
Russian Hackers Exploit Hotel Wi-Fi in New CaptiveCrunch Espionage Campaign
Microsoft Threat Intelligence has uncovered CaptiveCrunch, a cyber espionage campaign linked to Storm-2945, a subgroup of Midnight Blizzard, the Russian state-linked threat actor associated with Russia's Foreign Intelligence Service (SVR).
Active since early May 2026, the operation targets business travelers by exploiting hospitality Wi-Fi networks and captive portals in hotels, conference centers, and similar venues. The campaign combines adversary-in-the-middle attacks, phishing, malware deployment, and AI-assisted development to steal credentials and infiltrate enterprise environments.
Storm-2945 Uses Hospitality Networks to Target Travelers
According to Microsoft, Storm-2945 ma...