Microsoft has linked the global CaptiveCrunch hotel Wi-Fi campaign to Midnight Blizzard, the Russia-linked threat group also associated with Storm-2945. According to the company, the operation focused on hotel wireless networks and used that access to go after Microsoft 365 accounts.
The reported technique combined several tactics. Microsoft said the attackers used captive-portal hijacking on hotel Wi-Fi, device-code phishing, and custom malware as part of the effort. The campaign appears to have taken advantage of shared Wi-Fi infrastructure, a setup that can expose many travelers and organizations through the same network environment.
By tying the activity to Midnight Blizzard and identifying custom tools used in the attacks, Microsoft is giving defenders more context on how the campaign worked. The mention of fake Windows-related lures suggests the attackers tried to make malicious prompts or downloads appear routine to users connecting through hotel networks.
The disclosure adds to concerns about business travel security, especially when employees sign in to cloud services such as Microsoft 365 over public or semi-public hotel internet access. Microsoft’s findings indicate that hotel Wi-Fi remains an attractive pathway for sophisticated groups looking to steal credentials and compromise enterprise accounts.