ALITEQ.

that hotel wifi login screen you clicked through? it might be russian spies

Microsoft says a Kremlin-linked group has been hijacking hotel and conference Wi-Fi captive portals since May to install espionage malware on business travelers' laptops.

Ravi MalhotraUpdated 55m ago6 min readWeb story
A Wi-Fi router in a hotel setting, illustrating the captive portal infrastructure hijacked in Microsoft's CaptiveCrunch disclosure

If you've connected to hotel Wi-Fi and clicked through a login page that then asked you to update your browser, Microsoft wants you to know that page might not have been the hotel's. On July 31, 2026, Microsoft's threat intelligence team disclosed a campaign it calls CaptiveCrunch, run by a Midnight Blizzard sub-cluster it tracks as Storm-2945 — the same Russian, SVR-linked group behind the 2020 SolarWinds breach — and it's been quietly hijacking hotel and conference Wi-Fi captive portals since at least May.

How the attack actually works

Captive portals — the login page that pops up before hotel Wi-Fi lets you online — are a soft target almost by design. They're run by third-party hospitality vendors, rarely patched, and every guest is trained to click through whatever they show without thinking twice. Storm-2945 tampers with DNS and HTTP responses on that infrastructure, then routes travelers to one of a few destinations: a cloned Microsoft 365 login built to harvest credentials and, where possible, live session tokens; a device-code phishing page that abuses Microsoft's own device authentication flow to get a valid token without ever touching a password; or, since July, a fake browser or Windows update prompt using ClickFix-style social engineering, where the 'update' is actually the malware installer.

Once CornFlake or ChocoShell land, the group isn't just after a password. ChocoShell specifically goes after .tbres files in the Windows Token Broker cache — where Windows stores live Microsoft 365 and Azure AD access and refresh tokens — which means a stolen token can outlive a changed password.

The two tools Microsoft found

CornFlake

Tool
Go-based Windows RAT
Type
Keystrokes, screenshots, webcam/audio, browser credentials, Microsoft 365 session tokens

ChocoShell

Tool
In-memory PowerShell stealer
Type
Browser cookies, saved passwords, Microsoft 365/Azure AD tokens from the Token Broker cache

Why this group, why now

Midnight Blizzard doesn't do smash-and-grab. This is the same operational lineage as the SolarWinds compromise and years of targeted espionage against governments, NGOs, and increasingly private companies whose executives travel. Corporate travelers are a specific kind of target: unfamiliar networks, distracted, and their laptops are usually carrying live sessions into whatever their employer runs on Microsoft 365 and Azure. That's a much bigger prize than a personal inbox.

It also isn't the only recent case of attackers going after trust and credentials rather than a fresh software bug. OpenAI's own coding agents recently found real zero-days and used them to breach Hugging Face, a chipmaker whose parts sit inside plenty of the hardware we cover confirmed its files were stolen and posted to a leak site, and five fabricated online identities talked an AI coding assistant into shipping malicious code earlier this year. Different targets, same principle: the cheapest way in is still convincing something — human or machine — that what it's looking at is legitimate.

Skip the hotel captive portal for anything sensitive — tether to your phone instead.

Never accept a browser or Windows update prompt served through a Wi-Fi login page.

Turn on phishing-resistant MFA — passkeys or a hardware key — it blocks the token-theft flows CornFlake and ChocoShell rely on.

Disable device-code authentication in your org's Azure AD/Entra tenant if nobody actually needs it.

5

If you connected to unfamiliar Wi-Fi recently and got an odd update prompt, report it to IT rather than assuming it was nothing.

A business traveler using a laptop in a hotel lobby, the setting Midnight Blizzard's CaptiveCrunch campaign specifically targets
Microsoft says the campaign has targeted hotel and conference Wi-Fi since at least May 2026. · Unsplash

Who is Midnight Blizzard?
Midnight Blizzard is Microsoft's name for the threat actor the US and UK governments attribute to Russia's SVR foreign intelligence service — the same group, previously tracked as NOBELIUM, behind the 2020 SolarWinds breach.
How long has CaptiveCrunch been running?
Microsoft says the DNS/HTTP tampering activity dates to at least May 2026, with related device-code phishing from the same cluster going back to February 2026.
Does a VPN protect me from this attack?
Only a pre-configured, employer-trusted VPN that connects before you do anything else on the network helps — the danger is the captive portal itself, which can intercept traffic before a VPN tunnel is up.
Is this only a Microsoft 365 problem?
The confirmed target is Microsoft 365 and Azure AD credentials and tokens specifically, but CornFlake's broader capabilities — keylogging, webcam access, browser credential theft — aren't limited to one platform once it's installed.

Microsoft's disclosure names the campaign and the tools, which at least gives security teams IOCs to hunt for — but the underlying weakness, a hospitality industry running unpatched, third-party captive portal software, isn't going away because one campaign got a name. Expect copycats. The realistic fix isn't 'hotels patch their Wi-Fi gear' — it's business travelers and IT departments treating every hotel network as adversarial by default, the same way you'd treat an open network at a coffee shop, because as of this week, that's exactly the threat model Microsoft says it is.

Hardware Editor

Ravi Malhotra

Ravi has been building and taking apart PCs since the single-core days — his idea of a good weekend is a repaste and a spreadsheet full of thermals. He covers GPUs, CPUs and the build decisions that actually move frame rates, and he'd rather hand you a benchmark than a press release.

Work out the hardware

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading