# When You Connect to the Hotel Wi-Fi, Russia May Already Be Waiting
The login screen looked exactly like it should. A splash page, a field for your email, a browser prompt that your session needed to be authenticated. Standard captive portal friction — the kind every road warrior clicks through without thinking.
That's the point.
Microsoft disclosed this week that Storm-2945, a subgroup of Midnight Blizzard — the SVR-backed threat actor better known as APT29 or Cozy Bear — has been running a credential theft operation through compromised public Wi-Fi gateways since at least May. The campaign, which Microsoft is calling CaptiveCrunch, doesn't need you to click a phishing link or open a suspicious attachment. It just needs you to connect to Wi-Fi at the wrong hotel.
## How the Plumbing Gets Poisoned
The attack vector is grimly elegant. Hotels, conference centers, and shared office venues typically run captive portal networks — those intermediary systems that redirect your traffic to a login page before granting internet access. These portals depend on small appliances and SOHO routers that are, broadly speaking, the forgotten underclass of enterprise security. They run old firmware, they're managed by hospitality IT staff who aren't threat hunters, and they sit in exactly the right position on the network to intercept everything.
Storm-2945 modified the DNS configurations on these devices to redirect traffic toward attacker-controlled infrastructure. Once they owned the DNS, they owned the conversation. Every Microsoft 365 authentication attempt flowing through the captive portal became an adversary-in-the-middle interception point. Credentials. Session tokens. Device information. All of it.
ReliaQuest flagged the campaign roughly a week before Microsoft's disclosure, noting the DNS manipulation and drawing early comparisons to FrostArmada — a campaign attributed to APT28, a different Russian intelligence shop (GRU, not SVR). The attribution uncertainty mattered: APT28 and APT29 have overlapping tradecraft but represent different principals with different operational objectives. Microsoft has now settled the question. This is Cozy Bear's work.
## The Malware Toolkit
What makes CaptiveCrunch more than a clever network position is what Storm-2945 does once they have access. Users who connected through compromised portals were served Golang-based Windows remote access trojans disguised as browser update prompts — a ClickFix technique that's become a reliable social engineering staple across multiple threat actors over the past 18 months.
The RAT Microsoft calls CornFlake is a serious piece of work. It handles reconnaissance, credential and session token theft, file and keystroke collection, audio and video surveillance, and remote shell access. Paired with ChocoShell, a PowerShell-based infostealer, the implants give Storm-2945 persistent access to the victim's device and everything flowing through it. Command and control runs through a web-based panel Microsoft calls FruitStone.
Android users weren't spared. The attackers used similar ClickFix-style lures to push APK installations — a meaningful escalation given how many traveling employees conduct sensitive work on mobile.
The most recent wrinkle, observed over the past two weeks: some CaptiveCrunch landing pages started redirecting victims into device code authentication flows. Users were prompted to enter device codes into legitimate Microsoft sign-in pages — effectively authenticating *the attacker's* session under the guise of a normal login. Microsoft notes this technique isn't new for Midnight Blizzard; they've used device code phishing since at least August 2024. But integrating it into a captive portal operation raises the legitimacy perception substantially. You're already on a page that looks like a login screen. The ask to authenticate doesn't feel out of place.
## Who Got Hit
Microsoft identified compromises across hospitality-related organizations in several countries, though the targeting extended well beyond hotel guests. Sectors affected include financial services, professional services, legal, healthcare, energy, and retail — essentially any industry whose employees travel to industry conferences, client meetings, or deal signings.
That target list is telling. This isn't opportunistic credential harvesting. SVR intelligence collection in these sectors directly supports Russian foreign policy and economic intelligence priorities: legal firms handling sanctions work, financial services firms managing restricted transactions, energy companies negotiating contracts in geopolitically sensitive regions. The hotel Wi-Fi is the means; the conference attendees are the targets.
## HackWire Analysis
CaptiveCrunch deserves more attention than it's getting from the "just use a VPN" crowd, because the attack surface here isn't the user — it's the infrastructure operator. Your VPN protects your traffic, but it doesn't protect the captive portal authentication step that happens before your VPN client connects. On many enterprise devices, VPN auto-connect is configured to trigger after network authentication, which means there's a window. Storm-2945 is operating in that window.
The deeper problem is structural. Captive portal appliances are treated as commodity hardware, not security assets. They're often managed by third-party hospitality IT vendors who service dozens of properties, which means a single supplier compromise — or a single set of stolen credentials to that vendor's management portal — could grant access to gateway equipment across an entire hotel chain or conference venue network. That's the "access to shared services within the captive portal ecosystem" language Microsoft used, and it's worth sitting with. We may not be talking about individual router compromises here. We may be talking about supply-chain-level access to hospitality networking infrastructure.
The ClickFix browser-update lure deserves its own flag: this technique has shown up across ransomware groups, initial access brokers, and now SVR operators. When nation-state actors adopt criminal-ecosystem tradecraft this smoothly, it complicates attribution and gives them plausible deniability. Defenders tracking TTPs need to treat ClickFix as a priority detection target regardless of suspected actor — because the same lure now serves multiple principals.
For organizations with traveling employees — particularly those in the targeted sectors — the concrete action items are specific: ensure VPN pre-login tunnel is enforced (not just post-auth), deploy Conditional Access policies that flag authentication from anomalous network paths, and audit device code authentication flows in Entra ID logs. The session token theft component of CornFlake means that MFA alone is insufficient; token-binding enforcement matters.
Hotels and conference venues should treat their captive portal providers as third-party risk, full stop. Firmware update cadence, management credential hygiene, and DNS integrity monitoring for those appliances are baseline requirements that most hospitality operators aren't currently meeting.
The SVR didn't suddenly discover hotel Wi-Fi is useful. They've known this for years — Cozy Bear's 2017 "EvilCorp" adjacent operations touched hospitality infrastructure, and APT28's FancyBear Hotel operation predates it. What's changed is the tooling sophistication and the integrated device code phishing layer, which turns a credential interception campaign into a session hijacking campaign. That's a meaningful upgrade in persistence.
— HackWire Editorial
---
## Related Coverage