AI Security AI安全 19h ago Updated 15h ago 更新于 15小时前 41

Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking 俄罗斯国家APT组织与近期公共Wi-Fi网关入侵事件相关

Storm-2945, a subgroup of Russian state-sponsored Midnight Blizzard (APT29), is behind "CaptiveCrunch," a credential theft campaign targeting public Wi-Fi captive portal networks Attackers compromised SOHO routers to manipulate DNS and HTTP traffic, redirecting users to attacker-controlled infrastructure for adversary-in-the-middle (AitM) attacks against Microsoft 365 credentials Malware delivery included Golang-based Windows RATs disguised as browser updates, ClickFix social engineering, and An 俄罗斯国家赞助的APT组织Storm-2945(Midnight Blizzard子组)通过劫持公共Wi-Fi网关设备发起名为CaptiveCrunch的凭据窃取活动 攻击者利用中间人(AitM)技术拦截Microsoft 365凭据,目标涵盖金融、法律、医疗、能源和零售等行业差旅员工 攻击者使用Golang编写的RAT恶意软件伪装成浏览器更新,结合ClickFix社会工程学和设备代码钓鱼技术诱导用户 攻击活动自5月起通过酒店、会议中心等captive portal网络实施,使用FruitStone C2面板管理基础设施

65
Hot 热度
55
Quality 质量
52
Impact 影响力

Analysis 深度分析

TL;DR

  • Storm-2945, a subgroup of Russian state-sponsored Midnight Blizzard (APT29), is behind "CaptiveCrunch," a credential theft campaign targeting public Wi-Fi captive portal networks
  • Attackers compromised SOHO routers to manipulate DNS and HTTP traffic, redirecting users to attacker-controlled infrastructure for adversary-in-the-middle (AitM) attacks against Microsoft 365 credentials
  • Malware delivery included Golang-based Windows RATs disguised as browser updates, ClickFix social engineering, and Android APKs, managed via the FruitStone C2 panel
  • The campaign recently incorporated device code phishing flows, increasing the legitimacy perception of authentication prompts within captive portal environments
  • Targeted sectors include financial services, legal, healthcare, energy, retail, and hospitality organizations across multiple countries since May

Why It Matters

This campaign demonstrates how state-sponsored actors are increasingly targeting the physical-digital intersection by compromising shared infrastructure like hotel and conference center Wi-Fi to conduct large-scale credential harvesting. The integration of device code phishing with captive portal traffic manipulation represents an evolution in AitM tactics that exploits the trust users place in official-looking Microsoft authentication flows while traveling.

Technical Details

  • Infrastructure Compromise: Attackers gained access to shared services within the captive portal ecosystem, modifying DNS configurations of SOHO routers to redirect traffic to attacker-controlled infrastructure
  • Malware Arsenal: Deployed CornFlake RAT and infostealer implant, ChocoShell PowerShell-based infostealer, and Golang-based Windows RATs served as fake browser updates; Android users were targeted with malicious APKs
  • Social Engineering: Utilized ClickFix techniques to trick users into downloading malware and recently integrated device code authentication flow phishing, directing victims to enter codes on Microsoft sign-in pages
  • Command and Control: Managed all infrastructure and agents through FruitStone, a web-based C2 panel, enabling reconnaissance, credential/session token theft, file and keystroke collection, audio/video surveillance, and remote shell access
  • Target Profile: Primarily Microsoft 365 credentials of traveling employees across financial services, professional services, legal, healthcare, energy, and retail sectors in hospitality and conference venues

Industry Insight

  • Organizations relying on captive portal Wi-Fi should implement network segmentation, monitor DNS and HTTP traffic anomalies, and enforce conditional access policies that detect device code phishing patterns
  • Security awareness programs must educate traveling employees about the risks of public Wi-Fi authentication flows and the importance of verifying Microsoft sign-in requests through out-of-band channels
  • The convergence of device code phishing with infrastructure-level traffic manipulation suggests APT groups are refining multi-layered attack chains; defenders should prioritize monitoring for coordinated DNS redirection alongside authentication anomalies

TL;DR

  • 俄罗斯国家赞助的APT组织Storm-2945(Midnight Blizzard子组)通过劫持公共Wi-Fi网关设备发起名为CaptiveCrunch的凭据窃取活动
  • 攻击者利用中间人(AitM)技术拦截Microsoft 365凭据,目标涵盖金融、法律、医疗、能源和零售等行业差旅员工
  • 攻击者使用Golang编写的RAT恶意软件伪装成浏览器更新,结合ClickFix社会工程学和设备代码钓鱼技术诱导用户
  • 攻击活动自5月起通过酒店、会议中心等captive portal网络实施,使用FruitStone C2面板管理基础设施

为什么值得看

本文揭示了国家级APT组织如何将公共Wi-Fi基础设施作为攻击入口,展示了现代网络间谍活动的技术演进。对于企业安全团队和IT管理者而言,这提供了关于差旅员工保护和captive portal安全的重要警示。

技术解析

  • 攻击者通过修改SOHO路由器的DNS配置,将用户流量重定向至攻击者控制的基础设施,实现中间人攻击
  • 恶意软件采用Golang编写的Windows RAT(CornFlake),伪装成浏览器更新分发,具备侦察、凭据/会话令牌窃取、文件收集、键盘记录、音视频监控和远程shell访问能力
  • 攻击者使用ClickFix技术诱导用户执行恶意操作,针对Android用户则诱导安装APK文件
  • 部分攻击页面引导受害者进入设备代码认证流程,要求输入设备代码以认证攻击者会话,与Midnight Blizzard自2024年8月以来的设备代码钓鱼活动一致
  • 攻击者通过FruitStone Web-based C2面板管理基础设施和代理,使用ChocoShell PowerShell infostealer作为辅助工具

行业启示

  • 企业应加强对差旅员工的安全培训,特别是关于公共Wi-Fi使用风险和设备代码认证的识别
  • 组织需审查captive portal网络供应商的安全实践,确保网关设备固件和配置的安全性
  • 实施零信任架构和多因素认证,降低凭据窃取后的横向移动风险

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究