CaptiveCrunch: Russia's Midnight Blizzard Hijacks Hotel Wi-Fi to Steal Microsoft 365 Tokens

Proactive Security for the AI Era
NodeZero continuously and autonomously pentests infrastructure, identity, cloud, and now web applications, chaining weaknesses across every domain the way real attackers do. Every finding ships with replayable proof showing exploitable business impact, not theoretical risk.
CaptiveCrunch hotel Wi-Fi credential theft has compromised business travelers' Microsoft 365 accounts in at least three countries since May 2026, with Russia's Midnight Blizzard (APT29/SVR) actively expanding the campaign through a new device code phishing phase added on July 16, 2026 that bypasses MFA without requiring any malware on the victim's device. Microsoft published the full threat intelligence disclosure on July 31, 2026, attributing the campaign to Storm-2945, a Midnight Blizzard sub-cluster linked to Russia's Foreign Intelligence Service.
Storm-2945 compromises hotel and conference center captive portal infrastructure -- the sign-in page systems that control Wi-Fi access -- and uses DNS and HTTP manipulation to intercept traveler sessions. Travelers who connect to a compromised hotel Wi-Fi and follow what appears to be a routine network access prompt receive CornFlake, a Go-based Windows remote access trojan providing persistent backdoor access, or ChocoShell, a PowerShell infostealer that runs 100% in memory and exfiltrates Microsoft 365 SSO tokens, browser session cookies, saved passwords, and Wi-Fi credentials in a single pass without writing any files to disk.
The device code phishing phase is the most operationally significant development. Storm-2945's FruitStone C2 panel now serves captive portal landing pages that redirect travelers to a legitimate Microsoft page at microsoft.com/devicelogin and present them with an alphanumeric device code. When the traveler enters the code and completes their standard MFA challenge, they authenticate Storm-2945's pre-generated Entra ID session. The attacker receives a valid Microsoft 365 refresh token. MFA did not protect the account. A subsequent password reset will not revoke that token. The access persists for up to 90 days in default Entra ID configurations unless sessions are explicitly revoked.
How Does the CaptiveCrunch Hotel Wi-Fi Attack Work?
The CaptiveCrunch hotel Wi-Fi attack operates in two independent phases that Storm-2945 often combines during a single compromise.
Phase 1 -- malware delivery -- begins with Storm-2945 compromising the captive portal management system of a hotel or conference center. Captive portals are the network appliances that authenticate Wi-Fi users through a browser-based sign-in page. Storm-2945 manipulates DNS resolution and HTTP traffic at the portal level, intercepting sessions before the traveler reaches the open internet. Travelers are served pages claiming that a browser update, Windows system update, network repair tool, security certificate, or compliance scan is required before connectivity continues. These prompts are visually convincing and use branding elements consistent with their operating system and browser. Travelers who click download and execute the file become immediately compromised. CornFlake installs a scheduled task or registry run key for persistence and begins keylogging and screenshot capture within seconds of execution. ChocoShell -- the PowerShell-based infostealer -- runs in memory as a single scriptblock, enumerates browser profile directories, decrypts saved credentials using DPAPI, extracts Microsoft 365 SSO tokens from the browser session store, and exfiltrates them via HTTP to Storm-2945 infrastructure before terminating. ChocoShell leaves no files on disk; the only forensic artifact is a PowerShell Script Block Logging entry (Event ID 4104) if that capability is enabled on the endpoint.
Phase 2 -- device code phishing, active since July 16, 2026 -- requires no malware on the victim's device. Storm-2945's FruitStone C2 panel serves a captive portal landing page that presents an alphanumeric code and directs the traveler to visit microsoft.com/devicelogin -- a real Microsoft URL for the OAuth device authorization grant, a feature built for authenticating on TVs and conference room displays. The traveler sees a legitimate Microsoft login page, enters their normal password, and completes their MFA challenge. This authentication does not sign the traveler into their own session. The device code they entered is tied to an authentication request that Storm-2945 pre-generated. By completing the login flow, the traveler authorizes Storm-2945's Entra ID session and delivers a valid refresh token to the attacker. The attack succeeds even with phishing-resistant FIDO2 keys in the default device code flow configuration, because the attacker-controlled code is already bound to their authentication request before the victim acts.
