Midnight Blizzard Abuses Hotel Wi‑Fi Captive Portals

eSecurity Planet · High sophistication
Last updated October 8, 2026

Microsoft reports a real Midnight Blizzard-linked campaign where attackers tamper with hotel Wi‑Fi captive portals to redirect travelers to phishing and fake update pages. The goal is to steal credentials or trick users into installing malware, which can follow employees back into corporate accounts and devices after the trip.

How the attack worked

Microsoft reports that Storm-2945, assessed as a Midnight Blizzard sub-cluster, resumed a campaign called CaptiveCrunch on Sept. 29. The attackers manipulate DNS and HTTP traffic on networks served by hotel captive portals, the sign-in pages travelers see before a guest Wi-Fi network grants internet access. By controlling that traffic path, they can redirect users toward phishing pages or fake browser and operating-system updates before the traveler ever reaches the site they intended to visit.

The three user-facing lures

Three workflows have been described in connection with this campaign:

  • A fake update prompt that tells the user a browser or OS update is required before internet access is granted.
  • ClickFix-style instructions that tell the user to open PowerShell or Terminal and run commands to fix a connectivity issue, with the user effectively installing malware themselves.
  • Device-code phishing, where the victim is sent to a legitimate Microsoft sign-in page but enters a code tied to a session the attacker initiated, authorizing the attacker's access instead of their own.

Malware families associated with the campaign include CornFlake, which provides persistent Windows remote access, and ChocoShell, which steals cookies, tokens, and passwords. Both can enable account and device compromise that follows the employee home after travel.

Why it succeeded

Travelers expect friction when connecting to hotel Wi-Fi: sign-in pages, acceptance screens, and occasional update prompts are normal parts of that experience. This expectation makes it easy for a manipulated captive portal to insert a fake update, a troubleshooting script, or a sign-in flow without raising immediate suspicion, especially for employees focused on getting online quickly between meetings or travel.

What to watch for

  • Updates being prompted by a Wi-Fi sign-in page instead of the device's normal update mechanism.
  • Unexpected redirects before reaching an intended website.
  • A portal asking to install software, certificates, or troubleshooting tools to get online.
  • Any instruction to open PowerShell or Terminal as part of connecting to Wi-Fi.
  • A sign-in or device-code prompt that does not match the action the user intended to take.

How to build resistance

Employees should avoid installing updates, certificates, or troubleshooting tools presented through captive portals, and treat unexpected PowerShell or Terminal instructions as suspicious. Organizations can disable device-code authentication where it isn't needed and adopt phishing-resistant MFA. If an employee reports a fake update, unusual captive portal, or unexpected sign-in flow, security teams should treat it as a possible compromise: revoke sign-in sessions and refresh tokens, invalidate application sessions where supported, and review recent cloud sign-ins for activity that doesn't match the employee's travel or normal account use.

Key findings

  • Microsoft says Storm-2945 (assessed as a Midnight Blizzard sub-cluster) resumed the CaptiveCrunch campaign on Sept. 29.
  • Attackers manipulate DNS and HTTP traffic on captive-portal networks to redirect travelers to attacker-controlled pages (including fake updates).
  • Two described user-facing lures/workflows are ClickFix-style instructions (users run commands themselves) and device-code phishing (user completes a sign-in that authorizes the attacker session).
  • Malware families mentioned include CornFlake (persistent Windows remote access) and ChocoShell (cookie/token/password theft), enabling post-travel account/device compromise.

Who’s being targeted

  • Commonly targeted roles: All employees who travel, Executives, Sales, Consultants, IT / Service Desk, Identity & Access Management (IAM) team.
  • Affected industries: Hospitality (hotels and guest Wi‑Fi providers), Any organization with traveling employees (cross-industry).
  • Attack channels: website.
  • Impersonated: Hotel Wi‑Fi captive portal (and a fake browser/operating-system update page), Hotel Wi‑Fi support / captive portal troubleshooting page, Microsoft sign-in (legitimate page used in a misleading flow).

Red flags to watch for

  • Updates are being prompted by a Wi‑Fi sign-in page (not the device’s normal update mechanism)
  • Unexpected redirect before reaching the intended website
  • Portal asks to install software/certificates to get online
  • Any Wi‑Fi portal telling users to run command-line instructions
  • Instructions to open PowerShell/Terminal as part of “getting online”
  • “Fix” steps that install tools/scripts rather than simply logging in
  • Sign-in flow appears during Wi‑Fi access, not normal work activity
  • A code-based login that the user did not initiate
  • Authentication prompt doesn’t match the user’s intended action/site
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the CaptiveCrunch campaign?

It is a campaign Microsoft attributes to Storm-2945, a Midnight Blizzard sub-cluster, that resumed on Sept. 29 and manipulates DNS and HTTP traffic on hotel captive-portal networks to redirect travelers to attacker-controlled pages.

How do attackers trick users on hotel Wi-Fi?

Attackers control the captive portal traffic path to show fake browser or operating-system updates, ClickFix-style instructions that ask users to run commands themselves, and device-code phishing that leads to a real Microsoft sign-in page tied to an attacker-generated code.

What malware is involved?

The campaign has been linked to CornFlake, which provides persistent Windows remote access, and ChocoShell, which steals cookies, tokens, and passwords, enabling post-travel account and device compromise.

What should employees do if they see an unusual captive portal?

Avoid installing any updates, certificates, or troubleshooting tools prompted by the portal, treat unexpected PowerShell or Terminal instructions as suspicious, and report the incident so security teams can review sign-ins and revoke sessions if needed.

Read the video transcript

You connect to hotel Wi‑Fi, and before Google even loads, a page pops up: “Before you can access the internet, you must install a required browser update.” Microsoft says Midnight Blizzard’s Storm‑2945 hijacks hotel captive portals like this, manipulating DNS and HTTP so you land on fake update pages that drop CornFlake or ChocoShell, or ClickFix pages telling you to run PowerShell or Terminal commands yourself. Here’s the trick: the update or “fix” comes from the Wi‑Fi sign‑in page, not your device’s normal updater. You get weird redirects before your real site loads, and the portal suddenly wants you to install software, certificates, or run command-line fixes just to get online. If any hotel Wi‑Fi portal ever asks you to install updates, certificates, or run commands, stop immediately, disconnect, and report it as a security incident, this isn’t a Wi‑Fi problem, it’s an attack path back into our accounts.

Categories

Similar attacks

Fake Gmail Attachment Lure Drops Antino Backdoor

Fake Gmail Attachment Lure Drops Antino Backdoor

A China-nexus threat group targeted government and policy organizations across Asia using spear-phishing emails tailored to the victim’s interests. The emails used spoofed trusted senders and a realistic fake Gmail attachment preview that linked to attacker-controlled pages, ultimately installing…

October 2, 2026
Passkey-Themed Phishing Hits Microsoft 365

Passkey-Themed Phishing Hits Microsoft 365

Microsoft warns of an active social engineering campaign where attackers pose as an IT help desk and pressure employees to “update” passkeys/MFA/SSO. Victims are sent to fake Microsoft sign-in pages or tricked into approving access via device-code login, enabling attackers to add their own MFA…

September 14, 2026
Phishing Uses Google Links to Steal Microsoft Logins

Phishing Uses Google Links to Steal Microsoft Logins

Researchers reported an active, large-scale phishing campaign that starts with links hosted on legitimate Google services, then redirects victims to attacker-controlled sites. The final pages mimic Microsoft sign-in or “identity verification” flows to steal credentials/MFA codes or trick targets…

September 9, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026