MICROSOFT'S report details the CaptiveCrunch malware campaign, attributed to an actor called Storm-2945, part of Russia-linked Midnight Blizzard. The campaign targets corporate travelers by hijacking hotel and conference Wi-Fi networks to deliver malware and steal credentials since May 2026. The attack manipulates DNS and HTTP traffic, redirecting users to fake updates that also aim at Android devices. The malware toolkit includes a Go-based remote access trojan and a PowerShell script for credential theft.
The operation is extensive but lacks victim count and financial details. Users are advised to treat such networks as untrusted and to utilize VPNs and multi-factor authentication.