Russian State APT Targets Public Wi-Fi Networks for Credential Theft
A Russian state-sponsored advanced persistent threat (APT) group, identified as Storm-2945, has been linked to a recent campaign targeting public Wi-Fi networks to steal Microsoft 365 credentials. The attackers used compromised routers to redirect users to malicious infrastructure, employing an adversary-in-the-middle technique. This campaign, dubbed CaptiveCrunch, primarily targeted sectors such as financial services, healthcare, and retail. The operation involved serving malware disguised as browser updates, enabling the attackers to conduct reconnaissance and steal credentials.