LIVE · cybersecurity feed
Live wire

midnight blizzard

malwarehigh

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

A sophisticated threat actor known as Storm-2945, a sub-cluster of Midnight Blizzard, is targeting travelers worldwide through captive portal networks. The group manipulates network traffic to deliver malware, including a Go-based RAT called CornFlake, and conducts phishing attacks to steal credentials and register devices with Microsoft Entra ID. This campaign, dubbed CaptiveCrunch, leverages AI and mimics legitimate system updates to trick victims into downloading malicious software.