Russian Hackers Target Hotel Wi-Fi to Steal Microsoft 365 Credentials
Microsoft links a global campaign targeting hotel and conference center Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. The campaign, dubbed CaptiveCrunch, has been active since at least early May 2026 and manipulates DNS settings on captive portal equipment to intercept user connections and redirect victims to convincing Microsoft 365 phishing pages.
The attackers employ multiple infection methods, including fake browser and operating system update pages that deliver malware through deceptive ClickFix verification prompts. Microsoft also identifies two custom Windows malware families called CornFlake and ChocoShell, which provide persistent access, credential theft, surveillance, and data exfiltration capabilities. CornFlake, a Go-based remote access trojan, enables keylogging, screen capturing, webcam and microphone monitoring, browser credential theft, and Microsoft 365 session token theft.
While the exact method of initial compromise remains unclear, Microsoft notes signs of breaches in shared network infrastructure rather than isolated devices. The threat actor has been running device and OAuth code phishing operations since February, and evidence suggests the campaign also targets Android devices through malicious APK files. Organizations are advised to educate travelers about the risks of connecting to untrusted hospitality networks and to implement strong authentication measures.