Midnight Blizzard Hijacks Hotel Wi-Fi Portals to Steal Traveler Credentials
The CaptiveCrunch campaign exploits a fundamental trust gap: travelers connecting to hotel Wi-Fi routinely accept captive portal prompts without verifying their legitimacy, making them easy targets for adversary-in-the-middle (AiTM) attacks. By compromising hotel captive portal infrastructure, Storm-2945 intercepts authentication flows to harvest credentials and session tokens before victims even realize they're on a malicious network. The use of AI-augmented phishing and fake software update lures dramatically lowers the technical barrier for deception, meaning even cautious users can be fooled. This campaign is particularly dangerous because it targets travelers in high-value contexts — business trips, diplomatic travel, and corporate events — where sensitive accounts and VPN credentials are frequently in use. The consequences extend beyond individual victims, as stolen session tokens can bypass multi-factor authentication entirely.
Tactical Insight
Immediate actions
- Mandate the use of a corporate or trusted VPN before connecting to any public or hotel Wi-Fi network.
- Train employees to never install software updates or enter credentials when prompted by a captive portal page.
- Enable phishing-resistant MFA (e.g., FIDO2/passkeys) on all corporate accounts to reduce session token theft impact.
Long-term improvements
- Implement a Zero Trust Network Access (ZTNA) architecture so device and user identity is continuously verified regardless of network location.
- Establish a travel security policy requiring pre-trip briefings for employees visiting high-risk regions or attending major events.
- Deploy endpoint detection and response (EDR) tools configured to flag unauthorized software installations triggered from browser processes.
Detection measures
- Monitor for anomalous session token usage, such as the same token appearing from geographically disparate IP addresses within a short time window.
- Integrate threat intelligence feeds covering nation-state AiTM campaigns to enable proactive blocking of known infrastructure used by Storm-2945.
- Enable conditional access policies that invalidate sessions when device posture or network context changes unexpectedly.