← Threat Actors & APT Groups

Midnight Blizzard

Every article that identifies Midnight Blizzard as responsible for or connected to reported activity.

Nation-StateMicrosoft Security Blog·3 weeks ago

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been targeting hospitality sign-in portals since May 2026 to deliver malware to travelers and harvest credentials in an operation dubbed CaptiveCrunch. By compromising hotel authentication systems, the threat actor gains access to a high-volume channel for distributing malware and stealing login credentials from a geographically diverse victim pool.