Microsoft has linked a global cyber-espionage campaign targeting hotel and conference center Wi-Fi networks to the Russian state-backed hacking group Midnight Blizzard, also known as APT29.
The company says the operation, tracked as CaptiveCrunch, has been active since at least May, with related phishing activity dating back to February.
According to Microsoft’s investigation, the attackers compromise Wi-Fi infrastructure by altering DNS and HTTP settings on captive portal devices, allowing them to intercept internet traffic. Victims connecting to affected hotel or conference Wi-Fi networks can be redirected to fake Microsoft 365 login pages or fraudulent Microsoft Entra device code authentication screens designed to steal account credentials. Since July, Microsoft has also observed the hackers using fake browser and operating system update pages that trick users into installing malware through ClickFix prompts.
The campaign also introduces two previously undocumented malware families named CornFlake and ChocoShell. CornFlake is a Go-based remote access trojan that provides attackers with persistent access to infected Windows systems. It can record keystrokes, monitor the clipboard, capture screenshots, activate microphones and webcams, steal browser passwords, cookies and Microsoft 365 session tokens, monitor USB devices, collect system information, and exfiltrate files. To avoid suspicion, the malware displays fake Windows update or security scan screens while installing itself and disguises itself as a legitimate Windows service called “Cloud Sync Service.” It also uses multiple persistence techniques to ensure it remains active even if one method is removed.
ChocoShell is an in-memory PowerShell malware focused on stealing sensitive credentials, including browser cookies, saved passwords, Microsoft 365 and Azure Active Directory tokens, and stored Wi-Fi credentials. Microsoft also discovered an exposed web-based management panel used by the attackers to manage compromised devices, browse stolen files, execute PowerShell commands, capture screenshots, and log keystrokes.
Microsoft believes the malware may have been partially developed with the assistance of AI tools based on extensive comments found within the code. The company recommends treating hotel and conference Wi-Fi networks as untrusted, using mobile data or managed VPN connections whenever possible, avoiding software updates offered through captive portals, enabling phishing-resistant authentication such as passkeys and multi-factor authentication, disabling Microsoft Entra device code authentication when unnecessary, and avoiding the use of corporate credentials when registering for guest Wi-Fi access.





