---
schema: 1
kind: threat
title: "CaptiveCrunch: an SVR-linked sub-cluster hijacks hotel and conference captive portals to serve fake update lures, a Go RAT and a token-stealing PowerShell module to travelling staff"
headline: "Microsoft attributes worldwide captive-portal traffic manipulation to Storm-2945, delivering the CornFlake RAT and ChocoShell stealer to travellers"
summary: >
  Microsoft Threat Intelligence disclosed CaptiveCrunch on 2026-07-31, a campaign it attributes to Storm-2945, assessed
  as an operational sub-cluster of the SVR-attributed actor Midnight Blizzard. Since early May 2026 the actor has
  manipulated DNS and HTTP traffic on hospitality networks served by captive portals worldwide, redirecting users
  through its own infrastructure and answering browser connectivity checks with ClickFix-style fake browser and OS
  update prompts. The payloads are CornFlake, a Go Windows RAT with redundant persistence and a watchdog that restores
  anything defenders remove, and ChocoShell, an in-memory PowerShell stealer that takes browser cookies, saved
  passwords, Microsoft 365 SSO tokens and Wi-Fi credentials. Since 16 July some landing pages also drive Entra ID
  device-code phishing. Travelling government and diplomatic staff are named target populations.
discovered_at: "2026-08-01T04:24:59Z"
event_date: "2026-07-31"
run_id: 2026-08-01T0409Z-intel
priority: high
immediate_action: null
tags: [nation-state, espionage, phishing, identity, infostealer, ai-abuse]
regions: [global, europe]
sectors: [public-sector, defense, finance, healthcare, energy, legal-services]
entities: [actor:midnight-blizzard, actor:storm-2945, campaign:captivecrunch-storm-2945-hospitality-wifi, malware:cornflake-go-rat, tool:chocoshell-powershell-stealer]
techniques: [T1557, T1204.004, T1543.003, T1547.001, T1053.005, T1036.005, T1056.001, T1113, T1115, T1123, T1125, T1082, T1518.001, T1555.003, T1539, T1528, T1550.001, T1548.002, T1546.015, T1685, T1497, T1059.001, T1573.002]
affected_products: ["Microsoft 365", "Microsoft Entra ID"]
cves: []
sources:
  - url: "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/"
    publisher: "Microsoft Threat Intelligence"
    date: "2026-07-31"
    role: primary
  - url: "https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/"
    publisher: "ReliaQuest"
    date: "2026-07-23"
    role: corroborating
closed_sources: []
evidence:
  - quote: "Microsoft Threat Intelligence assesses that Storm-2945 is an operational sub-cluster of Midnight Blizzard based on distinctive technical and operational overlaps."
    publisher: "Microsoft Threat Intelligence"
  - quote: "It establishes redundant persistence mechanisms: Windows service registrations, Registry Run keys, named scheduled tasks, and a persistence watchdog routine that runs continuously to restore any persistence mechanism that is removed by defenders or endpoint protection."
    publisher: "Microsoft Threat Intelligence"
  - quote: "Additionally, ChocoShell collects Microsoft 365 and Azure Active Directory (AD) access tokens, refresh tokens, and Web Account Manager (WAM) tokens from .tbres files in the Token Broker cache. Collection of these tokens represents a significant threat to enterprise environments, as threat actors could replay SSO sessions without browser cookies."
    publisher: "Microsoft Threat Intelligence"
  - quote: "Compromised Wi-Fi gateways were identified across multiple US cities and internationally in India and Saudi Arabia, primarily in hotel and hospitality organizations"
    publisher: "ReliaQuest"
  - quote: "This campaign isn't currently assessed to be FrostArmada itself, but it shares enough tactics, techniques, and procedures (TTPs) to suggest tradecraft reuse at a minimum."
    publisher: "ReliaQuest"
verification: multi-source
sourcing_note: >
  The Storm-2945 attribution, the Midnight Blizzard sub-cluster assessment and every technical detail of CornFlake,
  ChocoShell and the FruitStone panel rest on Microsoft alone. ReliaQuest's 2026-07-23 report corroborates the broader
  captive-portal-hijacking attack surface — compromised hospitality gateways, corporate travellers as the objective —
  but assesses its own cases as resembling APT28 / Forest Blizzard tradecraft, a different Russian service from the
  one Microsoft names, and never evaluates the Midnight Blizzard hypothesis; the single attribution it declines is to
  a specific APT28-linked campaign, not to this cluster. The two are therefore treated as a corroborated attack
  surface carrying an unresolved service-level attribution divergence, not as two sources for one claim, and the
  divergence is surfaced in the body rather than smoothed over. Microsoft states its investigation into how the captive-portal networks were initially compromised is still
  ongoing, so no initial-access vector for the gateways themselves is asserted here. Indicators of compromise and
  vendor rule content in the source are deliberately not reproduced.
confidence: high
update_of: null
references: []
deep_dive: true
deep_dive_category: apt-campaign
org_triage: null
classification:
  reliability: B
  credibility: 2
watchlist_hit: false
actions:
  - "For staff travelling in the next fortnight, issue managed cellular connectivity (hotspot, eSIM data or a managed travel router) instead of venue Wi-Fi, and tell them that any browser or OS update prompt appearing on connecting to a hotel or conference network is the lure — the campaign fires it in response to the automatic connectivity check, before the user has browsed anywhere."
  - "Enforce always-on, full-tunnel VPN on corporate devices so DNS and web traffic leave through the corporate network before touching a venue gateway — ReliaQuest assesses this single control closes the primary exposure, and it defeats the traffic-manipulation position the whole campaign depends on."
  - "Restrict the Entra ID device-code authentication flow via Conditional Access, or block it where no device requires it, since a portion of CaptiveCrunch landing pages have been redirecting users into that flow since 16 July."
migrated_from: null
---

