Microsoft has linked CaptiveCrunch, a worldwide campaign that manipulates hotel and conference Wi-Fi traffic to steal Microsoft 365 access and install surveillance malware, to Storm-2945, which it assesses is a sub-cluster of the Russia-based Midnight Blizzard espionage group. BleepingComputer reported the attribution and expanded technical findings on August 3, within 24 hours of this article's preparation.

Microsoft Threat Intelligence said the actor has run device-code and OAuth phishing since February 2026 and has manipulated DNS and HTTP traffic on captive-portal networks since early May. The company observed affected hospitality networks in several countries but did not identify venues, providers or the number of successful compromises. ReliaQuest previously documented overlapping infrastructure and activity at hotels, conference centers and other shared venues.

After gaining an adversary-in-the-middle position, the operators redirect automatic connectivity checks or web traffic to Microsoft 365 phishing pages, device-code authentication prompts, or fake browser and operating-system updates. Microsoft said the initial route into the captive-portal infrastructure remains under investigation. Some fake update pages use ClickFix instructions, meaning a victim must execute an attacker-supplied command rather than being silently infected merely by joining Wi-Fi.

The primary Windows implant, CornFlake, is a Go-based remote access trojan that can log keystrokes, capture screenshots, monitor clipboards and removable media, record microphone and webcam data, steal browser credentials and session tokens, exfiltrate files, and open a remote shell. It copies itself under the AppData directory and uses services, registry run keys, scheduled tasks and a watchdog for persistence. Microsoft also identified ChocoShell, an in-memory PowerShell stealer targeting browser data, Wi-Fi credentials, and Microsoft 365 and Azure Active Directory tokens.

Microsoft found that ChocoShell can evade scanning, attempt user account control bypasses, and replay collected single sign-on material. A web panel called FruitStone gave operators facilities to manage infected endpoints and collected data. Microsoft assessed that AI likely assisted development because of extensive code comments and consistent implementation, but that assessment does not establish which AI service was used. The public reporting provides no confirmed victim count.

Defenders should treat hotel, conference and other guest networks as untrusted, favor cellular or enterprise-managed encrypted connections, and reject updates, certificates or troubleshooting tools offered by captive portals. Microsoft recommends phishing-resistant authentication, restricting Entra device-code flow where it is unnecessary, reviewing risky sign-ins, and hunting for suspicious downloads immediately after Wi-Fi connectivity checks. Travelers should install updates only through trusted operating-system or application mechanisms.