Microsoft says a Russian state-sponsored group, Storm-2945 of Midnight Blizzard, is behind CaptiveCrunch, a campaign that hijacks captive portal Wi-Fi traffic to steal Microsoft 365 credentials. The attackers used malicious browser updates, device code phishing, and multiple malware families to target travelers and organizations across several sectors. #MidnightBlizzard #Storm2945 #CaptiveCrunch #CornFlakeRAT #ChocoShell #FruitStone
Keypoints
- Microsoft attributed CaptiveCrunch to Storm-2945, a subgroup of Midnight Blizzard.
- The campaign abused hacked captive portal Wi-Fi networks and modified DNS and HTTP traffic.
- Attackers used adversary-in-the-middle tactics to steal Microsoft 365 credentials and session tokens.
- Malicious browser updates delivered Golang-based RATs, including CornFlake RAT and ChocoShell.
- The operation also used device code phishing and targeted Android users with APK lures.
Read More: https://www.securityweek.com/russian-state-apt-linked-to-recent-public-wi-fi-gateway-hacking/