Nation-StateMicrosoft Security Blog·3 weeks ago
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been targeting hospitality sign-in portals since May 2026 to deliver malware to travelers and harvest credentials in an operation dubbed CaptiveCrunch. By compromising hotel authentication systems, the threat actor gains access to a high-volume channel for distributing malware and stealing login credentials from a geographically diverse victim pool.