Back to Feed
Threat IntelligenceSep 10, 2026

Detect and disrupt AI-themed attacks with Microsoft Defender

Midnight Blizzard sub-cluster Storm-2945 targets hospitality sign-in portals for malware and credential theft.

Summary

A sub-cluster of the Russian threat actor Midnight Blizzard, known as Storm-2945, has been actively targeting hospitality organizations since May 2026. Operating under the campaign name CaptiveCrunch, the group compromises hotel sign-in portals to deliver malware and steal traveler credentials.

Full text

July 31 20 min read CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch.

Indicators of Compromise

  • mitre_attack — T1566
  • mitre_attack — T1078
  • mitre_attack — T1190

Entities

Midnight Blizzard (threat_actor)Storm-2945 (threat_actor)CaptiveCrunch (campaign)Microsoft (vendor)