Microsoft has linked a global campaign against hospitality Wi-Fi networks to Midnight Blizzard, a Russian threat actor also known as APT29.

The hotel Wi-Fi attacks target Microsoft 365 accounts through manipulated DNS settings, phishing pages, device code abuse, and custom malware. Microsoft calls the campaign CaptiveCrunch.

The activity has been active since at least early May. However, Microsoft believes the attackers have run device code and OAuth phishing operations since February.

Attackers alter hotel Wi-Fi DNS settings

Cybersecurity company ReliaQuest previously reported on the campaign. Its researchers found that attackers changed DNS settings on Wi-Fi equipment to steal Microsoft 365 accounts.

Microsoft attributed the activity to Storm-2945, a Midnight Blizzard sub-cluster. The company could not confirm the exact initial access method.

However, investigators found signs that attackers compromised shared infrastructure rather than individual network devices.

The attackers manipulate DNS and HTTP traffic on networks that use captive portal equipment. This allows them to intercept connections to hotel and conference centre Wi-Fi networks.

After changing the DNS configuration, the group can redirect users to fake Microsoft 365 sign-in pages. It can also send victims to device code phishing pages that abuse Microsoft Entra ID authentication flows.

Microsoft observed this phishing activity from July.

Fake updates deliver CornFlake malware

CaptiveCrunch also uses fake browser and operating system update pages. These pages use ClickFix prompts that try to persuade users to complete a supposed verification step.

Instead, the prompts deliver malware to Windows devices. Microsoft also found evidence that some ClickFix pages target Android users with malicious APK files.

One of the malware families, CornFlake, is a Go-based remote access trojan. It can provide attackers with remote shell access and collect a wide range of information from infected systems.

Its capabilities include:

  • Keylogging and clipboard monitoring
  • Screenshot, microphone, and webcam surveillance
  • Browser credential and cookie theft
  • Microsoft 365 session token theft
  • File exfiltration and USB monitoring
  • System reconnaissance

CornFlake displays a fake progress window when it runs. The malware copies itself to the AppData folder to establish persistence while distracting the victim.

Attackers can configure the fake window to resemble a Windows update, Defender scan, disk optimisation tool, network diagnostic, browser update, or document viewer installer.

The malware uses the name Cloud Sync Service to look like a legitimate Windows component. It can maintain access through Windows services, Registry Run keys, scheduled tasks, and a watchdog routine that restores its persistence methods.

ChocoShell steals credentials in memory

Microsoft also identified ChocoShell, an in-memory PowerShell credential stealer.

ChocoShell targets browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials. Microsoft noted extensive comments in the code of both malware families and assessed that AI tools likely assisted their development.

Researchers also discovered an exposed web management panel called FruitStone. The threat actor used it to manage infected devices, browse victim files, run PowerShell commands, and capture screenshots and keystrokes.

Hotel Wi-Fi attacks can put corporate credentials at risk because travellers often connect from unfamiliar networks. Microsoft recommends treating hotel and conference Wi-Fi as untrusted.

Where possible, travellers should use private cellular or managed connections. They should also avoid installing updates or tools offered through captive portals.

Organisations should use phishing-resistant MFA and passkeys, disable Microsoft Entra device code authentication when it is not needed, and avoid using corporate credentials to register for guest Wi-Fi.


0 responses to “Hotel Wi-Fi Attacks Target Microsoft 365 Accounts”