Midnight Blizzard Exploits Hotel Wi-Fi Portals with CaptiveCrunch Attack

Travelers using hotel Wi-Fi should be on high alert. A hacking group tied to Midnight Blizzard is deploying a campaign called CaptiveCrunch to corrupt captive portals—those login pages people often see before using guest wireless—and use them to infect devices with malware, steal credentials, and hijack cloud sessions. These attacks threaten more than just one device; they can be a gateway into corporate systems and business accounts.

How CaptiveCrunch Works

The CaptiveCrunch operation hijacks DNS and HTTP traffic on guest networks. Instead of being shown the usual “connect” page after connecting, users are redirected to pages controlled by attackers. These spoofed portals may mimic an operating system or browser update, or request account sign‐ins, tricking users into believing they’re completing routine tasks. It appears many venues are affected—especially those that share captive-portal infrastructure—rather than isolated locations.

Attackers use malware like CornFlake—a remote access tool (RAT) that installs itself under names like “Cloud Sync Service,” hides in application data directories, copies files, survives reboots, and collects audio, video, keystrokes, and files. On Android, victims are shown APK download prompts. “ClickFix” fake repair or verification notices are also used to dupe victims into granting higher access or installing malicious code.

Threats to Credentials, Cloud Access, and Sessions

Alongside CornFlake, the attackers deploy ChocoShell, an infostealer built in PowerShell. It steals browser cookies, saved passwords, Microsoft 365 single-sign-on tokens, and even Wi-Fi credentials. With usable tokens and session data, attackers can bypass passwords completely and gain access to online services or cloud accounts. These tools also include evasion tactics—disabling malware controls, disguising network paths, and checking for virtual machines to avoid detection.

Device code authentication is leveraged as well. Victims may be asked to provide a “device code” on a legitimate sign-in page, but it actually authorizes the attacker’s session. This mirrors earlier credential-theft schemes tied to Midnight Blizzard.

What to Watch For & How to Defend Yourself

Indicators of this campaign include several redirect domains (for example “cdn-gstat[.]com”, “sslcdnhost[.]com”, “network-privacy[.]com”) and other lookalike domains mimicking Microsoft 365 services. Malicious IPs tied to data exfiltration, C2 (command-and-control) servers, and malware delivery are also part of the infrastructure.

For travelers, using private hotspots instead of public Wi-Fi is advised. Never accept downloads or follow prompt requests from captive portals. Only updates authorized through normal operating system or browser channels should be trusted. Corporate or managed devices should avoid untrusted networks, and organizations should invest in travel routers, encrypted VPNs, and network access policies.

At the organizational level, enforcing phishing-resistant multi-factor authentication (MFA), using passkeys, limiting device-code authentication, and implementing risk-based access controls are all crucial. Endpoint monitoring, identifying artifacts of CornFlake, unexpected downloads after connecting, and inspecting anomalous login flows help identify breaches early.

The CaptiveCrunch campaign marks a serious escalation from phishing emails or malicious links. It weaponizes something travelers often take for granted—hotel Wi-Fi. The blending of social engineering with credential theft and authentic-session hijacking means that this threat could sidestep many common security layers. It’s essential to rethink how devices and credentials are protected during travel—and for cybersecurity defenses to adapt to attacks that target our connections even before we’re fully online.