Skip to main content
World Today News
  • Home
  • News
  • World
  • Sport
  • Entertainment
  • Business
  • Health
  • Technology
Menu
  • Home
  • News
  • World
  • Sport
  • Entertainment
  • Business
  • Health
  • Technology

Microsoft Warns of CaptiveCrunch Malware Targeting Hotel Wi-Fi Networks

August 26, 2026 Rachel Kim – Technology Editor Technology

Microsoft has issued a security warning regarding a global cyber-espionage campaign dubbed “CaptiveCrunch.” The operation, which has been active since May 2026, targets travelers by compromising hotel Wi-Fi networks to deploy malware and steal sensitive credentials.

Hotel Wi-Fi Networks Exploited in Global Espionage Campaign

The campaign is attributed to the threat actor group Storm-2945, a sub-cluster of the group known as Midnight Blizzard.

The Arsenal Behind CaptiveCrunch

Attackers are utilizing specialized software to gain unauthorized access to target systems and exfiltrate information. According to security reports, the campaign relies on “CornFlake,” a Remote Access Trojan written in the Go programming language, and “ChocoShell,” a PowerShell-based infostealer.

Microsoft identified specific indicators of compromise linked to the campaign’s infrastructure, including the domains ms365-device.com, ms365-live.com, m365-owa.com, and owa-ms365.com. The company also confirmed three IP addresses associated with the operation: 31.57.243.154, 38.146.28.75, and 107.189.26.194. The security firm ReliaQuest reported observing an increase in these activities across various U.S. cities starting in June.

Intercepting Traffic via DNS and HTTP

The threat actors manipulate DNS and HTTP traffic within hotel networks to intercept and redirect user data. A primary component of the strategy is “device-code phishing,” a technique designed to bypass multi-factor authentication.

Microsoft Warns of CaptiveCrunch Malware Targeting Hotel Wi-Fi Networks
Photo: ad-hoc-news.de

By presenting users with a fraudulent interface, attackers trick them into entering an authentication code on a malicious website. This simple deception grants the group unauthorized access to enterprise accounts.

Defensive Measures for Corporate Travelers

To mitigate the risks posed by CaptiveCrunch, Microsoft recommends that organizations implement full-tunnel VPN solutions for mobile employees. This measure ensures that all data traffic is encrypted through the company’s internal infrastructure, preventing interception within local hotel networks.

View this post on Instagram about microsoft captivecrunch malware targeting, CaptiveCrunch Hotel-WLAN
From Instagram — related to microsoft captivecrunch malware targeting, CaptiveCrunch Hotel-WLAN

Additionally, Microsoft advises IT departments to block the “device-code flow” at the system level if it is not strictly required for business operations. This step is intended to neutralize the primary mechanism used for the current wave of phishing attacks. These guidelines are part of a broader set of security policies released by Microsoft to protect corporate data on mobile devices during the peak travel season.

CaptiveCrunch: Neue Angriffsmasche über öffentliches WLAN – Microsoft warnt

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

Keep reading

  • OpenAI Report Reveals How AI Model Escaped Sandbox to Breach Hugging Face
  • Apple Schedules September 9 Event for iPhone 18 Pro and Foldable iPhone Debut

Related

Search:

World Today News

World Today News is your trusted source for global journalism — breaking headlines, in-depth analysis, and reporting from around the world.

Quick Links

  • Privacy Policy
  • About Us
  • Accessibility statement
  • California Privacy Notice (CCPA/CPRA)
  • Contact
  • Cookie Policy
  • Disclaimer
  • DMCA Policy
  • Do not sell my info
  • EDITORIAL TEAM
  • Terms & Conditions

Browse by Location

  • GB
  • NZ
  • US

Connect With Us

© 2026 World Today News. All rights reserved. Your trusted global news source directory.
For contact, advertising, copyright, issues email: [email protected]

Privacy Policy Terms of Service