CaptiveCrunch returns: Microsoft says Midnight Blizzard sub-cluster Storm-2945 resumed hijacking hotel and venue Wi-Fi captive portals on 29 Sep, now with a Rust CornFlake stealer
Microsoft Threat Intelligence updated its CaptiveCrunch report on 5 October 2026 to say Storm-2945, which it assesses as an operational sub-cluster of Russia's Midnight Blizzard (attributed by the US and UK to the SVR), resumed the campaign on 29 September 2026. Microsoft first reported it on 31 July: since early May 2026 the group has manipulated DNS and HTTP traffic on guest Wi-Fi networks served by captive portals, mainly in hospitality, redirecting travellers to phishing pages that imitate Microsoft services, device-code phishing aimed at Microsoft Entra ID, and fake browser or operating-system updates using ClickFix-style instructions. Payloads include Go-based Windows remote access trojans such as CornFlake that steal credentials and session tokens, log keystrokes, collect files, record audio and video and give a remote shell; some landing pages also told Android users to install an APK. Microsoft says it has seen widespread compromise of such networks in several countries, and ReliaQuest has seen it at conference centres and other shared venues, with the aim of reaching corporate travellers' accounts. The update says the return fits Black Lotus Labs reporting that several hospitality managed service providers are implicated, that continued access to those providers likely allowed the fast redeployment, and that infostealer deliveries now use a Rust variant of CornFlake consistent with AI-assisted malware development. Microsoft added fresh infrastructure indicators and hunting queries and credits Google Threat Intelligence Group. Primary: Microsoft Security Blog; wire: Cybersecurity News (6 Oct).
- Product
- Hotel, conference and venue guest Wi-Fi captive portals; Windows and Android devices of travellers; Microsoft Entra ID / Microsoft 365 accounts
- Versions
- n/a — campaign; no CVE named. Initial compromise of the captive portal networks still under investigation by Microsoft
- Exploited in Australia?
- unknown
- Patch to
- Treat hotel, conference, airport and other guest Wi-Fi as hostile: use an always-on VPN for corporate devices and never run an 'update' or command a captive page asks for. Block the Entra ID device code flow with Conditional Access where it is not needed, use phishing-resistant MFA and token protection, and watch for new device registrations and unusual sign-ins from travelling staff. Run Microsoft's updated hunting queries and indicators from the 5 October update, and brief travelling executives.
Primary: Microsoft Security Blog — CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft (31 Jul 2026, updated 5 Oct 2026) · Cybersecurity News — Midnight Blizzard abuses hotel Wi-Fi captive portals to deliver malware and steal credentials (6 Oct 2026)
