Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Microsoft linked the CaptiveCrunch campaign to Midnight Blizzard (APT29), saying it targets hotel and conference Wi-Fi networks to steal Microsoft 365 accounts through DNS tampering, phishing, and malware delivery. The campaign uses the CornFlake and ChocoShell malware families, along with the FruitStone panel, to maintain access, collect credentials, and exfiltrate data. #MidnightBlizzard #APT29 #CaptiveCrunch #CornFlake #ChocoShell #FruitStone

Keypoints

  • Microsoft attributed the CaptiveCrunch campaign to Midnight Blizzard, also tracked as APT29 and Storm-2945.
  • Attackers manipulate DNS and HTTP traffic on captive portal Wi-Fi networks to steal Microsoft 365 accounts.
  • The campaign uses phishing pages, device code phishing, and fake update prompts to deliver malware.
  • CornFlake provides remote access, surveillance, credential theft, and persistence on Windows systems.
  • ChocoShell steals browser cookies, passwords, Microsoft 365 tokens, Azure AD tokens, and Wi-Fi credentials.

Read More: https://www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/