August 11, 2026

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

In brief

Microsoft Threat Intelligence has identified a campaign called CaptiveCrunch, attributed to Storm-2945, an operational subgroup of the Russian SVR-linked Midnight Blizzard/APT29. Since early May 2026, the attackers have manipulated DNS and HTTP traffic on captive-portal networks at hotels, conference centers and other shared venues in several countries. Travelers are redirected to deceptive pages imitating Windows updates, Google verification checks, browser updates or software installers, where they are persuaded to execute CornFlake, a persistent Windows remote-access trojan. CornFlake can record keystrokes, capture screens, audio and webcam feeds, steal browser credentials and files, monitor USB devices and execute commands through an encrypted command-and-control channel. Microsoft also found indications that Android users may be targeted with malicious APK downloads.

The campaign also uses ChocoShell, a memory-resident PowerShell infostealer that extracts Microsoft 365, Azure AD and Web Account Manager tokens, potentially allowing attackers to replay authenticated corporate sessions without traditional browser cookies. It can harvest Wi-Fi passwords, bypass User Account Control, interfere with Microsoft Defender updates and extract Chrome cookies. Some landing pages additionally employ device-code phishing, tricking users into authorizing an attacker-controlled session through Microsoft’s legitimate authentication process, including multifactor authentication. Organizations are advised to block device-code authentication where unnecessary, while travelers should regard public venue Wi-Fi as untrusted, prefer cellular connections or personal hotspots, avoid installing anything presented by a captive portal and never enter corporate credentials into venue registration pages.

Source: Security Affairs

Explore More Insightful Articles: