Skip to content
archiveAPT / state · 31 Jul 2026 · 21:01 UTC

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

last 60 dispatches · spectrum

Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch.

grounded ✓primary source ↗

loading threat intel…

Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected