Storm-2945 hijacked public Wi-Fi gateways, stole M365 logins

Microsoft links Storm-2945, a subgroup of Midnight Blizzard, to CaptiveCrunch attacks that hijacked captive-portal Wi‑Fi gateways to capture Microsoft 365 credentials and push malware.

Microsoft reported that a subgroup of the Russian-linked Midnight Blizzard operation, tracked as Storm-2945, manipulated captive-portal Wi‑Fi gateway equipment at hotels, conference centers and other shared venues beginning in May to intercept Microsoft 365 credentials and deliver Windows and Android malware.

Security firm ReliaQuest flagged the activity after noticing modified DNS settings on small office/home office routers that redirected users to attacker-controlled infrastructure. Microsoft and ReliaQuest identified the campaign roughly a week ago and Microsoft named the operation CaptiveCrunch.

The attackers used DNS and HTTP traffic manipulation to perform adversary-in-the-middle interceptions of users connecting through captive portals. Some pages presented fake browser update prompts that installed Golang-based Windows remote access trojans, while Android users were prompted to download and install malicious APK files.

Microsoft reported the Windows implants include a CornFlake remote access trojan and a PowerShell-based infostealer called ChocoShell. Operators managed agents and infrastructure through a web-based command-and-control panel labeled FruitStone. The tools collected credentials and session tokens, files, keystrokes, and could record audio and video and provide remote shell access.

In several recent landing pages, victims were directed into a device code authentication flow and instructed to enter device codes on Microsoft sign-in pages to authenticate the attacker’s session. Microsoft wrote that ‘Midnight Blizzard operations often involve compromise of valid accounts and, in some highly targeted cases, advanced techniques to compromise authentication mechanisms within an organization to expand access and evade detection.’ The company noted it has tracked device code phishing since August 2024.

Microsoft said Storm-2945 has targeted employees in financial services, professional services, legal, healthcare, energy and retail sectors. The company identified widespread compromise of Wi‑Fi networks at hospitality-related organizations and other captive-portal serviced networks in several countries but did not publish a list of affected venues or a total number of victims.

Microsoft attributed CaptiveCrunch to Storm-2945, a subgroup of Midnight Blizzard (also tracked as APT29, Cozy Bear and the Dukes), which Microsoft believes is sponsored by Russia’s Foreign Intelligence Service (SVR). Midnight Blizzard has previously targeted government, diplomatic and IT service organizations for intelligence collection.

Microsoft urged operators of captive portals, hospitality venues and shared Wi‑Fi services to review router and gateway configurations, monitor for DNS and traffic manipulation, and investigate suspicious authentication requests.

Articles by this author