Microsoft has issued a cybersecurity warning about a hacking campaign named "CaptiveCrunch" targeting public Wi-Fi networks at hotels, airports, and conference centers worldwide since May 2026 [1, 2, 3, 4, 5, 6, 7]. The campaign is conducted by Storm-2945, a Russian state-sponsored hacker group linked to Midnight Blizzard (also called APT29 or Cozy Bear) and Russia's SVR intelligence agency [1, 2, 3, 4, 8, 5, 6, 7].

The attackers infiltrate Wi-Fi networks, especially those requiring users to log into captive portals to access the internet. They manipulate login pages and DNS or HTTP traffic to redirect victims to phishing websites or fake update and authentication prompts [9, 5, 6, 7]. These spoofed pages impersonate legitimate Windows updates, Windows Defender scans, browser updates, PDF readers, disk optimization tools, and Google verification screens to lure users into downloading malware [1, 2, 3, 4, 8, 5, 6, 7].

The malware steals sensitive data including passwords, browser cookies, documents, keystrokes, screenshots, microphone and camera feeds, clipboard contents, and allows remote control of devices [1, 2, 3, 4, 8, 5, 6, 7]. Two main malware strains have been identified: "CornFlake," a remote access Trojan with spying capabilities, and "ChocoShell," which targets Microsoft 365 and Azure AD tokens as well as Wi-Fi passwords [5, 6, 7].

The hackers exploit Microsoft’s Device Code authentication flow to access Microsoft 365 accounts without passwords and bypass multi-factor authentication (MFA), according to Microsoft Threat Intelligence, which publicly disclosed the campaign on August 1, 2026 [8, 6, 7]. Both Windows PCs and Android devices are targeted [8, 5, 6, 7].

Security firms such as ReliaQuest have observed compromised hotel Wi-Fi networks in the US, India, Saudi Arabia, and other countries [8, 5, 6, 7]. Microsoft urged travelers to avoid connecting to public Wi-Fi networks at hotels, airports, and conference centers. "We strongly recommend that travelers avoid connecting to public Wi-Fi networks at hotels, airports, and conference centers and instead use mobile hotspots or personal networks whenever possible," the company said [1]. Users are advised not to enter credentials on suspicious pages or perform downloads and updates via captive portals, and to enable MFA wherever possible [1, 2, 3, 4, 9, 8, 5, 6, 7].