Yaamlabs

Identity

CaptiveCrunch is back: hotel Wi-Fi attacks on travellers resume

Microsoft says Midnight Blizzard's Storm-2945 resumed hijacking hotel Wi-Fi on September 29. What changed, and what to set in Entra before staff travel.

On October 5, Microsoft updated its CaptiveCrunch report to say that Storm-2945 resumed the campaign on September 29. Storm-2945 is a sub-cluster of Midnight Blizzard (also tracked as APT29), the group the US and UK governments attribute to Russia's Foreign Intelligence Service (SVR). The campaign hijacks hotel and other guest Wi-Fi at the captive portal, the page that asks you to accept terms or enter a room number, and uses that position to push malware and phishing at whoever connects.

Microsoft first described the activity on July 31, after watching it since early May. Its update says multiple hospitality managed service providers (MSPs) appear to be involved and that Storm-2945's continued access to those upstream providers is the likely reason it could come back so quickly. ReliaQuest, which first reported part of the activity on July 23, found compromised gateways in several US cities, India and Saudi Arabia, saw traffic from financial services, professional services, legal, health care, energy and retail employees, and concluded that the target is travelling staff in general. If your people work from hotels or conference centres, the controls below belong in place before their next trip.

How it works

When a laptop or phone joins a network, the operating system and browser make a plain HTTP request to a known address (Windows uses its Network Connectivity Status Indicator, NCSI, against hosts such as msftconnecttest.com). On a captive portal network the gateway intercepts that request and redirects it to the sign-in page. Because that interception is normal, users expect a page they did not ask for, which makes a compromised gateway an ideal place for an attacker.

Storm-2945 controls DNS and HTTP answers on those gateways. Microsoft describes three outcomes. The first is a ClickFix page, a fake update or verification prompt (Windows Update, Defender scan, DirectX, a browser update) telling the user to paste and run a command, which installs malware. The second is an adversary-in-the-middle (AiTM) page, a proxy that relays a real Microsoft 365 sign-in and keeps the session cookie. The third sends the user to the genuine Microsoft device code page with a code the attacker requested, so the user's own MFA approves the attacker's session. We covered device code phishing in detail in our EvilTokens post, and AiTM session theft in our post on TA419.

ReliaQuest also saw attempts to abuse WPAD, the Windows Web Proxy Auto-Discovery feature, in about a third of the cases it examined. A device that looks up a proxy configuration on a hostile network can be told to send far more than its sign-in traffic through the attacker. ReliaQuest could not confirm those attempts succeeded.

What the malware does

CornFlake is a Windows remote access trojan (RAT), originally written in Go. Its dropper shows a fake progress window while it copies itself to %APPDATA%\svchost32\svchost32.exe, then registers a Windows service, Run keys, scheduled tasks and a watchdog that restores any persistence a defender removes. It logs keystrokes, takes screenshots, records from the microphone and webcam, steals browser credentials and session tokens, watches USB drives and gives the operator a remote shell.

ChocoShell is a PowerShell stealer that runs in memory. It goes after browser cookies and saved passwords, Microsoft 365 access and refresh tokens from the Windows Token Broker cache, and saved Wi-Fi passwords. Those broker tokens let an attacker replay a single sign-on session without needing a browser cookie at all.

The new detail in the October update is a Rust variant of CornFlake, which Microsoft says shows continued AI-assisted malware development. Microsoft also says how the portal networks were first compromised is still under investigation, and ClickFix pages carried instructions for installing an Android APK, so phones are in scope too.

What to do

1. Close the identity routes in Entra ID

  • Block device code flow. In the Microsoft Entra admin center go to Entra ID > Conditional Access > Policies > New policy, include all users (exclude break-glass accounts), target all resources, then under Conditions > Authentication flows select Device code flow and grant Block access. Run it in report-only mode first to find the few accounts with a real need.
  • Require a compliant or Entra-joined device for Microsoft 365 access. A session phished through AiTM or device code then starts on a machine the attacker controls, which fails that check.
  • Turn on token protection (a Conditional Access session control) for Exchange Online, SharePoint Online and Teams. It accepts only sign-in tokens bound to the registered device, which is what makes ChocoShell's stolen broker tokens hard to replay elsewhere. Support depends on platform and app, so check Microsoft's supported list and pilot it in report-only mode with a group of travellers first.
  • Move travellers and administrators to passkeys or other phishing-resistant MFA, and add a sign-in risk policy that blocks or challenges medium and high risk sign-ins.

2. Change how staff connect on the road

ReliaQuest's advice is an always-on, full-tunnel VPN with no split-tunnel exceptions, so DNS and sign-in traffic go to corporate resolvers whatever the hotel network says, and internet access stays blocked until the tunnel is up. Microsoft adds managed travel routers or hotspots that tunnel back to corporate infrastructure, and recommends mobile data over guest Wi-Fi where practical. Disable WPAD on managed Windows devices that do not need it.

Tell travellers that a captive portal never needs them to install an update, a certificate or a tool, and never asks them to open PowerShell, Terminal or a Run box.

3. Check whether you were hit

  • In Entra sign-in logs, filter Authentication protocol to Device code. In Log Analytics, SigninLogs | where AuthenticationProtocol == "deviceCode" returns the same set; look hardest at successful sign-ins with no device ID and at dates when the user was travelling.
  • Search endpoints for any file or process at \svchost32\svchost32.exe under a user's AppData folder. Microsoft's report includes Defender hunting queries for that path and for the service CornFlake registers, plus one that flags executables and archives written shortly after a connectivity check.
  • Match your DNS and proxy logs against the indicators in Microsoft's report, which it updated on October 5 with new redirect domains and IP addresses first seen from September 29.

4. If you find something

Revoke the user's sessions and refresh tokens (Entra admin center, or Revoke-MgUserSignInSession), then reset the password from a trusted device. Rebuild the laptop rather than cleaning it, because CornFlake is built to restore its own persistence. Remove any device registered to the user in Entra ID that they do not recognise, and check the mailbox for new rules and forwarding.

The wider lesson

Many companies call hotel Wi-Fi untrusted in policy, yet let laptops talk to it unfiltered while the portal page loads, and that window is all Storm-2945 needs. Controls that hold on any network, such as Conditional Access and a tunnel that comes up first, protect travellers better than reminders about public Wi-Fi.

Our safeguarding and hardening work reviews Conditional Access, device code exposure and VPN settings for travelling staff, and our security operations team hunts for device code sign-ins and implants like CornFlake. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.


Sources: Microsoft Threat Intelligence, CaptiveCrunch (updated October 5, 2026), eSecurityPlanet, iTnews, ReliaQuest, Zscaler ThreatLabz, Microsoft Learn: block authentication flows, Microsoft Learn: token protection.

Back to the blog, or read this post on the full site.