Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. [...]
AI Analysis
Technical Summary
Microsoft linked a global campaign called CaptiveCrunch to the Russian APT group Midnight Blizzard (APT29), targeting hotel and conference Wi-Fi networks worldwide. The attackers manipulate DNS settings on captive portal devices to intercept user connections and redirect victims to phishing pages mimicking Microsoft 365 login portals or device code phishing pages abusing Microsoft Entra ID authentication flows. Additionally, fake browser and OS update pages deliver malware via ClickFix prompts. Two malware families were identified: CornFlake, a Go-based RAT with capabilities including remote shell, keylogging, credential theft, and surveillance; and ChocoShell, a PowerShell credential stealer targeting browser cookies, passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials. The malware uses multiple persistence mechanisms and disguises itself as legitimate Windows components. An exposed web management panel named FruitStone was used by the attackers to control infected systems. Microsoft advises avoiding captive portal updates, using private or cellular connections, enabling phishing-resistant MFA, and disabling unnecessary device code authentication.
Potential Impact
The campaign enables attackers to gain persistent remote access to infected Windows systems, steal Microsoft 365 credentials and session tokens, browser cookies, saved passwords, and Wi-Fi credentials, and conduct surveillance via keylogging, screenshots, microphone, and webcam capture. This compromises user accounts and sensitive data, potentially leading to unauthorized access to corporate resources. The manipulation of DNS and HTTP traffic on hospitality Wi-Fi networks facilitates large-scale credential theft and malware deployment. The presence of a web-based management panel allows attackers to control infected hosts extensively.
Mitigation Recommendations
Microsoft recommends treating hotel and conference Wi-Fi networks as untrusted environments. Use private cellular or managed network connections whenever possible. Avoid installing software updates or tools offered through captive portals. Adopt phishing-resistant authentication methods such as multi-factor authentication (MFA) and passkeys. Disable Microsoft Entra device code authentication if it is not required. Avoid using corporate credentials on guest Wi-Fi networks. There is no vendor advisory indicating an official patch; therefore, follow these mitigation steps to reduce risk.
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Description
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. [...]
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Microsoft linked a global campaign called CaptiveCrunch to the Russian APT group Midnight Blizzard (APT29), targeting hotel and conference Wi-Fi networks worldwide. The attackers manipulate DNS settings on captive portal devices to intercept user connections and redirect victims to phishing pages mimicking Microsoft 365 login portals or device code phishing pages abusing Microsoft Entra ID authentication flows. Additionally, fake browser and OS update pages deliver malware via ClickFix prompts. Two malware families were identified: CornFlake, a Go-based RAT with capabilities including remote shell, keylogging, credential theft, and surveillance; and ChocoShell, a PowerShell credential stealer targeting browser cookies, passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials. The malware uses multiple persistence mechanisms and disguises itself as legitimate Windows components. An exposed web management panel named FruitStone was used by the attackers to control infected systems. Microsoft advises avoiding captive portal updates, using private or cellular connections, enabling phishing-resistant MFA, and disabling unnecessary device code authentication.
Potential Impact
The campaign enables attackers to gain persistent remote access to infected Windows systems, steal Microsoft 365 credentials and session tokens, browser cookies, saved passwords, and Wi-Fi credentials, and conduct surveillance via keylogging, screenshots, microphone, and webcam capture. This compromises user accounts and sensitive data, potentially leading to unauthorized access to corporate resources. The manipulation of DNS and HTTP traffic on hospitality Wi-Fi networks facilitates large-scale credential theft and malware deployment. The presence of a web-based management panel allows attackers to control infected hosts extensively.
Defensive Guidance
Microsoft recommends treating hotel and conference Wi-Fi networks as untrusted environments. Use private cellular or managed network connections whenever possible. Avoid installing software updates or tools offered through captive portals. Adopt phishing-resistant authentication methods such as multi-factor authentication (MFA) and passkeys. Disable Microsoft Entra device code authentication if it is not required. Avoid using corporate credentials on guest Wi-Fi networks. There is no vendor advisory indicating an official patch; therefore, follow these mitigation steps to reduce risk.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/","fetched":true,"fetchedAt":"2026-08-04T00:33:01.067Z","wordCount":904}
- Classification
- {"confidence":0.82,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6a71333dbf32cb7a3476735e
Added to database: 08/04/2026, 00:33:01 UTC
Last enriched: 08/04/2026, 00:33:13 UTC
Last updated: 09/17/2026, 21:01:57 UTC
Views: 120
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.