Microsoft Says Storm-2945 Hijacked Captive Portals in Several Countries, Using AI to Steal Traveler Credentials
Updated
Updated · Microsoft · Jul 31
Microsoft Says Storm-2945 Hijacked Captive Portals in Several Countries, Using AI to Steal Traveler Credentials
3 articles · Updated · Microsoft · Jul 31
Summary
Since early May, Microsoft has tracked Storm-2945 redirecting traffic on captive-portal networks worldwide to phishing pages and fake update prompts that install malware on travelers’ devices.
The Russia-linked group used AI across much of the campaign, pairing adversary-in-the-middle phishing with device-code abuse in Microsoft Entra ID to capture Microsoft 365 data and corporate account access.
Microsoft said the operation hit hospitality and other shared venues in several countries, with signs the attackers may have accessed shared captive-portal services rather than only isolated hotel networks.
The malware includes CornFlake, a Go-based Windows RAT, and ChocoShell, a PowerShell infostealer that steals cookies, passwords, Microsoft 365 tokens and Wi-Fi credentials; Android APK lures were also observed.
Microsoft assesses Storm-2945 as a sub-cluster of Midnight Blizzard, the SVR-linked espionage actor, and urged travelers to avoid public Wi-Fi downloads while organizations restrict device-code flow and harden MFA.
Could the standard security update prompt on your airport Wi-Fi actually be an AI-powered espionage weapon?
Why is a notorious espionage group suddenly targeting everyday business travelers instead of high-level government officials?
2026 CaptiveCrunch Wi-Fi Attacks: How Russian State Hackers and AI Threaten Corporate Travelers and Hospitality Networks
Overview
In 2026, the CaptiveCrunch campaign exposed how state-sponsored hackers, linked to Russia’s SVR, hijacked hotel Wi-Fi networks worldwide. Attackers exploited weak admin credentials to seize control of captive portal gateways, forged DNS responses, and redirected guests to fake update pages. Victims were tricked into running the CornFlake RAT, which stole sensitive data by bypassing browser protections. Later, attackers abused Microsoft’s device code authentication to bypass MFA and access corporate accounts. The campaign also used AI to automate phishing and malware development, making attacks faster and harder to detect. Traditional VPNs proved inadequate, as a single stolen credential could compromise entire networks, highlighting the urgent need for zero trust security and better defenses in the hospitality industry.