Hotel Captive Portal Compromise
Storm-2945 compromises hotel or conference center captive portal infrastructure via exploitation or credential abuse, gaining control of DNS and HTTP traffic for all devices connecting to the Wi-Fi network.
Session Interception (AiTM)
DNS and HTTP manipulation intercepts traveler browser sessions. Requests to legitimate destinations are redirected to Storm-2945-controlled pages mimicking update or network-access prompts.
Malware Delivery or Device Code Redirect
Phase 1: Traveler clicks a fake update prompt and downloads CornFlake or ChocoShell. Phase 2: Traveler is shown a device code and directed to microsoft.com/devicelogin.
Credential and Token Theft
CornFlake establishes persistent backdoor with keylogger. ChocoShell steals M365 tokens, cookies, and saved passwords in-memory. Device code phase delivers a valid Entra ID refresh token directly to Storm-2945.
Post-Compromise Collection
Storm-2945 uses stolen tokens to access Microsoft 365 email, SharePoint, OneDrive, and Teams. Large mail reads, inbox rule creation, and file enumeration occur within 30 minutes of token acquisition.
Persistent Access Maintained
Refresh tokens remain valid up to 90 days. CornFlake provides continued remote access. Password resets do not revoke tokens. Organizations remain compromised until explicit session revocation.
Who Are Storm-2945 and Midnight Blizzard?
Storm-2945 is a sub-cluster of Midnight Blizzard (also known as APT29, Cozy Bear, and The Dukes), a threat group the US and UK governments attribute to Russia's Foreign Intelligence Service (SVR). Midnight Blizzard has conducted some of the most impactful cyber operations of the last decade, including the 2020 SolarWinds SUNBURST supply chain compromise that compromised 18,000 organizations and nine US government agencies, and the January 2024 breach of Microsoft corporate email accounts targeting senior leadership and the cybersecurity team.
Storm-2945 began as an AI-assisted credential harvesting operation in February 2026, conducting targeted device code and OAuth phishing campaigns against Microsoft 365 users and registering attacker-controlled devices with Entra ID to maintain persistent access. The pivot to compromising hotel captive portal infrastructure in May 2026 extends Midnight Blizzard's collection beyond the corporate network perimeter into the physical environments where high-value targets carry their work devices on untrusted networks. Hotel Wi-Fi at diplomatic summits, defense conferences, and government trade visits gives Storm-2945 access to a concentration of high-value individuals that would be difficult to reach through targeted phishing alone.
Midnight Blizzard's established targeting profile includes government agencies, diplomatic missions, defense contractors, NATO-affiliated organizations, think tanks, NGOs, and technology companies with visibility into foreign policy decisions. CaptiveCrunch is consistent with SVR operational objectives -- collect credentials from personnel who travel to conferences, embassies, and diplomatic events where their devices carry access to sensitive material that standard boundary security would protect at the office.
In the Storm-1865 ClickFix reservation phishing campaign, attackers targeted hotel guests through fraudulent Booking.com communications. CaptiveCrunch is a more sophisticated infrastructure-level attack -- any traveler connecting to the compromised hotel network is in scope, not only those who receive a targeted phishing email.
“Storm-2945 conducts widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide.”
Microsoft Threat Intelligence, July 31, 2026
Briefings like this, every morning before 9am.
Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.
Who Faces the Highest CaptiveCrunch Exposure?
Microsoft confirmed CaptiveCrunch activity at hotels in the United States, India, and Saudi Arabia, with broader worldwide scope indicated. Any organization whose employees travel for business and use Microsoft 365 faces active exposure.
