Select a theme from the list.
Insights

From our experts

Latest
CaptiveCrunch Turns Hotel Networks Into Identity and Malware Delivery ChannelsDeparted Employee Access Magnifies the Fallout From the TanStack Supply Chain AttackBragJack Turns Malicious Browser Extensions Into AI Agent ControllersWindows 11 Tests Remote Cloud Rebuild for Faster Enterprise RecoveryPublic Linux Root Exploits Put Unpatched Servers on a Short ClockGyazo Breach Turns Screenshot Metadata Into a Privacy CrisisMicrosoft's Email Benchmark Shows Why Inbox Defense Cannot Stop at DeliveryMalicious DNS Zones Can Turn Unbound Resolvers Into Code-Execution TargetsRatHat Gives Android Malware an AI-Powered Pair of HandsMITRE ATT&CK Splits Hiding From Blinding in Major Defensive Model ChangeParaShells Flaw Leaves Intel Mac Users Without a Confirmed Parallels FixWindows 11 Security Update Knocks Some Enterprise PCs Off Their DomainsCaptiveCrunch Turns Hotel Networks Into Identity and Malware Delivery ChannelsDeparted Employee Access Magnifies the Fallout From the TanStack Supply Chain AttackBragJack Turns Malicious Browser Extensions Into AI Agent ControllersWindows 11 Tests Remote Cloud Rebuild for Faster Enterprise RecoveryPublic Linux Root Exploits Put Unpatched Servers on a Short ClockGyazo Breach Turns Screenshot Metadata Into a Privacy CrisisMicrosoft's Email Benchmark Shows Why Inbox Defense Cannot Stop at DeliveryMalicious DNS Zones Can Turn Unbound Resolvers Into Code-Execution TargetsRatHat Gives Android Malware an AI-Powered Pair of HandsMITRE ATT&CK Splits Hiding From Blinding in Major Defensive Model ChangeParaShells Flaw Leaves Intel Mac Users Without a Confirmed Parallels FixWindows 11 Security Update Knocks Some Enterprise PCs Off Their Domains
Security Insight

CaptiveCrunch Turns Hotel Networks Into Identity and Malware Delivery Channels

CaptiveCrunch Turns Hotel Networks Into Identity and Malware Delivery Channels
Photo by Miguel Á. Padriñán on Pexels

Microsoft has described a campaign in which a Midnight Blizzard subcluster manipulated DNS and HTTP traffic across hospitality networks. Known as CaptiveCrunch, the operation redirected travelers toward either device-code phishing through a legitimate Microsoft sign-in process or fraudulent software updates carrying malware. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/09/17/from-guidance-to-action-security-fundamentals-that-materially-reduce-risk/))

Hospitality networks are attractive espionage targets because they sit between travelers and the services those travelers trust. Microsoft Threat Intelligence has now detailed CaptiveCrunch, a campaign associated with Storm-2945, a subcluster of the Russia-linked group commonly known as Midnight Blizzard.

The operation manipulated DNS and HTTP traffic across hospitality environments, allowing a normal network interaction to become the opening stage of an identity or endpoint attack. Travelers could be redirected toward device-code phishing involving a legitimate Microsoft sign-in page or toward counterfeit update prompts designed to install malware. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/09/17/from-guidance-to-action-security-fundamentals-that-materially-reduce-risk/))

One Redirection, Two Compromise Paths

The device-code route is dangerous because the authentication page itself can be genuine. The deception occurs when the attacker persuades the victim to authorize a code created for the attacker's session. If successful, the criminal may gain cloud access without constructing a visibly fake password page.

The second route targets the device. A fraudulent update can install malware capable of gathering credentials, session tokens, security configuration details and remote-access history. This dual approach gives operators flexibility: they can pursue the user's cloud identity, the endpoint or both, depending on which route succeeds.

Reducing Exposure

  • Disable device-code authentication where business requirements do not justify it.
  • Apply Conditional Access rules based on device compliance and sign-in risk.
  • Use phishing-resistant authentication methods for sensitive accounts.
  • Instruct travelers to obtain updates directly from operating system or vendor tools.
  • Treat unexpected captive portal downloads as suspicious.
  • Use encrypted DNS and trusted mobile connectivity for high-risk travel.

In my view, CaptiveCrunch is a reminder that organizations do not control every network used by their employees. Security architecture must therefore assume that local DNS, captive portals and network traffic can be hostile. A valid certificate or authentic Microsoft page is not sufficient evidence that the surrounding authentication request is legitimate.

Enterprises with frequently traveling employees should combine technical restrictions with focused travel guidance. The goal is not to make users diagnose network attacks, but to limit which authentication flows and software installations are possible when they are connected through infrastructure the organization does not manage.

Talk to our team →

Latest

CaptiveCrunch Turns Hotel Networks Into Identity and Malware Delivery ChannelsSep 20, 2026Departed Employee Access Magnifies the Fallout From the TanStack Supply Chain AttackSep 20, 2026BragJack Turns Malicious Browser Extensions Into AI Agent ControllersSep 20, 2026Windows 11 Tests Remote Cloud Rebuild for Faster Enterprise RecoverySep 19, 2026Public Linux Root Exploits Put Unpatched Servers on a Short ClockSep 19, 2026Gyazo Breach Turns Screenshot Metadata Into a Privacy CrisisSep 19, 2026

Most read

1Microsoft Redraws the Security Boundary for Edge AI2French Hospital Fine Turns Weak Identity Controls Into a GDPR Warning3Ted Implant Turns Compromised HAProxy Servers Into Invisible Interception Points4IDScan Lawsuits Put Mass Identity Collection Under the Microscope5Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server Memory6BigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session Hijacking