Midnight Blizzard hijacks hotel Wi-Fi and steals logins from travellers
Microsoft published an account on 31 July 2026 of the campaign it calls CaptiveCrunch. The activity is attributed to Midnight Blizzard, an actor Microsoft links to Russia, and it has been observed since early May 2026. The attackers hijack wireless networks at hotels and other places travellers connect from, and use the network sign in portal to send the user onwards to content they control themselves. The goal is to deliver malware, steal passwords and obtain Microsoft 365 access tokens. Microsoft names three components in the campaign, the remote access tool CornFlake, the stealer ChocoShell and the operator panel FruitStone.
What happens technically
A hotel guest network uses a sign in portal, known as a captive portal. The portal works by intervening in the traffic before the guest is allowed onwards, meaning it answers name service lookups and sends the browser to its own page with terms and login. This built in redirection is the entire point of the portal, and it is also what the attacker takes over. Microsoft describes how the actor manipulates DNS and HTTP traffic on networks using such portal equipment, so that the user ends up in infrastructure the attacker controls. Your machine asks for a connectivity check of its own accord when it joins a new network, and the response to that check is the opening the attacker uses to present something that looks like a browser or operating system update.
The next element is social engineering of the ClickFix kind, where the user is asked to paste and run a command to fix a problem that looks technical. The malware then starts, and the user has done the work that would otherwise require a vulnerability. CornFlake is a remote access trojan that logs keystrokes, takes screenshots and pulls credentials from browsers, among other things. ChocoShell runs in memory and collects session cookies, saved passwords, Microsoft 365 access tokens and wireless network passwords. FruitStone is the panel the operators run the campaign from. The most important part to grasp is the theft of access tokens, meaning the digital proofs a service issues once login and multi factor authentication have been completed. Whoever steals such a token can use the service without going through the login again, and without triggering multi factor authentication. Microsoft also states that the actor has run device code phishing since February 2026.
What this means for you if you travel with a work machine
This case lands unevenly, and as we read it, it lands at the top. The people who spend most nights in hotels are executives, sales staff, consultants and board members, meaning the same people who hold the broadest access in the systems. If you are one of them, you have little time to stop and think in a lobby at 23:00. The attack requires no vulnerability in your machine, only a network you trust and a dialogue box that looks reasonable. The measures that work for you therefore sit with travel and with identity, not with the firewall back home.
The theft of access tokens also changes what your response has to contain. Changing the password alone does not stop an attacker who already holds a valid token, because the token was issued before the password changed. Your response must therefore include revoking sessions and reviewing which tokens are in use. If you are covered by NIS2, this is Article 21 in practical form, covering both access control and incident handling. In our assessment the cheapest effective measure is a travel rule simple enough to be remembered, namely that your work machine never joins the hotel network, but uses mobile broadband.
Berigo recommends
- Have travellers use mobile broadband or the organisation's own solution, and keep the work machine off open guest networks.
- Teach staff that no legitimate update ever asks you to paste and run a command.
- Restrict or disable device code authentication with conditional access, since the actor also uses that route.
- Require compliant devices and passwordless sign in methods for access to company services.
- After travel, look for unusual sign ins and token use, and revoke sessions on suspicion rather than only changing the password.
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch