Midnight Blizzard is again using hospitality Wi-Fi infrastructure to reach travelers with malware and credential theft.
In an Oct. 5 update, Microsoft said Storm-2945, which it assesses as a Midnight Blizzard sub-cluster, resumed its CaptiveCrunch campaign on Sept. 29. Microsoft first reported the activity in July. Corporate devices and accounts may be exposed outside networks an employer controls.
A captive portal — the sign-in or acceptance page shown before a guest network grants internet access — can redirect travelers toward phishing or malware before they reach their intended site.
Captive portals become the route into the attack
Since early May, Storm-2945 has manipulated DNS and HTTP traffic on networks served by captive portals, according to Microsoft's updated research. Control of that traffic path can send users to fake browser or operating-system updates and other attacker-controlled pages.
Victims can then encounter different attack routes:
- ClickFix instructions can tell users to run commands that install malware themselves. Similar ClickFix techniques have been used to turn fake troubleshooting steps into malware delivery.
- Device-code phishing can send victims to a legitimate Microsoft sign-in page with a code tied to an attacker-initiated session. Completing the login can authorize that session instead of the one the user thinks they are approving.
Researchers have not fully established how every captive-portal environment is first compromised. Shared equipment and management systems across affected networks raised questions about access beyond individual hotels, and later findings indicate hospitality managed service providers may give attackers a route back into multiple locations.
CornFlake and ChocoShell extend the compromise beyond Wi-Fi
Successful delivery can leave a foothold on the device after the network session ends. Two malware components play different roles in the campaign.
Malware | Role | Capabilities |
| CornFlake | Persistent Windows remote access malware | Can establish persistence, provide remote command access and collect keystrokes, files, browser credentials and session tokens |
| ChocoShell | Credential and session theft | Can collect browser cookies, saved passwords, Microsoft 365 SSO tokens and stored Wi-Fi credentials |
Stolen authentication material may allow attackers to reuse an authenticated session instead of relying only on a victim's password.
Researchers also identified a Rust variant of CornFlake and assessed its characteristics as consistent with continued AI-assisted malware development.
Corporate travel can carry the compromise back to work
If you manage laptops or employee identities, a report of unusual hotel Wi-Fi behavior should trigger an endpoint and account review. Disconnecting from the network only ends the current connection. It does not address sessions or malware established during it.
Travel policies can reduce some exposure before an incident occurs. Managed hotspots or other private connectivity are better options for sensitive work where available. Employees should avoid installing updates, certificates, or troubleshooting tools presented through captive portals, and unexpected instructions to open PowerShell or Terminal should be treated as suspicious.
Identity controls can limit what attackers are able to reuse after a compromise. Disable device-code authentication where employees do not need it and use phishing-resistant MFA where possible. Endpoint detection and response can also flag suspicious process activity on corporate devices even when the initial exposure occurs outside the company network.
If an employee reports a fake update, unusual captive portal, or unexpected sign-in flow, security teams should treat it as a possible account and endpoint compromise:
- Revoke sign-in sessions and refresh tokens, and invalidate application sessions where supported. Some access tokens or application sessions may remain usable until they expire or are separately revoked.
- Review recent cloud sign-ins for activity that does not match the employee's travel or normal account use.
- Inspect the device for malware, persistence, or credential theft before returning it to normal use.
- Reset affected credentials promptly from a trusted device, alongside session revocation and endpoint investigation.
Travel-related Wi-Fi incidents can follow an employee back into the enterprise environment, so unusual activity during a trip warrants the same attention as an incident discovered on a company-managed network.
More cybersecurity news: Dell has patched a high-severity DSU vulnerability that could give remote attackers root-level access.





