Microsoft Threat Intelligence has told business travellers to stop trusting guest Wi-Fi. In a report published on 31 July, the company detailed a campaign it calls CaptiveCrunch, in which attackers have
taken control of the sign-in infrastructure behind hotel and conference-centre networks and are using it to push fake software updates and phishing pages at anyone who connects.
Microsoft attributes the campaign to a cluster it tracks as Storm-2945, which it assesses to be an operational sub-unit of Midnight Blizzard, the group better known as APT29 or Cozy Bear. The US and UK governments have publicly linked that broader actor to Russia’s Foreign Intelligence Service, the SVR. Security firm ReliaQuest flagged the same activity on 23 July, eight days before Microsoft’s disclosure.
What The Attackers Are Actually Doing
The weak point is the captive portal, the sign-in page that hijacks your browser the moment you join a guest network. On the compromised venues ReliaQuest examined, that same portal gateway was also handing out DNS answers to every device on the network. Control the gateway and you control where every connected laptop gets sent.
Since early May, Microsoft says Storm-2945 has been manipulating DNS and HTTP traffic on these networks. The most common trick is to intercept the automatic connectivity check your laptop runs when it joins a new Wi-Fi network and answer it with something that looks like a system prompt. Some pages use ClickFix-style instructions, which tell you to open a terminal or a Windows utility and paste in a command the attacker supplies.
That distinction matters. The hijacked gateway decides where you land. It does not infect your machine on its own. Every version of this attack needs you to click, download or type something.
Two Routes Into Your Account
Fake system prompts. Microsoft has catalogued a set of decoy windows served through these portals, each impersonating something routine: a Windows Update screen telling you not to switch off your computer, a Windows Security scan, a DirectX web installer, a Visual C++ redistributable, a disk optimiser, a network diagnostics tool, a browser update, a document viewer. Some copy Google’s unusual-traffic security check almost exactly.
Credential and session theft. Others drop you on a convincing Microsoft sign-in page. Since 16 July, Microsoft has also seen landing pages steering users into device code authentication, a legitimate Microsoft sign-in method built for screens that cannot show a normal login box. The abuse is elegant: the attacker starts a sign-in, gets a code, and persuades you to type it into a genuine Microsoft page. Nothing about the page you are typing into is fake, which is exactly why it works.
What Happens If The Malware Lands
Once installed, the payload gives the operator close to total visibility. Microsoft lists keystroke logging, audio and video recording, screenshots, theft of browser cookies and saved passwords, USB drive monitoring, and remote command execution through PowerShell or Command Prompt. Victims can also find their traffic routed through an attacker-controlled proxy for further credential harvesting.
The end goal, according to ReliaQuest, is corporate travellers’ accounts. Get into a Microsoft 365 tenant and you have the email, the OneDrive files and a route into the corporate network behind them.
The AI Angle
Microsoft says Storm-2945 has been running AI-augmented operations since February, including device code and OAuth phishing that ends with attacker-controlled devices registered in Entra ID. The company says AI supported a significant share of the group’s work but has not said which systems were used or which tasks were automated. Anthropic and OpenAI both assisted the investigation, though Microsoft has not detailed how.
There is also an Android component. Some ClickFix pages tell mobile users to sideload an APK, which Microsoft describes as noticeably less developed than the Windows tooling, suggesting the group is still experimenting there.
How Not To Get Caught
Use your own connection. A personal mobile hotspot removes the entire attack surface. If you must use guest Wi-Fi, run a VPN so the compromised network sees encrypted packets and nothing else.
Treat every prompt from a captive portal as hostile. Legitimate browser updates, Windows updates, security patches and network certificates never arrive through a hotel sign-in page. If a network asks you to install something, the answer is no.
Never paste a command you did not write. ClickFix works because people follow instructions that look technical. No genuine troubleshooting flow asks you to open PowerShell and run a string from a web page.
Be suspicious of device codes. If you did not initiate a sign-in, do not enter a code, even on a real Microsoft page.
For IT teams: enforce phishing-resistant MFA, audit Entra device registrations, and review how much information staff hand over to hospitality providers on the road.
Microsoft has published Defender detections and indicators of compromise specific to CaptiveCrunch in its full advisory. It also notes the tactics resemble a DNS hijacking operation it attributed to Forest Blizzard, the group tracked elsewhere as APT28, back in April. Despite the overlap, this one is pinned on Storm-2945.











