Midnight Blizzard Targets Hotel Wi-Fi: Malware and Phishing Put Travelers at Risk

Midnight Blizzard is abusing hotel Wi-Fi captive portals to deliver malware and steal credentials from travelers, putting corporate devices and accounts at risk.

Oct 7, 2026
3 minute read
Orange wireless signal symbol above white “WiFi” lettering on a dark glass window.

Hotel Wi-Fi networks are being used in a Midnight Blizzard campaign that targets travelers with malicious redirects, malware, and credential theft. Source: Dreamlike Street/Unsplash

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Midnight Blizzard is again using hospitality Wi-Fi infrastructure to reach travelers with malware and credential theft.

In an Oct. 5 update, Microsoft said Storm-2945, which it assesses as a Midnight Blizzard sub-cluster, resumed its CaptiveCrunch campaign on Sept. 29. Microsoft first reported the activity in July. Corporate devices and accounts may be exposed outside networks an employer controls.

A captive portal — the sign-in or acceptance page shown before a guest network grants internet access — can redirect travelers toward phishing or malware before they reach their intended site.

Captive portals become the route into the attack

Since early May, Storm-2945 has manipulated DNS and HTTP traffic on networks served by captive portals, according to Microsoft's updated research. Control of that traffic path can send users to fake browser or operating-system updates and other attacker-controlled pages.

Victims can then encounter different attack routes:

  • ClickFix instructions can tell users to run commands that install malware themselves. Similar ClickFix techniques have been used to turn fake troubleshooting steps into malware delivery.
  • Device-code phishing can send victims to a legitimate Microsoft sign-in page with a code tied to an attacker-initiated session. Completing the login can authorize that session instead of the one the user thinks they are approving. 

Researchers have not fully established how every captive-portal environment is first compromised. Shared equipment and management systems across affected networks raised questions about access beyond individual hotels, and later findings indicate hospitality managed service providers may give attackers a route back into multiple locations.

Advertisement

CornFlake and ChocoShell extend the compromise beyond Wi-Fi

Successful delivery can leave a foothold on the device after the network session ends. Two malware components play different roles in the campaign.

Malware

Role

Capabilities

CornFlakePersistent Windows remote access malwareCan establish persistence, provide remote command access and collect keystrokes, files, browser credentials and session tokens
ChocoShellCredential and session theftCan collect browser cookies, saved passwords, Microsoft 365 SSO tokens and stored Wi-Fi credentials

Stolen authentication material may allow attackers to reuse an authenticated session instead of relying only on a victim's password.

Researchers also identified a Rust variant of CornFlake and assessed its characteristics as consistent with continued AI-assisted malware development.

Corporate travel can carry the compromise back to work

If you manage laptops or employee identities, a report of unusual hotel Wi-Fi behavior should trigger an endpoint and account review. Disconnecting from the network only ends the current connection. It does not address sessions or malware established during it.

Travel policies can reduce some exposure before an incident occurs. Managed hotspots or other private connectivity are better options for sensitive work where available. Employees should avoid installing updates, certificates, or troubleshooting tools presented through captive portals, and unexpected instructions to open PowerShell or Terminal should be treated as suspicious.

Identity controls can limit what attackers are able to reuse after a compromise. Disable device-code authentication where employees do not need it and use phishing-resistant MFA where possible. Endpoint detection and response can also flag suspicious process activity on corporate devices even when the initial exposure occurs outside the company network. 

Advertisement

If an employee reports a fake update, unusual captive portal, or unexpected sign-in flow, security teams should treat it as a possible account and endpoint compromise:

  1. Revoke sign-in sessions and refresh tokens, and invalidate application sessions where supported. Some access tokens or application sessions may remain usable until they expire or are separately revoked.
  2. Review recent cloud sign-ins for activity that does not match the employee's travel or normal account use.
  3. Inspect the device for malware, persistence, or credential theft before returning it to normal use.
  4. Reset affected credentials promptly from a trusted device, alongside session revocation and endpoint investigation.

Travel-related Wi-Fi incidents can follow an employee back into the enterprise environment, so unusual activity during a trip warrants the same attention as an incident discovered on a company-managed network.

More cybersecurity news: Dell has patched a high-severity DSU vulnerability that could give remote attackers root-level access.


Liz Laurente-Ticong

Liz Laurente-Ticong

IT Staff Writer

Liz Laurente-Ticong is a tech specialist and multi-niche writer with a decade of experience covering software and technology topics and news. Her work has appeared in TechnologyAdvice.com as well as ghostwritten for a variety of international clients. When not writing, you can find Liz reading and watching historical and investigative documentaries. She is based in the Philippines.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.