Microsoft Links 2 New Malware Strains to Russian Wi-Fi Attacks on Microsoft 365 Users
Updated
Updated · BleepingComputer · Aug 4
Microsoft Links 2 New Malware Strains to Russian Wi-Fi Attacks on Microsoft 365 Users
3 articles · Updated · BleepingComputer · Aug 4
Summary
Microsoft said the CaptiveCrunch campaign has targeted hospitality Wi-Fi worldwide since at least May, tying it to Russian state-linked Storm-2945, a Midnight Blizzard sub-cluster.
DNS and HTTP tampering on hotel and conference captive portals lets attackers redirect users to fake Microsoft 365 logins, device-code phishing pages, or bogus update screens that deliver malware.
CornFlake and ChocoShell give the operators persistent access and broad theft capabilities, including browser credentials, Microsoft 365 and Azure AD tokens, Wi-Fi passwords, screenshots, keystrokes, and file exfiltration.
Microsoft also found signs of Android APK delivery, an exposed FruitStone control panel for managing infected systems, and code comments suggesting AI tools likely helped build the malware.
The company urged travelers and security teams to treat hospitality Wi-Fi as untrusted, prefer cellular or managed connections, and use phishing-resistant MFA or passkeys while disabling unused Entra device-code authentication.