Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
Russian state APT Midnight Blizzard steals Microsoft credentials via compromised Wi-Fi gateways in hospitality sector.
Summary
Microsoft attributes a credential theft campaign called CaptiveCrunch to Storm-2945, a subgroup of Midnight Blizzard (APT29), a Russian SVR-sponsored threat actor. The campaign compromises public Wi-Fi gateways at hotels, conferences, and hospitality venues to redirect users and perform DNS/HTTP manipulation attacks, stealing Microsoft 365 credentials from traveling employees. The attackers serve Golang-based RATs (CornFlake, ChocoShell) disguised as browser updates and use device code phishing to intercept authentication sessions.
Full text
A Russian state-sponsored APT is behind a recent credential theft campaign mounted via hacked public Wi-Fi gateway appliances at organizations running captive portal networks, Microsoft reports. The campaign was flagged roughly a week ago by ReliaQuest, which noticed that hackers had modified the DNS configurations of compromised small office/home office (SOHO) routers to redirect users to attacker-controlled infrastructure. The attackers were using the adversary-in-the-middle (AitM) technique to intercept the Microsoft 365 credentials of traveling employees within the financial services, professional services, legal, healthcare, energy, and retail sectors. ReliaQuest pointed out that the campaign shared similarities with FrostArmada, an espionage operation mounted by Russia-linked APT28 (also known as Forest Blizzard and Fancy Bear), but did not make a clear attribution. Now Microsoft says that Storm-2945, a subgroup of Midnight Blizzard (also tracked as APT29, Cozy Bear, the Dukes, and Yttrium), a threat actor believed to be sponsored by the Russian Foreign Intelligence Service (SVR), is behind the fresh campaign, dubbed CaptiveCrunch. Midnight Blizzard is known for targeting government and diplomatic entities, non-governmental organizations (NGOs), and IT services providers in the US and Europe for intelligence gathering in support of Russian foreign policy interests.Advertisement. Scroll to continue reading. “Midnight Blizzard operations often involve compromise of valid accounts and, in some highly targeted cases, advanced techniques to compromise authentication mechanisms within an organization to expand access and evade detection,” Microsoft notes. Storm-2945, the tech giant says, started manipulating DNS and HTTP traffic from captive portal networks, such as those at hotels, conference centers, and other shared venues, in May, likely through access to shared services within the captive portal ecosystem. As part of CaptiveCrunch, the attackers have been serving Golang-based Windows remote access trojans (RATs) in the form of browser updates. The malware enabled reconnaissance, credential and session token theft, file and keystroke collection, audio and video surveillance, and remote shell access. The threat actor has been using various ClickFix techniques to convince users to download malware and appears to have been targeting Android users with similar methods to entice them into fetching and installing an APK file. “To date, Microsoft has identified widespread compromise of Wi-Fi networks at hospitality-related organizations and other networks serviced by captive portal equipment in several countries,” the company notes. Storm-2945 targeted Windows users with the CornFlake RAT and infostealer implant and the ChocoShell PowerShell-based infostealer, and managed its infrastructure and agents via the FruitStone web-based command-and-control (C&C) panel. Over the past two weeks, Microsoft says, some CaptiveCrunch landing pages have been directing victims to device code authentication flow experiences, instructing them to enter device codes into Microsoft sign-in pages to authenticate the threat actor’s session. “This activity is consistent with previously reported device code phishing operations conducted by Midnight Blizzard since August 2024. The observed technique does not appear fundamentally novel; however, integrating device code phishing into captive portal and traffic manipulation operations might increase the likelihood that users perceive the authentication request as legitimate,” Microsoft notes. Related: US Charges Russian Individuals and Firms for Running Cybercrime Services Related: US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers Related: EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign Related: US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Critical Flaw Allowed to Azure Cosmos DB PwnageCareCloud Data Breach Impacts Over 350,000Critical Code Execution Vulnerability Patched in TeamCity DataBahn Raises $40 Million for Agentic Data Pipeline ManagementDiscern Security Raises $13 Million in Series A FundingCantina Emerges From Stealth With $8 Million in FundingCritical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms US and Allies Update SBOM Guidance Latest News US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other StatesBalance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity InvestmentsRuby on Rails Patches Critical VulnerabilityIn Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto ResearchCyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian HackersGoogle AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching PaceEU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in BrusselsPrompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MovePNC Financial Services Group has appointed Christian Winward as CISO.Brian Gumbel has joined Armadin as Chief Revenue Officer.EigenQ has appointed Mark Pecen as Vice Chairman and Alexander Truskovsky as CISO.More People On The MoveExpert Insights Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- malware — CornFlake RAT
- malware — ChocoShell
- malware — FruitStone