Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking

Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
Microsoft says a Russian state-sponsored group, Storm-2945 of Midnight Blizzard, is behind CaptiveCrunch, a campaign that hijacks captive portal Wi-Fi traffic to steal Microsoft 365 credentials. The attackers used malicious browser updates, device code phishing, and multiple malware families to target travelers and organizations across several sectors. #MidnightBlizzard #Storm2945 #CaptiveCrunch #CornFlakeRAT #ChocoShell #FruitStone

Keypoints

  • Microsoft attributed CaptiveCrunch to Storm-2945, a subgroup of Midnight Blizzard.
  • The campaign abused hacked captive portal Wi-Fi networks and modified DNS and HTTP traffic.
  • Attackers used adversary-in-the-middle tactics to steal Microsoft 365 credentials and session tokens.
  • Malicious browser updates delivered Golang-based RATs, including CornFlake RAT and ChocoShell.
  • The operation also used device code phishing and targeted Android users with APK lures.

Read More: https://www.securityweek.com/russian-state-apt-linked-to-recent-public-wi-fi-gateway-hacking/