<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Nation-State Threats - PhishFort | AI-Powered Brand Protection</title><link>https://phishfort.com/resources/blog/tag/nation-state-threats/</link><description>PhishFort delivers agentic brand protection: detecting and eliminating phishing sites, fake apps, and impersonations across every digital channel.</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><lastBuildDate>Thu, 03 Sep 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://phishfort.com/resources/blog/tag/nation-state-threats/index.xml" rel="self" type="application/rss+xml"/><item><title>The Hotel Wi-Fi Trap: How Russian Spies are Weaponizing Captive Portals (And Why You Should Stick to 5G)</title><link>https://phishfort.com/hotel-wifi-captivecrunch-apt29/</link><pubDate>Thu, 03 Sep 2026 12:00:00 +0000</pubDate><dc:creator>PhishFort Team</dc:creator><guid>https://phishfort.com/hotel-wifi-captivecrunch-apt29/</guid><description><![CDATA[<h1 id="the-hotel-wi-fi-trap-how-spies-are-weaponizing-captive-portals-and-why-you-should-stick-to-5g">The Hotel Wi-Fi Trap: How Spies are Weaponizing Captive Portals (And Why You Should Stick to 5G)</h1>
<h2 id="apt29--storm-2945-captivecrunch-campaign-hijacking-hotel-captive-portals-to-deliver-cornflake-rat-with-mfa-bypass">APT29 / Storm-2945 CaptiveCrunch Campaign: Hijacking Hotel Captive Portals to Deliver CornFlake RAT with MFA Bypass</h2>
<p>Imagine you&rsquo;re staying at a hotel and you want to use the Wi-Fi on your phone or laptop. You turn on Wi-Fi, pick the hotel&rsquo;s network, and connect. But instead of going straight to the internet, a special webpage suddenly pops up on your screen. That webpage is the hotel captive portal: pretty standard.</p>]]></description><content:encoded><![CDATA[<h1 id="the-hotel-wi-fi-trap-how-spies-are-weaponizing-captive-portals-and-why-you-should-stick-to-5g">The Hotel Wi-Fi Trap: How Spies are Weaponizing Captive Portals (And Why You Should Stick to 5G)</h1>
<h2 id="apt29--storm-2945-captivecrunch-campaign-hijacking-hotel-captive-portals-to-deliver-cornflake-rat-with-mfa-bypass">APT29 / Storm-2945 CaptiveCrunch Campaign: Hijacking Hotel Captive Portals to Deliver CornFlake RAT with MFA Bypass</h2>
<p>Imagine you&rsquo;re staying at a hotel and you want to use the Wi-Fi on your phone or laptop. You turn on Wi-Fi, pick the hotel&rsquo;s network, and connect. But instead of going straight to the internet, a special webpage suddenly pops up on your screen. That webpage is the hotel captive portal: pretty standard.</p>
<p>It says: &ldquo;Hi! Before you can use the internet, please type in your room number (or last name) and click &lsquo;I agree&rsquo; to the rules.&rdquo; Once you do that, the gatekeeper lets you through and you can finally open Google, YouTube, email, and so on.</p>
<p>That&rsquo;s all a captive portal is: just the little sign-in page the hotel, coffee shop, or other business forces you to see before giving you internet access. That&rsquo;s usually fine, but recently threat actors have managed to hijack some of those portals, potentially exposing users to PII data theft, phishing, and session hijacking. The worst part: MFA and 2FA don&rsquo;t help here.</p>
<p>We all know the drill when checking into a hotel: drop the bags, find the room key, connect to the Wi-Fi. But if you&rsquo;re a corporate employee at a Fortune 500 company, a government official, NGO worker, diplomat, or an infosec professional heading to a conference like Black Hat, that complimentary hotel Wi-Fi could currently be an espionage trap.</p>
<p>A sophisticated Russian threat actor known as Midnight Blizzard (also tracked as APT29, UNC7005, or STORM-2945) is running a massive, global campaign dubbed CaptiveCrunch. They are manipulating hotel Wi-Fi captive portals to deliver malware and steal credentials.</p>
<p>We&rsquo;re not here to fear-monger. The reality is that public Wi-Fi is riskier than ever, but the mitigation is incredibly simple: ignore the Wi-Fi and stick with your 5G connection.</p>
<p>ClickFix isn&rsquo;t limited to hotel networks either — the same social engineering technique has been deployed through malicious Google Ads targeting developers. <a href="/chatgpt-codex-clickfix-malvertising-macsync/" target="_blank" rel="noopener noreferrer nofollow">See how ClickFix was used to deliver the MacSync infostealer via a fake ChatGPT link →</a></p>
<h2 id="what-is-the-captivecrunch-campaign">What is the CaptiveCrunch Campaign?</h2>
<p>Since early May 2026, threat intelligence teams have observed a distinct sub-cluster of Midnight Blizzard intercepting and manipulating DNS and HTTP traffic on hospitality networks. When a user connects to a compromised hotel network and gets redirected to the standard captive portal, the attackers route that traffic through their own malicious infrastructure.</p>
<p>














