CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
In this article The CaptiveCrunch campaign Storm-2945 and Midnight Blizzard CaptiveCrunch tradecraft and tooling How to protect against CaptiveCrunch activity Microsoft Defender detections and hunting guidance Indicators of compromise Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide. Despite some tactic, technique, and procedure (TTP) similarities to the Forest Blizzard DNS hijacking operation that we publicly disclosed in April 2026, we attribute this campaign, which we call CaptiveCrunch, to Storm-2945. As reported by ReliaQuest on July 23, a portion of this activity leverages doppelganger domains mimicking Microsoft online services to conduct follow-on adversary-in-the-middle (AitM) phishing operations that abuse the device code authentication flow in Microsoft Entra ID. Microsoft Threat Intelligence has also identified active traffic manipulation attacks leading to the delivery of malware on impacted systems. Microsoft has observed Storm-2945 leveraging AI to support a significant portion of these operations. Today, we are sharing our findings on these ongoing intrusions to raise awareness of this threat and enable customers to protect their devices, especially while traveling. We provide our assessment of Storm-2945’s relationship to Midnight Blizzard and analysis of the CaptiveCrunch campaign, detailing the malware and tradecraft used in these operations. We also provide mitigation, detection, and hunting guidance to help organizations identify and defend against Storm-2945 and related activity. Microsoft Threat Intelligence would like to thank our partners at Anthropic and OpenAI for their collaboration and support during this investigation. The CaptiveCrunch campaign Since February 2026, Storm-2945 has conducted AI-augmented operations including targeted device code and OAuth code phishing campaigns leading to Entra device registration and subsequent data collection from Microsoft 365. Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945 manipulating DNS and HTTP traffic from networks served by captive portals to redirect user traffic through actor-controlled infrastructure. Although our investigation into the initial compromise vector for the captive portal networks is ongoing, we have observed notable commonalities in the equipment and management systems used across multiple affected networks. These similarities suggest that the activity might not be limited to isolated compromises of individual venues and could reflect access to shared services within portions of the captive portal ecosystem. Figure 1. Overview of the CaptiveCrunch attack flow As part of the CaptiveCrunch campaign, Storm-2945 has leveraged their AitM position to redirect users through actor-controlled phishing infrastructure and has also delivered malware purporting to be browser or operating system updates in response to automated connectivity checks issued by users’ browsers. Multiple variants have been delivered, including fully-featured Windows remote access trojans (RAT) in compiled Golang, with functionality to conduct system enumeration, collect files and keystrokes, steal credentials and session tokens, conduct audio and video surveillance, monitor for removable media, and provide the threat actor a remote shell on infected systems. The threat actor infrastructure leverages a variety of ClickFix techniques to elicit the user into downloading and executing the malware: Figure 2. ClickFix prompt with manual user instructions Figure 3. ClickFix prompt with additional user instructions after verification failure In addition to variants of malware targeting Windows systems, Microsoft Threat Intelligence is also aware of indications that the threat actor might be targeting Android devices with similar techniques as the ClickFi…
AI Analysis
Technical Summary
Storm-2945, a subgroup of the Russian threat actor Midnight Blizzard, has been conducting a campaign named CaptiveCrunch since May 2026. The operation targets the sign-in portals of hospitality-related organizations, such as hotels, to compromise these portals and deliver malware to travelers. The campaign also aims to steal credentials from affected users. The attack vector involves compromising legitimate hospitality sign-in portals rather than exploiting a specific software vulnerability. There is no indication of known exploits in the wild beyond this campaign, and no patches or fixes are referenced. The threat actor's activity is global, targeting travelers worldwide.
Potential Impact
Travelers using compromised hospitality sign-in portals risk malware infection and credential theft. This can lead to unauthorized access to personal or corporate accounts and potential further compromise of affected systems. The impact is primarily on the confidentiality and integrity of user credentials and devices. There is no information about direct impact on the hospitality organizations' infrastructure beyond portal compromise.
Mitigation Recommendations
No specific patches or fixes are available as this threat involves compromise of hospitality sign-in portals rather than a software vulnerability. Organizations in the hospitality sector should review and strengthen the security of their sign-in portals and authentication mechanisms. Travelers should exercise caution when using public or hospitality Wi-Fi and sign-in portals, employ multi-factor authentication where possible, and maintain updated endpoint security solutions. Monitor official vendor advisories for any updates related to this threat.
