CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials
IntroductionOn July 31, Microsoft Threat Intelligence reported an ongoing credential theft campaign tracked as CaptiveCrunch. Microsoft attributes this activity to Storm-2945, a sub-cluster of Midnight Blizzard (also known as APT29, Cozy Bear, NOBELIUM, and BlueBravo), a threat group linked to Russia. The campaign manipulates DNS and HTTP traffic on captive portal networks at hospitality venues, redirecting victims to attacker-controlled infrastructure for Microsoft 365 credential harvesting, device code phishing, and malware delivery.Evidence suggests that Storm-2945 compromised shared captiv
● loading threat intel…