ThinkPatternGet the app
Story
TECHNOLOGY · AUG 2, 2026

Microsoft Corporation Warns of CaptiveCrunch Campaign Targeting Hotel Wi-Fi

Microsoft Corporation identified a Russian-linked hacking campaign called CaptiveCrunch that uses compromised hotel Wi-Fi networks to steal corporate credentials and deploy surveillance malware.

Microsoft Corporation issued a security warning regarding a global hacking campaign named CaptiveCrunch that targets corporate travelers through compromised hotel and guest Wi-Fi networks. The company attributed the activity to Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard. The attackers utilize AI to deploy fraudulent Microsoft 365 sign-in pages, verification checks, and fake software updates to steal credentials and deliver malware.

Technical analysis from Microsoft Corporation and cybersecurity firm ReliaQuest reveals that hackers have been tampering with Wi-Fi gateways in several U.S. cities since at least June 2026. The campaign involves altering Domain Name System settings to redirect users to fake login pages or trick them into approving device code authentication prompts to bypass multifactor authentication. In some cases, attackers abused Web Proxy Auto-Discovery to manipulate network activity.

Microsoft Threat Intelligence identified a remote-access trojan called CornFlake, which can record keystrokes, steal session tokens, and hijack audio and video for surveillance. While primarily targeting Windows PCs, the attackers are also targeting Android devices via APK file installations. The campaign has impacted a broad range of sectors, including financial, legal, health care, energy, and retail services. Security experts recommend that travelers use cellular hotspots or full-tunnel VPNs and disable unnecessary device code authentication.


Reported across 191 outlets
Actors
Microsoft CorporationReliaQuest

Keep reading in the app

The full story and every source, free in the app.

Download on the App StoreComing soonGoogle Play