Russian Hackers Hijack Hotel Wi-Fi Networks to Steal Microsoft 365 Accounts
- CVE ID
- N/A
- Affected Products / Orgs
- Hospitality captive portal Wi-Fi networks, Microsoft Entra ID / Microsoft 365 enterprise users
Threat actors affiliated with Russia’s state-sponsored Midnight Blizzard group—tracked by Microsoft as Storm-2945 and broadly known as APT29—are executing a global campaign using hotel Wi-Fi attacks to compromise Microsoft 365 accounts. The activity, dubbed CaptiveCrunch, manipulates DNS and HTTP traffic on gateway devices serving hotel and conference center captive portals. By hijacking network resolution at the public gateway, the attackers force connected business travelers onto credential phishing pages or deliver new custom malware families built for persistent espionage.
APT29 traditionally focuses on intelligence gathering against government, diplomatic, defense, and corporate targets. Targeting roaming executives and remote personnel through guest network infrastructure allows the threat actor to bypass traditional enterprise perimeters, exploiting corporate devices while they operate outside the protection of internal security stacks.
The CaptiveCrunch Attack Chain
Microsoft assesses that the CaptiveCrunch campaign has been active since at least early May, though related device and OAuth code phishing operations date back to February. The threat actor began integrating active DNS manipulation and ClickFix social engineering lures into captive portal redirections around July.
While cybersecurity firm ReliaQuest previously identified DNS hijacking on public Wi-Fi equipment in connection with this campaign, Microsoft’s research details how the compromise progresses once shared network infrastructure is breached:
- DNS and Traffic Hijacking: After altering DNS settings on captive portal equipment, the attacker intercepts outgoing HTTP and HTTPS requests from devices connecting to guest Wi-Fi networks.
- OAuth and Device Code Phishing: When victims attempt to access web resources, the network redirects them to spoofed Microsoft 365 login portals or Microsoft Entra ID device code authentication screens. Device code phishing tricks users into entering an authorization code on an attacker-controlled prompt, allowing the adversary to obtain valid OAuth tokens and hijack cloud sessions without triggering standard password alerts.
- ClickFix Malware Delivery: The actor also displays fake operating system and browser update prompts via ClickFix landing pages, tricking users into manually copying and executing malicious commands under the guise of system verification. In some cases, ClickFix pages targeted mobile users with malicious Android APK downloads.
Custom Payloads: CornFlake, ChocoShell, and FruitStone
When victims succumb to ClickFix social engineering on Windows hosts, the campaign deploys two newly identified malware payloads. Code comments and structure suggest that the threat actor likely used generative AI tools during development.
CornFlake RAT
CornFlake is a Go-based remote access trojan (RAT) engineered to establish persistent access. Upon execution, it displays a fake progress window—configurable to mimic a Windows update, a Defender virus scan, a disk optimization utility, network diagnostics, a browser update prompt, or a document viewer installer—to distract the user. Simultaneously, the binary copies itself to %AppData% under the process name Cloud Sync Service.
To ensure long-term persistence, CornFlake employs redundant mechanisms, including Windows service registrations, registry run keys, scheduled tasks, and a dedicated watchdog routine designed to reinstall any persistence mechanism that gets removed by security software.
ChocoShell Credential Stealer
ChocoShell is an in-memory PowerShell script focused on credential harvesting. It extracts browser cookies, saved passwords, Wi-Fi credentials, and active Microsoft 365 and Azure AD (Entra ID) authentication tokens directly from memory.
FruitStone Management Panel
Storm-2945 managed infected hosts using an exposed web-based administration interface named FruitStone. The panel allowed operators to browse victim file systems, run arbitrary PowerShell commands, capture screenshots, and log keystrokes from compromised systems.
Risk and Impact Assessment
The blast radius of a successful CaptiveCrunch compromise extends far beyond a single infected host. By securing valid Entra ID session tokens and cloud credentials while an employee is traveling, attackers bypass traditional password controls and perimeter access rules.
Once inside a victim’s Microsoft 365 cloud environment, Midnight Blizzard typically conducts long-term intelligence collection—monitoring Outlook communications, exfiltrating sensitive business files from SharePoint and OneDrive, and abusing internal tenant trust relationships to pivot into secondary connected enterprise environments.
Mitigating Public and Hospitality Wi-Fi Threats
Defending against gateway-level network interception requires security teams to treat all guest and hospitality networks as inherently compromised. Enterprise environments should implement targeted technical controls:
- Enforce Secure Connectivity: Mandate the use of corporate-managed cellular connections or always-on VPN and Secure Access Service Edge (SASE) solutions that encrypt traffic before it reaches local Wi-Fi gateways.
- Restrict Entra ID Device Code Flows: Disable Microsoft Entra device code authentication across the tenant for users who do not require it for dedicated device enrollment.
- Require Phishing-Resistant MFA: Implement FIDO2 passkeys or certificate-based authentication, which bind authentication tokens to specific domain origins and neutralize OAuth token theft via spoofed portals.
- Establish Roaming Policies: Instruct employees to never approve browser update prompts, run verification commands, or use corporate login credentials when registering for public Wi-Fi networks.
Related content
Inside a Post-Breach Intrusion: SQL Injection, BadIIS, and Evasion Techniques
Security NewsBing Ads Malvertising Pushes Fake Claude Desktop App Delivering SectopRAT
Security NewsAttackers Spoof OAuth Client IDs to Evade Microsoft Cloud Sign-in Logs
Security NewsHackers Hijack Hotel Wi-Fi DNS Settings to Steal Microsoft 365 Credentials
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call