Hospitality networks are attractive espionage targets because they sit between travelers and the services those travelers trust. Microsoft Threat Intelligence has now detailed CaptiveCrunch, a campaign associated with Storm-2945, a subcluster of the Russia-linked group commonly known as Midnight Blizzard.
The operation manipulated DNS and HTTP traffic across hospitality environments, allowing a normal network interaction to become the opening stage of an identity or endpoint attack. Travelers could be redirected toward device-code phishing involving a legitimate Microsoft sign-in page or toward counterfeit update prompts designed to install malware. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/09/17/from-guidance-to-action-security-fundamentals-that-materially-reduce-risk/))
One Redirection, Two Compromise Paths
The device-code route is dangerous because the authentication page itself can be genuine. The deception occurs when the attacker persuades the victim to authorize a code created for the attacker's session. If successful, the criminal may gain cloud access without constructing a visibly fake password page.
The second route targets the device. A fraudulent update can install malware capable of gathering credentials, session tokens, security configuration details and remote-access history. This dual approach gives operators flexibility: they can pursue the user's cloud identity, the endpoint or both, depending on which route succeeds.
Reducing Exposure
- Disable device-code authentication where business requirements do not justify it.
- Apply Conditional Access rules based on device compliance and sign-in risk.
- Use phishing-resistant authentication methods for sensitive accounts.
- Instruct travelers to obtain updates directly from operating system or vendor tools.
- Treat unexpected captive portal downloads as suspicious.
- Use encrypted DNS and trusted mobile connectivity for high-risk travel.
In my view, CaptiveCrunch is a reminder that organizations do not control every network used by their employees. Security architecture must therefore assume that local DNS, captive portals and network traffic can be hostile. A valid certificate or authentic Microsoft page is not sufficient evidence that the surrounding authentication request is legitimate.
Enterprises with frequently traveling employees should combine technical restrictions with focused travel guidance. The goal is not to make users diagnose network attacks, but to limit which authentication flows and software installations are possible when they are connected through infrastructure the organization does not manage.
