Drooid Logo
Back to story perspectives

Full Breakdown

Hotel Wi-Fi Hijacking Campaign Targets Microsoft 365 Users

8/3/2026, 11:47:09 PM

Core Event: CaptiveCrunch hijacks hospitality Wi-Fi portals

Travelers connecting to hotel, conference-center or airport Wi-Fi are redirected to counterfeit Microsoft 365 sign-in pages. Attackers compromise the venue’s captive-portal gateway, alter its DNS configuration, and serve fake login sites that capture corporate credentials. In some cases they trigger Microsoft’s device-code authentication flow, causing a legitimate OAuth token to be issued after the victim approves the request. The compromised gateway can also deliver malware disguised as Windows or browser updates, giving the adversary persistent remote-access capabilities.

Background & Context

Microsoft attributes the operation, dubbed CaptiveCrunch, to Storm-2945, a sub-cluster of the Russian state-sponsored espionage group Midnight Blizzard (APT29/Cozy Bear). The campaign has been active since at least May 2026 and targets corporate travelers worldwide.

Timeline

  • May 8 – Public DNS services such as Google’s 8.8.8.8 prove ineffective against the attack.
  • July 16 – Landing pages begin steering victims into Microsoft’s device-code authentication flow, allowing attackers to obtain MFA-validated sessions.
  • July 23 – ReliaQuest documents overlapping captive-portal infrastructure and confirms compromised gateways in several U.S. cities.
  • July 31 – Microsoft publishes a detailed report identifying Storm-2945 as the actor behind CaptiveCrunch.

Data & Statistics

  • Attackers registered four phishing domains that mimic Microsoft branding: `m365-owa.com`, `owa-ms365.com`, `ms365-device.com`, and `ms365-live.com`.
  • ? 33 % of incidents included attempts to abuse the Web Proxy Auto-Discovery (WPAD) protocol, which could route Windows traffic through a malicious proxy.
  • Compromised gateways have affected organizations in financial services, professional services, legal, health care, energy, and retail sectors.
  • The primary malware identified is CornFlake, a Go-based remote-access trojan capable of keylogging, screenshot capture, audio/video hijacking, and persistent command-and-control communication. Microsoft also identified a PowerShell-based infostealer ChocoShell and a web-based control panel FruitStone.

Official Statements & Responses

  • Microsoft thanked Anthropic and OpenAI for collaborative support during the investigation.
  • Recommendations: disable Microsoft Entra ID device-code authentication when not needed, turn off WPAD where unnecessary, and deploy phishing-resistant MFA such as passkeys.
  • ReliaQuest advises travelers to use an always-on full-tunnel VPN or a cellular hotspot for sensitive work, verify every Microsoft login URL, keep devices and browsers patched, and run security software with web-protection features.

Verbatim Quotes

  • “Organizations should assume that public and hospitality network infrastructure might not be trustworthy and should adopt controls that limit exposure to traffic manipulation, credential theft, and device code phishing,” — Fake Microsoft
  • “This threat actor is known to primarily target governments, diplomatic entities, non-governmental organizations (NGOs), and information technology (IT) service providers, primarily in the US and Europe,” — Fake Microsoft

On-the-Ground Reports

Users may see fake Windows-Update screens, counterfeit security scans, or bogus “DirectX” installers. Accepting these prompts can install the CornFlake trojan, which records keystrokes, captures webcam and microphone feeds, and provides persistent remote access.

Conflicting Reports & Gaps

ReliaQuest’s earlier analysis documented the compromised gateways but did not attribute the activity to a known threat actor. Microsoft’s later report links the campaign to Storm-2945. The discrepancy reflects differing investigative scopes rather than contradictory technical evidence.

What’s Next

Microsoft urges organizations to treat all guest-network connections as untrusted, enforce enterprise-managed VPN use, and monitor for suspicious device registrations. The company also advises reviewing the information employees share with hospitality providers when connecting to captive portals. No specific remediation timeline has been announced.