← Threat Actors & APT Groups

Storm-2945

Every article that identifies Storm-2945 as responsible for or connected to reported activity.

Nation-StateInfosecurity Magazine·2 weeks ago

Midnight Blizzard Targets Travelers via Captive Portals

Russian-nexus threat actor Storm-2945, operating under the Midnight Blizzard banner, has been hijacking hotel captive portals to distribute fake software updates and harvest authentication tokens from travelers. The campaign leverages the trust users place in hotel network login systems to deliver malicious payloads in a hospitality-focused targeting strategy.