Detect and disrupt AI-themed attacks with Microsoft Defender
Midnight Blizzard sub-cluster Storm-2945 targets hospitality sign-in portals for malware and credential theft.
Summary
A sub-cluster of the Russian threat actor Midnight Blizzard, known as Storm-2945, has been actively targeting hospitality organizations since May 2026. Operating under the campaign name CaptiveCrunch, the group compromises hotel sign-in portals to deliver malware and steal traveler credentials.
Full text
July 31 20 min read CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch.
Indicators of Compromise
- mitre_attack — T1566
- mitre_attack — T1078
- mitre_attack — T1190