CaptiveCrunch Malware Campaign Targets Travelers
Summary
Microsoft has disclosed CaptiveCrunch, an active campaign linked to Midnight Blizzard that hijacks traffic on hospitality and captive portal networks to steal credentials and deliver malware. The threat is especially relevant for organizations with frequent travelers because attackers are abusing Entra ID device code flows, fake update prompts, and adversary-in-the-middle phishing to compromise corporate accounts and endpoints.
Introduction
Microsoft Threat Intelligence has warned of a new campaign called CaptiveCrunch that targets travelers using hotel, conference, and other captive portal-based Wi-Fi networks. For IT and security teams, this matters because the activity combines network traffic manipulation, Microsoft Entra ID phishing, and malware delivery to compromise both user accounts and devices.
What’s new
Microsoft attributes CaptiveCrunch to Storm-2945, a sub-cluster of Midnight Blizzard, the Russia-linked threat actor also known as SVR.
Key findings include:
- Attackers are manipulating DNS and HTTP traffic on hospitality-related networks served by captive portals.
- Victims are redirected to actor-controlled infrastructure for adversary-in-the-middle phishing.
- The campaign abuses device code and OAuth authentication flows in Microsoft Entra ID to capture credentials and gain access to Microsoft 365 data.
- Threat actors are also delivering malware disguised as browser or operating system updates.
- Microsoft observed AI-assisted operations supporting parts of the campaign.
- In addition to Windows payloads, there are signs attackers may also be attempting to target Android devices with malicious APK downloads.
Malware details
A key malware family in this campaign is CornFlake, a Windows RAT written in Go.
According to Microsoft, CornFlake can:
- Enumerate systems
- Steal files, credentials, and session tokens
- Log keystrokes
- Enable audio and video surveillance
- Monitor removable media
- Provide remote shell access
The malware uses fake update or installer screens to distract users while it installs persistence mechanisms, including services, scheduled tasks, and registry keys.
Impact on IT administrators
This is a high-priority risk for organizations with executives, consultants, sales teams, and other frequent travelers. Even if your tenant is well secured, users connecting through compromised captive portals may be exposed to phishing and malware before they realize anything is wrong.
The campaign also reinforces the need to monitor Entra device registration, OAuth abuse, suspicious sign-ins, and anomalous Microsoft 365 access patterns.
Recommended next steps
IT and security teams should:
- Remind users to avoid installing updates or apps prompted by public Wi-Fi portals
- Enforce phishing-resistant MFA where possible
- Review controls around device code flow and OAuth consent
- Monitor Entra ID sign-in logs for suspicious device registrations and token abuse
- Use Microsoft Defender detections and hunting guidance from Microsoft’s advisory
- Strengthen endpoint protection for traveling users, especially on unmanaged or high-risk networks
Organizations with a mobile workforce should treat CaptiveCrunch as an active travel-related threat and update user guidance and detection rules accordingly.
Need help with Security?
Our experts can help you implement and optimize your Microsoft solutions.
Talk to an ExpertStay updated on Microsoft technologies