Microsoft Threat Intelligence published its analysis of CaptiveCrunch on 2026-07-31, describing a campaign that has been running since early May 2026 in which Storm-2945 conducts "widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide" ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)). The attribution is the first thing that matters for a government reader: Microsoft "assesses that Storm-2945 is an operational sub-cluster of Midnight Blizzard based on distinctive technical and operational overlaps", citing similarities to Storm-2372, Graph-based email exfiltration, social engineering over commercial messaging apps and victimology; Midnight Blizzard is described as a Russia-based actor attributed by the US and UK governments to the SVR, primarily targeting governments, diplomatic entities, NGOs and IT service providers in the US and Europe ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)). Microsoft also records that the actor has been leveraging AI to support a significant portion of these operations, and thanks Anthropic and OpenAI for collaboration during the investigation ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)).

**Where the position comes from.** The actor manipulates DNS and HTTP traffic on networks served by captive portals to route users through infrastructure it controls — an adversary-in-the-middle position obtained at the venue rather than at the target. Microsoft's investigation into how those portal networks were first compromised is still open, but it flags a systemic possibility worth registering: it observed "notable commonalities in the equipment and management systems used across multiple affected networks", suggesting the activity "might not be limited to isolated compromises of individual venues and could reflect access to shared services within portions of the captive portal ecosystem" ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)). If that holds, the exposure is not "avoid one compromised hotel" but a class of venue connectivity.

**The lure fires before the user does anything.** From the AitM position, malware is delivered "purporting to be browser or operating system updates in response to automated connectivity checks issued by users' browsers" ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)). That is the detail that defeats ordinary user caution: the connectivity check is issued automatically by the operating system or browser on joining a network, so the fake update appears as the first thing on screen rather than as the consequence of visiting a site. The infrastructure then uses ClickFix techniques — paste-and-run style instructions, including a second, more insistent prompt shown after a "verification failure" — to get the user to execute the payload themselves. Microsoft is also aware of indications the actor may be targeting Android devices, since the ClickFix landings include instructions to download and install an APK ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)).

