WASHINGTON – Sometime between February and May of this year, while business travelers were checking into hotels and clicking through the usual captive portal login screens, Storm-2945 was waiting. The group, a subdivision of Midnight Blizzard that Microsoft links to Russia’s Foreign Intelligence Service, had compromised the guest Wi-Fi networks of hotels, conference centers, and other hospitality venues. Every user who connected was a potential target.
Microsoft disclosed the operation on Monday, naming it CaptiveCrunch. The company described the threat as “widespread” but offered no count of affected users, and declined to explain when contacted by ABC News why it waited three months after detecting the campaign in May to warn the public.
The attack begins at the captive portal, the browser-based login screen that most hotel guests encounter before they can access the internet. Storm-2945 compromised these networks and redirected Wi-Fi traffic through attacker-controlled infrastructure, positioning itself between the user and the network. Once in that position, the group had two primary tools for turning access into intelligence.
The first is CornFlake, a remote access trojan written in Go. Microsoft describes it as capable of logging keystrokes, monitoring clipboard contents, capturing screenshots, recording audio and video through the device’s built-in hardware, harvesting browser credentials, tracking USB device activity, and exfiltrating files. It also provides attackers with a persistent remote shell on the infected machine.
The second tool is ChocoShell, an in-memory PowerShell infostealer that extracts browser cookies, saved passwords, single sign-on tokens, and Wi-Fi credentials from infected devices. Because it runs entirely in memory rather than writing to disk, conventional endpoint security tools are less likely to detect it. The primary targets of both tools are Microsoft 365 accounts, meaning corporate email, OneDrive files, and the cloud access that traveling employees carry on their laptops.
Storm-2945 also used device code phishing, exploiting OAuth authentication flows to redirect users to attacker-controlled sessions through fake Microsoft login pages. Users who authenticate on what appears to be a legitimate Microsoft portal may hand over access tokens for their enterprise accounts without triggering any obvious alert. The attack requires no malware download. It needs only a click.
The campaign also deployed a catalog of eight spoofed system interfaces designed to mimic legitimate software: Windows Update, Windows Defender, DirectX, Microsoft Visual C++ Redistributable, a system optimizer, a network diagnostic tool, a generic browser update prompt, and a PDF viewer. When these appeared as pop-ups on a hotel network, the prompt to download or update was the attack itself. The group additionally used fake Google “unusual activity” security checks as a separate credential-harvesting channel.
Microsoft’s own timeline raises a question the company has not answered publicly. The CaptiveCrunch activity began in February 2026. Traffic manipulation at captive portals was first observed in May 2026. The public advisory came on August 3, 2026, three months after the campaign was detected in its active form. When ABC News asked Microsoft why it waited, the company declined to comment. How many users were exposed during those three months is not disclosed.
The targets are traveling professionals, particularly those using hotel and conference center Wi-Fi for work. Storm-2945 focused primarily on Windows machines, though Microsoft noted that Android variants of CornFlake are in development, suggesting the group intends to expand its reach to mobile devices. The intelligence mission appears to be credential collection and persistent access. There is no ransomware component, no encryption, nothing that signals the compromise to the victim. The damage is invisible until the stolen credentials are used elsewhere.
Microsoft’s recommendations for travelers are direct. Use a personal mobile hotspot instead of hotel Wi-Fi when handling sensitive communications or enterprise systems. Organizations should consider disabling device code authentication flows, which Storm-2945 exploited for OAuth phishing. Implementing passwordless authentication removes the password as a target. For individuals, the most practical instruction is the simplest: do not download or install software through unexpected pop-ups on public networks, regardless of how familiar the prompt appears.
Midnight Blizzard, the broader group Storm-2945 operates within, is also tracked as APT29 and Cozy Bear, and has been attributed to the SolarWinds supply chain compromise of 2020. Its connection to the SVR places it within Russia’s foreign intelligence apparatus rather than its military hacking units. In June, Russia’s SVR accused the European Union of fabricating evidence in a separate dispute involving religious institutions, a reflection of how broadly the service operates across different theatres simultaneously.
The disclosure fits a larger pattern of credential and data security incidents that have shaped the year’s threat landscape. Tata Electronics, Apple’s largest Indian manufacturing partner, suffered a breach in July that placed confidential supply chain data on the dark web. That attack targeted infrastructure. CaptiveCrunch targets the humans moving through it. The credential is the point of entry in both cases. And as Satya Nadella warned last month in a discussion about enterprise AI dependency, organizations that assume any layer of their technology stack is safely managed without active oversight have misread where the risks actually live. On Monday, his own company confirmed that the hotel lobby is one of them.

