Microsoft Threat Intelligence reported the campaign, named CaptiveCrunch, on July 31, attributing it to a group tracked as Storm-2945. The company said the campaign has been operating since early May, with the goal of stealing login credentials from corporate and government business travelers, Kyiv Post reported.
***
The group is reportedly an operational sub-cluster of Midnight Blizzard – a threat actor the US and UK governments have linked to Russia’s Foreign Intelligence Service (SVR).
“Midnight Blizzard is consistent and persistent in their operational targeting, and their objectives rarely change,” Microsoft reported, adding that “their focus is to collect intelligence through longstanding and dedicated espionage in support of Russian foreign policy interests.”
The hackers reportedly exploited the equipment and management systems behind hotel Wi-Fi registration pages, known as captive portals.
They then manipulated the domain name system (DNS) and hypertext transfer protocol (HTTP) traffic to redirect guests through infrastructure under their control.
According to Microsoft, this technique shares some similarities with a separate DNS hijacking operation reported in April.
Once redirected, victims received fake update prompts disguised as routine browser or operating system checks. When clicked, these prompts delivered malware, including a Windows remote access trojan called CornFlake, capable of logging keystrokes, stealing credentials and session tokens, as well as conducting audio and video surveillance on infected devices.
Microsoft said the investigation into how the captive portal networks were initially breached is ongoing.
However, the company noted that shared equipment and management systems across multiple affected venues suggest the intrusions may stem from a common point of access, rather than isolated compromises.
04
Aug


