EXECUTIVE SUMMARY
The Russia-based threat actor Midnight Blizzard is conducting a campaign named CaptiveCrunch to steal credentials and sensitive data from corporate travelers. This operation primarily targets the hospitality sector across multiple countries by compromising captive portal networks found in hotels and conference centers. The attackers manipulate network traffic to redirect users to fraudulent sites, aiming to harvest authentication tokens and session cookies. Their ultimate goal is long-term espionage and intelligence gathering in support of foreign policy interests, specifically focusing on high-value corporate and government targets while they are away from their secure office environments.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
The Russia-based threat actor Midnight Blizzard is conducting a campaign named CaptiveCrunch to steal credentials and sensitive data from corporate travelers. This operation primarily targets the hospitality sector across multiple countries by compromising captive portal networks found in hotels and conference centers. The attackers manipulate network traffic to redirect users to fraudulent sites, aiming to harvest authentication tokens and session cookies. Their ultimate goal is long-term espionage and intelligence gathering in support of foreign policy interests, specifically focusing on high-value corporate and government targets while they are away from their secure office environments.[emaillocker id="1283"]
Attackers gain access by manipulating DNS and HTTP traffic on compromised Wi-Fi networks to intercept connection attempts. Victims encounter deceptive prompts mimicking legitimate system updates that trick them into manually downloading and executing malicious software. Once installed, a remote access trojan establishes persistence by registering as a system service and creating registry keys to ensure survival. This malware enables the theft of stored passwords, keystrokes, and files.
The group also uses adversary-in-the-middle techniques to intercept authentication flows, granting them ongoing access to cloud accounts without needing direct credentials. This threat poses significant risk because it bypasses email security filters by exploiting network infrastructure rather than relying on phishing messages. Corporate travelers are especially vulnerable when using public Wi-Fi, as the attack appears to be a standard system update. Detecting these intrusions is difficult due to the use of encrypted traffic and legitimate-looking processes. Organizations should warn employees about the risks of public networks and enforce the use of virtual private networks. Additionally, maintaining offline backups, applying security patches promptly, and monitoring for suspicious service registrations are critical steps to mitigate the risk of compromise.
THREAT PROFILE:
| Tactic | Technique ID | Technique | Sub-technique |
| Initial Access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defense Evasion | T1562.001 | Impair Defenses | Disable or Modify Tools |
| Credential Access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Credential Access | T1552.001 | Unsecured Credentials | Credentials In Files |
| Discovery | T1082 | System Information Discovery | — |
| Command and Control | T1573.002 | Encrypted Channel | Asymmetric Cryptography |
| Command and Control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | — |
MBC MAPPING:No MBC Mapping content found in HTML.
REFERENCES:
reports contain further technical details:
https://www.securityweek.com/russian-state-apt-linked-to-recent-public-wi-fi-gateway-hacking/
https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/