A Russian state-sponsored Advanced Persistent Threat (APT), identified as Storm-2945, is accused of conducting a credential theft campaign via compromised public Wi-Fi gateways, targeting employees in various sectors like finance and healthcare. Microsoft reported that these hackers manipulated DNS settings on small office/home office routers to redirect victims, using adversary-in-the-middle techniques to steal Microsoft 365 credentials.
The operation, dubbed CaptiveCrunch, leveraged malware disguised as browser updates to enable surveillance and data theft. Similar tactics have been linked to past Russian espionage activities, and Microsoft emphasizes the recurring risks associated with captive portal networks and device code phishing.