A Russian state-sponsored APT is behind a recent credential theft campaign mounted via hacked public Wi-Fi gateway appliances at organizations running captive portal networks, Microsoft reports.
The campaign was flagged roughly a week ago by ReliaQuest, which noticed that hackers had modified the DNS configurations of compromised small office/home office (SOHO) routers to redirect users to attacker-controlled infrastructure.
The attackers were using the adversary-in-the-middle (AitM) technique to intercept the Microsoft 365 credentials of traveling employees within the financial services, professional services, legal, healthcare, energy, and retail sectors.
ReliaQuest pointed out that the campaign shared similarities with FrostArmada, an espionage operation mounted by Russia-linked APT28 (also known as Forest Blizzard and Fancy Bear), but did not make a clear attribution.
Now Microsoft says that Storm-2945, a subgroup of Midnight Blizzard (also tracked as APT29, Cozy Bear, the Dukes, and Yttrium), a threat actor believed to be sponsored by the Russian Foreign Intelligence Service (SVR), is behind the fresh campaign, dubbed CaptiveCrunch.
Midnight Blizzard is known for targeting government and diplomatic entities, non-governmental organizations (NGOs), and IT services providers in the US and Europe for intelligence gathering in support of Russian foreign policy interests.
“Midnight Blizzard operations often involve compromise of valid accounts and, in some highly targeted cases, advanced techniques to compromise authentication mechanisms within an organization to expand access and evade detection,” Microsoft notes.
Storm-2945, the tech giant says, started manipulating DNS and HTTP traffic from captive portal networks, such as those at hotels, conference centers, and other shared venues, in May, likely through access to shared services within the captive portal ecosystem.
As part of CaptiveCrunch, the attackers have been serving Golang-based Windows remote access trojans (RATs) in the form of browser updates. The malware enabled reconnaissance, credential and session token theft, file and keystroke collection, audio and video surveillance, and remote shell access.
The threat actor has been using various ClickFix techniques to convince users to download malware and appears to have been targeting Android users with similar methods to entice them into fetching and installing an APK file.
“To date, Microsoft has identified widespread compromise of Wi-Fi networks at hospitality-related organizations and other networks serviced by captive portal equipment in several countries,” the company notes.
Storm-2945 targeted Windows users with the CornFlake RAT and infostealer implant and the ChocoShell PowerShell-based infostealer, and managed its infrastructure and agents via the FruitStone web-based command-and-control (C&C) panel.
Over the past two weeks, Microsoft says, some CaptiveCrunch landing pages have been directing victims to device code authentication flow experiences, instructing them to enter device codes into Microsoft sign-in pages to authenticate the threat actor’s session.
“This activity is consistent with previously reported device code phishing operations conducted by Midnight Blizzard since August 2024. The observed technique does not appear fundamentally novel; however, integrating device code phishing into captive portal and traffic manipulation operations might increase the likelihood that users perceive the authentication request as legitimate,” Microsoft notes.
Related: US Charges Russian Individuals and Firms for Running Cybercrime Services
Related: US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers