# Russia's APT29 Turned Hotel Wi-Fi Into a Credential Trap — And Built the Malware With AI


When a diplomat, executive, or government contractor checks into a conference hotel and connects to the complimentary Wi-Fi, they're placing a small bet. The bet: that the network they're trusting is actually the one the hotel is running.


APT29 has been collecting on that bet since at least February.


Microsoft disclosed this week that Midnight Blizzard — Russia's SVR-linked threat group — has been running a systematic campaign against hospitality networks that goes well beyond the DNS redirect tricks first flagged by ReliaQuest. The operation, which Microsoft calls CaptiveCrunch, involves two newly identified malware families, a third attack vector involving fake browser updates, evidence of Android targeting, and a management panel left exposed on the open internet. Microsoft attributes the activity to Storm-2945, a sub-cluster of the broader APT29 constellation.


The campaign has been active since at least May, with OAuth and device code phishing operations stretching back to February. That's six months of access across hotel and conference center networks before this went public.


---


## The Trap at Check-In


The attack begins in the captive portal — that login screen that stands between you and the internet when you connect to hotel Wi-Fi. Attackers compromise the networking equipment serving these portals, modify DNS settings, and intercept traffic before it ever reaches the legitimate hotel gateway.


From there, victims get one of three options, each calibrated to the moment:


A fake Microsoft 365 login portal captures credentials directly. A device code phishing page abuses Microsoft Entra ID's legitimate OAuth flows, tricking the user into authorizing attacker-controlled applications. And a third vector — not previously disclosed — serves ClickFix prompts: fake browser or Windows update pages that instruct users to run a verification command, which instead deploys malware.


That third vector matters. ClickFix has become one of the more insidious social engineering techniques in circulation because it weaponizes the user's own instinct to cooperate with a "required update." Seeing it deployed by a nation-state actor targeting high-value travelers signals that Russia's operators are paying close attention to what works in the wider threat landscape and adapting accordingly.


Microsoft also found evidence that the campaign is targeting Android devices through similar ClickFix landing pages, delivering malicious APK files. The scope of targeting is broader than "Windows users at hotels."


---


## CornFlake and ChocoShell: A Malware Breakfast


Microsoft identified two new Windows malware families deployed through this campaign, and whoever named them was clearly amused.


CornFlake is a Go-based remote access trojan with an extensive capability set: remote shell access, keylogging, clipboard monitoring, screenshot capture, microphone and webcam surveillance, browser credential and cookie theft, Microsoft 365 session token exfiltration, file exfiltration, USB monitoring, and system reconnaissance. When executed, it shows the user a fake progress window — configurable to look like a Windows Update screen, a Defender virus scan, a disk optimization tool, a network diagnostics utility, a browser update prompt, or a document installer. It then copies itself to %AppData%, registers as a Windows service named "Cloud Sync Service," adds registry run keys, creates scheduled tasks, and deploys a watchdog routine that restores any persistence mechanisms if they're removed.


This is not a quick-and-dirty implant. The redundant persistence architecture — four separate mechanisms plus a watchdog — suggests the operators expect endpoint detection to catch individual persistence methods and are building for survivability.


ChocoShell is lighter: an in-memory PowerShell credential stealer targeting browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials. The in-memory execution is deliberate — it leaves no file on disk for endpoint tools to scan.


And then there's FruitStone, the web-based management panel that Storm-2945 used to manage infected systems, browse victim files, execute PowerShell commands, and capture screenshots and keystrokes. It was left unprotected. An exposed C2 panel is an OPSEC failure, but it's also an opportunity — any defender or researcher who located it had visibility into active operations.


---


## The AI-Assisted Author


One detail buried in Microsoft's analysis deserves more attention than it's getting: based on extensive comments throughout the code, Microsoft assesses that AI tools were likely used to develop CornFlake and ChocoShell.


This is consistent with a pattern that's been emerging across multiple threat actors over the past 18 months. Nation-state groups — including multiple APT clusters — have begun using generative AI to accelerate malware development, write evasion logic, and generate convincing phishing content. What this does is compress the development cycle. A capability that might have taken weeks to build and test can now be drafted, refined, and deployed in days.


The extensive commenting is the tell. Human malware authors rarely document their own code this thoroughly — they're building for operational use, not readability. AI-assisted code tends to arrive heavily commented because the models are trained on well-documented open source repositories. That habit carries over even when the output is malicious.


---


## Who's Actually at Risk


The targeting profile of CaptiveCrunch isn't random. Hotel and conference center Wi-Fi skews toward business travelers, government officials, journalists, diplomats, and executives — exactly the populations APT29 has historically prioritized. Russia's foreign intelligence service doesn't build this kind of infrastructure to steal credentials from tourists.


The Microsoft 365 focus is equally deliberate. M365 accounts at target organizations often carry email archives, OneDrive files, SharePoint access, and Teams communications — a single OAuth token can unlock an organization's entire collaboration history.


Any organization whose employees regularly travel to international conferences, government events, or industry summits should treat this campaign as directly relevant.


---


## HackWire Analysis


CaptiveCrunch fits a pattern that's been building for years, but this iteration is more dangerous than the hotel Wi-Fi attacks of the past — and the AI malware development angle is the piece most coverage is underplaying.


When Cozy Bear (another APT29 alias) made headlines for hotel-based operations years ago, the tradecraft was simpler: compromise the network, harvest credentials, move on. CaptiveCrunch is more architecturally sophisticated. The combination of four distinct persistence mechanisms plus a watchdog in CornFlake reflects an adversary that has been caught and evicted before and built redundancy specifically to survive endpoint detection. That's iterative learning from prior failures.


The ClickFix adoption is also significant. This technique originated in the criminal ecosystem — it's been used by ransomware affiliates and info-stealer campaigns to bypass endpoint controls by making the user execute the malicious command themselves. APT29 importing it signals that the line between nation-state TTPs and criminal tradecraft continues to blur. Defenders who've been categorizing ClickFix as a "criminal malware problem" need to update that mental model.


The exposed FruitStone panel is worth watching. Microsoft has likely sinkholed or notified affected infrastructure, but the existence of an exposed management interface suggests either operational sloppiness or — less comfortably — a decoy. APT29 has historically run sophisticated counter-detection operations. An exposed panel that generates noise and attention while the real C2 runs quietly elsewhere isn't implausible.


For defenders: zero-trust the hotel network. Your mobile hotspot is not optional when you're traveling to a conference with sensitive materials. Phishing-resistant MFA (passkeys, hardware tokens) closes the credential theft vector even when the phishing page is convincing. And if your endpoint tools flagged anything named "Cloud Sync Service" in the last six months, that log entry deserves a second look.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)