**CornFlake, the persistent foothold.** CornFlake is a Go Windows RAT that runs first in dropper mode, "displays a convincing fake progress window designed to occupy the victim's attention" — configurable at build time to imitate Windows Update, a Windows Security scan, a DirectX or Visual C++ redistributable installer, a disk optimiser, network diagnostics, a browser update or a document-viewer installer — while copying itself into the user's roaming profile and establishing persistence ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)). It registers as a Windows service under a name and description chosen to read as a cloud-sync utility and deliberately to mimic the legitimate `svchost.exe` process, and it "establishes redundant persistence mechanisms: Windows service registrations, Registry Run keys, named scheduled tasks, and a persistence watchdog routine that runs continuously to restore any persistence mechanism that is removed by defenders or endpoint protection" ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)). That watchdog is an eviction problem, not a detection problem: removing one autostart entry and declaring the host clean will fail.

Command and control uses an ephemeral ECDH P-256 key exchange with a SHA-256-derived session key over a custom JSON protocol inside the encrypted channel, with each session using a unique ephemeral key, "making decryption of captured traffic impossible without the session-specific private key" ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)) — captured PCAP will not yield content retrospectively. Its collection set is broad and individually toggled by configuration flag: keylogging via the raw input API including password fields, clipboard capture with the active window title recorded alongside, idle-triggered and on-demand screenshots, microphone capture through the Windows Audio Session API, webcam capture through Media Foundation, removable-media detection and scanning, file exfiltration by extension category with an upload throttle, and a security-posture sweep collecting eighteen categories of host intelligence including installed software, security products, Defender exclusions, UAC level, RDP history and Office recently-used files ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)). Browser credential theft uses a ChromeKatz-derived module supporting live cookie extraction from process memory and stored-password extraction from disk, including a Chrome App-Bound Encryption bypass and Firefox NSS decryption. CornFlake additionally exposes a localhost HTTP API that lets a companion payload task exfiltration or trigger a configuration reload over the already-established C2 channel ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)).

**ChocoShell, the credential harvest.** ChocoShell is a PowerShell stealer delivered and executed entirely in memory whose "primary objective is the high-volume theft of browser session cookies, saved passwords, Microsoft 365 Single Sign-On (SSO) tokens, and Wi-Fi credentials" ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)). It disables AMSI via .NET reflection, runs a timing-based sandbox check and exits silently if it detects one, and beacons over HTTPS with request paths shaped to look like an image tracking pixel and a JavaScript polyfill file. For elevation it tries three silent UAC bypasses in ordered fallback — a SilentCleanup scheduled-task hijack via a user-writable environment value, cleaned up two seconds later "to avoid cloud detection"; a COM handler hijack against the auto-elevating Windows Store reset tool; and a folder-handler hijack against the Windows Backup utility — falling back to a visible elevation prompt only if all three fail ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)). With elevation it locks Defender signature updates, impersonates a SYSTEM token borrowed from a core Windows process to defeat App-Bound Encryption, and — as a parallel path that bypasses ABE entirely — launches Chrome, Edge and Brave with remote debugging enabled and asks the browser itself for all cookies through the DevTools Protocol, relaunching the browser afterwards with session restore so the user notices nothing ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)).

The most consequential item it takes is not a password. Microsoft records that "ChocoShell collects Microsoft 365 and Azure Active Directory (AD) access tokens, refresh tokens, and Web Account Manager (WAM) tokens from .tbres files in the Token Broker cache. Collection of these tokens represents a significant threat to enterprise environments, as threat actors could replay SSO sessions without browser cookies" ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)). A password reset does not revoke those; token revocation does. Microsoft also notes a ChocoShell variant built to run inside the WinGet Desired State Configuration host process, suggesting an attack path through malicious provisioning configuration ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)).

**The identity leg, and where it overlaps other reporting.** Since 16 July, a portion of CaptiveCrunch landing pages have redirected users into the Entra ID device-code authentication flow, instructing them to enter an attacker-initiated code into a genuine Microsoft sign-in page so that "the victim authenticates the threat actor's session rather than their own" ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)). Microsoft is candid that the technique is not novel — it is consistent with Midnight Blizzard device-code phishing reported since August 2024 — but argues that embedding it in captive-portal traffic manipulation "might increase the likelihood that users perceive the authentication request as legitimate" ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)). Independently, ReliaQuest reported on 2026-07-23 that "compromised Wi-Fi gateways were identified across multiple US cities and internationally in India and Saudi Arabia, primarily in hotel and hospitality organizations" ([ReliaQuest, 2026-07-23](https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/)).

