Summary
Key Points:
- Storm-2945, a sub-cluster of Midnight Blizzard, is conducting targeted traffic manipulation attacks against hospitality sector networks globally, dubbed the CaptiveCrunch campaign.
- The campaign impacts hospitality networks, leading to credential theft and malware delivery via phishing techniques that exploit device code authentication in Microsoft Entra ID.
- Organizations should minimize trust in public Wi-Fi, implement strong identity and access controls, and educate users about phishing tactics.
Technical Details: Storm-2945 uses doppelganger domains for adversary-in-the-middle (AitM) phishing and has delivered malware such as the CornFlake RAT and ChocoShell infostealer. The malware is capable of extensive data collection, including browser credentials and session tokens.
MITRE ATT&CK Techniques:
- T1566.001 - Phishing: Spearphishing Link (Initial Access)
- T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
- T1003.001 - OS Credential Dumping: LSASS Memory (Credential Access)
- T1059.001 - Command and Scripting Interpreter: PowerShell (Execution)
- T1547.001 - Boot or Logon Autostart Execution: Registry Run Keys (Persistence)
IOCs Mentioned:
- ms365-device[.]com
- ms365-live[.]com
- m365-owa
Join the discussion — sign up to comment, upvote, and save articles.