Microsoft has attributed a recent wave of attacks against public Wi-Fi captive portal networks to Storm-2945, a subgroup of the Russian state-sponsored threat actor Midnight Blizzard, also known as APT29, Cozy Bear, the Dukes, and Yttrium. The group is believed to be linked to Russia’s Foreign Intelligence Service (SVR).

The campaign, tracked by Microsoft as CaptiveCrunch, was first flagged roughly a week earlier by ReliaQuest, which observed attackers modifying DNS configurations on compromised small office/home office routers to redirect users to attacker-controlled infrastructure. The technique used adversary-in-the-middle (AitM) interception to steal Microsoft 365 credentials from traveling employees across financial services, professional services, legal, healthcare, energy, and retail organizations. ReliaQuest noted similarities to FrostArmada, an espionage operation tied to APT28 (Forest Blizzard, Fancy Bear), but stopped short of firm attribution.

How the Campaign Works

According to Microsoft, Storm-2945 began manipulating DNS and HTTP traffic on captive portal networks, the login systems used at hotels, conference centers, and other shared venues, starting in May. The access is believed to stem from a compromise of shared services within the captive portal ecosystem rather than individual venue networks.

Victims are served fake browser update prompts that instead deliver Golang-based Windows remote access trojans. These tools support reconnaissance, credential and session token theft, keystroke and file collection, audio and video surveillance, and remote shell access. The threat actor has also used ClickFix social engineering techniques and appears to be targeting Android users with similar lures to install malicious APK files.

Microsoft identified Storm-2945 deploying the CornFlake RAT and infostealer, along with the ChocoShell PowerShell-based infostealer, managing operations through a web-based command-and-control panel dubbed FruitStone.

Device Code Phishing

Over the past two weeks, some CaptiveCrunch landing pages have redirected victims into device code authentication flows, prompting them to enter codes on legitimate Microsoft sign-in pages to authenticate the attacker’s session. Microsoft says this technique is consistent with device code phishing operations it has attributed to Midnight Blizzard since August 2024, though embedding it within captive portal traffic manipulation may make the requests appear more legitimate to victims.

Microsoft says it has identified widespread compromise of Wi-Fi networks at hospitality organizations and other venues serviced by captive portal equipment across several countries.