← All Incident Reports
Incident report · TESSOC: Cyber / Espionage
Shaping activity - Phase Zero · Probing

CaptiveCrunch: the hotel Wi-Fi as a collection point

A Russian state cyber-espionage cluster has been taking administrative control of hotel Wi-Fi, forging the answers the network gives to guests' laptops, and using that position to serve fake update prompts that install a remote access trojan and steal authentication tokens.

The target is not the hotel. It is the traveller - and specifically the government, diplomatic and corporate traveller who has to connect to something when they arrive.

↓  Download one-page brief (PDF)
Who
Actor: tracked by Microsoft as Storm-2945, which Microsoft holds to be an operational sub-cluster of Midnight Blizzard, also known as APT29 and Cozy Bear. The UK's National Cyber Security Centre and international partners hold that APT29 is almost certainly part of Russia's Foreign Intelligence Service (SVR); the US and UK governments attribute the broader actor to the SVR. The link between this specific campaign and Storm-2945 is Microsoft's own attribution and has not been independently corroborated in public reporting. Casualties: none.
What
A traveller-targeting espionage campaign Microsoft names CaptiveCrunch. Compromised hospitality Wi-Fi is used to manipulate traffic and deliver malware: a Go-based Windows remote access trojan called CornFlake, and credential and token theft through a companion component.
Where
Hospitality-sector networks served by captive portals, described by Microsoft as worldwide. Midnight Blizzard's established targeting is governments, diplomatic entities, non-governmental organisations and IT service providers, chiefly in the United States and Europe.
When
Microsoft has observed the traffic manipulation since early May 2026. ReliaQuest reported a portion of the activity on 23 July 2026. Microsoft published its findings on 31 July 2026, with wider coverage on 1 August.
Why
Access to the accounts of corporate and official travellers, in support of longstanding SVR intelligence collection. Travellers are the route to the institutions they work for.
How
On the compromised networks investigated, the captive-portal gateway also acted as the DNS resolver handed to connected devices. Administrative control of that gateway let the attackers forge DNS answers and redirect traffic - including a laptop's automatic connectivity check - to a fake browser or operating-system update. The initial route into the gateway itself remains under investigation.
What happened
1

The guest connects, and the network answers

A captive portal is the page that intercepts a device when it joins a public network. On the networks examined, that same gateway was also the DNS resolver - the service that turns a name into an address. Whoever controls it controls what the device is told.

2

The connectivity check is redirected

Every laptop quietly checks whether it really has internet access when it joins a network. With forged DNS answers, that automatic check can be pointed at attacker-controlled content instead, without the user typing anything or clicking a link.

3

A convincing update prompt

The guest is shown what appears to be a browser or operating-system update. Microsoft describes CornFlake operating first as a dropper, displaying a fake progress window - one build option shows a Windows Update screen reading "Working on updates" - while it copies itself into place.

4

Persistence disguised as a normal service

The implant registers as a Windows service using a name and description chosen to resemble ordinary cloud synchronisation software, so that a glance at the running services list shows nothing unusual.

5

Collection, and the move to accounts

CornFlake is a full-featured remote access trojan with data collection and anti-detection capabilities. Alongside it, the campaign abuses the device-code authentication flow in Microsoft Entra ID through look-alike domains mimicking Microsoft online services, taking the operation from one laptop to the accounts behind it.

Impact
Individual
A traveller's laptop is compromised on arrival, through an action - joining the hotel Wi-Fi - that the job requires and that no policy realistically forbids.
Institutional
The value is not the device. Stolen session tokens and abuse of the device-code authentication flow give access to corporate, government and diplomatic accounts, which is where the intelligence actually sits.
Remediation
Token theft and session abuse do not respond to a password change in the way most incident plans assume. This is the same structural problem as the Exchange OWA campaign, arriving by a different door.
Sector
Hospitality networks are now an exploited link in the chain between an organisation and its own people. Hotels and conference venues carry a risk they have no visibility of and no reason to expect, and the guests carry the consequence.
Where this sits in the pattern
Apr 2026

Forest Blizzard router hijacking

Microsoft disclosed a separate Russian DNS hijacking operation in April 2026. It notes the similarity in technique while attributing CaptiveCrunch to Storm-2945 rather than to that actor.

