Microsoft has uncovered a worldwide cyberattack campaign by the Russian-linked threat group Storm-2945, which is manipulating guest Wi-Fi networks in hotels and conference centers. Active since February 2026, the operation deploys adversary-in-the-middle tactics to redirect travelers, distribute malware via fake updates, and compromise corporate credentials.
CaptiveCrunch: How the Wi-Fi Hotel Campaign Operates
Travelers logging into public wireless networks are increasingly facing sophisticated interception techniques. Tracked under the campaign name CaptiveCrunch, the operation targets public Wi-Fi infrastructure in hotels, conference centers, and other public venues worldwide, according to Microsoft as reported by the outlet. The campaign specifically compromises captive portals—the authentication pages that appear automatically when a user connects to a public network.
By injecting themselves into the traffic, operators behind the campaign manipulate the automatic checks that browsers perform immediately upon connection. Instead of the expected login screen, users see adversary-in-the-middle routing that pushes them toward phishing pages or fake software updates.
Storm-2945 Tactics, Artificial Intelligence, and Malware Deployment
The threat group orchestrating these intrusions is Storm-2945, an entity that has conducted operations since at least February 2026 and began interfering with guest wireless networks at the start of May. Researchers observed that the hackers actively utilized artificial intelligence during the preparation and execution phases of the attacks.
When users connect, malicious infrastructure prompts them to install supposed updates for their operating system, browser, or drivers. In some instances, victims are nudged to execute commands manually through Windows Terminal or PowerShell. For mobile devices running Android, the campaign utilizes tailored APK file installations, while desktop users face malicious payloads designed to establish a persistent foothold.
The primary payload deployed against Windows systems is the CornFlake trojan, written in the Golang programming language. This remote access tool grants operators extensive capabilities once inside a network. According to technical disclosures detailed in the release, the trojan can capture keystrokes, steal files, harvest passwords, cookies, and active session tokens, take screenshots, control microphones and cameras, monitor USB storage devices, and execute arbitrary commands.
Attribution to Midnight Blizzard and the Foreign Intelligence Service
Security analysts have linked Storm-2945 directly to Midnight Blizzard—also recognized in the cybersecurity industry as Nobelium—based on shared technical methods, consistent phishing techniques, and overlapping target profiles. Both groups attempt to compromise Microsoft 365 data and employ messaging applications for social engineering maneuvers.
Western authorities maintain that Midnight Blizzard operates as a state-directed cyber espionage unit tied to the Russian Foreign Intelligence Service. The collective has a documented history of high-profile operations, having orchestrated the SolarWinds supply-chain attack against United States government agencies in 2020 and executed a breach of Outlook mail clients in 2023.

“Midnight Blizzard is consistent and persistent in its goals, and its objectives rarely change. Their goal is to collect intelligence through multi-year and targeted espionage activities in support of Russia’s foreign policy interests”
Microsoft, Threat Intelligence Report
Government bodies across the United States and Europe remain the primary targets for these intelligence-gathering missions, alongside diplomatic posts, non-governmental organizations, and information technology service providers. The shift toward compromising hospitality networks represents an expansion of attack vectors aimed directly at corporate travelers.
Broader Intelligence Gathering and Official Responses
The hospitality Wi-Fi operation fits into a wider pattern of state-sponsored wireless infrastructure targeting. Intelligence services from Germany, the United States, and Ukraine previously discovered that the Russian hacker group APT28—also known as Fancy Bear or Forest Blizzard—compromised thousands of TP-Link routers globally to siphon intelligence regarding critical infrastructure.
As technical warnings multiply, government representatives in Moscow continue to reject accusations from Western nations regarding state-sponsored cyber operations. Russian officials have previously dismissed such claims as politically motivated propaganda efforts designed to cast blame without verifiable foundations.
Worth a look