**The two vendors point at two different Russian services, and a reader should not miss it.** ReliaQuest's own assessment of the cases it investigated is that "this tradecraft is similar to that of 'APT28' (also known as 'Fancy Bear' and 'Forest Blizzard'), a Russian military intelligence group that was previously linked to similar router-based campaigns compromising Microsoft 365 accounts" ([ReliaQuest, 2026-07-23](https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/)) — military intelligence, not the foreign-intelligence service Microsoft names. The one attribution ReliaQuest declines is narrower than a cluster-level disagreement: it says of a specific APT28-linked gateway-hijacking campaign that "this campaign isn't currently assessed to be FrostArmada itself, but it shares enough tactics, techniques, and procedures (TTPs) to suggest tradecraft reuse at a minimum" ([ReliaQuest, 2026-07-23](https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/)). It never evaluated the Midnight Blizzard hypothesis at all. Microsoft, for its part, addresses the same alternative reading head-on and rejects it: "despite some tactic, technique, and procedure (TTP) similarities to the Forest Blizzard DNS hijacking operation that we publicly disclosed in April 2026, we attribute this campaign, which we call CaptiveCrunch, to Storm-2945" ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)). Neither vendor is necessarily wrong — they may be describing overlapping but distinct operations on a shared attack surface — but for a government reader deciding which adversary model to plan against, the divergence is the most consequential open question in this reporting, and it is unresolved. The safe operational read is that the surface is corroborated by both, and the service-level attribution is not.

**Defender takeaway:** for a Swiss or European public-sector organisation the exposed asset is the travelling official, and the compromise happens in the first sixty seconds on the venue network — before any browsing, in response to an automatic connectivity check. Three controls follow directly from the mechanics rather than from general hygiene. First, remove the AitM position: Microsoft's own guidance is to prefer private connectivity such as mobile hotspots, eSIM cellular data or satellite over public Wi-Fi, to consider enterprise-managed travel routers that tunnel back to corporate infrastructure before anything sensitive is reached, and to use MDM policy to prevent managed devices connecting to non-provisioned networks ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)). Second, treat the identity leg as the objective: restrict or block device-code flow, prefer phishing-resistant methods, and enable Continuous Access Evaluation so a revocation actually lands. Third, plan eviction rather than cleanup — the persistence watchdog and the stolen refresh and WAM tokens mean that reimaging the laptop without revoking the identity's tokens leaves the intrusion live in the tenant. ReliaQuest offers the most compact version of the first control, assessing that organisations "can close the primary exposure with one control: enforce always-on, full-tunnel VPN on corporate devices", which routes all traffic including DNS through the corporate network before it reaches the hotel gateway ([ReliaQuest, 2026-07-23](https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/)). Microsoft also recommends minimising what staff disclose at guest-network registration and never reusing corporate credentials there ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)).

**Triage:** the highest-fidelity sequence available is temporal, and Microsoft's own hunting logic is built on it — a file creation on a device within roughly two minutes of that device performing a network connectivity-status check, which is what happens on joining a captive-portal network ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)). Benign software does download after a network join, so the connectivity-check-then-executable pattern alone is noisy; the discriminators are that the written file is an executable or archive in a user-writable path rather than an update delivered through the platform's own update service, and that it is followed by a service registration, a Run-key write and a scheduled-task creation in quick succession from the same process lineage — legitimate installers rarely lay down all three. For the browser-cookie theft, the tell is a browser process launched with a remote-debugging port by a non-user parent, then terminated and relaunched with session restore, which no ordinary user workflow produces. On the identity side, a device-code authentication completing for an account whose sign-in immediately follows travel to a hotel or conference network, especially where the same flow appears across several identities in a short window, is the cloud-side counterpart. Microsoft's Defender detection names for this activity, including a Russian-state-actor tag and specific UAC-bypass and device-code anomaly detections, are listed in the source for customers of that stack ([Microsoft Threat Intelligence, 2026-07-31](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/)).
