Drooid Logo
Back to today’s briefing

Story perspectives

Russian Wi-Fi Hijack CaptiveCrunch Targets US Travelers

8/3/2026

30 2 Full Breakdown

1 of 2

Story summary
  • CaptiveCrunch, a Wi-Fi hijack linked to Russia’s Storm-2945, is targeting U.S. travelers by hijacking captive portals and redirecting them to fake Microsoft 365 login pages.
  • Victims who enter credentials install the CornFlake trojan, which logs keystrokes, steals credentials and tokens, and provides access.
  • Microsoft identified the PowerShell infostealer ChocoShell that extracts passwords, cookies, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials, and recommends using VPN or mobile hotspots and phishing-resistant MFA.
1 / 2