  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
      
      

      <picture>
        <source srcset="/img/1787963049197-pasted-image_hu_678bcadea4ef6a.webp 480w, /img/1787963049197-pasted-image_hu_4ddca049c5588665.webp 768w, /img/1787963049197-pasted-image_hu_b7767ca1179ee2e3.webp 1200w, /img/1787963049197-pasted-image_hu_b5c9ade04a857572.webp 1600w, /img/1787963049197-pasted-image_hu_6fcbad3b13dc04c4.webp 2000w, /img/1787963049197-pasted-image_hu_89a0448b73219eed.webp 2048w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1787963049197-pasted-image.png"
          srcset="/img/1787963049197-pasted-image_hu_335b2db30f06b4bf.png 480w, /img/1787963049197-pasted-image_hu_154e73fe17f5ee0a.png 768w, /img/1787963049197-pasted-image_hu_c190c4205f9a424a.png 1200w, /img/1787963049197-pasted-image_hu_ba48189313cc500b.png 1600w, /img/1787963049197-pasted-image_hu_9750a278735521f.png 2000w, /img/1787963049197-pasted-image.png 2048w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt="hotel WiFi attack"
          
          width="2048" height="1496"
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<p>What&rsquo;s particularly concerning is the scale. Researchers from Google Threat Intelligence and Microsoft MSRC have noted commonalities in the equipment and management systems used across affected networks. This suggests the attackers haven&rsquo;t just compromised a single isolated hotel, but may have found a way into shared services within the broader captive portal ecosystem, allowing them to intercept travelers worldwide at their discretion.</p>
<h2 id="the-tactics-fake-updates-clickfix-and-ai">The Tactics: Fake Updates, ClickFix, and AI</h2>
<p>Midnight Blizzard isn&rsquo;t relying on outdated tricks. They&rsquo;re moving fast and adapting quickly, using AI to support a significant portion of these operations and scale their social engineering and phishing flows dynamically.</p>
<p>Here is what victims are seeing:</p>
<p><strong>ClickFix social engineering.</strong> Attackers serve up highly convincing fake error messages. You might see a &ldquo;Windows Driver Repair Utility&rdquo; prompt or a fake Google verification failure page that gives you &ldquo;manual instructions&rdquo; to fix your connection before letting you online.</p>
<p><strong>Authentication abuse.</strong> They heavily abuse legitimate authentication workflows, including OAuth device code phishing and app password phishing. Because these use real Microsoft or Google flows, they often bypass the typical red flags a user would recognize.</p>
<h2 id="the-payload-cornflake-and-chocoshell">The Payload: CornFlake and ChocoShell</h2>
<p>If a user falls for the trap and executes the download, they&rsquo;re hit with malware designed for long-term espionage.</p>
<p><strong>CornFlake</strong> is a full-featured Remote Access Trojan written in Go. Upon execution, it shows fake progress windows — a Windows Update screen or a PDF viewer installer — to distract the user while it embeds itself. Once running, it can log keystrokes, steal browser credentials, record audio and video, and monitor inserted USB drives.</p>
<p><strong>ChocoShell</strong> is a PowerShell-based infostealer that runs entirely in-memory. Its primary job is to rapidly collect browser session cookies, saved passwords, and Microsoft 365 Single Sign-On tokens.</p>
<p>The fake domains used in this campaign closely resemble Microsoft services:</p>
<ul>
<li><code>ms365-device\[.\]com</code></li>
<li><code>ms365-live\[.\]com</code></li>
<li><code>m365-owa\[.\]com</code></li>
<li><code>owa-ms365\[.\]com</code></li>
</ul>
<p>The infrastructure observed is hosted across various networks including AS262287.</p>
<p>














  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
      
        
      
      
      

      <picture>
        <source srcset="/img/1787963095977-pasted-image_hu_a59afc1d1a27e94a.webp 480w, /img/1787963095977-pasted-image_hu_74a68b758a88ed6.webp 768w, /img/1787963095977-pasted-image_hu_bf77a4f79740eed4.webp 1200w, /img/1787963095977-pasted-image_hu_404e4805fcedcfdd.webp 1414w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1787963095977-pasted-image.png"
          srcset="/img/1787963095977-pasted-image_hu_f78850b3f8a4495f.png 480w, /img/1787963095977-pasted-image_hu_e9899f147a638d6d.png 768w, /img/1787963095977-pasted-image_hu_92b981104c78d14a.png 1200w, /img/1787963095977-pasted-image.png 1414w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="1414" height="793"
          
          loading="lazy"
          >
      </picture>
    
  


















