Microsoft Threat Intelligence has issued an urgent global security alert warning business travelers and corporate networks about a sophisticated internet hijacking campaign dubbed CaptiveCrunch. Active since May, the campaign is operated by Storm-2945, a sub-cluster linked to the Russian state-sponsored threat group Midnight Blizzard. The threat actors compromise hospitality infrastructure and captive portal Wi-Fi landing pages at hotels and conference centers worldwide. By manipulating DNS and HTTP traffic, attackers force users onto fraudulent login portals and present convincing fake software update dialogues. These malicious prompts trick victims into downloading remote access trojans and fileless infostealers that harvest Microsoft 365 credentials, browser session cookies, and corporate network tokens. Successful exploitation grants hackers the ability to capture device keystrokes, record audio and video streams, and execute remote surveillance. Microsoft strongly urges individuals and corporate IT administrators to bypass public guest networks in favor of secure cellular hotspots and encrypted virtual private network connections.
Prepared by Jonathan Pierce and reviewed by editorial team.
Left: Outlines corporate vulnerabilities and demands strict federal cybersecurity regulations. Center: Reports factual Microsoft warnings and technical mitigation advice for travelers. Right: Focuses on foreign state-sponsored espionage threats targeting western business networks.
Microsoft published threat intelligence findings on August 10, 2026. https://www.microsoft.com/en-us/security/blog/
No left-leaning sources found for this story.
Microsoft Reverses Course to Allow Windows 11 Removal of Forced AI Photos App
Windows Latest Malwarebytes The Times of India CyberFence Platform Microsoft Security Blog CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft https://therecord.media/russian-wifi-hackers-hotels Malwarebytes Bias Rating: Center Help Net Security EdTech Innovation Hub Redmondmag Infosecurity Magazine SecurityWeek Dark Reading BleepingComputer The Hacker News SC Media CyberScoop Security Magazine TechCrunch The Register SiliconANGLE VentureBeatNo right-leaning sources found for this story.
Comments