A sophisticated cyberespionage campaign named CaptiveCrunch, orchestrated by the Russian state-sponsored group Midnight Blizzard, has been uncovered by Microsoft Threat Intelligence. This campaign is specifically targeting the hospitality sector's captive portal systems to execute adversary-in-the-middle attacks on unsuspecting travelers. By manipulating DNS and HTTP traffic, these cybercriminals reroute victims to malicious sites that deploy malware or phishing pages. Among the tactics used are Microsoft Entra device code authentication prompts aimed at taking over legitimate Microsoft 365 sessions.
Once a system is compromised, the attackers deploy the CornFlake remote access trojan and ChocoShell PowerShell infostealer. These tools enable the attackers to maintain persistence within the network, gather credentials and authentication tokens, conduct surveillance, and extract sensitive data from their targets. The malware can steal a wide array of information, including browser credentials, Microsoft 365 SSO and Azure AD tokens, Wi-Fi credentials, documents, and even audio and video recordings. Additionally, the attackers are employing artificial intelligence to enhance various aspects of their operations, such as malware development and campaign management.
The impact of this campaign is significant, posing a threat to the security and privacy of travelers using hospitality networks. The use of AI in cyberattacks marks a concerning evolution in the capabilities of threat actors. Organizations, especially those in the hospitality industry, must be vigilant and proactive in safeguarding their networks against such threats. Implementing robust security measures and keeping abreast of the latest threat intelligence are crucial steps in mitigating the risks posed by these advanced cyberattacks.


