CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Brief
In this article
- The CaptiveCrunch campaign
- Storm-2945 and Midnight Blizzard
- CaptiveCrunch tradecraft and tooling
- How to protect against CaptiveCrunch activity
- Microsoft Defender detections and hunting guidance
- Indicators of compromise
Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide.
Despite some tactic, technique, and procedure (TTP) similarities to the Forest Blizzard DNS hijacking operation that we publicly disclosed in April 2026, we attribute this campaign, which we call CaptiveCrunch, to Storm-2945.
