CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials
Zscaler, Tuesday, August 11th, 2026
Zscaler covers a Midnight Blizzard sub-cluster hijacking hotel captive portals for Microsoft 365 credential theft.
Zscaler covers CaptiveCrunch, a credential theft campaign reported by Microsoft Threat Intelligence on 31 July and attributed to Storm-2945, a sub-cluster of the Russia-linked Midnight Blizzard.
The campaign manipulates DNS and HTTP traffic on captive portal networks at hospitality venues, redirecting victims to attacker-controlled infrastructure for Microsoft 365 credential harvesting, device code phishing and malware delivery.
Evidence suggests Storm-2945 compromised shared captive portal services used by hotels and conference centres rather than breaching each location individually, with compromised gateways identified in several US cities, India and Saudi Arabia.