Russian state-sponsored threat actor Midnight Blizzard, linked to Russia's foreign intelligence service, has conducted a months-long campaign targeting users of public Wi-Fi networks at hotels and conference centers. Microsoft Threat Intelligence disclosed the operation, which focuses on stealing Microsoft 365 credentials through compromised wireless networks in hospitality and event venues.
Microsoft designated the campaign CaptiveCrunch and identified two distinct malware strains used in the attacks: CornFlake and ChocoShell. The findings build on earlier research published by security firm ReliaQuest on July 23, which first documented aspects of this threat activity. Midnight Blizzard has previously been associated with high-profile espionage operations and continues to target organizations through various attack vectors.
The attack exploits the inherent vulnerabilities of public Wi-Fi networks, which often lack robust security controls. When users connect to compromised networks at hotels or conference venues, the threat actors can intercept authentication attempts and deploy malware to steal credentials. The malware strains work together to establish persistence and exfiltrate sensitive data, particularly targeting Microsoft 365 accounts that provide access to corporate email, documents, and collaboration tools.
The campaign poses significant risks to business travelers and conference attendees who routinely use hotel Wi-Fi for work purposes. Compromised Microsoft 365 credentials can provide attackers with access to sensitive corporate communications, intellectual property, and additional network resources. The targeting of hospitality venues suggests a deliberate strategy to compromise individuals when they are away from their organization's protected networks.
Organizations should educate employees about the security risks of public Wi-Fi networks and establish clear policies for remote access. Security teams should enforce multi-factor authentication for all Microsoft 365 accounts, deploy virtual private network (VPN) solutions for remote workers, and monitor for suspicious authentication attempts from unusual locations. Companies should also consider implementing conditional access policies that restrict access from high-risk network locations and require additional verification steps when users connect from public networks.
Source: https://www.helpnetsecurity.com/2026/08/04/midnight-blizzard-hotel-wi-fi-networks-hacking/