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Description
In this article The CaptiveCrunch campaign Storm-2945 and Midnight Blizzard CaptiveCrunch tradecraft and tooling How to protect against CaptiveCrunch activity Microsoft Defender detections and hunting guidance Indicators of compromise Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide. Despite some tactic, technique, and procedure (TTP) similarities to the Forest Blizzard DNS hijacking operation that we publicly disclosed in April 2026, we attribute this campaign, which we call CaptiveCrunch, to Storm-2945. As reported by ReliaQuest on July 23, a portion of this activity leverages doppelganger domains mimicking Microsoft online services to conduct follow-on adversary-in-the-middle (AitM) phishing operations that abuse the device code authentication flow in Microsoft Entra ID. Microsoft Threat Intelligence has also identified active traffic manipulation attacks leading to the delivery of malware on impacted systems. Microsoft has observed Storm-2945 leveraging AI to support a significant portion of these operations. Today, we are sharing our findings on these ongoing intrusions to raise awareness of this threat and enable customers to protect their devices, especially while traveling. We provide our assessment of Storm-2945’s relationship to Midnight Blizzard and analysis of the CaptiveCrunch campaign, detailing the malware and tradecraft used in these operations. We also provide mitigation, detection, and hunting guidance to help organizations identify and defend against Storm-2945 and related activity. Microsoft Threat Intelligence would like to thank our partners at Anthropic and OpenAI for their collaboration and support during this investigation. The CaptiveCrunch campaign Since February 2026, Storm-2945 has conducted AI-augmented operations including targeted device code and OAuth code phishing campaigns leading to Entra device registration and subsequent data collection from Microsoft 365. Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945 manipulating DNS and HTTP traffic from networks served by captive portals to redirect user traffic through actor-controlled infrastructure. Although our investigation into the initial compromise vector for the captive portal networks is ongoing, we have observed notable commonalities in the equipment and management systems used across multiple affected networks. These similarities suggest that the activity might not be limited to isolated compromises of individual venues and could reflect access to shared services within portions of the captive portal ecosystem. Figure 1. Overview of the CaptiveCrunch attack flow As part of the CaptiveCrunch campaign, Storm-2945 has leveraged their AitM position to redirect users through actor-controlled phishing infrastructure and has also delivered malware purporting to be browser or operating system updates in response to automated connectivity checks issued by users’ browsers. Multiple variants have been delivered, including fully-featured Windows remote access trojans (RAT) in compiled Golang, with functionality to conduct system enumeration, collect files and keystrokes, steal credentials and session tokens, conduct audio and video surveillance, monitor for removable media, and provide the threat actor a remote shell on infected systems. The threat actor infrastructure leverages a variety of ClickFix techniques to elicit the user into downloading and executing the malware: Figure 2. ClickFix prompt with manual user instructions Figure 3. ClickFix prompt with additional user instructions after verification failure In addition to variants of malware targeting Windows systems, Microsoft Threat Intelligence is also aware of indications that the threat actor might be targeting Android devices with similar techniques as the ClickFi…
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Storm-2945, a subgroup of the Russian threat actor Midnight Blizzard, has been conducting a campaign named CaptiveCrunch since May 2026. The operation targets the sign-in portals of hospitality-related organizations, such as hotels, to compromise these portals and deliver malware to travelers. The campaign also aims to steal credentials from affected users. The attack vector involves compromising legitimate hospitality sign-in portals rather than exploiting a specific software vulnerability. There is no indication of known exploits in the wild beyond this campaign, and no patches or fixes are referenced. The threat actor's activity is global, targeting travelers worldwide.
Potential Impact
Travelers using compromised hospitality sign-in portals risk malware infection and credential theft. This can lead to unauthorized access to personal or corporate accounts and potential further compromise of affected systems. The impact is primarily on the confidentiality and integrity of user credentials and devices. There is no information about direct impact on the hospitality organizations' infrastructure beyond portal compromise.
Defensive Guidance
No specific patches or fixes are available as this threat involves compromise of hospitality sign-in portals rather than a software vulnerability. Organizations in the hospitality sector should review and strengthen the security of their sign-in portals and authentication mechanisms. Travelers should exercise caution when using public or hospitality Wi-Fi and sign-in portals, employ multi-factor authentication where possible, and maintain updated endpoint security solutions. Monitor official vendor advisories for any updates related to this threat.
Technical Details
- Article Source
- {"url":"https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/","fetched":true,"fetchedAt":"2026-08-01T07:58:46.689Z","wordCount":5512}
- Classification
- {"confidence":0.76,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6a6da738bf32cb7a346171d4
Added to database: 08/01/2026, 07:58:48 UTC
Last enriched: 08/01/2026, 07:58:55 UTC
Last updated: 09/15/2026, 19:10:09 UTC
Views: 470
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.