
Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens in CaptiveCrunch Campaign
APTBreakingNewsHackingIntelligenceMalwareSecurityAPT29CaptiveCrunchCyberespionageHackingNewsHotelWi-FiInformationSecurityNewsITInformationSecurityMidnightBlizzardRussiaSecurityAffairsSecurityNewsStorm-2945
Microsoft Threat Intelligence identified a campaign called CaptiveCrunch, attributed to Storm-2945, a sub-cluster of the Russian SVR-linked group Midnight Blizzard (also known as APT29 or Cozy Bear). The threat actors hijacked hotel Wi-Fi portals to distribute malware and steal Microsoft 365 tokens from travelers. The campaign has been active since early May 2026, involving DNS manipulation to redirect victims. No specific CVEs or additional technical attack vectors were disclosed in the report. The primary impact involves unauthorized access to corporate and personal accounts via stolen authentication tokens.