Zscaler ThreatLabz has published a practical look at CaptiveCrunch, a campaign Microsoft attributes to Storm-2945, a Midnight Blizzard/APT29 sub-cluster. The important part for defenders is not just that Russian state-linked operators are targeting travelers. It is that the attack path starts in a place many security programs still treat as background noise: hotel and conference Wi-Fi.
The campaign abuses captive portal infrastructure and network-layer traffic manipulation to push victims toward Microsoft 365 credential theft, device-code phishing, fake update prompts, and malware delivery. For SMBs and government contractors, this is a clean reminder that identity compromise does not always begin inside the office, on a managed network, or from a classic phishing email.
What Zscaler Reported
According to Zscaler, CaptiveCrunch manipulates DNS and HTTP traffic on hospitality networks so that a traveler trying to get online can be redirected through attacker-controlled infrastructure. The campaign can lead users to Microsoft 365 lookalike sign-in pages, device-code phishing flows, or fake browser and operating-system update prompts.
The malware side of the campaign includes CornFlake, a Go-based remote access trojan, and ChocoShell, an in-memory PowerShell stealer. Zscaler describes collection of browser credentials, cookies, Microsoft 365 and Azure AD/WAM tokens, Wi-Fi credentials, host data, and other sensitive artifacts. The campaign has also reportedly expanded toward Android APK delivery, which matters for workforces that rely heavily on mobile devices during travel.
Why This Matters
Travel creates an awkward security gap. Users are outside the normal perimeter, often tired, rushed, and trying to join meetings or retrieve documents. Captive portals already train people to click through unfamiliar web pages just to get online. CaptiveCrunch turns that trust pattern into an identity and malware delivery path.
The most concerning piece is device-code phishing. A user may believe they are completing a legitimate Microsoft authentication step, while in reality they are authorizing an attacker-controlled session. Conventional MFA can struggle here because the user is still interacting with a real identity flow. The defensive answer is not simply “train harder.” Organizations need controls that reduce the blast radius when a user encounters hostile network infrastructure.
Defensive Takeaways for SMBs and Government Contractors
- Enforce full-tunnel VPN or SSE/ZTNA for travel users. DNS and web traffic should not silently fall back to local hotel or conference network resolvers.
- Block outbound DNS except to approved resolvers. If unmanaged DNS is allowed, captive portal manipulation becomes much harder to detect and control.
- Move high-risk users toward phishing-resistant MFA. FIDO2/passkeys with clear conditional-access rules are stronger than push prompts or device-code flows alone.
- Restrict device-code authentication where it is not needed. Monitor for unusual device-code sign-ins, new device registrations, and authentication from travel-heavy geographies.
- Harden endpoint execution paths. Fake update and ClickFix-style lures depend on users running commands or installers. Application control, script restrictions, and EDR visibility matter here.
- Watch for cloud token theft after travel. A successful hotel Wi-Fi attack may show up later as mailbox access, file downloads, OAuth consent activity, or suspicious Entra device registration.
Bulwark Black Assessment
CaptiveCrunch is a good example of the modern identity attack chain: manipulate the network path, abuse legitimate authentication flows, steal cloud tokens, then use malware only where it helps persistence or collection. For small teams, the biggest risk is assuming this is only a nation-state problem. The tradecraft will not stay rare. Once adversaries prove a captive portal pattern works, criminal groups can reuse the concept against executives, finance staff, engineers, lawyers, and cleared contractor personnel on travel.
The practical move is to treat travel networks as hostile by default. Force traffic through trusted security controls, reduce dependence on phishable authentication, and build detections around device-code use, token theft, and new cloud access after travel. If your organization supports remote staff, conference travel, field operations, or government site visits, this belongs in the travel-security checklist now.
Source: Zscaler ThreatLabz — CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals
