Briefing financecommunications
CaptiveCrunch: Midnight Blizzard Targets Corporate Travellers via Hotel Wi-Fi
Russian threat actor Storm-2945, linked to Midnight Blizzard, has been compromising hotel and conference Wi-Fi captive portals since May 2026 to harvest Microsoft 365 credentials from corporate travellers using custom malware families CornFlake and ChocoShell.