CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials

    Date: 08/14/2026

    Severity: High

    Summary

    On July 31, Threat Intelligence reported an ongoing credential theft campaign tracked as CaptiveCrunch, attributed to Storm-2945, a sub-group of Russia-linked Midnight Blizzard (APT29). The campaign abuses captive portal networks at hotels, conference centers, and similar venues to redirect victims to attacker-controlled infrastructure. Attackers use these redirects to harvest Microsoft 365 credentials, conduct device-code phishing, and deliver malware. Evidence indicates that Storm-2945 compromised shared captive portal services instead of targeting individual venues directly, with compromised gateways identified in the U.S., India, and Saudi Arabia. Microsoft also found evidence that the group used AI tools to assist operations, including the development of the CornFlake and ChocoShell malware. The campaign has expanded to Android devices through malicious APK files, while its initial access method remains under investigation.

    Indicators of Compromise (IOC) List

    Domains/URLs

    ms365-device.com

    ms365-live.com

    m365-owa.com

    owa-ms365.com

    213.145.86.112/t/pixel.gif

    213.145.86.112/cdn/chunks/polyfill-7e2b.min.js

    213.145.86.112/t/event

    IP Address

    31.57.243.154

    38.146.28.75

    38.146.28.132

    104.194.159.150

    107.189.26.194

    213.145.86.112

    Hash

    918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593

    be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "m365-owa.com" or url like "m365-owa.com" or siteurl like "m365-owa.com" or domainname like "ms365-device.com" or url like "ms365-device.com" or siteurl like "ms365-device.com" or domainname like "ms365-live.com" or url like "ms365-live.com" or siteurl like "ms365-live.com" or domainname like "owa-ms365.com" or url like "owa-ms365.com" or siteurl like "owa-ms365.com" or domainname like "213.145.86.112/t/pixel.gif" or url like "213.145.86.112/t/pixel.gif" or siteurl like "213.145.86.112/t/pixel.gif" or domainname like "213.145.86.112/cdn/chunks/polyfill-7e2b.min.js" or url like "213.145.86.112/cdn/chunks/polyfill-7e2b.min.js" or siteurl like "213.145.86.112/cdn/chunks/polyfill-7e2b.min.js" or domainname like "213.145.86.112/t/event" or url like "213.145.86.112/t/event" or siteurl like "213.145.86.112/t/event"

    Detection Query 2 :

    dstipaddress IN ("213.145.86.112","31.57.243.154","38.146.28.132","38.146.28.75","104.194.159.150","107.189.26.194") or srcipaddress IN ("213.145.86.112","31.57.243.154","38.146.28.132","38.146.28.75","104.194.159.150","107.189.26.194")

    Detection Query 3 :

    sha256hash IN ("918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593","be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c")

    Reference:    

    https://www.zscaler.com/blogs/security-research/captivecrunch-midnight-blizzard-weaponizes-hotel-wi-fi-captive-portals                                    


    Tags

    MalwareThreat ActorPhishingBlizzardCredential HarvestingRussiaAPTMicrosoftUnited StatesIndiaSaudi ArabiaAndroid MalwareCornflakeAI

    « Previous Article

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags