Microsoft Threat Intelligence disclosed the CaptiveCrunch operation on July 31, 2026: a campaign by Storm-2945, an operational subgroup of Midnight Blizzard (APT29/SVR), that transforms hospitality captive portal networks worldwide into platforms for malware delivery and Microsoft Entra ID credential theft. These are not isolated, one-off compromises. According to Microsoft, "notable commonalities in the equipment and management systems used across multiple affected networks" indicate potentially systemic access to shared captive portal ecosystem services.
- Microsoft attributes the CaptiveCrunch campaign to Storm-2945, an operational subgroup of Midnight Blizzard (APT29/SVR), active since early May 2026.
- The primary malware, CornFlake, is a Go-based Windows RAT featuring ECDH P-256 encryption, keylogging, audio/video surveillance, and a watchdog persistence mechanism that restores removed persistence artifacts.
- Storm-2945 exploits adversary-in-the-middle positions on captive portal networks to manipulate DNS and HTTP, respond to automatic browser connectivity checks, and redirect victims to device code phishing pages.
- Microsoft observed the group using AI to support "a significant portion" of CaptiveCrunch operations, including generating evasive code with comments referencing specific Microsoft detection signatures.
How the Attack Works: From Captive Portal to RAT
The operation unfolds in three layers. First, compromise of the captive portal network infrastructure, which allows Storm-2945 to intercept and manipulate DNS and HTTP traffic from connected clients. Second, use of that adversary-in-the-middle position to redirect users to phishing infrastructure or to respond directly to automatic browser connectivity checks — the attempt to reach a known Microsoft domain that confirms "the connection works" — with a malicious payload instead of the legitimate response.
Third, delivery of the CornFlake malware, a Go-compiled Windows RAT that serves as the campaign's primary persistent implant. CornFlake installs to %APPDATA%\svchost32\svchost32.exe and registers a Windows service named "Cloud Sync Service." Persistence is reinforced by a watchdog that monitors and restores persistence mechanisms if they are removed. The runtime configuration file sync.dat supports hot reconfiguration of C2, working directories, file patterns, and TLS parameters.
Command-and-control communication traverses an encrypted channel employing ECDH P-256 for ephemeral key exchange and SHA-256 for session key derivation. Each C2 session uses a unique ephemeral key: intercepted traffic without the specific private key is, per Microsoft's documentation, impossible to decrypt.
CornFlake: Technical Capabilities of the Malware
The RAT's technical specifications, detailed in Microsoft's analysis, describe a multi-function tool built for active espionage. CornFlake supports: keylogging, clipboard monitoring, screenshot capture, audio surveillance via WASAPI with WAV output, video surveillance via Media Foundation with JPEG frames, file exfiltration, remote shell, and monitoring of removable storage devices.
A distinctive feature is false window management: at build time, the operator can configure the malware to masquerade as Windows Update (winupdate), Microsoft Defender (defender), DirectX (directx), Visual C++ Redistributable (vcredist), or Netflix (netfix). This flexibility points to modular design intended to adapt to the victim's context.
The command-and-control infrastructure runs on FruitStone, a web panel branded as a fictitious enterprise cloud product. The choice of a C2 interface with commercial cosmetics aligns with Storm-2945's practice of disguising malicious activity as legitimate services.
Device Code Phishing and MFA Bypass
Starting July 16, 2026, some captive portal pages began redirecting users to Microsoft Entra ID device code authentication flows. The technique itself is not new — as Microsoft noted, "the technique was not new but embedding it in a captive portal made the request more likely to seem legitimate" — but the context makes it uniquely effective: the user, accustomed to entering codes to access Wi-Fi, does not perceive the anomaly of entering an attacker-supplied code on a genuine Microsoft page.
The device code authentication flow is designed for input-constrained devices: the user enters a code on a separate device to authorize access. Storm-2945 inverts the logic: it supplies the code to the victim, who enters it and thereby authenticates a session controlled by the attacker. The result is account access without password theft and, critically, bypass of multi-factor authentication: the token obtained is legitimate, not stolen.
In parallel, ReliaQuest identified doppelganger domains mimicking Microsoft online services, with a report dated July 23, 2026. The activity extends beyond hotels: conference centers and other shared venues fall within the targeting perimeter, with the explicit objective of compromising business travelers' accounts.
AI as an Offensive Force Multiplier
An aspect marking the campaign's escalation is the systemic integration of AI into operations. Microsoft observed Storm-2945 using AI to support "a significant portion" of CaptiveCrunch operations. More specifically, comments in CornFlake's code cite "specific Microsoft detection signatures and explained each evasion choice," which Microsoft interprets as AI-assisted generation.
The use of AI for evasive malware customization lowers the per-target operational cost of variants: instead of manually developing evasion techniques, the operator can generate, test, and iterate code that responds to specific defensive controls. The effect is an arms race in which the latency between detection and evasion compresses.
Microsoft thanked Anthropic and OpenAI for their collaboration in the investigation. The dossier does not specify the exact role of the two companies, which are not identified as victims or accomplices of the attack.
Recommended Actions
- Microsoft recommends assuming that public and hospitality network infrastructure is untrustworthy and adopting controls that limit exposure to traffic manipulation, credential theft, and device code phishing.
- Organizations should evaluate policies that restrict the use of public Wi-Fi for sensitive business operations, favoring cellular connections or trusted VPNs.
- Security teams should review Conditional Access configurations to detect sessions from anomalous geographic locations or networks, with particular attention to unsolicited device code flows.
- Defenders should monitor for the "Cloud Sync Service" and the path %APPDATA%\svchost32\svchost32.exe as known indicators of compromise.
"Organizations should assume that public and hospitality network infrastructure might not be trustworthy and should adopt controls that limit exposure to traffic manipulation, credential theft, and device code phishing" — Microsoft Security Blog
Why This Matters
CaptiveCrunch redefines the risk perimeter for organizations with a mobile workforce. Hotel and conference center Wi-Fi, traditionally considered "secure enough" for light email or web browsing, is now documented as a vector for nation-state APT compromise with persistent malware and cloud credential theft. Individual awareness is insufficient: device code phishing exploits legitimate user behaviors in a context that appears normal.
The most significant escalation for defenders is the use of AI for evasive generation. If confirmed as a trend, it marks a turning point in the offensive-defensive dynamic: malware customization shifts from a specialist capability to an operational commodity. Defenses must adapt to an adversary that can iterate variants faster than signature update cycles.
Frequently Asked Questions
- What exactly is a captive portal?
- A web page that blocks Internet access until the user takes an action, typically authentication or acceptance of terms of service. It is the standard Wi-Fi access method in hotels, airports, and public spaces. Microsoft has documented how this interface was weaponized for the attack.
- Does device code phishing steal my password?
- No. The technique obtains a legitimate authentication token by having the user enter a code already generated by the attacker. The password is not intercepted; the bypass occurs at the authentication flow level, not through traditional credential theft.
- Does the attack only affect Windows?
- The CornFlake RAT is Windows-specific. However, Microsoft observed indications of Android targeting via APKs in ClickFix instructions, though the dossier does not document technical details of this component.
Sources
- https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/
- https://www.infosecurity-magazine.com/news/captivecrunch-midnight-blizzard/
- https://thecyberexpress.com/captivecrunch-midnight-blizzard/
- https://thewindowsupdate.com/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft-2/
- https://southfloridareporter.com/is-hotel-wi-fi-trapping-you-what-microsofts-new-alert-means-for-your-privacy/
- https://thenationaldesk.com/news/americas-news-now/microsoft-warns-windows-pc-users-of-russian-hackers-on-hotel-wifi-anthropic-openai-threat-intelligence-android
- https://tech.yahoo.com/cybersecurity/articles/microsoft-issues-hotel-wi-fi-125650555.html
- https://southfloridareporter.com/who-we-are/
- https://southfloridareporter.com/?page_id=21342
- https://southfloridareporter.com/td_d_slug_15/
Information verified against cited sources and current as of publication.