Storm-2945, a sub-cluster of Midnight Blizzard, is running CaptiveCrunch to hijack hotel and conference Wi-Fi captive portals, redirecting travelers to attacker-controlled sites for Microsoft 365 credential theft, device code phishing, and malware delivery. The campaign uses CornFlake and ChocoShell, manipulates DNS/HTTP traffic, and extends to Android via malicious APKs. #Storm2945 #MidnightBlizzard #CaptiveCrunch #CornFlake #ChocoShell #Microsoft365 #MicrosoftEntraID #Android
Keypoints
- Storm-2945, linked by Microsoft to Midnight Blizzard, is behind the CaptiveCrunch credential theft campaign.
- The attackers target captive portal networks at hospitality venues, including hotels and conference centers, by manipulating DNS and HTTP traffic.
- Victims are redirected to attacker-controlled infrastructure for Microsoft 365 credential harvesting, device code phishing, and malware delivery.
- Microsoft and ReliaQuest found evidence of compromised shared captive portal services and gateways across multiple countries and U.S. cities.
- The campaign uses AI-assisted malware development, including CornFlake, a Go-based RAT, and ChocoShell, an in-memory PowerShell stealer.
- Storm-2945 also expanded targeting to Android devices through malicious APK files.
- Zscaler recommends full tunnel routing, DNS security, SSL inspection, sandboxing, and file-type controls to reduce exposure.
MITRE Techniques
- [T1557.002 ] Adversary-in-the-Middle â Storm-2945 places victims into an AitM position by manipulating captive portal traffic and redirecting requests to attacker infrastructure. (âtraffic is redirected through an Adversary-in-the-Middle (AitM) position to attacker-controlled infrastructureâ)
- [T1565.002 ] Data Manipulation: Transmitted Data Manipulation â The group manipulates DNS and HTTP traffic on captive portal networks to alter where victims are sent. (âmanipulates DNS and HTTP traffic on captive portal networksâ)
- [T1189 ] Drive-by Compromise â Victims are funneled to malicious portal and update pages that deliver phishing or malware payloads. (âredirecting victims to attacker-controlled infrastructure for Microsoft 365 credential harvesting, device code phishing, and malware deliveryâ)
- [T1056.001 ] Keylogging â CornFlake captures keystrokes for credential theft and surveillance. (âkeyloggingâ)
- [T1113 ] Screen Capture â CornFlake captures screenshots from infected systems. (âscreenshot captureâ)
- [T1123 ] Audio Capture â CornFlake enables microphone surveillance. (âmicrophone ⌠surveillanceâ)
- [T1125 ] Video Capture â CornFlake enables webcam surveillance. (âwebcam surveillanceâ)
- [T1083 ] File and Directory Discovery â ChocoShell steals browser data, tokens, and other locally stored credentials. (âharvests browser cookies and passwordsâ)
- [T1555.003 ] Credentials from Password Stores â ChocoShell extracts stored browser passwords and credentials. (âbrowser cookies and passwordsâ)
- [T1528 ] Steal Application Access Token â ChocoShell harvests Microsoft 365 and Azure AD/WAM tokens from the Token Broker cache. (âharvests Microsoft 365 and Azure AD/WAM tokensâ)
- [T1119 ] Automated Collection â CornFlake collects multiple categories of host intelligence at scale. (âcollects 18 categories of host intelligenceâ)
- [T1020 ] Data Exfiltration â CornFlake and ChocoShell exfiltrate stolen data from compromised hosts. (âexfiltrated via HTTPS POST to C2 endpointsâ)
- [T1071.001 ] Web Protocols â The malware uses HTTPS POST, pixel-like URIs, and web endpoints for C2 and exfiltration. (âexfiltrated via HTTPS POST to C2 endpoints disguised as tracking pixelsâ)
- [T1547.001 ] Registry Run Keys / Startup Folder â CornFlake establishes persistence using Registry Run keys. (âservice registration, Registry Run keys, scheduled tasksâ)
- [T1053.005 ] Scheduled Task/Job: Scheduled Task â CornFlake uses scheduled tasks and a watchdog routine to persist. (âscheduled tasks, and a watchdog routineâ)
- [T1543.003 ] Create or Modify System Process: Windows Service â CornFlake persists through service registration. (âservice registrationâ)
- [T1105 ] Ingress Tool Transfer â ChocoShell retrieves additional tooling from a disguised JS polyfill URI. (âretrieves additional tooling from a URI disguised as a JS polyfill fileâ)
- [T1620 ] Reflective Code Loading â ChocoShell disables AMSI via .NET reflection. (âdisables Windows Antimalware Scan Interface (AMSI) via .NET reflectionâ)
- [T1497.001 ] Virtualization/Sandbox Evasion: System Checks â ChocoShell detects sandboxes and VMs. (âperforms sandbox and VM detectionâ)
- [T1548.002 ] Abuse Elevation Control Mechanism: Bypass User Account Control â ChocoShell uses silent UAC bypass techniques. (âsilent User Account Control (UAC) bypass techniquesâ)
- [T1218.014 ] System Binary Proxy Execution: MMC â ChocoShell abuses wsreset.exe and sdclt.exe-related hijacks for privilege escalation. (âwsreset.exe COM hijack, and sdclt.exe folder hijackâ)
- [T1027 ] Obfuscated Files or Information â ChocoShell compresses, encodes, and wraps stolen data before exfiltration. (âGZip-compressed, Base64-wrapped JSONâ)
- [T1106 ] Native API â ChocoShell uses Chrome DevTools Protocol remote debugging and Windows utilities such as netsh wlan. (âChrome DevTools Protocol remote debuggingâ, âWi-Fi credentials via netsh wlanâ)
- [T1115 ] Clipboard Data â The ClickFix flow instructs victims to paste and run commands. (âVictims are instructed to paste and run commandsâ)
- [T1204.002 ] User Execution: Malicious File â Users are induced to run commands and install APKs from fake update prompts. (âfake Windows Update⌠promptsâ, âinstructions for Android APK installationâ)
Indicators of Compromise
- [Domains] CaptiveCrunch redirect and AitM infrastructure â ms365-device.com, ms365-live.com, and 2 more domains
- [IP addresses] CaptiveCrunch AitM infrastructure and DNS resolver nodes â 31.57.243.154, 38.146.28.75, and 4 more IPs
- [IP address] ChocoShell C2 server / CaptiveCrunch DNS resolver â 213.145.86.112
- [SHA-256 hashes] Malware samples â 918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593, be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c
- [URLs] ChocoShell beaconing, payload retrieval, and exfiltration endpoints â 213.145.86.112/t/pixel.gif, 213.145.86.112/cdn/chunks/polyfill-7e2b.min.js, and 1 more URL
- [Threat names] Zscaler detections tied to the campaign â HTML.Phish.Microsoft.RZ, Win32.Downloader.ChocoShell.RZ