Skip to content
Beveiligingsnieuws

CaptiveCrunch: how Russian APT Wi‑Fi gateway hacks work

Impliciet vertrouwen

A recent credential theft campaign has been linked to a Russian state-sponsored APT, and Microsoft says its latest activity is being run through compromised public Wi‑Fi gateway appliances. The operation, tracked as CaptiveCrunch Wi‑Fi gateway, targets organizations that use captive portal networks—common at hotels, conference centers, and other shared venues where users are asked to “sign in” before accessing the internet.

In practical terms, the attackers manipulate how users are redirected after connecting to Wi‑Fi, then use an interception approach to capture Microsoft 365 credentials and sessions. Below is what Microsoft and earlier observers reported about how the campaign works, who it targets, and why it matters for travelers and customer-facing environments.

Why captive portals became an attack path

Captive portals are designed to control access by routing users through a login or consent page before giving them internet connectivity. When the gateway equipment behind those networks is compromised, the flow can be altered. Microsoft reports that the campaign involves manipulating traffic coming from captive portal environments and using that access to reach victims who are “traveling employees” within targeted organizations.

Earlier reporting also pointed to a related pattern: hackers modified DNS settings on compromised small office/home office (SOHO) routers to redirect users toward infrastructure controlled by the attackers. Microsoft’s update shifts the focus toward a dedicated captive portal gateway intrusion path, but the underlying theme is the same—subtle redirection that leads users to attacker-prepared destinations.

DNS and HTTP manipulation at the gateway

According to Microsoft, CaptiveCrunch Wi‑Fi gateway began in May with the manipulation of DNS and HTTP traffic from captive portal networks. The company suggests this may have been enabled through access to shared services within the captive portal ecosystem, implying that the attackers did not need to compromise every individual venue manually.

By altering DNS responses and shaping HTTP flows, attackers can influence which sites or pages users see when they connect and attempt authentication. Microsoft describes the technique as part of the campaign’s broader attempt to steer victims into a compromised interaction instead of a normal sign-in.

AitM interception of Microsoft 365 credentials

ReliaQuest flagged the campaign about a week before Microsoft’s attribution, noting that the attackers were using an adversary-in-the-middle (AitM) technique. This approach allows an attacker to observe, modify, or relay communications between a victim and a legitimate service.

In this case, the goal was to intercept Microsoft 365 credentials for employees traveling through targeted sectors. Microsoft links victims across multiple industries, including financial services, professional services, legal services, healthcare, energy, and retail.

The combination of gateway manipulation plus AitM interception is important: even if the user reaches an authentication page that looks plausible, the attacker may still capture the submitted credentials and leverage them to gain access.

Golang-based RATs delivered via “browser updates”

As part of CaptiveCrunch Wi‑Fi gateway, Microsoft reports that attackers served Windows remote access trojans (RATs) built with Golang. The payload was presented to victims in the form of browser updates—an attempt to make the download behavior feel routine.

Once installed, the malware supported multiple malicious capabilities, including reconnaissance, credential theft, session token theft, file and keystroke collection, and audio/video surveillance. Microsoft also describes remote shell access, giving the threat operator further control over compromised systems.

In addition to Windows targeting, Microsoft says the attackers appeared to go after Android users as well. The approach involved ClickFix-style techniques to persuade users to download and install an APK file.

Targets and malware families associated with the campaign

Microsoft names specific components used by Storm-2945, the subgroup it attributes to this fresh activity. For Windows users, the company points to the CornFlake RAT and an infostealer implant, along with the ChocoShell PowerShell-based infostealer.

For command and control, Microsoft describes a web-based panel called FruitStone. This type of infrastructure supports coordination of infected hosts and delivery of subsequent instructions.

Microsoft also notes that the campaign bears similarities to FrostArmada, an espionage operation associated with Russia-linked APT28 (also tracked as Forest Blizzard and Fancy Bear). However, Microsoft stopped short of making a clear attribution at that earlier stage.

Midnight Blizzard and Storm-2945 attribution

Microsoft’s attribution centers on Storm-2945, described as a subgroup of Midnight Blizzard. The same actor has multiple tracking names, including APT29, Cozy Bear, the Dukes, and Yttrium.

Microsoft assesses that Storm-2945 is likely sponsored by the Russian Foreign Intelligence Service (SVR). It also characterizes Midnight Blizzard as a group known for targeting government and diplomatic entities, non-governmental organizations (NGOs), and IT services providers in the US and Europe for intelligence collection tied to Russian foreign policy interests.

Importantly, Microsoft highlights that Midnight Blizzard operations often include compromising legitimate accounts, and in highly targeted scenarios, attempting to compromise authentication mechanisms within an organization to expand access and avoid detection.

Device code phishing blended into captive portal flows

One of the more concerning aspects of the update is the integration of device-code authentication activity into the captive portal context. Over the past two weeks, Microsoft reports that some CaptiveCrunch Wi‑Fi gateway landing pages directed victims to experiences aligned with device code authentication flows.

The reported behavior involved instructing victims to enter device codes into Microsoft sign-in pages to authenticate the attacker’s session. Microsoft notes that this aligns with previously reported device code phishing operations associated with Midnight Blizzard since August 2024.

While Microsoft says the technique itself does not appear fundamentally new, it believes combining device code phishing with gateway/traffic manipulation can make the authentication request feel more legitimate to users.

What organizations can take away

Microsoft reports widespread compromise of Wi‑Fi networks at hospitality-related organizations and other networks serviced by captive portal equipment in several countries. That means the exposure is not limited to a single enterprise network; it can affect travelers and organizations that rely on third-party or venue-provided connectivity.

From a defense perspective, the key lesson is to treat captive portal authentication and Wi‑Fi redirection as part of the threat surface. In practical terms, organizations may want to review how traveling employees sign in when outside the corporate network, and how security teams detect unusual sign-in patterns that could indicate interception.

Even when the portal environment is meant to be simple and user-friendly, the underlying infrastructure can be manipulated, and attackers can follow up with malware and account abuse.

Bottom line

The CaptiveCrunch Wi‑Fi gateway campaign illustrates how attackers can chain together compromised gateway appliances, DNS/HTTP manipulation, and adversary-in-the-middle interception to target Microsoft 365 credentials. Microsoft also reports malware delivery via “browser updates,” infostealers and RATs for Windows, Android lure attempts via APK delivery, and command-and-control through a dedicated web panel.

For organizations with employees who travel—or that rely on captive portal networks at partner venues—this is a reminder that internet access at “public” locations can be part of an active intrusion workflow. The most effective response is to combine user awareness with monitoring for suspicious authentication and session behavior.

Source: https://www.securityweek.com/russian-state-apt-linked-to-recent-public-wi-fi-gateway-hacking/