
RUSSIAN hackers have been hijacking hotel Wi-Fi to steal Microsoft 365 tokens from travelers since May 2026, SecurityAffairs reports.
The operation, dubbed CaptiveCrunch, works by altering DNS and HTTP traffic on captive portal networks so that users are sent to attacker‑controlled sites that drop the CornFlake remote access trojan and the ChocoShell infostealer. CornFlake masquerades as a legitimate Windows process while gathering screenshots, keystrokes and other data, and ChocoShell focuses on harvesting Microsoft 365 authentication tokens.
Microsoft has not issued a CVE for this activity because the abuse relies on manipulating network traffic rather than exploiting a software vulnerability. Stolen tokens allow the attackers to sign in to cloud services as the victim, bypassing password prompts and multifactor checks that rely solely on knowledge‑based factors.
Researchers link the campaign to the Storm-2945 cluster, which is associated with the APT29 group known for targeting governmental and corporate entities. Microsoft has advised travellers to treat any public wireless network as hostile and to prefer personal hotspots or vetted VPN connections when handling sensitive data.
Individuals should avoid logging into corporate resources while connected to hotel Wi‑Fi and instead use a trusted mobile hotspot or a VPN that enforces strong encryption and strict routing. Enterprises can reduce risk by enforcing conditional access policies that block sign‑ins from unfamiliar locations, requiring hardware‑based multifactor authentication and monitoring token replay attempts.
Security teams should watch authentication logs for impossible travel alerts, sudden token reuse or sign‑ins from unfamiliar IP ranges, and investigate any anomalies promptly. User training that highlights the dangers of captive portals and encourages the habit of verifying network legitimacy before accessing confidential information complements technical controls.