2026-08-01 · view entry permalink →
CaptiveCrunch: an SVR-linked sub-cluster hijacks hotel and conference captive portals to serve fake update lures, a Go RAT and a token-stealing PowerShell module to travelling staff
Microsoft Threat Intelligence published its analysis of CaptiveCrunch on 2026-07-31, describing a campaign that has been running since early May 2026 in which Storm-2945 conducts "widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide" (Microsoft Threat Intelligence, 2026-07-31). The attribution is the first thing that matters for a government reader: Microsoft "assesses that Storm-2945 is an operational sub-cluster of Midnight Blizzard based on distinctive technical and operational overlaps", citing similarities to Storm-2372, Graph-based email exfiltration, social engineering over commercial messaging apps and victimology; Midnight Blizzard is described as a Russia-based actor attributed by the US and UK governments to the SVR, primarily targeting governments, diplomatic entities, NGOs and IT service providers in the US and Europe (Microsoft Threat Intelligence, 2026-07-31). Microsoft also records that the actor has been leveraging AI to support a significant portion of these operations, and thanks Anthropic and OpenAI for collaboration during the investigation (Microsoft Threat Intelligence, 2026-07-31).
Where the position comes from. The actor manipulates DNS and HTTP traffic on networks served by captive portals to route users through infrastructure it controls — an adversary-in-the-middle position obtained at the venue rather than at the target. Microsoft's investigation into how those portal networks were first compromised is still open, but it flags a systemic possibility worth registering: it observed "notable commonalities in the equipment and management systems used across multiple affected networks", suggesting the activity "might not be limited to isolated compromises of individual venues and could reflect access to shared services within portions of the captive portal ecosystem" (Microsoft Threat Intelligence, 2026-07-31). If that holds, the exposure is not "avoid one compromised hotel" but a class of venue connectivity.
The lure fires before the user does anything. From the AitM position, malware is delivered "purporting to be browser or operating system updates in response to automated connectivity checks issued by users' browsers" (Microsoft Threat Intelligence, 2026-07-31). That is the detail that defeats ordinary user caution: the connectivity check is issued automatically by the operating system or browser on joining a network, so the fake update appears as the first thing on screen rather than as the consequence of visiting a site. The infrastructure then uses ClickFix techniques — paste-and-run style instructions, including a second, more insistent prompt shown after a "verification failure" — to get the user to execute the payload themselves. Microsoft is also aware of indications the actor may be targeting Android devices, since the ClickFix landings include instructions to download and install an APK (Microsoft Threat Intelligence, 2026-07-31).
CornFlake, the persistent foothold. CornFlake is a Go Windows RAT that runs first in dropper mode, "displays a convincing fake progress window designed to occupy the victim's attention" — configurable at build time to imitate Windows Update, a Windows Security scan, a DirectX or Visual C++ redistributable installer, a disk optimiser, network diagnostics, a browser update or a document-viewer installer — while copying itself into the user's roaming profile and establishing persistence (Microsoft Threat Intelligence, 2026-07-31). It registers as a Windows service under a name and description chosen to read as a cloud-sync utility and deliberately to mimic the legitimate svchost.exe process, and it "establishes redundant persistence mechanisms: Windows service registrations, Registry Run keys, named scheduled tasks, and a persistence watchdog routine that runs continuously to restore any persistence mechanism that is removed by defenders or endpoint protection" (Microsoft Threat Intelligence, 2026-07-31). That watchdog is an eviction problem, not a detection problem: removing one autostart entry and declaring the host clean will fail.
Command and control uses an ephemeral ECDH P-256 key exchange with a SHA-256-derived session key over a custom JSON protocol inside the encrypted channel, with each session using a unique ephemeral key, "making decryption of captured traffic impossible without the session-specific private key" (Microsoft Threat Intelligence, 2026-07-31) — captured PCAP will not yield content retrospectively. Its collection set is broad and individually toggled by configuration flag: keylogging via the raw input API including password fields, clipboard capture with the active window title recorded alongside, idle-triggered and on-demand screenshots, microphone capture through the Windows Audio Session API, webcam capture through Media Foundation, removable-media detection and scanning, file exfiltration by extension category with an upload throttle, and a security-posture sweep collecting eighteen categories of host intelligence including installed software, security products, Defender exclusions, UAC level, RDP history and Office recently-used files (Microsoft Threat Intelligence, 2026-07-31). Browser credential theft uses a ChromeKatz-derived module supporting live cookie extraction from process memory and stored-password extraction from disk, including a Chrome App-Bound Encryption bypass and Firefox NSS decryption. CornFlake additionally exposes a localhost HTTP API that lets a companion payload task exfiltration or trigger a configuration reload over the already-established C2 channel (Microsoft Threat Intelligence, 2026-07-31).
ChocoShell, the credential harvest. ChocoShell is a PowerShell stealer delivered and executed entirely in memory whose "primary objective is the high-volume theft of browser session cookies, saved passwords, Microsoft 365 Single Sign-On (SSO) tokens, and Wi-Fi credentials" (Microsoft Threat Intelligence, 2026-07-31). It disables AMSI via .NET reflection, runs a timing-based sandbox check and exits silently if it detects one, and beacons over HTTPS with request paths shaped to look like an image tracking pixel and a JavaScript polyfill file. For elevation it tries three silent UAC bypasses in ordered fallback — a SilentCleanup scheduled-task hijack via a user-writable environment value, cleaned up two seconds later "to avoid cloud detection"; a COM handler hijack against the auto-elevating Windows Store reset tool; and a folder-handler hijack against the Windows Backup utility — falling back to a visible elevation prompt only if all three fail (Microsoft Threat Intelligence, 2026-07-31). With elevation it locks Defender signature updates, impersonates a SYSTEM token borrowed from a core Windows process to defeat App-Bound Encryption, and — as a parallel path that bypasses ABE entirely — launches Chrome, Edge and Brave with remote debugging enabled and asks the browser itself for all cookies through the DevTools Protocol, relaunching the browser afterwards with session restore so the user notices nothing (Microsoft Threat Intelligence, 2026-07-31).
