The Hotel Wi-Fi Trap: How Spies are Weaponizing Captive Portals (And Why You Should Stick to 5G)
APT29 / Storm-2945 CaptiveCrunch Campaign: Hijacking Hotel Captive Portals to Deliver CornFlake RAT with MFA Bypass
Imagine you’re staying at a hotel and you want to use the Wi-Fi on your phone or laptop. You turn on Wi-Fi, pick the hotel’s network, and connect. But instead of going straight to the internet, a special webpage suddenly pops up on your screen. That webpage is the hotel captive portal: pretty standard.
It says: “Hi! Before you can use the internet, please type in your room number (or last name) and click ‘I agree’ to the rules.” Once you do that, the gatekeeper lets you through and you can finally open Google, YouTube, email, and so on.
That’s all a captive portal is: just the little sign-in page the hotel, coffee shop, or other business forces you to see before giving you internet access. That’s usually fine, but recently threat actors have managed to hijack some of those portals, potentially exposing users to PII data theft, phishing, and session hijacking. The worst part: MFA and 2FA don’t help here.
We all know the drill when checking into a hotel: drop the bags, find the room key, connect to the Wi-Fi. But if you’re a corporate employee at a Fortune 500 company, a government official, NGO worker, diplomat, or an infosec professional heading to a conference like Black Hat, that complimentary hotel Wi-Fi could currently be an espionage trap.
A sophisticated Russian threat actor known as Midnight Blizzard (also tracked as APT29, UNC7005, or STORM-2945) is running a massive, global campaign dubbed CaptiveCrunch. They are manipulating hotel Wi-Fi captive portals to deliver malware and steal credentials.
We’re not here to fear-monger. The reality is that public Wi-Fi is riskier than ever, but the mitigation is incredibly simple: ignore the Wi-Fi and stick with your 5G connection.
ClickFix isn’t limited to hotel networks either — the same social engineering technique has been deployed through malicious Google Ads targeting developers. See how ClickFix was used to deliver the MacSync infostealer via a fake ChatGPT link →
What is the CaptiveCrunch Campaign?
Since early May 2026, threat intelligence teams have observed a distinct sub-cluster of Midnight Blizzard intercepting and manipulating DNS and HTTP traffic on hospitality networks. When a user connects to a compromised hotel network and gets redirected to the standard captive portal, the attackers route that traffic through their own malicious infrastructure.

What’s particularly concerning is the scale. Researchers from Google Threat Intelligence and Microsoft MSRC have noted commonalities in the equipment and management systems used across affected networks. This suggests the attackers haven’t just compromised a single isolated hotel, but may have found a way into shared services within the broader captive portal ecosystem, allowing them to intercept travelers worldwide at their discretion.
The Tactics: Fake Updates, ClickFix, and AI
Midnight Blizzard isn’t relying on outdated tricks. They’re moving fast and adapting quickly, using AI to support a significant portion of these operations and scale their social engineering and phishing flows dynamically.
Here is what victims are seeing:
ClickFix social engineering. Attackers serve up highly convincing fake error messages. You might see a “Windows Driver Repair Utility” prompt or a fake Google verification failure page that gives you “manual instructions” to fix your connection before letting you online.
Authentication abuse. They heavily abuse legitimate authentication workflows, including OAuth device code phishing and app password phishing. Because these use real Microsoft or Google flows, they often bypass the typical red flags a user would recognize.
The Payload: CornFlake and ChocoShell
If a user falls for the trap and executes the download, they’re hit with malware designed for long-term espionage.
CornFlake is a full-featured Remote Access Trojan written in Go. Upon execution, it shows fake progress windows — a Windows Update screen or a PDF viewer installer — to distract the user while it embeds itself. Once running, it can log keystrokes, steal browser credentials, record audio and video, and monitor inserted USB drives.
ChocoShell is a PowerShell-based infostealer that runs entirely in-memory. Its primary job is to rapidly collect browser session cookies, saved passwords, and Microsoft 365 Single Sign-On tokens.
The fake domains used in this campaign closely resemble Microsoft services:
ms365-device\[.\]comms365-live\[.\]comm365-owa\[.\]comowa-ms365\[.\]com
The infrastructure observed is hosted across various networks including AS262287.

Who Are They Targeting?
Midnight Blizzard’s operations align with Russian foreign policy interests. This specific campaign heavily targets individuals of interest to Russia: personnel in academia, aerospace, defense, government, diplomatic entities, and NGOs across the US and Europe.
If you’re traveling for business in any of these sectors, or if you’re heading to major cybersecurity conferences like Black Hat, you’re squarely in the crosshairs.
The Fix: Stick to 5G

It sounds like a sophisticated, scary threat, but the solution is surprisingly straightforward. You don’t need complex workarounds, VPN gymnastics, or specialized hardware.
Don’t connect to hotel Wi-Fi, especially if you’re a corporate employee at a Fortune 500 firm, a government official, NGO worker, diplomat, or an infosec professional. Consider that complimentary hotel Wi-Fi as if it does not exist. Anything with an intermediate captive portal — hotels, airports — should be treated with caution. Stick to mobile, cellular, or 5G.
Today’s 5G coverage is robust, fast, and vastly more secure than a shared hospitality network. Use your smartphone’s cellular data or a dedicated 5G mobile hotspot. If you must use a laptop, tether it to your phone. The minor inconvenience of using your data plan is infinitely better than handing your Microsoft 365 session tokens and device control to a nation-state intelligence service.
Stay safe, stay off the captive portals, and travel smart.
Sources:



