Microsoft linked the CaptiveCrunch campaign to Midnight Blizzard (APT29), saying it targets hotel and conference Wi-Fi networks to steal Microsoft 365 accounts through DNS tampering, phishing, and malware delivery. The campaign uses the CornFlake and ChocoShell malware families, along with the FruitStone panel, to maintain access, collect credentials, and exfiltrate data. #MidnightBlizzard #APT29 #CaptiveCrunch #CornFlake #ChocoShell #FruitStone
Keypoints
- Microsoft attributed the CaptiveCrunch campaign to Midnight Blizzard, also tracked as APT29 and Storm-2945.
- Attackers manipulate DNS and HTTP traffic on captive portal Wi-Fi networks to steal Microsoft 365 accounts.
- The campaign uses phishing pages, device code phishing, and fake update prompts to deliver malware.
- CornFlake provides remote access, surveillance, credential theft, and persistence on Windows systems.
- ChocoShell steals browser cookies, passwords, Microsoft 365 tokens, Azure AD tokens, and Wi-Fi credentials.