Threats

Russian State APT Storm-2945 Linked to Public Wi-Fi Gateway Hacking

August 3, 2026 12:02 · 12 min read
Russian State APT Storm-2945 Linked to Public Wi-Fi Gateway Hacking

A Russian state-sponsored Advanced Persistent Threat (APT) group, known as Storm-2945, a subgroup of Midnight Blizzard (also tracked as APT29, Cozy Bear, the Dukes, and Yttrium), has been linked to a recent credential theft campaign targeting public Wi-Fi gateway appliances at organizations running captive portal networks, according to a report by Microsoft.

Background on the Threat Actor

Midnight Blizzard is a threat actor believed to be sponsored by the Russian Foreign Intelligence Service (SVR), known for targeting government and diplomatic entities, non-governmental organizations (NGOs), and IT services providers in the US and Europe for intelligence gathering in support of Russian foreign policy interests.

Campaign Tactics and Techniques

The campaign, dubbed CaptiveCrunch, was first flagged by ReliaQuest roughly a week ago, which noticed that hackers had modified the DNS configurations of compromised small office/home office (SOHO) routers to redirect users to attacker-controlled infrastructure. The attackers were using the adversary-in-the-middle (AitM) technique to intercept the Microsoft 365 credentials of traveling employees within the financial services, professional services, legal, healthcare, energy, and retail sectors.

Storm-2945 started manipulating DNS and HTTP traffic from captive portal networks, such as those at hotels, conference centers, and other shared venues, in May, likely through access to shared services within the captive portal ecosystem. As part of CaptiveCrunch, the attackers have been serving Golang-based Windows remote access trojans (RATs) in the form of browser updates.

Malware and Tools Used

The malware enabled reconnaissance, credential and session token theft, file and keystroke collection, audio and video surveillance, and remote shell access. The threat actor has been using various ClickFix techniques to convince users to download malware and appears to have been targeting Android users with similar methods to entice them into fetching and installing an APK file.

Storm-2945 targeted Windows users with the CornFlake RAT and infostealer implant and the ChocoShell PowerShell-based infostealer, and managed its infrastructure and agents via the FruitStone web-based command-and-control (C&C) panel.

Impact and Attribution

To date, Microsoft has identified widespread compromise of Wi-Fi networks at hospitality-related organizations and other networks serviced by captive portal equipment in several countries. The campaign shared similarities with FrostArmada, an espionage operation mounted by Russia-linked APT28 (also known as Forest Blizzard and Fancy Bear), but Microsoft has now clearly attributed the fresh campaign to Storm-2945.

Over the past two weeks, Microsoft says, some CaptiveCrunch landing pages have been directing victims to device code authentication flow experiences, instructing them to enter device codes into Microsoft sign-in pages to authenticate the threat actor’s session. This activity is consistent with previously reported device code phishing operations conducted by Midnight Blizzard since August 2024.

Microsoft notes that Midnight Blizzard operations often involve compromise of valid accounts and, in some highly targeted cases, advanced techniques to compromise authentication mechanisms within an organization to expand access and evade detection.

Conclusion

The CaptiveCrunch campaign highlights the ongoing threat posed by Russian state-sponsored APT groups, which continue to evolve and refine their tactics, techniques, and procedures (TTPs) to compromise targeted organizations and individuals. The use of public Wi-Fi gateway appliances as a vector for credential theft and malware distribution underscores the importance of securing these often-overlooked devices and networks.


Source: SecurityWeek

Source: SecurityWeek

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free