LIVE NEWS
  • White House Nominates New 3-Stars for Air University, Deputy CSO for Ops
  • Brains don’t always rot: Scientists may finally know how human brains have evaded decay for thousands of years
  • Oil prices fall on hopes Strait of Hormuz could reopen
  • Italy’s Biggest Bank Cuts IBIT Exposure by 94% While Buying More Staked Ethereum
  • Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)
  • My in-Laws Bought the House Next Door From Us; Pros and Cons so Far
  • EU chief criticises Spain’s migrant plan after Ceuta crisis meeting | European Union
  • North Sea oil is a litmus test for Burnham | Oil
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware
Cybersecurity

Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware

primereportsBy primereportsAugust 4, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware
Share
Facebook Twitter LinkedIn Pinterest Email


Midnight Blizzard, the Russian threat actor tied to the country’s foreign intelligence service, has spent months targeting users of public Wi-Fi networks at places like hotels and conference centers, according to new findings from Microsoft Threat Intelligence.

Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware

Overview of the CaptiveCrunch attack flow (Source: Microsoft)

Microsoft named the campaign CaptiveCrunch and identified two malware strains behind it, CornFlake and ChocoShell.

Building on earlier research from security firm ReliaQuest, published July 23, Microsoft ties this activity to Storm-2945, a sub-cluster of Midnight Blizzard.

Microsoft says the broader operation, which shows signs of AI assistance, dates back to February 2026, with the traffic manipulation piece observed since early May.

“Although our investigation into the initial compromise vector for the captive portal networks is ongoing, we have observed notable commonalities in the equipment and management systems used across multiple affected networks. These similarities suggest that the activity might not be limited to isolated compromises of individual venues and could reflect access to shared services within portions of the captive portal ecosystem,” Microsoft wrote.

By manipulating DNS and HTTP traffic on compromised captive portal networks, the attackers redirected victims down three paths. Two led to credential theft: phishing pages impersonating Microsoft 365 sign-in portals, and device code phishing pages abusing Microsoft Entra ID authentication flows.

The third displayed fake browser or operating system update pages that used the ClickFix social engineering method to persuade victims to download and run malware.

Microsoft also found ClickFix pages configured to push an APK file, suggesting the threat actor might be targeting Android devices too.

CornFlake and ChocoShell

Researchers describe CornFlake as a Windows RAT written in Go with a wide range of capabilities that include:

  • Keylogging
  • Clipboard monitoring
  • Screenshot capture
  • Audio surveillance
  • Video surveillance
  • Browser credential theft
  • File exfiltration
  • USB drive monitoring
  • Security posture sweep
  • Remote shell access

“On initial execution, CornFlake operates in dropper mode: it displays a convincing fake progress window designed to occupy the victim’s attention while the binary copies itself to %APPDATA%\svchost32\svchost32.exe and establishes persistence,” they added.

The second identified malware, ChocoShell, is an in-memory PowerShell credential stealer targeting browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials.

“Where CornFlake provides the operator with a persistent, long-running foothold on the device, ChocoShell is designed to extract the most operationally valuable credentials, giving the operator access to victim cloud environments,” Microsoft noted.

Researchers also discovered a web-based C2 panel, FruitStone, that Storm-2945 operators use to run the CaptiveCrunch infrastructure. Built as a single-page HTML and JavaScript application with no authentication on any of its functions, it gives operators a dashboard for managing compromised endpoints, building and deploying new payloads, and reviewing collected data such as screenshots, keystrokes, and browser credentials.

Recommendations

Microsoft recommends treating hotel and conference Wi-Fi as untrusted, using private cellular or managed connections where practical, and avoiding software updates or tools offered through captive portals.

Organizations are advised to review what information employees provide to hospitality providers when connecting to guest networks.

“Organizations should assume that public and hospitality network infrastructure might not be trustworthy and should adopt controls that limit exposure to traffic manipulation, credential theft, and device code phishing,” Microsoft concluded.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCalifornia’s diesel prices have jumped since the Iran war started, with ripple effects across the country
Next Article US crypto regulation loses four key Washington allies
primereports
  • Website

Related Posts

Cybersecurity

Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)

August 4, 2026
Cybersecurity

Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack

August 3, 2026
Cybersecurity

Chinese Threat Actors Weaponize New Vulnerabilities in Under a Day

August 3, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Threat of further violence looms after Mexican cartel rampage

February 25, 2026113 Views

‘Two-sided risk’ Medicare Advantage plans improve patient outcomes

February 24, 202673 Views

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202626 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Cybersecurity
  • Crypto
  • Artificial Intelligence
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • White House Nominates New 3-Stars for Air University, Deputy CSO for Ops
  • Brains don’t always rot: Scientists may finally know how human brains have evaded decay for thousands of years
  • Oil prices fall on hopes Strait of Hormuz could reopen
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.