The campaign also uses ChocoShell, a memory-resident PowerShell infostealer that extracts Microsoft 365, Azure AD and Web Account Manager tokens, potentially allowing attackers to replay authenticated corporate sessions without traditional browser cookies. It can harvest Wi-Fi passwords, bypass User Account Control, interfere with Microsoft Defender updates and extract Chrome cookies. Some landing pages additionally employ device-code phishing, tricking users into authorizing an attacker-controlled session through Microsoft’s legitimate authentication process, including multifactor authentication. Organizations are advised to block device-code authentication where unnecessary, while travelers should regard public venue Wi-Fi as untrusted, prefer cellular connections or personal hotspots, avoid installing anything presented by a captive portal and never enter corporate credentials into venue registration pages.
Source: Security Affairs