CaptiveCrunch: Midnight Blizzard Targets Public Wi‑Fi to Steal Microsoft 365 Credentials
Midnight Blizzard's CaptiveCrunch campaign hijacks public Wi-Fi captive portals to steal Microsoft 365 credentials using device code phishing and custom malware tools.
Illustrative image generated with AI
Attribution and Threat Profile
Microsoft has confirmed that CaptiveCrunch is the work of Storm‑2945, a subgroup of Midnight Blizzard (APT29, Cozy Bear), known for its ties to the Russian Foreign Intelligence Service (SVR). ReliaQuest’s intelligence team reported the activity in late July 2026 and, in coordination with the Microsoft Threat Intelligence Center, was able to confidently attribute the campaign to this specific cluster. Some tactical similarities with FrostArmada (APT28) initially complicated attribution.
The infrastructure used has been active since at least May 2026, when attackers began tampering with DNS and HTTP traffic directed to captive portals of hotels, conference centers, and co‑working spaces. The goal was never mere disruption, but the silent interception of Microsoft 365 credentials and access tokens.
Attack Chain: From SOHO Routers to Device Code Phishing
The campaign unfolds in three main stages.
Router Compromise. Attackers seized control of SOHO (Small Office/Home Office) devices by modifying their DNS configurations. Since around July 28, ReliaQuest observed routers from undisclosed brands redirecting connected users to an adversary‑in‑the‑middle (AitM) infrastructure. When a guest attempted to authenticate to a legitimate captive portal, their traffic was routed to a controlled server that intercepted Microsoft 365 usernames, passwords, and session tokens.
Evolution with Device Code. From mid‑July 2026, attackers added a second technique: fake portals presenting a device code authentication flow. The victim receives an alphanumeric code and an invitation to enter it at microsoft.com/devicelogin, a legitimate Microsoft page. Once authorization is completed, the malicious actor obtains a valid session token without ever seeing the password. Midnight Blizzard has been using this ruse since at least August 2024.
Malware Distribution. To extend control, ClickFix techniques are exploited: fake browser update warnings push the user to download an executable. On Android, the same screen leads to the installation of a malicious APK. In this way, attackers deploy deeper implants.
The Software Arsenal: CornFlake, ChocoShell, and FruitStone
The CaptiveCrunch campaign brings three custom tools.
- CornFlake is a Remote Access Trojan written in Go for Windows. It performs reconnaissance, steals saved credentials and tokens, collects files and keystrokes, activates the microphone and webcam, and offers a remote shell.
- ChocoShell is a PowerShell‑based infostealer. It is used for rapid pilfering of credentials and session data when the prolonged execution of CornFlake is unnecessary or impossible.
- FruitStone serves as a web‑based command‑and‑control panel. It allows operators to manage infected machines in a centralized manner.
All three are new, attributable to Midnight Blizzard’s toolkit, and have not yet been observed in campaigns by other groups.
Who Was Targeted and What Damage Was Incurred
The most targeted sectors are financial services, professional and legal firms, healthcare, energy, and retail. Victims are largely employees on business travel forced to connect to public Wi‑Fi networks.
The documented impact includes:
- unauthorized access to mailboxes, documents, and business applications on Microsoft 365;
- exfiltration of confidential files and communications;
- potential lateral movement to internal corporate systems through stolen tokens;
- audio/video surveillance via CornFlake, capturing recordings that could include protected meetings or private conversations.
The risk grows further for international travelers, less protected by corporate safeguards and more reliant on makeshift connections.
How to Defend
The Microsoft report does not describe custom countermeasures for CaptiveCrunch, but the nature of the attack points to some immediate priorities.
- Apply firmware updates to routers and home or travel network devices without delay. Manually check that DNS settings have not been altered.
- Monitor anomalous DNS queries from corporate endpoints and, where possible, enforce the use of trusted DNS resolvers.
- Restrict the device code authentication flow to only indispensable scenarios. Microsoft 365 allows this via policy. Blocking it where not needed cuts the stealthiest channel of this campaign.
- Train users never to enter codes on login pages unless they have verified legitimacy with IT administration. The same applies to any prompt to download updates from pop‑ups.
- Prohibit the execution of unsigned or unknown‑source software, especially on devices that access corporate data.
Sources
This article is an original reworking based on the sources below.




