Microsoft Warns of CaptiveCrunch Malware Targeting Hotel Wi-Fi Networks
Microsoft has issued a security warning regarding a global cyber-espionage campaign dubbed “CaptiveCrunch.” The operation, which has been active since May 2026, targets travelers by compromising hotel Wi-Fi networks to deploy malware and steal sensitive credentials.
Hotel Wi-Fi Networks Exploited in Global Espionage Campaign
The campaign is attributed to the threat actor group Storm-2945, a sub-cluster of the group known as Midnight Blizzard.
The Arsenal Behind CaptiveCrunch
Attackers are utilizing specialized software to gain unauthorized access to target systems and exfiltrate information. According to security reports, the campaign relies on “CornFlake,” a Remote Access Trojan written in the Go programming language, and “ChocoShell,” a PowerShell-based infostealer.
Microsoft identified specific indicators of compromise linked to the campaign’s infrastructure, including the domains ms365-device.com, ms365-live.com, m365-owa.com, and owa-ms365.com. The company also confirmed three IP addresses associated with the operation: 31.57.243.154, 38.146.28.75, and 107.189.26.194. The security firm ReliaQuest reported observing an increase in these activities across various U.S. cities starting in June.
Intercepting Traffic via DNS and HTTP
The threat actors manipulate DNS and HTTP traffic within hotel networks to intercept and redirect user data. A primary component of the strategy is “device-code phishing,” a technique designed to bypass multi-factor authentication.

By presenting users with a fraudulent interface, attackers trick them into entering an authentication code on a malicious website. This simple deception grants the group unauthorized access to enterprise accounts.
Defensive Measures for Corporate Travelers
To mitigate the risks posed by CaptiveCrunch, Microsoft recommends that organizations implement full-tunnel VPN solutions for mobile employees. This measure ensures that all data traffic is encrypted through the company’s internal infrastructure, preventing interception within local hotel networks.
Additionally, Microsoft advises IT departments to block the “device-code flow” at the system level if it is not strictly required for business operations. This step is intended to neutralize the primary mechanism used for the current wave of phishing attacks. These guidelines are part of a broader set of security policies released by Microsoft to protect corporate data on mobile devices during the peak travel season.