ai-cybersecurityvendorNewsThe Broadside2 min read

Midnight Blizzard weaponizes hotel Wi-Fi for malware and credential theft

The SVR-linked crew is now using compromised captive portals to serve malware disguised as browser updates and siphon Microsoft 365 credentials from travelers, and AI is doing much of the operational heavy lifting.


TL;DR

Since early May 2026, Midnight Blizzard sub-cluster Storm-2945 has been compromising captive portal networks at hotels and hospitality venues worldwide, redirecting traveler traffic through actor-controlled infrastructure. The campaign delivers Windows RATs disguised as browser or OS updates via ClickFix prompts, and uses adversary-in-the-middle phishing against Microsoft Entra ID device code flows to steal credentials and session tokens. Microsoft assesses that AI tools supported a significant portion of the operation. Attribution is to Russia's SVR.

The campaign, which Microsoft calls CaptiveCrunch, exploits a vulnerability travelers can't patch: the Wi-Fi login page at their hotel. Once Storm-2945 controls the captive portal, every device that connects to the network hits actor-controlled DNS and HTTP infrastructure. Users trying to get online are served malware under the guise of routine browser or OS updates, or redirected through AitM phishing pages that capture Entra ID device-code authentication flows.

The Windows malware is written in compiled Golang, fully featured remote access trojans capable of system enumeration, file and keystroke collection, credential and session token theft, audio and video surveillance, removable media monitoring, and remote shell access. Microsoft also notes indicators that Android devices may be targeted through similar techniques, though that vector is less fully described.

Microsoft's attribution to Storm-2945 (a sub-cluster of Midnight Blizzard, itself the SVR) rests partly on TTP overlaps with the Forest Blizzard DNS hijacking operation disclosed in April 2026, but the company draws a distinction between the two campaigns. The captive portal compromise vector remains under investigation; Microsoft flags commonalities in equipment and management systems across affected venues that suggest access to shared services within the captive portal ecosystem, not just isolated compromises of individual hotels.

One element that separates this disclosure from the standard Midnight Blizzard advisory is the explicit callout to AI. Microsoft thanks Anthropic and OpenAI for "collaboration and support during this investigation," and states that AI augmented a significant portion of Storm-2945's operations, presumably on the attacker side, though the blog's language leaves room for ambiguity. Either way, it's a notable data point: a state-sponsored actor integrating LLM-based tooling into operational tradecraft, not merely experimenting with it.

For defenders, the operational takeaway is uncomfortable. The attack surface isn't the endpoint or the identity provider, it's the network your employees join when they open a laptop in a hotel lobby. Conditional Access policies that require compliant devices help, but a traveler who downloads and runs a fake Chrome update on a managed laptop has already lost the device. The mitigation section in Microsoft's blog leans heavily on its own Defender product line, as expected, but the structural problem (third-party network infrastructure you don't control, serving traffic to devices you do) doesn't have a clean product fix.


Published ·Deep Fathom