← Back to news

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Microsoft Security Blog31/07/2026, 21:01
Read full article →

Summary

AI-Generated

Key Points:

  • Storm-2945, a sub-cluster of Midnight Blizzard, is conducting targeted traffic manipulation attacks against hospitality sector networks globally, dubbed the CaptiveCrunch campaign.
  • The campaign impacts hospitality networks, leading to credential theft and malware delivery via phishing techniques that exploit device code authentication in Microsoft Entra ID.
  • Organizations should minimize trust in public Wi-Fi, implement strong identity and access controls, and educate users about phishing tactics.

Technical Details: Storm-2945 uses doppelganger domains for adversary-in-the-middle (AitM) phishing and has delivered malware such as the CornFlake RAT and ChocoShell infostealer. The malware is capable of extensive data collection, including browser credentials and session tokens.

MITRE ATT&CK Techniques:

  • T1566.001 - Phishing: Spearphishing Link (Initial Access)
  • T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
  • T1003.001 - OS Credential Dumping: LSASS Memory (Credential Access)
  • T1059.001 - Command and Scripting Interpreter: PowerShell (Execution)
  • T1547.001 - Boot or Logon Autostart Execution: Registry Run Keys (Persistence)

IOCs Mentioned:

  • ms365-device[.]com
  • ms365-live[.]com
  • m365-owa

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.