A widespread adversary campaign targeting traveling corporate users has been uncovered, abusing compromised hotel Wi-Fi captive portals to deploy surveillance trojans and identity stealers. The threat actors manipulate gateway DNS settings to force browser update prompts that drop persistent implants.
The operation, designated CaptiveCrunch and linked to Midnight Blizzard sub-cluster Storm-2945, compromises captive portal gateways that act as primary DNS resolvers for connected clients. Armed with administrative gateway control, attackers forge DNS responses to intercept automated device connectivity checks, serving fake browser updates. Victims executing the fake installers download CornFlake, a Go-based RAT that steals browser credentials, captures audio and webcam feeds, and opens remote shells. Concurrently, the attackers deploy ChocoShell, an in-memory PowerShell stealer designed to extract Microsoft 365 and Azure Active Directory access tokens directly from the Windows Token Broker cache.
Compromising network transit DNS resolvers bypasses standard endpoint perimeter filters. Stealing active Web Account Manager tokens allows threat actors to execute session replay attacks into corporate cloud environments, completely bypassing multi-factor authentication requirements without prompting secondary verification alerts.
– Instruct remote employees to connect strictly through encrypted zero trust VPN tunnels when using public or hospitality Wi-Fi.
– Enforce strict endpoint protection policies that block unverified utility executions initiated from browser temporary directories.
– Monitor cloud identity access logs for anomalous user session authentications originating from unexpected geographic IP ranges.
– Transition authentication configurations to enforce hardware-bound conditional access controls for corporate cloud applications.
Remote connectivity safety relies on mandatory transport encryption combined with hardware-bound identity validation to ensure public wireless gateways cannot function as automated credential theft vectors. #CodeDefence #Microsoft #CaptiveCrunch #Storm2945 #DNSHijacking #TokenStealing #IdentitySecurity #EndpointSecurity
/
