"Where CornFlake provides the operator with a persistent, long-running foothold on the device, ChocoShell is designed to extract the most operationally valuable credentials, giving the operator access to victim cloud environments," Microsoft said.
How Storm-2945 turns captive portals into an adversary-in-the-middle
Microsoft has attributed a months-long campaign it calls "CaptiveCrunch" to Storm-2945, a subdivision of the SVR's Midnight Blizzard (aka Nobellium), saying the group compromised captive-portal networks at hotels, conference centers and other hospitality venues to deliver malware. With ReliaQuest's earlier work supporting Microsoft's investigation, Redmond traced traffic manipulation back to at least early May 2026, while noting the broader, AI-assisted operation dates to February 2026.
After gaining control of the network layer, Microsoft said Storm-2945 manipulates DNS and HTTP traffic to reroute users through attacker-controlled infrastructure. The crew also abuses operating systems' connectivity checks to trigger malicious prompts and redirects, creating an adversary-in-the-middle (AitM) position that serves fake prompts and landing pages to connected devices.
CornFlake and ChocoShell: a persistent implant and its in-memory stealer
Microsoft described one of the delivered payloads, CornFlake, as "a full-featured Windows RAT" written in Go and used as the SVR's go-to persistent implant in these hospitality network attacks. After convincing users to install it—sometimes via a "convincing" fake Windows update progress window—CornFlake grants a wide range of capabilities, which Microsoft listed as:
- Keylogging
- Clipboard monitoring
- Screenshot capture
- Audio surveillance
- Video surveillance
- Browser credential theft
- File exfiltration
- USB drive monitoring
- Security posture sweep
- Remote shell
Microsoft also said CornFlake exposes a localhost HTTP API server that lets operators use it as a modular platform to deliver additional payloads, including ChocoShell. ChocoShell is PowerShell-based, "delivered and executed entirely in-memory," and is used primarily to harvest browser session cookies, saved passwords, SSO tokens and Wi‑Fi credentials.

Built by Nubivance.
OSINTSights' secure edge-first architecture, AI content pipeline, and serverless ops are designed by Nubivance. We do this for clients too.
Talk to us →Device code phishing embedded in captive-portal flows
In addition to malware installation, Microsoft reported that "a portion" of CaptiveCrunch activity is devoted to device code phishing. In this technique the attacker requests an authentication code from Microsoft, sends that code to a phishing target, and then prompts the target—via the attacker-served landing page—to enter the code into a legitimate Microsoft authentication window. Selecting an account then completes the OAuth flow and authenticates the attacker into the victim's Microsoft 365 account, yielding a valid token until it expires or is revoked.
Microsoft noted the technique is not novel and observed it in Midnight Blizzard operations since August 2024, but warned that integrating device code phishing into captive-portal and traffic-manipulation operations could increase the likelihood victims perceive the authentication request as legitimate.
Microsoft's advice and organizational mitigations
Microsoft's central user-directed advice is clear: stop trusting public Wi‑Fi by default. The company did not tell users to avoid hospitality Wi‑Fi outright, but recommended favoring personal hotspots and satellite internet over public networks where possible. Practical education items Microsoft emphasized include teaching users not to download updates or accept prompts over public networks and training users to recognize ClickFix-style fraudulent prompts that mimic OS updates, driver repairs and web verification failures.
On the organizational side, Microsoft highlighted technical controls. Passwordless authentication can thwart many phishing techniques, Microsoft said, though it cautioned device code phishing "may bypass even passkeys." Microsoft suggested disabling the device code authentication flow wherever possible to prevent employees from unintentionally authorizing attacker sessions.
What this means for conference-goers, IT teams, and hospitality operators
- Conference-goers and general users: Microsoft recommends preferring personal hotspots and satellite connections over public Wi‑Fi and avoiding installing updates or following prompts while on shared networks.
- IT and security teams: Microsoft points to passwordless authentication as a mitigation and specifically recommends disabling the device code authentication flow where practicable to reduce the risk of OAuth token compromise.
- Hospitality operators: Because Microsoft is still trying to determine how captive-portal networks are initially compromised, venue operators face pressure to audit and harden captive-portal infrastructure and DNS/HTTP handling to prevent traffic manipulation.
Microsoft's account of CaptiveCrunch leaves one practical question squarely on the table: how did Storm-2945 first gain control of captive-portal infrastructure? Redmond continues to investigate that initial compromise while tracking traffic manipulation activity that Microsoft observed since early May 2026. Until that gap is closed, the company’s guidance is blunt: assume public Wi‑Fi is risky, harden authentication flows, and teach users not to install updates or enter codes handed to them by a page delivered via a captive portal.