23 Jul 2026

ReliaQuest reports part of the activity

Doppelganger domains mimicking Microsoft online services, used for follow-on adversary-in-the-middle phishing that abuses the Entra ID device-code flow.

31 Jul 2026

Microsoft publishes CaptiveCrunch

The traffic manipulation, the CornFlake implant and the campaign infrastructure are set out in full.

The technique is not new, and that is the point worth carrying. Hostile-state exploitation of untrusted public and hotel Wi-Fi against travelling officials has been a documented concern for years. What has changed is industrialisation: this is the same idea run at the DNS level, across the hospitality sector, with purpose-built malware and a management console behind it.

Assessment
1

The user did nothing wrong, and that is the design

There is no phishing email to spot and no link to avoid. The victim joins a hotel network and accepts what looks like a routine update. Any control that depends on the traveller behaving well has already been bypassed, which is the same conclusion as the half-click exploitation in the Exchange campaign and points the same way: technical controls, not awareness alone.

2

Attribution is layered, and the layers carry different weight

Two separate claims sit inside this case and should not be collapsed into one. That APT29 is almost certainly part of the SVR is a government attribution, held by the NCSC and partners. That this particular campaign belongs to a sub-cluster of that actor is Microsoft's assessment, and public reporting notes no independent technical corroboration of that link. The first is firmer than the second.

3

The initial compromise is unexplained

How the gateways were taken in the first place has not been established. ReliaQuest holds, with low to medium confidence, that exposed management interfaces and weak or reused administrator credentials may have provided access, while noting that visibility constraints prevented confirmation. Until that is resolved, no venue can be confident it is not affected.

4

Travel is the exposure, and it is predictable

The population at risk is defined by behaviour rather than seniority: whoever travels, stays in hotels and attends conferences. Those movements are often published in advance, which makes the targeting straightforward - the same principle as the public naming of the target at Damietta, applied to people rather than infrastructure.

5

The requirement is durable and the method is cheap

A compromised gateway serves every guest who connects. It is almost certain that Russian state actors continue to target travelling officials and executives through the networks they depend on abroad, and likely that untrusted public Wi-Fi remains a preferred route for as long as organisations permit direct connection to it.

The comparison worth making

At Akrotiri a person is accused of standing outside a base and watching it. Here the adversary owns the network your staff connect to the moment they land. Both are collection against people who are simply doing their jobs - but this one scales to every guest in the building, and asks nothing of them but arrival.

What should carry
  • Require a VPN before anything else on any network you do not control. A tunnel established before general traffic flows removes the value of controlling the local resolver. This is the single most effective measure available against this technique.
  • Prefer a mobile hotspot to hotel Wi-Fi for travelling staff. Cellular tethering avoids the captive portal entirely, and the cost is trivial against the exposure.
  • Tell staff that software updates are never delivered by a hotel network. A prompt to update a browser or operating system immediately after connecting is the signature here, and it is a simple, memorable rule.
  • Treat session tokens as credentials in incident response. Revoking sessions and tokens is a separate action from resetting a password, and this campaign turns on exactly that distinction.
  • Scrutinise device-code authentication. The Entra ID device-code flow is abused here; restrict or monitor it, and alert on sign-ins that use it from unexpected locations.
  • Build travel into the security brief, not just the expenses policy. Where people are going, when, and what they carry are protective-security questions for any organisation whose staff travel to conferences or negotiations.
Sources

Compiled from open-source reporting for professional security discussion. Attribution of this campaign to Storm-2945 is Microsoft's, and public reporting notes that no separate technical report has independently corroborated the link; the attribution of the broader APT29 actor to Russia's SVR is held by the UK and US governments. Details may be revised as investigation continues. This is a protective-security lessons-learned assessment, not an operational account, and is not a substitute for vendor guidance.