Microsoft flags renewed attacks on hospitality Wi-Fi networks
The CaptiveCrunch campaign, attributed to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, is again targeting the hospitality sector via hijacked captive portals and abuse of Microsoft Entra ID. Fresh activity was observed on 29 September, two months after Microsoft's initial warning.
- Attacks use manipulated network traffic and captive portals
- Campaign uses domains mimicking Microsoft online services for phishing
- Abuses the device-code authentication flow in Microsoft Entra ID
- Storm-2945's continued access to upstream providers enables rapid re-deployment
Read next
Security