Storm-2945, a sub-cluster of Midnight Blizzard, compromised shared captive portal infrastructure at hospitality venues to manipulate DNS and HTTP traffic, redirecting victims to attacker-controlled infrastructure for Microsoft 365 credential harvesting, device code phishing, and malware delivery. The campaign deploys CornFlake, a Go-based RAT with surveillance and exfiltration capabilities, and ChocoShell, an in-memory PowerShell stealer targeting browser credentials, M365 tokens, and Wi-Fi passwords. Device code phishing abuses the Entra ID authentication flow to bypass conventional MFA.
Midnight Blizzard
3 posts
Midnight Blizzard launches CaptiveCrunch | ThreatLabz 3rd August – Threat Intelligence Report This weekly threat intelligence bulletin covers multiple critical vulnerabilities, active exploitation campaigns, and supply chain attacks. Key items include critical VMware vCenter/ESX flaws (CVSS 9.8) enabling VM escape, a TeamCity On-Premises unauthenticated RCE, and Russia-linked Storm-2945 compromising hotel captive portals to distribute malware harvesting M365/Azure AD tokens. A separate Russian campaign exploited CVE-2026-42897 in Microsoft OWA to deploy the OWAReaper browser implant, and an npm supply chain attack delivered OS-specific RATs via packages mimicking private Alibaba modules.
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft Microsoft Threat Intelligence identifies Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread captive portal traffic manipulation attacks since May 2026 targeting travelers at hospitality venues worldwide. The campaign delivers CornFlake, a Go-based Windows RAT with comprehensive surveillance and credential theft capabilities, and ChocoShell, a PowerShell-based infostealer that bypasses AMSI, employs multiple UAC bypass techniques, and extracts browser credentials via Chrome DevTools Protocol to circumvent Chrome App-Bound Encryption. The operation also integrates device code phishing against Microsoft Entra ID, leveraging AI-augmented social engineering and ClickFix techniques to maximize victim compliance.