Cybersecurity

CaptiveCrunch: The Russian Hack That Turns Hotel Wi-Fi Into a Credential Trap — What Summer Travelers Must Know

Microsoft has named the campaign: CaptiveCrunch. Russian hackers are hijacking hotel and airport Wi-Fi captive portals to steal your login credentials and install malware on your device. Here's exactly what the attack looks like — and 5 concrete steps to protect yourself this summer.

What's new since our earlier coverage: Our August 4 post introduced the threat at a high level. Since then, Microsoft published its full Security Blog analysis on July 31, naming the campaign CaptiveCrunch, identifying the specific malware strains involved, publishing a list of fake dialog boxes being used as lures, and confirming Android devices are also being targeted. This post covers all of that new detail.


You pull into the airport, connect to the free Wi-Fi, and get that familiar captive portal screen asking you to agree to the terms before you can browse. Nothing looks weird. You tap through, open your email — and somewhere in the background, Russian intelligence hackers just stole your Microsoft login.

That's not a hypothetical. It's a campaign Microsoft has now officially named CaptiveCrunch, and it's been running since at least early May 2026.

What Is CaptiveCrunch?

According to the Microsoft Security Blog, a threat actor sub-cluster called Storm-2945 — linked to the broader Midnight Blizzard group, which the US and UK governments have attributed to the Russian Foreign Intelligence Service (SVR) — has been conducting widespread traffic manipulation attacks on hospitality-sector Wi-Fi networks worldwide.

The mechanics are precise: attackers manipulate DNS and HTTP traffic flowing through hotel, conference center, and airport captive portal networks. From that position in the network path, they can do several things simultaneously:

  • Redirect your browser to attacker-controlled phishing pages that look exactly like Microsoft login screens, harvesting your credentials, device codes, and OAuth tokens.
  • Push fake software dialogs that trick you into downloading malware.
  • Silently proxy your traffic through their own infrastructure, intercepting anything that flows through it.

As Malwarebytes describes it, from the user's perspective nothing looks out of the ordinary — you connect to hotel Wi-Fi, you see the usual captive portal prompt, and maybe a familiar-looking message saying you need to update something before you can browse. That "update" is actually malware.

The Malware They're Installing

Microsoft researchers have identified two specific malware strains in active use. The first, called CornFlake, is a fully-featured remote access trojan (RAT) built in compiled Golang. According to Microsoft's analysis, CornFlake can capture webcam images, record microphone audio, log keystrokes, collect files, steal credentials and session tokens, monitor removable media, and give attackers a live remote shell on your machine.

The second, ChocoShell, is a fileless PowerShell-based infostealer that, per Malwarebytes, goes specifically after browser session cookies, saved passwords, Microsoft 365 Single Sign-On (SSO) tokens, and Wi-Fi credentials from compromised systems. "Fileless" means it runs in memory — making it harder for traditional antivirus tools to catch.

Microsoft also notes that Storm-2945 has been observed using AI to support a significant portion of these operations, representing another escalation in attacker sophistication.

The Fake Dialogs to Watch For

One of the most useful things Microsoft published in this report is a list of specific fake dialog boxes Storm-2945 uses to trick travelers into downloading malware. Malwarebytes has compiled them:

  • A bogus Windows Update window ("Working on updates… Don't turn off your computer.")
  • A fake Windows Security virus scan mimicking Microsoft Defender
  • A DirectX End-User Runtime Web Installer prompt
  • A Microsoft Visual C++ redistributable installer
  • A disk optimization utility
  • A Windows Network Diagnostics "fix" tool
  • A browser update prompt
  • A PDF viewer installer

These are ClickFix-style lures — and they're convincing precisely because they look like things Windows actually does. Some versions even add countdown timers or fake "user counters" to pressure you into acting fast.

The rule here is simple: you should never have to download anything just to log into Wi-Fi. If a captive portal asks you to install software, a certificate, or an "update" before you can connect, stop and close it.

Android Users Are Targeted Too

This isn't just a Windows problem. Microsoft's Security Blog notes that the ClickFix landing pages also include instructions for Android devices to download and install an APK file. If you travel with an Android phone and use hotel Wi-Fi, the same cautions apply.

5 Concrete Steps to Protect Yourself

Whether you're traveling for business or summer vacation, here's how to stay safe:

1. Use your phone's mobile hotspot instead. This is the single most effective protection. Microsoft explicitly warns travelers to "treat hotel, conference, airport, and other guest wireless networks as untrustworthy" and to opt for private connections whenever possible. An eSIM from a reputable carrier is particularly convenient for international travel.

2. If you must use public Wi-Fi, use a reputable paid VPN with a Kill Switch. Malwarebytes recommends completing the captive portal authentication first, then immediately launching your VPN before opening any app or website. The Kill Switch feature blocks all traffic if the VPN drops for even a second — closing the window attackers need. Avoid free VPNs, which carry their own risks.

3. Never download software, certificates, or "update" prompts from a captive portal. Microsoft is explicit on this point: do not download anything presented through public Wi-Fi captive portals or web prompts. Any dialog asking you to install something before you can browse is a red flag.

4. Don't enter high-value credentials through captive portal redirects. Malwarebytes advises avoiding entering Microsoft 365, Google Workspace, or other corporate credentials into any page reached via captive portal redirection. If you need to check work email, navigate directly to the URL you know — don't click through prompts.

5. Enable multi-factor authentication (MFA) on all important accounts — and keep devices updated before you leave. MFA won't stop an OAuth token theft completely, but it dramatically raises the cost of account takeover. And updating your browser, operating system, and apps before you travel means you won't be tempted by legitimate-looking update prompts while you're on the road.

A Note on How Deep This Goes

One of the more unsettling details in Microsoft's report is that investigators still don't fully know how the attackers are getting into these captive portal networks in the first place. PCWorld notes that Microsoft has observed "notable commonalities in the equipment and management systems used across multiple affected networks" — suggesting the compromise may involve shared services within the captive portal ecosystem, not just individual hotels being hacked one at a time. In other words, this could be broader than it first appears.

Bottom Line for Travelers This Summer

CaptiveCrunch is a sophisticated, state-sponsored campaign that exploits the one moment almost every traveler lets their guard down: logging into hotel Wi-Fi. The fix isn't complicated — use your phone's hotspot, get a paid VPN, and never install anything a captive portal asks you to install.

If you've recently connected to public Wi-Fi on a business trip and something felt off — an unexpected update prompt, a slow login, a browser behaving strangely — it may be worth having your device checked for signs of infection. We're here at Computer Works if you'd like a virus removal assessment.

Related local service
Worried this could be malware?
If your computer has pop-ups, redirects, suspicious downloads, or ransomware warnings, start with our local virus removal page.
Tags
cybersecurity vulnerability windows-security microsoft web-security
Call Now