Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
Storm-2945, a subgroup of Russian state-sponsored Midnight Blizzard (APT29), is behind "CaptiveCrunch," a credential theft campaign targeting public Wi-Fi captive portal networks Attackers compromised SOHO routers to manipulate DNS and HTTP traffic, redirecting users to attacker-controlled infrastructure for adversary-in-the-middle (AitM) attacks against Microsoft 365 credentials Malware delivery included Golang-based Windows RATs disguised as browser updates, ClickFix social engineering, and An
Analysis
TL;DR
- Storm-2945, a subgroup of Russian state-sponsored Midnight Blizzard (APT29), is behind "CaptiveCrunch," a credential theft campaign targeting public Wi-Fi captive portal networks
- Attackers compromised SOHO routers to manipulate DNS and HTTP traffic, redirecting users to attacker-controlled infrastructure for adversary-in-the-middle (AitM) attacks against Microsoft 365 credentials
- Malware delivery included Golang-based Windows RATs disguised as browser updates, ClickFix social engineering, and Android APKs, managed via the FruitStone C2 panel
- The campaign recently incorporated device code phishing flows, increasing the legitimacy perception of authentication prompts within captive portal environments
- Targeted sectors include financial services, legal, healthcare, energy, retail, and hospitality organizations across multiple countries since May
Why It Matters
This campaign demonstrates how state-sponsored actors are increasingly targeting the physical-digital intersection by compromising shared infrastructure like hotel and conference center Wi-Fi to conduct large-scale credential harvesting. The integration of device code phishing with captive portal traffic manipulation represents an evolution in AitM tactics that exploits the trust users place in official-looking Microsoft authentication flows while traveling.
Technical Details
- Infrastructure Compromise: Attackers gained access to shared services within the captive portal ecosystem, modifying DNS configurations of SOHO routers to redirect traffic to attacker-controlled infrastructure
- Malware Arsenal: Deployed CornFlake RAT and infostealer implant, ChocoShell PowerShell-based infostealer, and Golang-based Windows RATs served as fake browser updates; Android users were targeted with malicious APKs
- Social Engineering: Utilized ClickFix techniques to trick users into downloading malware and recently integrated device code authentication flow phishing, directing victims to enter codes on Microsoft sign-in pages
- Command and Control: Managed all infrastructure and agents through FruitStone, a web-based C2 panel, enabling reconnaissance, credential/session token theft, file and keystroke collection, audio/video surveillance, and remote shell access
- Target Profile: Primarily Microsoft 365 credentials of traveling employees across financial services, professional services, legal, healthcare, energy, and retail sectors in hospitality and conference venues
Industry Insight
- Organizations relying on captive portal Wi-Fi should implement network segmentation, monitor DNS and HTTP traffic anomalies, and enforce conditional access policies that detect device code phishing patterns
- Security awareness programs must educate traveling employees about the risks of public Wi-Fi authentication flows and the importance of verifying Microsoft sign-in requests through out-of-band channels
- The convergence of device code phishing with infrastructure-level traffic manipulation suggests APT groups are refining multi-layered attack chains; defenders should prioritize monitoring for coordinated DNS redirection alongside authentication anomalies
Disclaimer: The above content is generated by AI and is for reference only.