
Microsoft Says Midnight Blizzard Is Targeting Travelers Through Compromised Hospitality Wi-Fi
Microsoft says Midnight Blizzard-linked attackers are abusing compromised hospitality Wi-Fi to steal credentials and deliver malware.
Microsoft Threat Intelligence has warned that a Midnight Blizzard sub-cluster is using compromised hospitality and guest-network infrastructure to target travelers with credential theft and malware. The campaign, which Microsoft calls CaptiveCrunch, was disclosed on July 31 and is tied to Storm-2945, an operational group Microsoft assesses is part of the Russia-linked Midnight Blizzard activity set.
The report says Microsoft has observed the activity since early May 2026 on networks served by captive portals, the login and registration pages commonly used by hotels, conference centers, airports, and other guest Wi-Fi providers. Rather than relying only on phishing emails or fake collaboration messages, the attackers allegedly manipulate DNS and HTTP traffic from affected networks so that users can be redirected through actor-controlled infrastructure during ordinary browsing or connectivity checks.
Why the campaign matters
Captive portals sit at a sensitive point in the travel workflow: users expect network interruptions, login prompts, verification screens, and browser warnings. Microsoft says Storm-2945 has used that trust gap to send some users toward adversary-in-the-middle phishing pages and, in other cases, to present fake browser or operating-system update prompts. The company says the Windows malware delivered in the campaign includes Go-based remote access trojans with capabilities for enumeration, persistence, credential and token theft, file collection, keylogging, screenshots, microphone capture, webcam capture, USB monitoring, and remote shell access.
Microsoft also reports that some landing pages observed since July 16 incorporated device-code phishing, a technique that abuses a legitimate OAuth flow. In that scenario, the victim enters a code at a real Microsoft sign-in page but unknowingly authorizes the attacker’s session. The company says this is consistent with earlier Midnight Blizzard device-code operations, but the combination with captive-portal traffic manipulation could make the request look more credible to a traveler already trying to get online.
Defensive guidance
Microsoft recommends treating hospitality and other guest wireless networks as untrusted, especially for enterprise-managed devices. Practical defenses include using cellular data or managed hotspots where possible, avoiding software updates or certificates offered through captive-portal pages, blocking or tightly limiting device-code authentication flows, applying phishing-resistant multifactor authentication, and using conditional access policies to respond to risky sign-ins.
The disclosure is notable because it shifts attention from individual hotel phishing lures to the network access layer travelers depend on. Microsoft says its investigation into the initial compromise path for captive-portal networks is continuing, but commonalities in equipment and management systems suggest the activity may involve shared services within parts of the captive-portal ecosystem rather than isolated venue-by-venue intrusions.
Sources
Cover photo by Dan Nelson on Pexels, used under the Pexels License.
CyberOGZ Team






Comments (0)
Leave a Comment