Telecom Books

Signals. Spectrum. Stories.

Breaking News
Plan Shifts

Microsoft blames Russian group for hacking attacks

By Florence Bennett August 6, 2026
Microsoft blames Russian group for hacking attacks - russian hacking
Microsoft blames Russian group for hacking attacks

Microsoft has attributed a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard (APT29), specifically to a sub-cluster known as Storm-2945. The campaign, named CaptiveCrunch, manipulates DNS settings on hotel and conference Wi-Fi equipment to steal Microsoft 365 accounts.

The company believes the campaign has been active since at least early May, though the threat actor has run device and OAuth code phishing operations since February. Microsoft has identified two malware families, CornFlake and ChocoShell, used for persistent access, credential theft, surveillance, and data exfiltration.

The attackers manipulate DNS and HTTP traffic on networks served by captive portal equipment, allowing them to intercept user connections to hotel and conference center Wi-Fi. After modifying DNS settings, attackers can redirect victims in three ways.

The first method leads to phishing pages impersonating Microsoft 365 login portals. The second uses device code phishing pages that exploit Microsoft Entra ID authentication flows, which Microsoft has observed since July. The third involves fake browser and operating system update pages that deliver malware to Windows through ClickFix prompts requesting user verification.

Related: WhatsApp adds new group chat tools

CornFlake is a Go-based remote access trojan with a broad capability set, including remote shell access, keylogging, and browser credential theft. It disguises itself as “Cloud Sync Service” to appear legitimate and uses several persistence mechanisms. ChocoShell is an in-memory PowerShell credential stealer targeting browser cookies and Microsoft 365 tokens.

Microsoft analyzed the code comments of both malware families and assesses that AI tools were likely used to develop them. The company also discovered an unprotected web-based management panel, FruitStone, which the threat actor used to manage infected systems and capture screenshots and keystrokes.

They recommend treating hotel and conference Wi-Fi as untrusted and taking measures to reduce risk, such as using a private cellular or managed connection instead of hotel or conference Wi-Fi whenever possible. Users and organizations should also adopt phishing-resistant authentication with MFA and passkeys rather than relying on passwords alone.

Microsoft 365 accounts are vulnerable.

Leave a Reply

Your email address will not be published. Required fields are marked *

© 2026 Telecom Books. All rights reserved.