Bearing

Bearing

Going on vacation? Pay attention to your hotel Wi-Fi or just avoid it completely, especially in Europe where you don’t pay roaming through the nose. Midnight Blizzard (Russia/SVR) is running a campaign called CaptiveCrunch that compromises hotel and conference Wi-Fi captive portals to deliver malware and steal credentials from travelers. They hijack DNS/HTTP traffic on guest networks to serve fake browser updates (ClickFix) that drop a full-featured Go RAT, plus a PowerShell stealer that grabs browser cookies, M365 SSO tokens, and Wi-Fi creds. They’re also abusing device code auth flows through the same captive portal redirects.

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft… Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels… Microsoft Security Blog