CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials

CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials
Storm-2945, a sub-cluster of Midnight Blizzard, is running CaptiveCrunch to hijack hotel and conference Wi-Fi captive portals, redirecting travelers to attacker-controlled sites for Microsoft 365 credential theft, device code phishing, and malware delivery. The campaign uses CornFlake and ChocoShell, manipulates DNS/HTTP traffic, and extends to Android via malicious APKs. #Storm2945 #MidnightBlizzard #CaptiveCrunch #CornFlake #ChocoShell #Microsoft365 #MicrosoftEntraID #Android

Keypoints

  • Storm-2945, linked by Microsoft to Midnight Blizzard, is behind the CaptiveCrunch credential theft campaign.
  • The attackers target captive portal networks at hospitality venues, including hotels and conference centers, by manipulating DNS and HTTP traffic.
  • Victims are redirected to attacker-controlled infrastructure for Microsoft 365 credential harvesting, device code phishing, and malware delivery.
  • Microsoft and ReliaQuest found evidence of compromised shared captive portal services and gateways across multiple countries and U.S. cities.
  • The campaign uses AI-assisted malware development, including CornFlake, a Go-based RAT, and ChocoShell, an in-memory PowerShell stealer.
  • Storm-2945 also expanded targeting to Android devices through malicious APK files.
  • Zscaler recommends full tunnel routing, DNS security, SSL inspection, sandboxing, and file-type controls to reduce exposure.

MITRE Techniques

  • [T1557.002 ] Adversary-in-the-Middle – Storm-2945 places victims into an AitM position by manipulating captive portal traffic and redirecting requests to attacker infrastructure. (‘traffic is redirected through an Adversary-in-the-Middle (AitM) position to attacker-controlled infrastructure’)
  • [T1565.002 ] Data Manipulation: Transmitted Data Manipulation – The group manipulates DNS and HTTP traffic on captive portal networks to alter where victims are sent. (‘manipulates DNS and HTTP traffic on captive portal networks’)
  • [T1189 ] Drive-by Compromise – Victims are funneled to malicious portal and update pages that deliver phishing or malware payloads. (‘redirecting victims to attacker-controlled infrastructure for Microsoft 365 credential harvesting, device code phishing, and malware delivery’)
  • [T1056.001 ] Keylogging – CornFlake captures keystrokes for credential theft and surveillance. (‘keylogging’)
  • [T1113 ] Screen Capture – CornFlake captures screenshots from infected systems. (‘screenshot capture’)
  • [T1123 ] Audio Capture – CornFlake enables microphone surveillance. (‘microphone … surveillance’)
  • [T1125 ] Video Capture – CornFlake enables webcam surveillance. (‘webcam surveillance’)
  • [T1083 ] File and Directory Discovery – ChocoShell steals browser data, tokens, and other locally stored credentials. (‘harvests browser cookies and passwords’)
  • [T1555.003 ] Credentials from Password Stores – ChocoShell extracts stored browser passwords and credentials. (‘browser cookies and passwords’)
  • [T1528 ] Steal Application Access Token – ChocoShell harvests Microsoft 365 and Azure AD/WAM tokens from the Token Broker cache. (‘harvests Microsoft 365 and Azure AD/WAM tokens’)
  • [T1119 ] Automated Collection – CornFlake collects multiple categories of host intelligence at scale. (‘collects 18 categories of host intelligence’)
  • [T1020 ] Data Exfiltration – CornFlake and ChocoShell exfiltrate stolen data from compromised hosts. (‘exfiltrated via HTTPS POST to C2 endpoints’)
  • [T1071.001 ] Web Protocols – The malware uses HTTPS POST, pixel-like URIs, and web endpoints for C2 and exfiltration. (‘exfiltrated via HTTPS POST to C2 endpoints disguised as tracking pixels’)
  • [T1547.001 ] Registry Run Keys / Startup Folder – CornFlake establishes persistence using Registry Run keys. (‘service registration, Registry Run keys, scheduled tasks’)
  • [T1053.005 ] Scheduled Task/Job: Scheduled Task – CornFlake uses scheduled tasks and a watchdog routine to persist. (‘scheduled tasks, and a watchdog routine’)
  • [T1543.003 ] Create or Modify System Process: Windows Service – CornFlake persists through service registration. (‘service registration’)
  • [T1105 ] Ingress Tool Transfer – ChocoShell retrieves additional tooling from a disguised JS polyfill URI. (‘retrieves additional tooling from a URI disguised as a JS polyfill file’)
  • [T1620 ] Reflective Code Loading – ChocoShell disables AMSI via .NET reflection. (‘disables Windows Antimalware Scan Interface (AMSI) via .NET reflection’)
  • [T1497.001 ] Virtualization/Sandbox Evasion: System Checks – ChocoShell detects sandboxes and VMs. (‘performs sandbox and VM detection’)
  • [T1548.002 ] Abuse Elevation Control Mechanism: Bypass User Account Control – ChocoShell uses silent UAC bypass techniques. (‘silent User Account Control (UAC) bypass techniques’)
  • [T1218.014 ] System Binary Proxy Execution: MMC – ChocoShell abuses wsreset.exe and sdclt.exe-related hijacks for privilege escalation. (‘wsreset.exe COM hijack, and sdclt.exe folder hijack’)
  • [T1027 ] Obfuscated Files or Information – ChocoShell compresses, encodes, and wraps stolen data before exfiltration. (‘GZip-compressed, Base64-wrapped JSON’)
  • [T1106 ] Native API – ChocoShell uses Chrome DevTools Protocol remote debugging and Windows utilities such as netsh wlan. (‘Chrome DevTools Protocol remote debugging’, ‘Wi-Fi credentials via netsh wlan’)
  • [T1115 ] Clipboard Data – The ClickFix flow instructs victims to paste and run commands. (‘Victims are instructed to paste and run commands’)
  • [T1204.002 ] User Execution: Malicious File – Users are induced to run commands and install APKs from fake update prompts. (‘fake Windows Update… prompts’, ‘instructions for Android APK installation’)

Indicators of Compromise

  • [Domains] CaptiveCrunch redirect and AitM infrastructure – ms365-device.com, ms365-live.com, and 2 more domains
  • [IP addresses] CaptiveCrunch AitM infrastructure and DNS resolver nodes – 31.57.243.154, 38.146.28.75, and 4 more IPs
  • [IP address] ChocoShell C2 server / CaptiveCrunch DNS resolver – 213.145.86.112
  • [SHA-256 hashes] Malware samples – 918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593, be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c
  • [URLs] ChocoShell beaconing, payload retrieval, and exfiltration endpoints – 213.145.86.112/t/pixel.gif, 213.145.86.112/cdn/chunks/polyfill-7e2b.min.js, and 1 more URL
  • [Threat names] Zscaler detections tied to the campaign – HTML.Phish.Microsoft.RZ, Win32.Downloader.ChocoShell.RZ


Read more: https://www.zscaler.com/blogs/security-research/captivecrunch-midnight-blizzard-weaponizes-hotel-wi-fi-captive-portals