Microsoft Threat Intelligence published research on July 31 naming a campaign called CaptiveCrunch that has run since early May and which Microsoft attributes to Storm-2945, a sub-cluster of Midnight Blizzard.
Attribution and timeline: CaptiveCrunch and Storm-2945
Microsoft linked the activity it calls CaptiveCrunch to Storm-2945, itself a sub-cluster of Midnight Blizzard. The U.S. and U.K. governments have previously attributed Midnight Blizzard (also known as APT29, the Dukes, or Cozy Bear) to Russia’s Foreign Intelligence Service, the SVR. ReliaQuest reported part of the activity on July 23, and Microsoft’s analysis, published July 31, says the campaign has been active since early May.
Captive portals hijacked to serve fake updates
Attackers hijacked captive portals on hotel, conference and other shared Wi‑Fi networks to route guests through attacker infrastructure and serve fake browser and operating‑system update pages. Rather than waiting for a user to visit a website, the actor answered the automated connectivity checks that browsers and operating systems issue on joining a new network and returned pages offering browser or system updates.
Microsoft described landings that used ClickFix techniques—presenting fake verification failures with paste‑and‑run instructions—and said some pages served an APK, indicating possible Android targeting. From July 16, Microsoft observed some captive‑portal landings redirecting users into device code authentication flows and instructing them to enter an attacker‑supplied code on a genuine Microsoft sign‑in page; Microsoft noted the technique was not new but that embedding it in a captive portal increased the request’s apparent legitimacy.
Microsoft is still investigating how the portals were compromised but flagged commonalities in the equipment and management systems across affected networks, which could reflect access to shared services within the captive‑portal ecosystem rather than isolated venue compromises.

Built by Nubivance.
OSINTSights' secure edge-first architecture, AI content pipeline, and serverless ops are designed by Nubivance. We do this for clients too.
Talk to us →Three tools with a single cover story
Microsoft identified three primary operational components. The primary implant, CornFlake, is a Go remote‑access trojan (RAT) that displays a fake progress window while installing, then registers as a Windows service with the display name “Cloud Sync Service.” CornFlake includes keylogging, screenshot capture, microphone and webcam surveillance, browser credential theft and a remote shell, and it runs a watchdog routine that restores persistence mechanisms defenders remove.
A PowerShell infostealer called ChocoShell runs entirely in memory and disables the Antimalware Scan Interface (AMSI) before harvesting browser cookies, saved passwords, Microsoft 365 single‑sign‑on tokens and Wi‑Fi credentials. Microsoft noted developer comments in ChocoShell that named specific Microsoft detection signatures and explained each evasion choice; Microsoft said those comments suggested AI‑assisted code generation and that the actor used AI across a significant portion of the operation. The company also thanked Anthropic and OpenAI for their support during the investigation.
FruitStone web panel and the operational narrative
Operators managed the campaign from FruitStone, a web panel branded as a fictitious enterprise cloud product that matched the implants’ cover story. Microsoft’s findings link the malicious services, deceptive landing pages and backend control to this operational tradecraft, which targeted corporate travelers’ accounts at hotels, conference centers and other shared venues, according to ReliaQuest’s reporting.
What this means for corporate travelers, security teams, and venue operators
- Corporate travelers: Microsoft recommended treating hotel, conference and airport wireless as untrustworthy, preferring cellular or eSIM connectivity and never installing software offered through a captive portal.
- Security teams and technologists: Microsoft advised blocking device‑code flow where it is not required and deploying passkeys; defenders should also be alert to in‑memory PowerShell activity that disables AMSI and to services impersonating benign names like “Cloud Sync Service.”
- Venue operators and network managers: Microsoft’s observation of common equipment and management‑system traits across affected captive portals suggests venue operators and shared captive‑portal service providers should examine management systems and third‑party portal services for signs of compromise.
Microsoft’s investigation leaves at least one practical question in the air: how the captive portals were first compromised. Until that link is closed, the combination of automated connectivity checks, deceptive update pages, device‑code redirection and AI‑assisted tooling creates a credible path for espionage against travelers who rely on public Wi‑Fi. Defenders have clear mitigation steps from Microsoft—but the discovery also underscores that shared networking infrastructure can be an operational target in its own right.