The highest-risk category comprises employees whose credentials provide access to information within Midnight Blizzard's espionage mandate: government and diplomatic staff, defense industry employees, senior professionals at technology and professional services firms, researchers at think tanks and universities with government contracts, and any personnel attending events where Russian SVR collection interests converge -- NATO summits, bilateral meetings, defense industry conferences, and academic forums on policy topics relevant to Russian geopolitical objectives.
The Phase 2 device code attack requires nothing beyond connecting to the Wi-Fi network. The traveler does not need to click a suspicious link, download a file, or enter credentials on a fake-looking page. The attack begins at the captive portal -- the same sign-in page they use every time they connect to hotel Wi-Fi. The only signal that something is wrong is that the page presents a device code rather than their standard authentication flow. For travelers unfamiliar with what a device code prompt looks like (most are), this is not a distinguishable difference.
ChocoShell's in-memory design means endpoint detection tools will not flag a file on disk. CornFlake uses Go runtime characteristics that may appear in behavioral monitoring but blend with legitimate Go-based software. For most organizations, the first indication of a CaptiveCrunch compromise will be Microsoft Defender alerting on anomalous Microsoft 365 access or a Sentinel rule firing on a device code authentication event -- only if those detections are deployed and tuned.
Organizations should audit Microsoft 365 access for employees who traveled to the United States, India, and Saudi Arabia since May 2026 and hunt specifically for device code authentications from IP addresses they cannot attribute to known corporate infrastructure. See the EtherRAT Microsoft Teams fake IT support attack analysis for comparison -- EtherRAT also targets Microsoft 365 access through social engineering, and the post-compromise behavior patterns overlap with Storm-2945 collection activity.
CaptiveCrunch Indicators of Compromise
Microsoft published the full IOC list including spoofed domains, CornFlake and ChocoShell malware hashes, and FruitStone C2 infrastructure indicators in the July 31, 2026 threat intelligence blog at microsoft.com/security/blog. Organizations should pull the current list directly from that source -- Storm-2945 rotates infrastructure actively as defenders respond.
The following behavioral and artifact indicators should be hunted across endpoint telemetry, Microsoft Entra ID sign-in logs, and network traffic logs from the period May 2026 to present.
For CornFlake detection: hunt for Go-compiled PE64 binaries in browser download directories or temp folders. CornFlake establishes persistence via Windows scheduled tasks (look for tasks with randomized names created within minutes of a browser download event) and communicates outbound over HTTPS with a custom user-agent string. Process lineage showing a browser process spawning cmd.exe or PowerShell should be treated as high-priority.
For ChocoShell detection: enable PowerShell Script Block Logging (Event ID 4104) if not already active. ChocoShell appears as a single scriptblock session with browser profile directory enumeration, DPAPI decrypt calls (typically System.Security.Cryptography.ProtectedData), and Base64-encoded HTTP exfiltration -- all within one PowerShell session. Parent process will typically be a browser or a file opened from a browser download. The session is short (under 60 seconds) and terminates cleanly.
For device code phishing detection: hunt Entra ID SignInLogs for authenticationProtocol equals deviceCode with ResultType equals 0 from IP addresses that do not appear in your known corporate IP inventory. Cross-reference with recent travel records. Storm-2945 post-compromise activity leaves a distinct pattern: Microsoft Graph calls for mail reads at unusual hours, inbox rules created to forward or delete messages, OneDrive or SharePoint file enumeration, and app permission grant events -- all within 30 minutes of the device code authentication.
Subscribe to unlock Indicators of Compromise
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Sigma Detection Rules for CaptiveCrunch and Device Code Phishing
No CVE-specific Sigma rules exist for CaptiveCrunch because it exploits a legitimate authentication flow rather than a software vulnerability. The three rules below target the behaviors Storm-2945 produces in Entra ID and Microsoft 365 logs: MFA bypass via legacy authentication clients, AiTM phishing framework signatures in sign-in logs, and impossible travel activity consistent with token replay from an attacker-controlled location.
These rules require Azure Sign-In Logs and Microsoft 365 Unified Audit Logs forwarded to Microsoft Sentinel, Splunk, or an Elastic SIEM. Deploy in alert-only mode first, tune false positives against legitimate legacy authentication clients and VPN usage, then promote to block or isolate actions.
