www.microsoft.com 7/31/2026, 9:50:42 PM · external

Midnight Blizzard Offshoot Hits Travellers With CaptiveCrunch

Midnight Blizzard Offshoot Hits Travellers With CaptiveCrunch
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
🇷🇺 UNC2452

THE article discusses a new cyber threat campaign identified by Microsoft Threat Intelligence, dubbed "CaptiveCrunch," which is conducted by a sub-cluster of the Midnight Blizzard group. This campaign targets travelers by manipulating traffic through hospitality networks to deliver malware and perform credential theft. Specifically, the attackers utilize tactics similar to previous operations but focus on devices through captive portals. Key findings include:

1. **Attack Techniques:** The campaign involves adversary-in-the-middle phishing operations that exploit Microsoft Entra ID's device code authentication. Attackers employ techniques such as DNS hijacking and fake updates, leveraging doppelganger domains.

2. **Malware Distribution:** Key malware includes 'CornFlake,' a full-featured Windows remote access trojan (RAT), and 'ChocoShell,' a PowerShell-based infostealer that retrieves sensitive information like browser cookies and credentials.

3. **Operational Insights:** The sub-cluster is assessed to be a continuation of Midnight Blizzard's prior activities targeting the hospitality sector, indicating broad vulnerabilities within shared network environments.

4. **Mitigation Advice:** The report suggests minimizing trust in public Wi-Fi, strengthening identity protocols, educating users about phishing techniques, and using Microsoft Defender tools to detect suspicious activities.

Overall, the article emphasizes the need for heightened security awareness and protective measures against such ongoing cyber threats.

View full article

Article by CyberSIXT