Updated
Updated · BleepingComputer · Aug 4
Microsoft Links 2 New Malware Strains to Russian Wi-Fi Attacks on Microsoft 365 Users
Updated
Updated · BleepingComputer · Aug 4

Microsoft Links 2 New Malware Strains to Russian Wi-Fi Attacks on Microsoft 365 Users

3 articles · Updated · BleepingComputer · Aug 4

Summary

  • Microsoft said the CaptiveCrunch campaign has targeted hospitality Wi-Fi worldwide since at least May, tying it to Russian state-linked Storm-2945, a Midnight Blizzard sub-cluster.
  • DNS and HTTP tampering on hotel and conference captive portals lets attackers redirect users to fake Microsoft 365 logins, device-code phishing pages, or bogus update screens that deliver malware.
  • CornFlake and ChocoShell give the operators persistent access and broad theft capabilities, including browser credentials, Microsoft 365 and Azure AD tokens, Wi-Fi passwords, screenshots, keystrokes, and file exfiltration.
  • Microsoft also found signs of Android APK delivery, an exposed FruitStone control panel for managing infected systems, and code comments suggesting AI tools likely helped build the malware.
  • The company urged travelers and security teams to treat hospitality Wi-Fi as untrusted, prefer cellular or managed connections, and use phishing-resistant MFA or passkeys while disabling unused Entra device-code authentication.

Insights

How are hackers turning legitimate Microsoft authentication codes into master keys that keep your accounts unlocked even after a password change?
Why is your hotel Wi-Fi secretly bypassing multifactor authentication, and what makes this invisible network threat so difficult to detect?
If changing your DNS settings cannot protect you from rogue hotel networks, what is the only true way to secure your data abroad?