Date: 08/14/2026
Severity: High
Summary
On July 31, Threat Intelligence reported an ongoing credential theft campaign tracked as CaptiveCrunch, attributed to Storm-2945, a sub-group of Russia-linked Midnight Blizzard (APT29). The campaign abuses captive portal networks at hotels, conference centers, and similar venues to redirect victims to attacker-controlled infrastructure. Attackers use these redirects to harvest Microsoft 365 credentials, conduct device-code phishing, and deliver malware. Evidence indicates that Storm-2945 compromised shared captive portal services instead of targeting individual venues directly, with compromised gateways identified in the U.S., India, and Saudi Arabia. Microsoft also found evidence that the group used AI tools to assist operations, including the development of the CornFlake and ChocoShell malware. The campaign has expanded to Android devices through malicious APK files, while its initial access method remains under investigation.
Indicators of Compromise (IOC) List
Domains/URLs | ms365-device.com ms365-live.com m365-owa.com owa-ms365.com 213.145.86.112/t/pixel.gif 213.145.86.112/cdn/chunks/polyfill-7e2b.min.js 213.145.86.112/t/event |
IP Address | 31.57.243.154 38.146.28.75 38.146.28.132 104.194.159.150 107.189.26.194 213.145.86.112 |
Hash | 918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593
be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "m365-owa.com" or url like "m365-owa.com" or siteurl like "m365-owa.com" or domainname like "ms365-device.com" or url like "ms365-device.com" or siteurl like "ms365-device.com" or domainname like "ms365-live.com" or url like "ms365-live.com" or siteurl like "ms365-live.com" or domainname like "owa-ms365.com" or url like "owa-ms365.com" or siteurl like "owa-ms365.com" or domainname like "213.145.86.112/t/pixel.gif" or url like "213.145.86.112/t/pixel.gif" or siteurl like "213.145.86.112/t/pixel.gif" or domainname like "213.145.86.112/cdn/chunks/polyfill-7e2b.min.js" or url like "213.145.86.112/cdn/chunks/polyfill-7e2b.min.js" or siteurl like "213.145.86.112/cdn/chunks/polyfill-7e2b.min.js" or domainname like "213.145.86.112/t/event" or url like "213.145.86.112/t/event" or siteurl like "213.145.86.112/t/event" |
Detection Query 2 : | dstipaddress IN ("213.145.86.112","31.57.243.154","38.146.28.132","38.146.28.75","104.194.159.150","107.189.26.194") or srcipaddress IN ("213.145.86.112","31.57.243.154","38.146.28.132","38.146.28.75","104.194.159.150","107.189.26.194") |
Detection Query 3 : | sha256hash IN ("918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593","be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c")
|
Reference:
https://www.zscaler.com/blogs/security-research/captivecrunch-midnight-blizzard-weaponizes-hotel-wi-fi-captive-portals