Microsoft links AI-augmented CaptiveCrunch campaign to compromised hospitality Wi-Fi

The operation uses captive portals to deliver credential phishing and malware to travelers, while its route into affected networks remains under investigation.

A blue-toned cybersecurity image showing people and buildings connected by network lines and digital padlocks. It represents the credential and device risks associated with compromised shared Wi-Fi networks.

Travelers connecting to hospitality and shared Wi-Fi networks in several countries have been redirected through attacker-controlled infrastructure in an ongoing operation that Microsoft Threat Intelligence says has used AI to support a significant share of its activity.

Microsoft attributes the CaptiveCrunch campaign to Storm-2945, which it assesses is an operational sub-cluster of Midnight Blizzard. The attacks can expose users to device code phishing or malware capable of stealing credentials, files and Microsoft 365 authentication tokens.

Since early May 2026, Microsoft has observed Storm-2945 manipulating DNS and HTTP traffic from networks served by captive portals. ReliaQuest has identified activity at hotels, conference centers and other shared venues, assessing that corporate travelers’ accounts are the intended targets.

The initial route used to compromise the captive portal networks has not been established. However, Microsoft found common equipment and management systems across multiple affected networks. It says this could indicate access to shared services within parts of the captive portal ecosystem rather than a series of unrelated venue compromises.

No number of compromised networks, affected users or list of countries was disclosed.

Fake updates deliver surveillance and credential-stealing malware

Some users are redirected to fake Microsoft services, browser updates or operating system repair tools. ClickFix techniques then attempt to persuade them to download malware or manually run commands through Windows Terminal.

One of the principal tools identified by Microsoft is CornFlake, a Windows remote access trojan written in Go. Its functions include collecting files and keystrokes, stealing credentials and session tokens, capturing screenshots, monitoring removable media and providing remote access to an infected computer.

The malware can also activate microphones and webcams. It establishes several persistence mechanisms and displays fake Windows Update, security scan or software installation windows while installing itself.

A second tool, ChocoShell, operates in memory through PowerShell. Microsoft says it is designed to collect browser cookies, saved passwords, Microsoft 365 single sign-on tokens and Wi-Fi credentials. These stolen tokens could allow an attacker to reuse an authenticated session.

Microsoft found detailed developer comments within the ChocoShell code, including references to detection signatures and explanations of evasion decisions. The company says the consistency and level of commentary suggest that AI-assisted code generation may have been used, although this has not been confirmed.

The investigation has also found indications of possible Android targeting. Some landing pages include instructions to download and install an APK file, but Microsoft does not confirm that Android malware was successfully deployed.

AI use extends beyond possible malware development

Storm-2945 has conducted AI-augmented operations since February 2026, according to Microsoft. These include device code and OAuth code phishing campaigns that can result in Microsoft Entra device registration and subsequent collection of Microsoft 365 data.

Microsoft says AI has supported a significant portion of the group’s operations, but its disclosure does not identify the systems used or specify which tasks were automated. Anthropic and OpenAI collaborated with Microsoft during the investigation, although the nature of their support was not detailed.

Since July 16, some CaptiveCrunch landing pages have directed users into device code authentication processes. Device code authentication is a legitimate OAuth workflow for devices that cannot support a conventional sign-in. Attackers can abuse it by persuading a user to enter an attacker-controlled code into a genuine Microsoft sign-in page, causing the user to authenticate the attacker’s session.

Microsoft notes that the technique itself is not fundamentally new. Its integration with captive portal traffic manipulation could, however, make the authentication request appear more credible to someone attempting to connect to a venue’s network.

The company attributes Midnight Blizzard to Russia. The US and UK governments have linked the group to the Foreign Intelligence Service of the Russian Federation, also known as the SVR.

Microsoft advises organizations to limit trust in guest networks

Microsoft recommends treating hotel, conference, airport and other guest wireless networks as untrusted. Its guidance favors private connections such as mobile hotspots, cellular data services and organization-managed travel routers when practical.

Organizations can also prevent managed devices from joining Wi-Fi networks that have not been provisioned through mobile device management. Microsoft advises users not to download updates, certificates or security utilities presented through captive portals or unexpected web prompts.

For identity protection, the company recommends passkeys, multifactor authentication, conditional access policies and sign-in risk monitoring. It advises organizations to block Microsoft Entra ID’s device code flow wherever it is not required.

Employees should not reuse corporate credentials when registering for hotel, conference or guest networks. Microsoft also recommends limiting the disclosure of identities, organizational affiliations and travel details during accommodation bookings and guest-network registration.

Previous
Previous

University of Greater Manchester embeds student-designed AI literacy framework in training

Next
Next

Google.org joins $50 million coalition to combat AI-enabled scams