Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

0
Medium
Malware
Published: 08/04/2026 (08/04/2026, 00:17:15 UTC)
Source: Bleeping Computer

Description

A global campaign named CaptiveCrunch, attributed to the Russian threat actor Midnight Blizzard (APT29), targets hospitality Wi-Fi networks to breach Microsoft 365 accounts. The attackers manipulate DNS and HTTP traffic on captive portal networks to redirect users to phishing pages or fake update prompts that deliver malware. Two malware families, CornFlake (a Go-based remote access trojan) and ChocoShell (an in-memory PowerShell credential stealer), enable persistent access, credential theft, surveillance, and data exfiltration. The campaign has been active since at least early May 2026, with phishing operations starting in February. Microsoft recommends treating hotel and conference Wi-Fi as untrusted and adopting phishing-resistant authentication methods.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/04/2026, 00:33:13 UTC

Technical Analysis

Microsoft linked a global campaign called CaptiveCrunch to the Russian APT group Midnight Blizzard (APT29), targeting hotel and conference Wi-Fi networks worldwide. The attackers manipulate DNS settings on captive portal devices to intercept user connections and redirect victims to phishing pages mimicking Microsoft 365 login portals or device code phishing pages abusing Microsoft Entra ID authentication flows. Additionally, fake browser and OS update pages deliver malware via ClickFix prompts. Two malware families were identified: CornFlake, a Go-based RAT with capabilities including remote shell, keylogging, credential theft, and surveillance; and ChocoShell, a PowerShell credential stealer targeting browser cookies, passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials. The malware uses multiple persistence mechanisms and disguises itself as legitimate Windows components. An exposed web management panel named FruitStone was used by the attackers to control infected systems. Microsoft advises avoiding captive portal updates, using private or cellular connections, enabling phishing-resistant MFA, and disabling unnecessary device code authentication.

Potential Impact

The campaign enables attackers to gain persistent remote access to infected Windows systems, steal Microsoft 365 credentials and session tokens, browser cookies, saved passwords, and Wi-Fi credentials, and conduct surveillance via keylogging, screenshots, microphone, and webcam capture. This compromises user accounts and sensitive data, potentially leading to unauthorized access to corporate resources. The manipulation of DNS and HTTP traffic on hospitality Wi-Fi networks facilitates large-scale credential theft and malware deployment. The presence of a web-based management panel allows attackers to control infected hosts extensively.

Mitigation Recommendations

Microsoft recommends treating hotel and conference Wi-Fi networks as untrusted environments. Use private cellular or managed network connections whenever possible. Avoid installing software updates or tools offered through captive portals. Adopt phishing-resistant authentication methods such as multi-factor authentication (MFA) and passkeys. Disable Microsoft Entra device code authentication if it is not required. Avoid using corporate credentials on guest Wi-Fi networks. There is no vendor advisory indicating an official patch; therefore, follow these mitigation steps to reduce risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/","fetched":true,"fetchedAt":"2026-08-04T00:33:01.067Z","wordCount":904}

Threat ID: 6a71333dbf32cb7a3476735e

Added to database: 08/04/2026, 00:33:01 UTC

Last enriched: 08/04/2026, 00:33:13 UTC

Last updated: 08/04/2026, 02:32:10 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses