Security

CaptiveCrunch Malware Campaign Targets Travelers

3 min read

Summary

Microsoft has disclosed CaptiveCrunch, an active campaign linked to Midnight Blizzard that hijacks traffic on hospitality and captive portal networks to steal credentials and deliver malware. The threat is especially relevant for organizations with frequent travelers because attackers are abusing Entra ID device code flows, fake update prompts, and adversary-in-the-middle phishing to compromise corporate accounts and endpoints.

Need help with Security?Talk to an Expert

Introduction

Microsoft Threat Intelligence has warned of a new campaign called CaptiveCrunch that targets travelers using hotel, conference, and other captive portal-based Wi-Fi networks. For IT and security teams, this matters because the activity combines network traffic manipulation, Microsoft Entra ID phishing, and malware delivery to compromise both user accounts and devices.

What’s new

Microsoft attributes CaptiveCrunch to Storm-2945, a sub-cluster of Midnight Blizzard, the Russia-linked threat actor also known as SVR.

Key findings include:

  • Attackers are manipulating DNS and HTTP traffic on hospitality-related networks served by captive portals.
  • Victims are redirected to actor-controlled infrastructure for adversary-in-the-middle phishing.
  • The campaign abuses device code and OAuth authentication flows in Microsoft Entra ID to capture credentials and gain access to Microsoft 365 data.
  • Threat actors are also delivering malware disguised as browser or operating system updates.
  • Microsoft observed AI-assisted operations supporting parts of the campaign.
  • In addition to Windows payloads, there are signs attackers may also be attempting to target Android devices with malicious APK downloads.

Malware details

A key malware family in this campaign is CornFlake, a Windows RAT written in Go.

According to Microsoft, CornFlake can:

  • Enumerate systems
  • Steal files, credentials, and session tokens
  • Log keystrokes
  • Enable audio and video surveillance
  • Monitor removable media
  • Provide remote shell access

The malware uses fake update or installer screens to distract users while it installs persistence mechanisms, including services, scheduled tasks, and registry keys.

Impact on IT administrators

This is a high-priority risk for organizations with executives, consultants, sales teams, and other frequent travelers. Even if your tenant is well secured, users connecting through compromised captive portals may be exposed to phishing and malware before they realize anything is wrong.

The campaign also reinforces the need to monitor Entra device registration, OAuth abuse, suspicious sign-ins, and anomalous Microsoft 365 access patterns.

IT and security teams should:

  • Remind users to avoid installing updates or apps prompted by public Wi-Fi portals
  • Enforce phishing-resistant MFA where possible
  • Review controls around device code flow and OAuth consent
  • Monitor Entra ID sign-in logs for suspicious device registrations and token abuse
  • Use Microsoft Defender detections and hunting guidance from Microsoft’s advisory
  • Strengthen endpoint protection for traveling users, especially on unmanaged or high-risk networks

Organizations with a mobile workforce should treat CaptiveCrunch as an active travel-related threat and update user guidance and detection rules accordingly.

Need help with Security?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

SecurityMidnight BlizzardEntra IDphishingmalware

Related Posts

Security

Microsoft Security July 2026: AI Defense Updates

Microsoft’s July 2026 security updates focus on protecting AI environments, embedding AI into security operations, and strengthening identity, cloud, and data protection foundations. Key additions include Project Perception, new Defender protections for prompt injection and cloud agents, Entra passkeys by default, and expanded Purview controls for Copilot and shadow AI apps.

Security

Microsoft Security: Better Questions for AI Risk

Microsoft is urging security leaders to treat AI security as a systems challenge that requires better questions, clearer objectives, and stronger governance across data, identities, and processes. The message matters for IT and security teams adopting AI because success depends not just on more signals or tools, but on layered controls, human oversight, and decision-making designed for resilience.

Security

Project Perception: Microsoft AI Security Preview

Microsoft has introduced Project Perception, a new agentic security system designed to help organizations defend against AI-driven threats at machine speed. Entering public preview on August 3, it combines specialized agents, security context, and a multi-model architecture to improve vulnerability management and automate protection while keeping human defenders in control.

Security

Microsoft AI Red Teaming: Global EXTRA Alliance

Microsoft has launched the External Red Team Alliance (EXTRA), a global expansion of its AI Red Team to improve AI safety and security testing with outside experts. The initiative funds 18 university labs across six continents and builds an external network of specialists to assess emerging AI risks that internal teams alone may miss.

Security

Email Threat Landscape Q2 2026: Key Security Trends

Microsoft’s Q2 2026 email threat report shows a major 92% drop in Tycoon2FA-linked phishing following disruption efforts, alongside declines in QR code and CAPTCHA-gated phishing. However, defenders should note that attackers are shifting tactics, with Teams-based social engineering, credential phishing, and fast-moving business email compromise campaigns continuing to pose significant risk.

Security

Microsoft and AXA XL Expand Cyber Incident Response

Microsoft has partnered with AXA XL to bring Microsoft Defender Experts Cybersecurity Incident Response directly to cyber insurance policyholders. The move aims to speed up containment and recovery by aligning security, legal, executive, and insurance workflows before an incident occurs.