Back to Newsroom
Threat Intel

Midnight Blizzard Turns Hotel Wi-Fi Sign-In Pages Into a Malware Delivery Channel

A campaign tracked as CaptiveCrunch hijacks hotel and venue Wi-Fi captive portals to push fake update prompts, plant remote-access malware, and hijack Microsoft 365 sessions — turning a routine connectivity check into a corporate credential heist.

Midnight Blizzard Turns Hotel Wi-Fi Sign-In Pages Into a Malware Delivery Channel

What happened

A newly documented campaign, tracked as CaptiveCrunch, hijacks the captive portals — the sign-in pages shown to guests before they get online — on hotel and other venue Wi-Fi networks. Researchers attribute the activity to Storm-2945, an operational sub-cluster linked to the threat actor Microsoft tracks as Midnight Blizzard. Network manipulation was first spotted in May 2026, with renewed activity recorded from September 29 onward, including a newer Rust-based variant of the main implant.

Instead of simply getting online, travelers on affected networks can be silently redirected through infrastructure the attackers control. The altered captive portal then throws up a convincing fake browser or operating-system update screen — a classic "ClickFix" trick that asks the victim to run a command or install a file to "verify" or "fix" their connection.

How the attack works

On Windows, accepting the prompt delivers CornFlake, a remote-access trojan that masquerades as a background "Cloud Sync Service" to blend in and survive reboots. It can harvest files and keystrokes, steal stored credentials and session tokens, capture audio or video, and open a remote command shell for its operator. A companion tool, ChocoShell, runs entirely in memory via PowerShell and focuses on browser cookies, saved passwords, Microsoft 365 single sign-on tokens, and stored Wi-Fi credentials — pulling browser encryption keys and using browser debugging interfaces to read cookies that would otherwise be protected. Both tools take steps to dodge antivirus scanning and sandboxed analysis before exfiltrating data and clearing their tracks.

On Android, the same fake-update pages push victims toward installing a malicious APK instead.

A separate technique layered into the campaign abuses Microsoft's device-code sign-in flow: a victim is shown a genuine Microsoft login page and asked to enter a code, but approving it actually hands the attacker an authenticated session — no password required. Some victims are also redirected to lookalike single sign-on domains for adversary-in-the-middle phishing.

Why it matters

The danger doesn't stop at one infected laptop. A stolen Microsoft 365 session token or a set of saved browser credentials can be reused to reach corporate mail, SharePoint, OneDrive, VPNs, and other cloud services without ever triggering a password prompt — collapsing the distance between "connected to hotel Wi-Fi" and "corporate account compromised." Because captive-portal infrastructure is often shared across many properties and vendors, a single compromise can expose guests across multiple venues and countries rather than one isolated network.

What to do

  • Treat hotel, conference, airport, and other guest Wi-Fi as untrusted by default; prefer a mobile hotspot or other private connection when possible.
  • Never install software or run commands offered by a Wi-Fi captive portal — apply updates only through your operating system's or browser's own update mechanism.
  • If a page asks you to press key combinations and paste something into PowerShell, a Run dialog, or a terminal, stop — that is the ClickFix pattern, not a real verification step.
  • Organizations should block managed devices from joining unapproved Wi-Fi where feasible, and issue travel routers or hotspots that connect only to trusted, encrypted infrastructure.
  • Never reuse corporate credentials on a guest-network registration page.
  • Adopt passkeys or phishing-resistant multifactor authentication, restrict device-code sign-in to cases that genuinely require it, and apply sign-in risk policies that challenge or block unusual access.
  • Security teams should hunt for unexpected downloads following connectivity checks, illegitimate "Cloud Sync Service" processes, and other CornFlake/ChocoShell artifacts on endpoints that recently used public Wi-Fi.
SHARE