Subscribe to unlock Sigma Detection Rules
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Subscribe to unlock WAF Detection Rules
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Immediate Defensive Steps: Close the CaptiveCrunch Attack Path
These steps address both the device code phishing phase and the malware delivery phase. Apply them in order -- step 1 closes the highest-risk attack vector before step 7 provides ongoing detection coverage.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Why CaptiveCrunch Hotel Wi-Fi Credential Theft Matters for Your Organization
The CaptiveCrunch campaign represents a maturation of Russian SVR targeting that moves the attack surface from the corporate network perimeter to the physical environments where professionals connect high-value credentials to low-trust networks. Traditional security controls -- MFA, endpoint protection, email filtering -- provide no defense against a device code phishing attack conducted at the Wi-Fi network layer against a traveler who has not received any suspicious email and whose device has no malware.
Three factors make CaptiveCrunch uniquely dangerous. First, the device code authentication flow is legitimate infrastructure that Microsoft built for real use cases; disabling it requires a deliberate Conditional Access policy change that most organizations have not made. Second, the stolen refresh token lifecycle -- up to 90 days -- means Storm-2945 maintains Microsoft 365 access for the entire period between a May conference trip and an August security review, with no alert firing unless detection rules are specifically deployed. Third, ChocoShell's in-memory design leaves no forensic artifact that retrospective endpoint investigation can recover, making post-incident reconstruction difficult.
The mitigation is achievable in a single afternoon: disable device code flow, revoke sessions for anyone who traveled to affected regions since May, and deploy the Sigma rules above to monitor for future device code authentications. Organizations that complete these three steps today eliminate the primary Storm-2945 attack vector for their environment. Those that do not remain exposed every time an employee connects to a hotel Wi-Fi network.
The bottom line
CaptiveCrunch hotel Wi-Fi credential theft by Russia's Midnight Blizzard proves that MFA-protected Microsoft 365 accounts can be compromised at the network layer before any authentication prompt reaches the user. Three takeaways define the risk: device code phishing produces valid OAuth tokens that survive password resets; ChocoShell's in-memory execution leaves no disk evidence; and hotel captive portal infrastructure is now an active attack surface for Russian state intelligence. Disable device code flow in Entra ID Conditional Access today, revoke sessions for anyone who connected to hotel Wi-Fi in the United States, India, or Saudi Arabia since May 2026, and hunt Entra sign-in logs for deviceCode authentications from unknown IPs before the end of business.
This analysis is generic. create a free account to score threats like this against your own stack.
Frequently asked questions
What is CaptiveCrunch and who is behind it?
CaptiveCrunch is an active adversary-in-the-middle campaign attributed by Microsoft to Storm-2945, a sub-cluster of Midnight Blizzard (APT29/Cozy Bear), which the US and UK governments attribute to Russia's Foreign Intelligence Service (SVR). Active since May 2026, Storm-2945 compromises hotel and conference center captive portal infrastructure worldwide to intercept traveler sessions, deliver custom malware (CornFlake and ChocoShell), and steal Microsoft 365 OAuth tokens. A device code phishing phase added on July 16, 2026 allows the attackers to bypass MFA without any malware on the victim's device.
How does the hotel Wi-Fi credential theft work in the CaptiveCrunch campaign?
Storm-2945 compromises hotel captive portal systems and uses DNS and HTTP manipulation to intercept and redirect traveler sessions. Victims see convincing prompts claiming a browser update, Windows update, or network repair tool is required before internet access continues. Clicking downloads CornFlake (a Go-based RAT) or ChocoShell (an in-memory PowerShell infostealer). Since July 16, 2026, a second phase redirects travelers to a fake Microsoft login page with a device code; completing that authentication at microsoft.com/devicelogin hands Storm-2945 a valid Microsoft 365 refresh token -- no malware required.
Which travelers and organizations are targeted by the CaptiveCrunch campaign?
