CaptiveCrunch: Midnight Blizzard Targets Travelers Worldwide for Malware Delivery and Credential Theft
Microsoft, Friday, July 31st, 2026
Microsoft details Storm-2945 compromising hotel sign-in portals since May to hit travelers with malware.
Microsoft Threat Intelligence detailed CaptiveCrunch, an operation by Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard. Since May 2026, the actor has compromised the sign-in portals of hospitality organizations such as hotels in order to deliver malware to travelers and steal their credentials.
Captive portals are an effective vector because users expect an unfamiliar authentication page when joining hotel networks.
Microsoft covers the infrastructure, malware, and targeting observed, along with detection guidance. The operation is global in scope rather than regionally focused.