Story perspectives
Russian Wi-Fi Hijack CaptiveCrunch Targets US Travelers
8/3/2026
1 of 2
Story summary
- CaptiveCrunch, a Wi-Fi hijack linked to Russia’s Storm-2945, is targeting U.S. travelers by hijacking captive portals and redirecting them to fake Microsoft 365 login pages.
- Victims who enter credentials install the CornFlake trojan, which logs keystrokes, steals credentials and tokens, and provides access.
- Microsoft identified the PowerShell infostealer ChocoShell that extracts passwords, cookies, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials, and recommends using VPN or mobile hotspots and phishing-resistant MFA.
1 / 2
