← All briefs
high August 9, 2026

CaptiveCrunch: Storm-2945 Hijacks Captive Portal Traffic for Credential Theft and Malware Delivery

Source report →

Storm-2945 is a sub-cluster of Midnight Blizzard, a Russia-based threat actor linked to the Foreign Intelligence Service. Since early May 2026, it has used access to captive portal infrastructure at hotels, airports, and conference venues as an initial access vector to corporate travelers. Microsoft has not determined how the affected environments were accessed or compromised. When a victim connects to an affected network, the actor can intercept and manipulate the device’s traffic, enabling credential theft or malware delivery. The ultimate objective is access to the traveler’s corporate cloud environment rather than the venue itself. The scale of the activity suggests the actor may have gained access to shared services within the captive portal ecosystem, potentially exposing travelers from any organization using an affected network.

Using the access to captive portal, the actor manipulates DNS and HTTP traffic to redirect victims through actor-controlled systems. Victims may be sent to Microsoft-themed adversary-in-the-middle phishing pages, including device-code lures that trick them into authorizing the actor’s session and granting access and refresh tokens. Alternatively, the actor intercepts automated browser or operating-system connectivity checks to present fake updates, driver-repair notices, or verification prompts that lead to malware execution. Some landing pages also indicate possible Android targeting by instructing users to download and install an APK file. On Windows, the primary payload is CornFlake, a custom Go-based remote access trojan associated with Storm-2945 that establishes multiple persistence mechanisms and supports keylogging, clipboard capture, screenshots, audio and video recording, file theft, system discovery, removable-drive monitoring, and interactive shell access.

Storm-2945 also deploys ChocoShell, an in-memory PowerShell infostealer focused on credential theft. It disables script scanning, checks for sandbox environments, attempts several privilege-escalation techniques, and collects browser cookies and encryption keys, Microsoft 365 and Entra ID tokens, Web Account Manager tokens, Firefox data, and saved wireless credentials. Stolen data is packaged and sent over HTTPS using paths that resemble legitimate web traffic. Operations are managed through FruitStone, a web-based control panel disguised as a cloud infrastructure portal that provides live agent telemetry, campaign configuration, payload customization, obfuscation settings, and management of proxies, beacon profiles, and staging servers.

DOMAIN 4
ms365-device.com
ms365-live.com
m365-owa.com
owa-ms365.com
IP ADDRESS 8
31.57.243.154
38.146.28.75
104.194.159.150
104.145.210.184
38.146.28.132
107.189.26.194
213.145.86.112
192.142.52.31
SHA256 FILE HASH 2
918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593
be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c
FILE NAME 1
svchost32.exe

Detections (10)

Enable detections →

Connect your environment for suggestions and queries personalized to your security telemetry.

  • Service Registry Entry Created for svchost32 or Cloud Sync Service
  • File Written or Process Executed From a Directory Named svchost32
  • Outbound Web Request Matching ChocoShell Command and Control URI Paths
  • User Environment Windir Value Set in the User Registry Hive
  • Sdclt Launched by a Script Host or User Writable Binary
  • WSReset Launched by a Script Host or User Writable Binary
  • Outbound Web Request to a Microsoft 365 Lookalike Registrable Domain
  • Successful Device Code Authentication From a Client or Location Unlike the User's Own Device
  • Executable Delivered Immediately After a Captive Portal Connectivity Check