Russian spies turn public Wi-Fi into malware delivery systems
Microsoft has disclosed that Storm-2945, a subdivision of Russia's SVR foreign intelligence service operating under the Midnight Blizzard umbrella, is compromising public Wi-Fi captive portals at hotels and conference venues to deliver spyware and steal credentials. The campaign, dubbed "CaptiveCrunch," matters because it turns everyday network sign-in pages used by travellers and conference attendees into a covert espionage tool, with Microsoft still investigating exactly how the hackers first gain control of these networks.
Active since at least February 2026, with traffic manipulation observed from early May, the operation manipulates DNS and HTTP traffic to place attackers in an adversary-in-the-middle position, then uses fake update or verification prompts to trick victims into installing malware. Two main tools are deployed: CornFlake, a Go-based Windows remote-access trojan capable of keylogging, screen and audio-visual surveillance, and credential theft; and ChocoShell, an in-memory PowerShell infostealer that harvests browser cookies, passwords and single sign-on tokens. The campaign, which also targets Android devices and uses device-code phishing to hijack Microsoft authentication sessions, has prompted Microsoft to put the hospitality sector on alert.
- Russian SVR hackers hijack public Wi-Fi captive portals to plant malware
- Campaign "CaptiveCrunch" uses CornFlake RAT and ChocoShell infostealer
- Targets hotels, conferences; also uses device-code phishing for account takeover