Microsoft dropped a formal warning Friday telling business travelers to assume hotel, conference, and airport Wi-Fi networks 'might not be trustworthy' — language that is notably blunter than the usual security boilerplate.
The reason is CaptiveCrunch, a global campaign Microsoft attributes to Storm-2945, a sub-cluster of Russia's Midnight Blizzard threat group. According to Microsoft, the campaign has been active since early May, targeting corporate travelers through compromised hospitality networks and captive portals worldwide.
Here's the thing. The attack does not require a phishing email or a compromised laptop to get started. Attackers manipulate network traffic at the gateway level, redirecting guests to fake sign-in pages that look indistinguishable from the hotel's own portal. A July report from ReliaQuest had already flagged a similar pattern targeting Microsoft 365 users through hijacked Wi-Fi gateways.
Some victims are funneled into Microsoft's legitimate device-code authentication flow. The attacker initiates a sign-in, hands the victim an attacker-supplied code, and if the victim approves, Microsoft issues valid authentication tokens — no stolen password required, no MFA bypass needed. The system works exactly as designed; the deception is entirely upstream.
Beyond credential theft, Microsoft says CaptiveCrunch can deliver malware directly to devices. The named payload is CornFlake, a Windows remote-access trojan built to steal credentials and session tokens, log keystrokes, collect files, capture screenshots, and hijack a device's audio and video for surveillance. It also provides attackers with persistent access. Fake Windows update prompts are among the delivery mechanisms.
Microsoft also flagged indications that Android devices may be in scope, with ClickFix-style landing pages including instructions to download and install an APK file.
In an unusual acknowledgment, Microsoft Threat Intelligence credited Anthropic and OpenAI for 'collaboration and support during this investigation,' adding that Storm-2945 used AI to support the campaign itself. The adversary is apparently running the same playbook as the defenders.
Microsoft's recommended mitigations: use a mobile hotspot or cellular connection instead of guest Wi-Fi, never install updates through a captive portal, enforce phishing-resistant authentication, strengthen Conditional Access policies, and block device-code authentication flows when they are not explicitly required.
Voltage take: CaptiveCrunch is a clean demonstration of why perimeter-level trust assumptions are a liability. The attack surface here is not a misconfigured endpoint or a weak password — it is the gap between a user's reasonable expectation that a hotel portal is what it claims to be and the reality that the underlying network infrastructure has no authentication of its own. Microsoft's advice to treat guest networks as hostile is correct, but it is also advice that most enterprise security teams have been ignoring for years because the friction is inconvenient. CornFlake does not care about convenience. The changelog on this one is worth reading before your next flight.



