Microsoft reports that the Russia-linked threat actor tracked as “Midnight Blizzard” uses abused public Wi‑Fi captive portals—often at hotels and conference centers—to compromise travelers and steal access credentials. Microsoft calls the campaign “CaptiveCrunch.” The attack flow redirects users from legitimate Wi‑Fi login pages to phishing prompts or fake software update pages, which Microsoft says are designed to capture Microsoft 365-related information and other session data.

Microsoft’s analysis identifies two main malware components. The first, “CornFlake,” is described as a Windows remote access trojan (RAT) capable of functions such as keylogging and capturing screenshots, webcam images, audio, and credentials and session tokens. The second, “ChocoShell,” is described as an in-memory PowerShell infostealer that targets browser cookies, saved passwords, Microsoft 365 single sign-on (SSO) tokens, and Wi‑Fi credentials.

Microsoft links the activity to its internal tracking under an earlier codename (NOBELIUM) and notes compromises have occurred in “several countries,” though it does not provide specific venue or victim counts. A related earlier investigation by ReliaQuest, cited by Microsoft, found compromised captive portal gateways across multiple US locations and also in India and Saudi Arabia, with targeting focused on traveling employees across various industries rather than a single sector.