Storm-2945 targets business travelers whose credentials provide access to organizations within Midnight Blizzard's espionage mandate: government agencies, diplomatic missions, defense contractors, NATO-affiliated organizations, think tanks, and technology companies. Confirmed attack locations include hotels in the United States, India, and Saudi Arabia. The attack requires no specific vulnerability on the traveler's device -- connecting to the compromised hotel Wi-Fi and following a routine-looking prompt is sufficient for compromise.
Is there a patch for the CaptiveCrunch hotel Wi-Fi attack?
No single patch fixes CaptiveCrunch because it exploits a legitimate Microsoft Entra ID feature (device code authentication) and compromised hotel network infrastructure, not a software vulnerability. Remediation requires configuration changes: disable the device code grant flow in Entra ID via Conditional Access, revoke existing OAuth tokens for potentially affected accounts using Entra's Revoke Sessions function, and deploy detection rules to alert on device code authentications from suspicious locations. No vendor patch can prevent hotel network compromise.
How do I detect if my Microsoft 365 account was compromised via device code phishing?
Query Entra ID sign-in logs for authentications where authenticationProtocol equals deviceCode and ResultType equals 0 (successful sign-in). Investigate accounts that authenticated via device code from IP addresses corresponding to hotel networks, travel destinations, or unknown locations. Follow with Microsoft Graph API activity review: large mail reads, inbox rule creation, OneDrive enumeration, or delegated permission grants within 30 minutes of a device code authentication are strong indicators of Storm-2945 post-compromise collection activity.
Does resetting a password stop a CaptiveCrunch device code phishing attack?
No. Password resets do not invalidate OAuth refresh tokens in default Microsoft Entra ID configurations. When Storm-2945 completes a device code phishing attack, they receive a refresh token valid for up to 90 days. Changing the victim's password leaves that token fully valid. The only remediation is explicit session revocation: use Entra ID portal (User profile → Revoke Sessions) or the Microsoft Graph API command Invoke-MgInvalidateSignIn. After revocation, the attacker's token becomes invalid within minutes.
What does CornFlake malware do on an infected device?
CornFlake is a Go-based Windows remote access trojan deployed by Storm-2945 as a persistent backdoor after hotel Wi-Fi compromise. It exposes a localhost HTTP API and provides keylogging, screenshot capture, and browser credential theft. CornFlake establishes persistence via Windows scheduled tasks or registry run keys and communicates with the FruitStone C2 infrastructure via HTTPS. Unlike ChocoShell, CornFlake writes files to disk -- detection relies on Go runtime behavioral indicators, unsigned PE binaries downloaded from browser-invoked URLs, and scheduled task creation patterns.
How do I disable device code authentication in Entra ID to stop device code phishing?
Create a Conditional Access policy in Microsoft Entra ID: Policies → New Policy → Users: All Users → Cloud Apps: All Cloud Apps → Conditions → Authentication Flows → Device Code Flow: Include → Grant: Block. Name it Block Device Code Authentication Flow and start in Report-Only mode to identify legitimate device code usage (conference room displays, smart TV sign-ins) before switching to Enforcement. Organizations with legitimate device code users should scope an exemption policy to specific compliant devices and applications before enforcing the block.
Sources & references
- Microsoft Security Blog: CaptiveCrunch -- Midnight Blizzard Targets Travelers Worldwide
- BleepingComputer: Hotel Wi-Fi Attacks Use Custom Malware to Breach Microsoft 365 Accounts
- Wiz Threat Intelligence: CaptiveCrunch -- Midnight Blizzard Hospitality Network AiTM Campaign
- Infosecurity Magazine: Midnight Blizzard Targets Travelers via Captive Portals
- Help Net Security: Russian Hackers Abuse Hotel Wi-Fi Networks to Steal Microsoft 365 Credentials
Free resources
Critical CVE Reference Card 2025–2026
25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.
Ransomware Incident Response Playbook
Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.
Get threat intel before your inbox does.
50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.
Unsubscribe anytime. We never sell your data.

Founder & Cybersecurity Evangelist, Decryption Digest
Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.
