Microsoft has confirmed a global campaign targeting hospitality Wi-Fi networks, which it attributes to the Russian state-sponsored threat actor Midnight Blizzard, also known as APT29. The campaign, dubbed "CaptiveCrunch" by Microsoft, has been active since at least early May, though the threat actor has engaged in device and OAuth code phishing operations since February.
The attackers manipulate DNS and HTTP traffic on networks served by captive portal equipment, allowing them to intercept user connections to hotel and conference center Wi-Fi. While the exact initial compromise method remains undetermined, Microsoft noted signs of breaches in shared infrastructure rather than isolated devices. After modifying DNS settings, victims are redirected to phishing pages impersonating Microsoft 365 login portals or to device code phishing pages that exploit Microsoft Entra ID authentication flows. This activity has been observed since July.
A newly disclosed tactic involves using fake browser and operating system update pages that deliver malware to Windows via "ClickFix" prompts for user verification. Evidence also suggests that Android devices are being targeted to deliver APK files through similar ClickFix landings.
Microsoft identified two new malware families, CornFlake and ChocoShell, used in the campaign. CornFlake is a Go-based remote access trojan (RAT) with capabilities including remote shell access, keylogging, clipboard monitoring, screenshot capturing, microphone and webcam surveillance, browser credential and cookie theft, Microsoft 365 session token theft, file exfiltration, USB monitoring, and system reconnaissance. When executed, CornFlake displays a fake progress window, which can appear as a Windows update, Defender virus scan, disk optimization utility, network diagnostics tool, browser update prompt, or document viewer installer, while it copies itself to %AppData% for persistence. It disguises itself as "Cloud Sync Service" and uses multiple persistence mechanisms, including Windows service registrations, registry run keys, named tasks, and a watchdog routine.
The second payload, ChocoShell, is an in-memory PowerShell credential stealer. It targets browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials. Based on extensive code comments, Microsoft assesses that AI tools were likely used in the development of both malware families.
Researchers also discovered an unprotected web-based management panel named "FruitStone" used by the threat actor to manage infected systems. This panel allowed them to browse victim files, execute PowerShell commands, and capture screenshots and keystrokes.
Microsoft recommends treating hotel and conference Wi-Fi as untrusted networks, advising users to utilize private cellular or managed connections whenever possible. Users should avoid installing software updates or tools offered through captive portals. The company also suggests adopting phishing-resistant authentication methods like MFA and passkeys, disabling Microsoft Entra device code authentication when not needed, and refraining from using corporate credentials to register for guest Wi-Fi networks.






