- Sources: primary, discussion
- Summary: Microsoft Threat Intelligence attributes the CaptiveCrunch campaign to Storm-2945, a sub-cluster it places under Midnight Blizzard. The report describes manipulation of DNS and HTTP traffic on captive-portal networks since early May 2026, delivering a Windows remote access trojan written in Go with keylogging, credential and session-token theft, and audio and video capture, and the same landing pages carry instructions for installing an Android APK. It names no affected software or versions, and states that the investigation into how the captive-portal networks were first compromised is ongoing, noting only commonalities in equipment and management systems across affected networks.
- Why it matters: An engineer on hotel or conference Wi-Fi is in the targeted population, and the named controls are refusing browser-prompted updates on captive-portal networks and blocking the device code authentication flow in Entra ID.
- Follow-up: Track whether Microsoft identifies the initial compromise vector for the affected captive-portal networks.
send feedback on this story