Midnight Blizzard exploits hotel Wi-Fi to steal Microsoft 365 credentials
The Russian hacker group Midnight Blizzard, linked to the country's foreign intelligence service, has exploited public Wi-Fi networks in hotels and conference centers to steal Microsoft 365 credentials and distribute malware. The campaign, dubbed CaptiveCrunch by Microsoft Threat Intelligence, employs two distinct malware: CornFlake and ChocoShell.
Quick Response
- Midnight Blizzard exploits unprotected Wi-Fi networks in hospitality establishments to steal Microsoft 365 credentials
- The CaptiveCrunch campaign uses two malware: CornFlake (RAT) and ChocoShell (credential stealer)
- The attacks exploit DNS and HTTP manipulation to redirect users to phishing pages or malware downloads
- Microsoft recommends avoiding public Wi-Fi and using private or managed connections
Attack technique: DNS and HTTP manipulation
The hackers manipulated DNS and HTTP traffic on compromised captive networks, redirecting users to three main paths. Two of these led to credential theft: phishing pages that mimicked Microsoft 365 access portals and device code phishing pages that exploited Microsoft Entra ID authentication flows.
The third path displayed fake update pages for browsers or operating systems, using the ClickFix social engineering technique to convince victims to download and execute malware. Microsoft also detected configurations for APK file pushes, indicating possible attacks on Android devices.
CornFlake: a multifunctional RAT
CornFlake is a Windows Remote Access Trojan (RAT) written in Go, with advanced capabilities including:
- Keylogging
- Clipboard monitoring
- Screenshot capture
- Audio and video surveillance
- Browser credential theft
- File exfiltration
- USB drive monitoring
- Security posture analysis
- Remote shell access
Upon launch, CornFlake operates in dropper mode, displaying a fake progress window to distract the victim while the binary copies itself to %APPDATA%\svchost32\svchost32.exe and establishes persistence.
ChocoShell: the in-memory credential stealer
ChocoShell is an in-memory malware that steals credentials from browsers, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials. While CornFlake provides a persistent foothold on the device, ChocoShell is designed to extract the most valuable credentials for the operator, providing access to victims' cloud environments.
FruitStone: the unauthenticated web C2 panel
Microsoft discovered FruitStone, a web command and control panel used by Storm-2945 operators to manage the CaptiveCrunch infrastructure. Built as a single-page HTML and JavaScript application without any authentication, it offers:
- A dashboard to manage compromised endpoints
- Tools to build and distribute new payloads
- Functionality to review collected data such as screenshots, keystrokes, and browser credentials
Security recommendations
Microsoft recommends treating hotel and conference Wi-Fi as untrusted, preferring private or managed cellular connections where possible. Organizations should:
- Review information that employees provide to hospitality service providers
- Adopt controls that limit exposure to traffic manipulation, credential theft, and device code phishing
The CaptiveCrunch campaign demonstrates the evolution of attack techniques, with significant use of compromised captive networks to gain persistent access and steal sensitive credentials. Organizations and individual users must remain vigilant when connecting to public Wi-Fi networks, adopting appropriate security measures to mitigate these risks.
Strategic impact and targeted victims
The CaptiveCrunch campaign is not random in its targeting choices. According to Microsoft's analysis, the attacks have focused on European diplomats, IT professionals, and employees of companies with access to sensitive information. The choice of hotels and conference centers reflects a particular focus on international events and business meetings, where the sharing of confidential information is more frequent.
A concerning aspect is the potential compromise of entire captive network ecosystems. Microsoft has found similarities in Wi-Fi network management systems across different locations, suggesting that attackers may have gained access to shared services within this ecosystem. This would imply a systemic risk for all users connecting to these networks, regardless of the specific venue.
Evolution of techniques: the use of AI
Microsoft's analysis reveals that the CaptiveCrunch campaign shows signs of assistance from artificial intelligence tools. This is particularly evident in the optimization of phishing pages and the customization of attacks based on victim profiles. AI would have been used to:
- Dynamically adapt the content of phishing pages based on the victim's browser and operating system
- Analyze browsing patterns to identify the most opportune moments for attack
- Generate custom malicious code for specific cloud environments
This technological integration represents a significant evolution compared to traditional campaigns, increasing the effectiveness of attacks and reducing detection time.
Implications for corporate security
In addition to the initial recommendations, Microsoft has developed a series of specific technical countermeasures to mitigate the risks associated with CaptiveCrunch:
- Implementation of DNS over HTTPS (DoH) to prevent DNS traffic manipulation
- Configuration of conditional access policies to limit the use of sensitive credentials on public networks
- Development of browser extensions that automatically block known phishing pages
- Advanced monitoring of authentication activities to detect anomalous behaviors
Organizations are also invited to conduct security audits of the information shared with hospitality service providers, considering that even seemingly innocuous details can be exploited to customize attacks.
The future of captive networks
The investigation into CaptiveCrunch raises fundamental questions about the security of public Wi-Fi networks. Microsoft suggests that the hospitality industry may need to adopt more stringent security standards, including:
- Implementation of mandatory two-factor authentication for network access
- Network segmentation to separate business users from generic users
- Continuous monitoring of suspicious activities on captive networks
- Collaboration with security service providers to implement protective solutions
The campaign demonstrates how traditionally low-risk network infrastructures can become significant vectors for sophisticated attacks, requiring a complete rethink of security strategies for mobile users.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not perform real-time information activities.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all responsibility for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decision.