Microsoft has disclosed a large cyber-espionage campaign orchestrated by Storm-2945, a sub-group of the Russian threat actor, tracked as Midnight Blizzard (APT29/Cozy Bear), that has been active since early May 2026.
The campaign, named CaptiveCrunch, targets hospitality networks that use captive portals, such as hotel Wi-Fi systems. According to Microsoft, the attackers manipulate DNS and HTTP traffic to redirect victims through attacker-controlled infrastructure. Microsoft says the operation is broader than the one described in a previous report from ReliaQuest.
Although the operation shares some techniques with the Forest Blizzard (APT28/Fancy Bear) DNS hijacking campaign disclosed earlier this year, Microsoft says CaptiveCrunch is a separate operation carried out by Midnight Blizzard, a cyber unit linked to Russia's Foreign Intelligence Service (SVR). It is also unrelated to an April FrostArmada campaign that targeted MikroTik and TP-Link routers.
In the CaptiveCrunch campaign, victims are redirected either to fake Microsoft login pages that steal Microsoft Entra device codes and OAuth codes, or to ClickFix pages that trick users into downloading malware. The phishing attacks abuse the Microsoft Entra ID device code authentication flow to bypass multi-factor authentication (MFA) and gain access to Microsoft 365 accounts and data.
Microsoft also identified two previously unknown malware families - CornFlake RAT and the CocoShel PowerShell-based infostealer. Both communicate with a command-and-control platform called FruitStone.
The company said Storm-2945 has used AI to support a significant portion of its operations, including device code and OAuth phishing campaigns that were used for Microsoft Entra device registration and data theft from Microsoft 365 environments.
Microsoft believes the attackers may have compromised shared services within the captive portal ecosystem rather than isolated hotel networks, suggesting the campaign is larger and more coordinated than initially reported.