The most consequential item it takes is not a password. Microsoft records that "ChocoShell collects Microsoft 365 and Azure Active Directory (AD) access tokens, refresh tokens, and Web Account Manager (WAM) tokens from .tbres files in the Token Broker cache. Collection of these tokens represents a significant threat to enterprise environments, as threat actors could replay SSO sessions without browser cookies" (Microsoft Threat Intelligence, 2026-07-31). A password reset does not revoke those; token revocation does. Microsoft also notes a ChocoShell variant built to run inside the WinGet Desired State Configuration host process, suggesting an attack path through malicious provisioning configuration (Microsoft Threat Intelligence, 2026-07-31).
The identity leg, and where it overlaps other reporting. Since 16 July, a portion of CaptiveCrunch landing pages have redirected users into the Entra ID device-code authentication flow, instructing them to enter an attacker-initiated code into a genuine Microsoft sign-in page so that "the victim authenticates the threat actor's session rather than their own" (Microsoft Threat Intelligence, 2026-07-31). Microsoft is candid that the technique is not novel — it is consistent with Midnight Blizzard device-code phishing reported since August 2024 — but argues that embedding it in captive-portal traffic manipulation "might increase the likelihood that users perceive the authentication request as legitimate" (Microsoft Threat Intelligence, 2026-07-31). Independently, ReliaQuest reported on 2026-07-23 that "compromised Wi-Fi gateways were identified across multiple US cities and internationally in India and Saudi Arabia, primarily in hotel and hospitality organizations" (ReliaQuest, 2026-07-23).
The two vendors point at two different Russian services, and a reader should not miss it. ReliaQuest's own assessment of the cases it investigated is that "this tradecraft is similar to that of 'APT28' (also known as 'Fancy Bear' and 'Forest Blizzard'), a Russian military intelligence group that was previously linked to similar router-based campaigns compromising Microsoft 365 accounts" (ReliaQuest, 2026-07-23) — military intelligence, not the foreign-intelligence service Microsoft names. The one attribution ReliaQuest declines is narrower than a cluster-level disagreement: it says of a specific APT28-linked gateway-hijacking campaign that "this campaign isn't currently assessed to be FrostArmada itself, but it shares enough tactics, techniques, and procedures (TTPs) to suggest tradecraft reuse at a minimum" (ReliaQuest, 2026-07-23). It never evaluated the Midnight Blizzard hypothesis at all. Microsoft, for its part, addresses the same alternative reading head-on and rejects it: "despite some tactic, technique, and procedure (TTP) similarities to the Forest Blizzard DNS hijacking operation that we publicly disclosed in April 2026, we attribute this campaign, which we call CaptiveCrunch, to Storm-2945" (Microsoft Threat Intelligence, 2026-07-31). Neither vendor is necessarily wrong — they may be describing overlapping but distinct operations on a shared attack surface — but for a government reader deciding which adversary model to plan against, the divergence is the most consequential open question in this reporting, and it is unresolved. The safe operational read is that the surface is corroborated by both, and the service-level attribution is not.
Triage: the highest-fidelity sequence available is temporal, and Microsoft's own hunting logic is built on it — a file creation on a device within roughly two minutes of that device performing a network connectivity-status check, which is what happens on joining a captive-portal network (Microsoft Threat Intelligence, 2026-07-31). Benign software does download after a network join, so the connectivity-check-then-executable pattern alone is noisy; the discriminators are that the written file is an executable or archive in a user-writable path rather than an update delivered through the platform's own update service, and that it is followed by a service registration, a Run-key write and a scheduled-task creation in quick succession from the same process lineage — legitimate installers rarely lay down all three. For the browser-cookie theft, the tell is a browser process launched with a remote-debugging port by a non-user parent, then terminated and relaunched with session restore, which no ordinary user workflow produces. On the identity side, a device-code authentication completing for an account whose sign-in immediately follows travel to a hotel or conference network, especially where the same flow appears across several identities in a short window, is the cloud-side counterpart. Microsoft's Defender detection names for this activity, including a Russian-state-actor tag and specific UAC-bypass and device-code anomaly detections, are listed in the source for customers of that stack (Microsoft Threat Intelligence, 2026-07-31).
Microsoft Threat Intelligence assesses that Storm-2945 is an operational sub-cluster of Midnight Blizzard based on distinctive technical and operational overlaps.
It establishes redundant persistence mechanisms: Windows service registrations, Registry Run keys, named scheduled tasks, and a persistence watchdog routine that runs continuously to restore any persistence mechanism that is removed by defenders or endpoint protection.
Additionally, ChocoShell collects Microsoft 365 and Azure Active Directory (AD) access tokens, refresh tokens, and Web Account Manager (WAM) tokens from .tbres files in the Token Broker cache. Collection of these tokens represents a significant threat to enterprise environments, as threat actors could replay SSO sessions without browser cookies.
Compromised Wi-Fi gateways were identified across multiple US cities and internationally in India and Saudi Arabia, primarily in hotel and hospitality organizations
This campaign isn't currently assessed to be FrostArmada itself, but it shares enough tactics, techniques, and procedures (TTPs) to suggest tradecraft reuse at a minimum.