Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals to Deliver Malware and Steal Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Travelers connecting to hotel Wi-Fi may now face more than an unreliable internet signal. A campaign linked to Midnight Blizzard has turned captive portals, the sign-in pages shown before online access, into a route for malware, credential theft, and possible access to corporate accounts.

The operation, known as CaptiveCrunch, has affected hospitality-related networks and other venues using captive-portal equipment in several countries.

It targets people during routine connectivity checks, replacing expected web pages with convincing update prompts or account sign-in requests.

Microsoft analysts identified the activity as the work of Storm-2945, an operational sub-cluster of Midnight Blizzard. Microsoft first observed network manipulation in May 2026.

In an October 5 update, researchers reported renewed activity beginning September 29, including a Rust variant of CornFlake consistent with continued AI-assisted malware development.

Microsoft said in a report shared with Cyber Security News (CSN) that the risk extends beyond a single infected laptop. Stolen passwords and cloud session tokens can expose business services, while device-code phishing can persuade victims to approve an attacker’s authentication session.

Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals

CaptiveCrunch begins when attackers manipulate DNS and HTTP traffic on affected guest networks, redirecting users through infrastructure they control.

The operation targets travelers worldwide, while evidence suggests compromises may involve shared captive-portal services rather than isolated venues.

The altered page can pose as a browser or operating-system update and exploit ClickFix techniques, which tell people to perform a supposed repair or verification step.

This turns familiar warnings into a delivery channel, much like recent fake update attacks, where user interaction installs the malicious payload.

Microsoft observed Windows remote-access trojans written in Go that can collect files and keystrokes, steal credentials and tokens, record audio or video, and open a remote command shell.

Researchers also saw Android instructions on ClickFix pages encouraging users to download and install an APK file. A principal implant, CornFlake, displays a false progress window while copying itself to an application-data folder and creating several ways to restart after reboot.

Overview of the CaptiveCrunch attack flow (Source - Microsoft)
Overview of the CaptiveCrunch attack flow (Source – Microsoft)

It masquerades as a Windows service called Cloud Sync Service, helping it blend in while maintaining access. The campaign also redirects some victims to lookalike online-service domains for adversary-in-the-middle phishing.

A user may be asked to enter a device code on a real sign-in page, but the code authorizes the attacker’s session, an evolution of earlier Teams credential theft operations associated with Midnight Blizzard.

Malware, Credential Theft, and Defense

ChocoShell, an in-memory PowerShell infostealer, focuses on browser cookies, saved passwords, Microsoft 365 single sign-on tokens, and stored Wi-Fi credentials.

It can retrieve browser encryption keys and use browser debugging features to obtain readable cookies, giving attackers a route to authenticated cloud sessions without relying only on a password.

That makes the campaign especially serious for corporate travelers. As infostealer fueled cloud breaches have shown, usable session data can be replayed against cloud services, VPNs, and SaaS applications, creating a fast path from device infection to account compromise.

The malware attempts to evade inspection by disabling Windows anti-malware scanning controls, checking for analysis environments, and using disguised HTTPS paths.

ClickFix prompt (Source - Microsoft)
ClickFix prompt (Source – Microsoft)

It can elevate privileges, compress stolen data, and send it to its command-and-control server before removing temporary traces. Travelers should treat hotel, conference, airport, and other guest wireless networks as untrusted.

Prefer a mobile hotspot or other private connection when practical, avoid downloads offered by a captive portal, and confirm updates only through normal operating-system or browser update channels.

Organizations should prevent managed devices from joining unapproved Wi-Fi networks where feasible and use travel routers or hotspots that establish encrypted connections to trusted infrastructure.

Staff should never reuse corporate credentials on a guest-network registration page or follow a prompt to paste commands into PowerShell or other system command tools.

Identity defenses matter as much as endpoint controls. Use passkeys and phishing-resistant multifactor authentication, restrict device-code authentication to required cases, and use sign-in risk policies to challenge or block suspicious access.

Security teams should investigate the listed infrastructure, unexpected downloads after connectivity tests, and CornFlake artifacts.

Indicators of compromise (IoCs):-

Type Indicator Description
Domain cdn-gstat[.]com CaptiveCrunch redirect
Domain sslcdnhost[.]com CaptiveCrunch redirect
Domain network-privacy[.]com CaptiveCrunch redirect
Domain ms365-device[.]com CaptiveCrunch device-code-flow redirect
Domain ms365-live[.]com CaptiveCrunch device-code-flow redirect
Domain m365-owa[.]com CaptiveCrunch adversary-in-the-middle infrastructure
Domain owa-ms365[.]com CaptiveCrunch adversary-in-the-middle infrastructure
IP address 154.29.75[.]245 CaptiveCrunch infrastructure
IP address 149.3.170[.]186 CaptiveCrunch device-code-flow infrastructure
IP address 31.57.243[.]154 CaptiveCrunch adversary-in-the-middle infrastructure
IP address 38.146.28[.]75 CaptiveCrunch adversary-in-the-middle infrastructure
IP address 38.146.28[.]132 CaptiveCrunch DNS resolver
IP address 104.194.159[.]150 CaptiveCrunch adversary-in-the-middle infrastructure
IP address 107.189.26[.]194 ChocoShell C2 and CaptiveCrunch DNS resolver
IP address 213.145.86[.]112 ChocoShell command-and-control server
URL path 213.145.86[.]112/t/pixel.gif?m= ChocoShell beacon pattern
URL path 213.145.86[.]112/cdn/chunks/polyfill-7e2b.min.js ChocoShell secondary module retrieval
URL path 213.145.86[.]112/t/event ChocoShell data-exfiltration endpoint
File path %APPDATA%svchost32svchost32.exe CornFlake RAT executable location
SHA-256 918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593 CornFlake
SHA-256 be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c ChocoShell

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals to Deliver Malware and Steal Credentials appeared first on Cyber Security News.