


Perceptive Security
SOC/SIEM Consultancy

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Published:
4 August 2026 at 00:17:15
Alert date:
4 August 2026 at 01:01:17
Source:
bleepingcomputer.com
Ransomware & Malware, Network Infrastructure, Identity & Access, Data Breach & Exfiltration, Enterprise Applications
Microsoft has attributed a global campaign targeting hospitality sector Wi-Fi networks to the Russian state-sponsored threat actor Midnight Blizzard, also known as APT29. The attackers deploy custom malware through hotel Wi-Fi infrastructure to compromise guests' Microsoft 365 accounts. This campaign represents a sophisticated supply-chain-style attack on transient network users, particularly targeting business travelers. The use of custom malware indicates significant resources and capabilities behind the operation. Microsoft 365 credentials and session tokens are likely the primary targets, enabling broader espionage operations. The campaign highlights the risks of using public or semi-public Wi-Fi networks in hospitality environments. APT29 is a well-known Russian intelligence-linked group with a history of high-profile cyber espionage operations.
Technical details
The campaign, dubbed CaptiveCrunch, is attributed to the Russian threat actor Midnight Blizzard (APT29), specifically a sub-cluster tracked as Storm-2945. Active since at least early May 2026 (with device and OAuth code phishing operations since February), attackers manipulate DNS and HTTP traffic on captive portal equipment used in hotel and conference center Wi-Fi networks. After modifying DNS settings, victims are redirected to: (1) phishing pages impersonating Microsoft 365 login portals, (2) device code phishing pages abusing Microsoft Entra ID authentication flows, or (3) fake browser/OS update pages delivering malware via ClickFix prompts. There is also evidence of Android APK delivery targeting. Two custom malware families were identified: CornFlake - a Go-based RAT with capabilities including remote shell access, keylogging, clipboard monitoring, screenshot capture, microphone/webcam surveillance, browser credential and cookie theft, Microsoft 365 session token theft, file exfiltration, USB monitoring, and system reconnaissance. It persists via Windows service registrations, registry run keys, named tasks, and a watchdog routine, disguising itself as 'Cloud Sync Service'. It displays fake progress windows mimicking Windows update, Defender virus scan, disk optimization, network diagnostics, browser update, or document viewer installer screens. ChocoShell - an in-memory PowerShell credential stealer targeting browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials. A web-based management panel named FruitStone was also discovered, used to manage infected systems, browse files, execute PowerShell commands, and capture screenshots and keystrokes. AI tools were assessed as likely used in malware development based on extensive code comments.
Mitigation steps:
1. Treat hotel and conference Wi-Fi as untrusted networks; use private cellular connections or managed/VPN connections whenever possible. 2. Avoid installing software updates or tools offered through captive portals. 3. Adopt phishing-resistant MFA using passkeys. 4. Disable Microsoft Entra device code authentication when not needed. 5. Avoid using corporate credentials to register for guest Wi-Fi networks. 6. Monitor for unauthorized DNS changes on network infrastructure. 7. Hunt for the malware families CornFlake and ChocoShell on endpoints, particularly looking for a 'Cloud Sync Service' process and suspicious persistence mechanisms (registry run keys, named tasks, Windows services). 8. Monitor for the FruitStone management panel indicators. 9. Review and monitor Microsoft 365 and Azure AD token usage for anomalies. 10. Implement network-level monitoring for suspicious DNS and HTTP traffic manipulation on Wi-Fi infrastructure.
Affected products:
Microsoft 365
Microsoft Entra ID (Azure AD)
Windows OS
Android devices
Hotel and conference center Wi-Fi captive portal equipment
Related links:
https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/
https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/
https://www.bleepingcomputer.com/news/security/new-forg365-phishing-platform-uses-ai-to-target-microsoft-365-accounts/
https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/
https://www.bleepingcomputer.com/news/security/consentfix-and-clickfix-how-microsoft-365-accounts-are-hijacked-in-3-seconds/
https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/
Related CVE's:
Related threat actors:
IOC's:
Malware family: CornFlake (Go-based RAT), Malware family: ChocoShell (in-memory PowerShell credential stealer), Management panel: FruitStone (web-based C2 panel), CornFlake persistence path: %AppData%, CornFlake disguise name: Cloud Sync Service, Delivery method: ClickFix prompts via fake browser/OS update pages, Delivery method: APK files targeting Android devices, Fake window types: Windows update screen, Defender virus scan, disk optimization utility, network diagnostics tool, browser update prompt, document viewer installer
This article was created with the assistance of AI technology by Perceptive.
