TL; DR
CaptiveCrunch abuses compromised hotel and public Wi-Fi infrastructure to redirect travelers toward fake updates, malware, and device code phishing. The campaign shows why enterprises must secure roaming endpoints, configure trusted VPN access, monitor suspicious execution, enforce device compliance, and train employees to distrust software prompts delivered through captive portals.
CaptiveCrunch turns an ordinary hotel Wi-Fi connection into an endpoint and identity attack path. Microsoft identified the campaign after attackers manipulated captive portals and network traffic at hospitality venues to redirect travelers toward fake browser updates, operating-system prompts, malware downloads, and Microsoft authentication flows.
Microsoft attributes the activity to Storm-2945, which it assesses as an operational sub-cluster of Midnight Blizzard. The campaign has targeted travelers across multiple countries since at least May 2026.
Unlike a conventional phishing email, CaptiveCrunch reaches victims through network infrastructure they expect to use. A traveler may connect to legitimate hotel Wi-Fi but still encounter attacker-controlled content before accessing the wider internet.
Strengthen Endpoint Security with Hexnode UEM
How CaptiveCrunch manipulates hotel Wi-Fi
Public and hospitality networks often use captive portals to display login, payment, or terms-of-service pages. Devices may also perform automatic connectivity checks to determine whether the network provides internet access.
CaptiveCrunch operators gain administrative access to, or otherwise manipulate, captive portal gateway infrastructure. They can then forge DNS responses or redirect HTTP and connectivity-check traffic toward attacker-controlled pages. These pages imitate browser updates, operating-system updates, security tools, or Microsoft sign-in workflows.
The fake update path relies on social engineering. Victims may download a malicious file or follow instructions that execute attacker-supplied commands. Because the prompt appears immediately after joining a hotel network, users may assume the update is necessary to complete the connection.
Top 10 Cybersecurity Challenges for Enterprises
Explore the top cybersecurity challenges enterprises face and practical strategies to reduce cyber risk.
CornFlake delivers persistent surveillance capabilities
One of the campaign’s main payloads is CornFlake, a Go-based Windows remote access trojan. Microsoft describes it as a persistent implant that gives attackers extensive control over a compromised endpoint.
CornFlake can establish persistence through mechanisms such as services, Registry Run keys, scheduled tasks, and watchdog processes. Once active, it can provide remote shell access and collect files, browser information, saved credentials, screenshots, keystrokes, webcam images, and microphone audio.
These capabilities make the malware particularly dangerous for corporate travelers. A compromised laptop may expose internal documents, active browser sessions, meeting conversations, authentication material, and access to enterprise applications.
ChocoShell targets cloud and browser credentials
Microsoft also identified ChocoShell, an in-memory PowerShell-based stealer associated with the campaign. It focuses on browser session data, saved passwords, Microsoft 365 single sign-on information, Azure identity tokens, and Web Account Manager token cache files.
Running primarily in memory can reduce the number of obvious files left on disk. PowerShell also gives attackers access to a legitimate administrative tool already present on Windows, which can make malicious activity harder to distinguish from approved operations without behavioral monitoring.
Stolen session tokens can be more valuable than passwords because they may allow attackers to reuse an authenticated session without repeating the normal sign-in process.
Device code phishing bypasses user expectations
Some CaptiveCrunch pages redirect users into Microsoft’s legitimate device code authentication process. The attacker supplies a code and instructs the victim to enter it on a real Microsoft sign-in page.
The victim sees the correct Microsoft domain and completes authentication, including multifactor authentication when required. However, the code belongs to the attacker’s session. Successful authentication can therefore grant the attacker access to the requested account or application.
This technique demonstrates why users cannot judge authentication safety from the sign-in page alone. Employees should never enter a device code that they did not initiate on a device or application they recognize.
Why CaptiveCrunch matters to enterprises
CaptiveCrunch combines several attack surfaces that security teams often manage separately:
- Untrusted network exposure: Attackers manipulate the network path before the user reaches corporate resources.
- Endpoint compromise: Fake updates deliver persistent malware and remote-access tooling.
- Credential and token theft: Browser passwords, cookies, and cloud session tokens become targets.
- Identity abuse: Device code phishing can produce authenticated cloud access.
- Traveler surveillance: Webcam, microphone, screen, and keystroke collection can expose sensitive activity.
The campaign shows that travel security requires more than advising employees not to use public Wi-Fi. Organizations need endpoint controls, secure network paths, identity restrictions, and incident visibility that continue to operate outside the office.
How Hexnode can support travel security
Hexnode should be positioned as a supporting endpoint and access-control layer, not as a tool that secures hotel captive portal infrastructure or guarantees detection of CaptiveCrunch.
- Configure managed VPN access: Hexnode UEM can deploy VPN configurations to supported Windows, macOS, iOS, and Android devices, including settings that route traffic through a specified network.
- Maintain patch compliance: Administrators can automate Windows and macOS operating-system updates and deploy supported application patches using defined filters, schedules, approval rules, and maintenance windows.
- Standardize browser controls: Hexnode UEM can configure Chrome browser policies on managed Windows, macOS, and ChromeOS devices, including force-installing, allowing, or restricting specified extensions.
- Enforce compliant-device access: Integrate Hexnode UEM with Microsoft Entra Conditional Access to use compliance data from enrolled and managed Android, iOS, and macOS 11+ devices when controlling access to configured organizational resources.
- Support endpoint investigation: Hexnode XDR provides threat telemetry, MITRE ATT&CK mapping, investigation capabilities, and documented response actions such as device isolation and file quarantine for Windows endpoints. These capabilities can support investigations involving Windows-based malware activity but should not be described as guaranteed detection of CornFlake, ChocoShell, or device code phishing.
FAQs
Can a VPN completely prevent CaptiveCrunch attacks?
A properly configured VPN can reduce exposure by routing traffic through a trusted encrypted connection. However, users may encounter a malicious captive portal before the VPN connects, and social engineering can still persuade them to download files or enter attacker-supplied device codes.
Why can device code phishing succeed despite MFA?
The victim completes authentication and MFA on Microsoft’s legitimate website, but the code belongs to the attacker’s session. The authentication therefore authorizes the attacker-controlled request rather than a sign-in the victim intentionally initiated.
Conclusion
CaptiveCrunch demonstrates how compromised travel networks can connect endpoint infection directly to cloud identity theft. Enterprises should require trusted network paths, discourage updates delivered through captive portals, maintain patched and managed devices, monitor suspicious PowerShell and persistence activity, and restrict sensitive access to compliant endpoints.
Travelers should treat unexpected update prompts and unsolicited device codes as warning signs, even when they appear through legitimate hotel Wi-Fi or redirect to an authentic Microsoft page.
Secure Devices on Public Wi-Fi
Protect endpoints, enforce secure access, and detect credential theft with Hexnode UEM and XDR.
Start Your Free Trial!