Microsoft Links CaptiveCrunch to Russian Threat Actor Midnight Blizzard
- Microsoft has attributed the CaptiveCrunch tool to Storm-2945, a sub-cluster of the Russian state-sponsored threat actor known as Midnight Blizzard.
- The activity involves the deployment of a captive portal, a web page that requires users to authenticate or agree to terms before accessing the internet.
- Midnight Blizzard is a recognized Russian state-sponsored actor that frequently targets government organizations and technology companies.
Microsoft has attributed the CaptiveCrunch tool to Storm-2945, a sub-cluster of the Russian state-sponsored threat actor known as Midnight Blizzard. According to reporting from iTnews on August 4, 2026, the group uses this tool to hijack hotel Wi-Fi networks to intercept data and target specific individuals.
The activity involves the deployment of a captive portal, a web page that requires users to authenticate or agree to terms before accessing the internet. In this instance, the portal serves as a mechanism for the Storm-2945 cluster to capture credentials and monitor network traffic.
Midnight Blizzard and the Storm-2945 Sub-cluster
Midnight Blizzard is a recognized Russian state-sponsored actor that frequently targets government organizations and technology companies. Microsoft identifies Storm-2945 as a specific sub-group within this broader operation, specializing in the deployment of CaptiveCrunch.
By targeting hotel Wi-Fi, the actors exploit a common vulnerability in traveler behavior. Users often trust the localized login pages provided by hospitality services, making these portals an effective vector for credential theft and man-in-the-middle attacks.
Technical Impact of CaptiveCrunch
CaptiveCrunch functions by mimicking the legitimate authentication process of a hotel’s internet service. Once a target connects to the compromised network, the tool intercepts the communication between the user’s device and the actual gateway.
This allows the Storm-2945 cluster to perform the following actions:
- Capture usernames and passwords entered into the fake portal.
- Redirect users to malicious sites designed to deliver further malware.
- Monitor unencrypted traffic passing through the hijacked connection.
The use of these tactics suggests a high-precision targeting strategy, as hotel networks are often frequented by corporate executives and government officials traveling for business.
