Canadian Cyber Security Journal
SOCIAL:
Filed under: Trends

CaptiveCrunch: Russia’s APT29 Hijacks Hotel Wi-Fi to Steal Microsoft 365 Credentials

What Happened

Microsoft Threat Intelligence published its disclosure of CaptiveCrunch on July 31, attributing the campaign to Storm-2945, an operational sub-cluster of Midnight Blizzard — the Russian SVR-linked group also known as APT29 and Cozy Bear. The operation has been active since at least May 2026, targeting business travelers at hotels, conference centres, and similar venues across the United States, India, Saudi Arabia, and other locations.

Attackers compromise hotel Wi-Fi gateways and manipulate DNS and HTTP traffic through captive portals. When a traveler connects to the network and opens their browser, the portal redirects them to a fake Microsoft sign-in page or delivers malware before reaching their intended destination. Two malware families are deployed: CornFlake, a Go-based Windows remote access trojan with keylogging, screenshot capture, and browser credential theft, and ChocoShell, an in-memory PowerShell infostealer that captures Microsoft 365 session tokens and Wi-Fi passwords without writing to disk. Microsoft also noted AI-assisted development in portions of the toolchain.

Why This Matters for Canadian Organizations

Canadian government employees, corporate executives, and security professionals regularly travel to conferences and government meetings in the United States and internationally. APT29 is one of the most sophisticated and persistent Russian intelligence threats tracked by the Canadian Centre for Cyber Security (CCCS) and the Communications Security Establishment (CSE). Canada is a member of the Five Eyes intelligence alliance, and APT29 has long targeted allied government and diplomatic personnel.

The specific risk here is the Microsoft 365 session token. Once ChocoShell captures a valid M365 token, attackers retain access to the victim’s email, SharePoint, Teams, and OneDrive regardless of whether the victim changes their password. Conditional Access policies and phishing-resistant MFA do not automatically invalidate stolen session tokens. For government employees and staff at federally regulated institutions, an M365 compromise at this level creates both a data exfiltration risk and a lateral movement opportunity into the broader enterprise.

Under PIPEDA and the Treasury Board’s Directive on Security Management, organizations must assess the risk of credential compromise for employees who travel with corporate devices and access government or regulated systems from public networks.

What to Do

Brief traveling employees on captive portal risks before they leave. Require the use of a corporate VPN before any M365 or SaaS authentication on public Wi-Fi. Enforce token binding or Continuous Access Evaluation in M365 tenants to limit session token portability. Review Entra ID sign-in logs for logins from hotel or conference network IP ranges. Employees who connected to hotel Wi-Fi at targeted locations since May 2026 should have their session tokens revoked and credentials reset as a precaution.

Source: Microsoft Security Blog | SecurityWeek

Enjoy this article? Don’t forget to share.