Microsoft Identifies "CaptiveCrunch" Campaign
Microsoft Threat Intelligence has uncovered a sophisticated cyberattack campaign, dubbed "CaptiveCrunch," specifically targeting free Wi-Fi networks in hotels and other public guest environments worldwide. The campaign, observed since early May 2026, aims to compromise devices and steal sensitive information, with a particular focus on business travelers and their corporate accounts.
Microsoft attributes this ongoing threat to Storm-2945, a subgroup of the notorious Russia-linked hacking group known as Midnight Blizzard (also identified as APT29 or Cozy Bear).
How Attackers Exploit Public Wi-Fi
The "CaptiveCrunch" campaign leverages a common vulnerability: captive portals. These are the login or verification pages users encounter before gaining internet access on public Wi-Fi networks.
- DNS and HTTP Manipulation: Storm-2945 manipulates DNS and HTTP traffic on compromised networks, redirecting users from legitimate captive portals to malicious websites.
- Fake Prompts: Users are then presented with deceptive prompts disguised as official Windows updates, browser verification screens, or security fixes. These prompts often instruct users to install fake software updates, complete a verification process, or address a supposed network issue.
- Malware Downloads: In some cases, Android users may be prompted to download and install malicious APK files.
- Device-Code Phishing: The campaign also employs device-code phishing, tricking users into authenticating attacker-controlled sessions, potentially granting access to corporate accounts.
Malware Designed for Data Theft
Microsoft has identified several types of malware deployed through the "CaptiveCrunch" campaign, each designed for extensive data exfiltration:
CornFlake
This Windows remote-access trojan (RAT) is highly potent, capable of:
- Stealing files and credentials
- Collecting keystrokes and session tokens
- Capturing screenshots
- Conducting audio and video surveillance
ChocoShell
Primarily focused on stealing browser-related data, ChocoShell targets:
- Browser session cookies
- Saved passwords
- Microsoft 365 single sign-on tokens
- Wi-Fi credentials
Microsoft's Recommendations for Travelers
To mitigate the risks posed by "CaptiveCrunch" and similar threats, Microsoft advises all travelers to treat hotel, airport, conference, and other public Wi-Fi networks as untrusted environments.
Key protective measures include:
- Use Private Connections: Whenever possible, opt for a mobile hotspot, eSIM, or another private, secure internet connection instead of public Wi-Fi.
- Avoid Software Downloads: Never download software, certificates, or security tools through Wi-Fi login pages or prompts encountered on public networks.
- Official Updates Only: Always install software and operating system updates exclusively through official operating system or application update mechanisms.
By exercising caution and implementing these recommendations, users can significantly reduce their risk of falling victim to sophisticated cyberattacks while traveling.