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
      
      
      

      <picture>
        <source srcset="/img/1787963109465-pasted-image_hu_4742a58ef0e30115.webp 480w, /img/1787963109465-pasted-image_hu_e0401e832d31e92d.webp 768w, /img/1787963109465-pasted-image_hu_7c9ae7df445232a7.webp 1200w, /img/1787963109465-pasted-image_hu_300a5bedf369fb4b.webp 1600w, /img/1787963109465-pasted-image_hu_509ba9c0931cb30e.webp 1905w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1787963109465-pasted-image.png"
          srcset="/img/1787963109465-pasted-image_hu_568c95275fb57f1e.png 480w, /img/1787963109465-pasted-image_hu_2e1e6cd6121ccad7.png 768w, /img/1787963109465-pasted-image_hu_80ff17c395d5b3bc.png 1200w, /img/1787963109465-pasted-image_hu_da556e700bd98bc0.png 1600w, /img/1787963109465-pasted-image.png 1905w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="1905" height="975"
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<h2 id="who-are-they-targeting">Who Are They Targeting?</h2>
<p>Midnight Blizzard&rsquo;s operations align with Russian foreign policy interests. This specific campaign heavily targets individuals of interest to Russia: personnel in academia, aerospace, defense, government, diplomatic entities, and NGOs across the US and Europe.</p>
<p>If you&rsquo;re traveling for business in any of these sectors, or if you&rsquo;re heading to major cybersecurity conferences like Black Hat, you&rsquo;re squarely in the crosshairs.</p>
<h2 id="the-fix-stick-to-5g">The Fix: Stick to 5G</h2>
<p>














  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
      
      

      <picture>
        <source srcset="/img/1787963145808-pasted-image_hu_88c29a954f8a59a7.webp 480w, /img/1787963145808-pasted-image_hu_b413a6a5d7bc5302.webp 768w, /img/1787963145808-pasted-image_hu_d1eb8a581b090578.webp 1200w, /img/1787963145808-pasted-image_hu_9535b15bad1c7e8f.webp 1600w, /img/1787963145808-pasted-image_hu_7a8be9b043b3e79d.webp 2000w, /img/1787963145808-pasted-image_hu_882678fb34c0f897.webp 2048w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1787963145808-pasted-image.png"
          srcset="/img/1787963145808-pasted-image_hu_1619abff5d4a463a.png 480w, /img/1787963145808-pasted-image_hu_9f860114efe77d40.png 768w, /img/1787963145808-pasted-image_hu_f16a57ec8f1929c8.png 1200w, /img/1787963145808-pasted-image_hu_c6aad851d4155889.png 1600w, /img/1787963145808-pasted-image_hu_94504f8ab3afc8af.png 2000w, /img/1787963145808-pasted-image.png 2048w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="2048" height="1117"
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<p>It sounds like a sophisticated, scary threat, but the solution is surprisingly straightforward. You don&rsquo;t need complex workarounds, VPN gymnastics, or specialized hardware.</p>
<p>Don&rsquo;t connect to hotel Wi-Fi, especially if you&rsquo;re a corporate employee at a Fortune 500 firm, a government official, NGO worker, diplomat, or an infosec professional. Consider that complimentary hotel Wi-Fi as if it does not exist. Anything with an intermediate captive portal — hotels, airports — should be treated with caution. Stick to mobile, cellular, or 5G.</p>
<p>Today&rsquo;s 5G coverage is robust, fast, and vastly more secure than a shared hospitality network. Use your smartphone&rsquo;s cellular data or a dedicated 5G mobile hotspot. If you must use a laptop, tether it to your phone. The minor inconvenience of using your data plan is infinitely better than handing your Microsoft 365 session tokens and device control to a nation-state intelligence service.</p>
<p>Stay safe, stay off the captive portals, and travel smart.</p>
<hr>
<p>Sources:</p>
<ul>
<li><a href="https://zscaler.com/blogs/security-research/captivecrunch-midnight-blizzard-weaponizes-hotel-wi-fi-captive-portals" target="_blank" rel="noopener">Zscaler: CaptiveCrunch — Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals</a>
 —</li>
<li><a href="https://cloud.google.com/blog/topics/threat-intelligence/distinct-clusters-target-individuals-of-interest-to-russia" target="_blank" rel="noopener">Google Threat Intelligence: Distinct Clusters Target Individuals of Interest to Russia</a>
</li>
<li><a href="microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft">Microsoft Security Blog: CaptiveCrunch — Midnight Blizzard Targets Travelers Worldwide</a>
</li>
</ul>
]]></content:encoded><category>Research</category><category>phishing</category><category>security</category><category>Malware</category><category>Nation-State Threats</category></item></channel></rss>